Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

RoPA international transfers entry listing country recipient and safeguard

RoPA International Transfers: Recording Them Right 2026

RoPA international transfers are one of the details regulators check first when they ask to see a record of processing. Article 30 requires the record to say whether personal data is transferred outside the European Economic Area and how that transfer is protected. Many records simply tick a box or write “yes, safeguards in place”, which does not help the reader and hides transfers that nobody assessed.

This guide explains what Article 30 requires for transfers, how to record each part of the entry, which transfer tools to name and how to link the record to your transfer assessments.

What Article 30 requires for transfers

Article 30(1)(e) of the GDPR requires the controller’s record to include, where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards. Article 30(2)(c) sets a similar requirement for processors. You can read the article on the GDPR text site.

The key points are identification and safeguards. A record that says “transfers to the US” for a group of twenty suppliers does not identify much. A useful record names the country, the recipient and the mechanism that makes the transfer lawful. Our guide to international data transfers explains the framework behind the mechanisms.

What to record for each transfer in the RoPA

FieldWhat to writeExample
CountryEach destination, including remote access from a third countryIndia (support team access)
RecipientName of the importer and roleExample Support Ltd, processor
Data and purposeCategories transferred and whyCustomer contact data for ticket handling
Transfer toolLegal mechanism relied onStandard contractual clauses, module 2
AssessmentReference to the transfer impact assessmentTIA-2026-014, reviewed March
Supplementary measuresAny technical or organisational measuresPseudonymisation before transfer
Review dateWhen the entry is next checkedAnnually or on change of law

Free transfer impact assessment

Can this transfer of personal data go ahead?

Check whether the transfer needs a TIA, map it, assess the laws and practice of the destination, rate the risks from 27 transfer scenarios and choose supplementary measures. Covers the EU SCCs and the UK IDTA and Addendum, free.

Start the free TIA →  or  View premium report sample

Counting remote access as a transfer

A transfer is not only the physical movement of a file. Remote access from a third country to data stored in the EEA can be a transfer, for example a support engineer outside the EEA viewing customer records. Include such access in the RoPA, name the country and record the mechanism. It is a frequent omission because the data never leaves the servers.

Consider onward transfers too. If a processor in a third country uses sub-processors elsewhere, those sub-processors and their countries should be traceable through the processor contract, and the chain should be captured in your records or referenced from them.

Naming the transfer tool

The record should say which mechanism you rely on. The main options are as follows.

  • Adequacy decision. The European Commission has decided that the country, territory or sector ensures an adequate level of protection. Name the decision and its scope. Some are limited, such as frameworks that only cover certified companies; our note on the Data Privacy Framework explains that case.
  • Standard contractual clauses. Record which module applies (controller to controller, controller to processor and so on) and the date signed.
  • Binding corporate rules. For intra-group transfers, record the approved rules and their scope.
  • Other appropriate safeguards. Approved codes of conduct or certification mechanisms, with binding commitments from the importer.
  • Derogations. Article 49 allows limited exceptions, such as explicit consent or necessity for a contract. They are for specific situations and are not a routine basis. Record the derogation and the reason it applies.

Linking RoPA international transfers to impact assessments

Where you rely on standard contractual clauses or similar tools, you need to assess whether the laws and practice of the destination undermine them. The RoPA should point to that assessment. Our guides to the transfer impact assessment of third country laws and to supplementary measures explain the work. A record with the tool named but no assessment reference will invite the question of whether the assessment exists.

UK and other regimes

If you are subject to the UK GDPR or another national regime with its own transfer rules, the mechanisms differ. The UK, for example, has its own international data transfer agreement and addendum. Record which regime each transfer falls under, so that the correct tool is named. Multinational organisations should note transfers out of every relevant jurisdiction, not only from the EEA. Our post on the UK IDTA and addendum covers the UK tools.

A hypothetical example of RoPA international transfers

The following is a hypothetical example invented for illustration. A European retailer reviews its RoPA and finds one line for “cloud and support vendors: transfers to third countries, safeguards in place”. The privacy lead splits it into six entries. The email platform is hosted in the EEA but its US parent has support access, so the entry names the US, cites the provider’s certification under an adequacy framework and records that the provider is certified. The customer service tool uses staff in two Asian countries; the entry names both, the standard clauses module and the assessment reference.

The payroll provider transfers HR data to a single third country under binding corporate rules. The lead records the rules and the approval. Two of the vendors, it turns out, have no transfer tool in place. The lead opens contract amendments and puts a temporary restriction on access. The RoPA now shows exactly where data goes and why each transfer is lawful, and the gaps have owners and dates.

Keeping RoPA international transfers up to date

Transfers change when suppliers change hosting, add sub-processors, open support centres or move staff. Add a transfer question to your procurement and change processes, and require suppliers to notify you of new locations. Review adequacy status and transfer tools when the law changes, such as when a decision is adopted, amended or challenged. Re-check assessments at their review dates. Where an assessment or tool fails, update the record and take action on the transfer itself.

Who maintains RoPA international transfers

Procurement and IT usually know where suppliers are and where data flows, while legal and privacy know which mechanisms apply. Bring them together: procurement flags every new supplier and location, IT confirms hosting and access paths, and privacy maintains the entries for RoPA international transfers and the linked assessments. Name a single owner for the transfer register, and give them a routine way to receive updates, such as a required field in the supplier onboarding form.

A quick check before every new supplier

Ask five questions before signing: where is the data stored, who can access it from where, which sub-processors are used and where are they, which transfer tool will apply, and has an assessment been done. If any answer is unknown, resolve it before the contract goes live. A few minutes at this point saves a scramble when the regulator asks for the RoPA international transfers entry.

Common mistakes with RoPA international transfers

Frequent problems include listing “third countries” without naming them, omitting remote access, naming no tool, citing an adequacy decision that does not cover the recipient, relying on derogations as a routine, forgetting sub-processors, no assessment reference, stale entries after a supplier change and different answers in the privacy notice. Another is treating group companies as exempt: intra-group transfers to third countries need a mechanism too.

Consistency with the privacy notice

Individuals must be told about transfers, including the safeguards and how to get a copy of them. The notice and the RoPA should be consistent. Check them together at each review, and make sure that when a new country appears in the record, the notice is updated. A mismatch is easy for a regulator to find, and it suggests that the record is not driving actual practice.

Templates for RoPA international transfers

A structured layout with dedicated transfer columns reduces omissions. The RoPA Report and Workbook provides an Article 30 record with fields for recipients, countries and safeguards. Whichever layout you use, keep the same fields for each activity so transfers can be filtered and reviewed in one view.

Remember to store the supporting documents alongside the record: signed clauses, adequacy references, assessments and supplier notifications. When a regulator asks for a transfer entry, being able to produce the supporting file at once shows control.

RoPA international transfers FAQ

Do we have to name each country in the RoPA?

Article 30 requires the third country or international organisation to be identified. Naming each country makes the record useful and is the safest reading of the requirement.

Does remote access from outside the EEA count?

It can. Access from a third country to data stored in the EEA may be a transfer, so include it in the record and identify the mechanism you rely on.

Which safeguards must be documented?

The record must identify the transfer. For derogations under the second subparagraph of Article 49(1), the suitable safeguards must be documented. In practice, record the tool for every transfer.

Do processors record transfers too?

Yes. Article 30(2) requires processors to record transfers of personal data made on behalf of a controller, including the identification of the third country and, in the same limited cases, the safeguards.

How often should transfer entries be reviewed?

At each scheduled RoPA review and whenever a supplier, location, law or transfer tool changes.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.