Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Supplementary measures for data transfers: technical, contractual and organisational measures after a transfer impact assessment

Supplementary Measures for Data Transfers: The Essential 2026 Guide to the EDPB Six Steps

Supplementary measures for data transfers are the extra protections you add when a transfer tool such as standard contractual clauses cannot, on its own, give personal data essentially the same protection it has in Europe. They became a mainstream compliance topic after the Schrems II ruling, and they remain the hardest part of a transfer assessment, because the law of the destination country is outside your control.

This guide walks through the six-step roadmap in the European Data Protection Board’s recommendations, explains the three types of measure, shows which technical measures tend to work and which do not, and covers how to document the decision so you can defend it.

When supplementary measures for data transfers are needed

Chapter V of the GDPR restricts transfers of personal data to countries without an adequacy decision. Article 46 allows a transfer if you provide appropriate safeguards and ensure that data subjects have enforceable rights and effective legal remedies. The common safeguards are standard data protection clauses adopted by the Commission and binding corporate rules, and you can read the provision in the text of GDPR Article 46.

The difficulty is that a contract between exporter and importer cannot bind a foreign government. If the destination country has laws that let public authorities access the data in ways that go beyond what is necessary and proportionate, the safeguard on paper may not hold in practice. That is when you assess whether supplementary measures for data transfers can close the gap. If no combination of measures can, the transfer should not go ahead.

Adequacy decisions work differently, because they make Article 46 tools unnecessary for the covered transfers. For the US, see our guide to the Data Privacy Framework and transfer impact assessments, and check the current status of the framework before relying on it.

The EDPB six-step roadmap

The EDPB published its Recommendations 01/2020 on measures that supplement transfer tools, with the final version following in June 2021 after public consultation. The recommendations set out a six-step process, which a law firm summary on the final recommendations describes clearly.

  1. Know your transfers. Map every transfer of personal data outside the European Economic Area, including remote access and onward transfers.
  2. Identify the transfer tool. Decide whether each transfer relies on adequacy, standard clauses, binding corporate rules or another mechanism.
  3. Assess the destination. Examine the law and practice of the destination country to see whether it undermines the tool in your specific case.
  4. Adopt supplementary measures. Where the assessment finds a gap, identify and apply measures that close it.
  5. Take procedural steps. Implement the measures, update contracts and consult authorities where required.
  6. Re-evaluate. Review the assessment at appropriate intervals as law, practice and the transfer change.

The final version put more weight on assessing actual practice as well as legislation, and it allows an exporter in some situations to rely on a well-documented conclusion that problematic laws are not applied to the transfer in practice. That route needs solid evidence, and senior sign-off is sensible. Step three is normally recorded in a transfer impact assessment, and our transfer impact assessment example shows what one contains.

The three types of supplementary measures

TypeExamplesStrength and limit
TechnicalStrong encryption with keys held in the EEA, pseudonymisation, split or multi-party processingCan be effective if the importer cannot access readable data. Weak where the importer needs clear data to do its job
ContractualAudit rights, commitments to challenge access requests, notification duties, transparency undertakingsAdds accountability but cannot override the importer’s national law by itself
OrganisationalInternal policies for handling access requests, access minimisation, staff training, documented governanceSupports the other measures. Rarely sufficient alone against public authority access

Technical measures that can work

Among supplementary measures for data transfers, technical measures carry the most weight because they change what an authority could actually obtain. Encryption is the standard example: if you encrypt data before it leaves Europe, hold the keys yourself and use strong, well-implemented algorithms, the importer may receive only unreadable data. That works for storage and backup use cases, where the provider does not need the plain text. Pseudonymisation can work where the additional information needed to re-identify people stays in Europe under your control.

The limits are just as important. If a cloud provider or a support team in the destination country must process the data in clear text to deliver the service, encryption in transit and at rest will not stop access at the point of use. In that case the technical measure does not close the gap, and you should treat the transfer as unsupported unless another approach does. Be honest in the assessment about what the measure does and does not prevent.

Contractual and organisational measures

These measures strengthen accountability but rarely solve the underlying legal exposure on their own. Useful commitments include an obligation on the importer to notify you of access requests where lawful, to challenge requests that appear unlawful, to disclose only the minimum data required and to publish transparency information where possible. Organisational steps include limiting who in the importing organization can reach the data, training staff on handling government requests, and keeping records of any request received. Treat them as layers around a technical core, not substitutes for one.

A worked example

Imagine a European software company that wants to store encrypted customer backups with a provider in a country whose surveillance laws are broad. The backup files are encrypted on the company’s own servers before upload, the keys stay in Europe under the company’s control, and the provider never needs to read the contents. Here, encryption plausibly closes the gap, because an authority ordering the provider to hand over data would receive unreadable files. The company records the algorithm, the key management arrangements, the fact that no clear-text access exists and the contract terms.

Now change the facts: the same provider must run the company’s analytics on the customer data and therefore needs readable records. Encryption at rest no longer helps, because the data is decrypted in the destination country for processing. The honest conclusion is that the measure does not close the gap, and the company must either keep the analytics in Europe or find a different arrangement. The difference between the two cases is exactly what your assessment should make visible.

Documenting your decision

For supplementary measures for data transfers, a regulator will ask three questions: what did you assess, what did you conclude, and why do the measures work? Record the transfer, the tool relied on, the destination law reviewed, the evidence about practice, each measure adopted and the reasoning that links measures to the identified risk. Keep the analysis with the contract file and give it an owner and a review date. Where the conclusion is that no measure is sufficient, record the decision to stop or redesign the transfer. Our guide to international data transfers gives the wider context, and the comparison of transfer risk assessments and TIAs helps if you operate under more than one regime.

Re-evaluating over time

The assessment is not a one-off. Laws change, courts rule, adequacy decisions are reviewed and your own processing shifts, so set a review cycle and triggers. Typical triggers include a change of provider or sub-processor, a new category of data, a legal development in the destination country or an access request received by the importer. Assign someone to watch for those events, and record each review even when nothing changes.

Common mistakes with supplementary measures for data transfers

  • Relying on the contract alone. Standard clauses do not by themselves neutralize foreign public authority access.
  • Encrypting where the importer needs clear text. The measure fails if the service requires readable data.
  • Copying a generic assessment. The analysis must fit your transfer, data and destination.
  • Ignoring onward transfers. Sub-processors and remote access count as transfers.
  • No review date. Laws and practices change.
  • Hiding a negative conclusion. If no measure works, record the decision to stop.

Build a transfer assessment that supports your measures

The supplementary measures for data transfers you choose are only as defensible as the assessment behind them. The Transfer Impact Assessment Report and Workbook gives you a structured report covering screening, destination laws, transfer risks, supplementary measures, sign-off and a live workbook for your own transfers.

Supplementary measures for data transfers FAQ

Are supplementary measures required for every international transfer?

No. They are needed only when your assessment finds that the transfer tool alone does not provide essentially equivalent protection in the destination country.

Is encryption enough on its own?

It can be, if you control the keys and the importer never needs readable data. It is not enough where the service requires processing in clear text in the destination country.

Can contractual clauses replace technical measures?

Generally not. Contracts add accountability, but they cannot stop a foreign authority from exercising its legal powers, so they work best alongside technical measures.

What if no supplementary measure is effective?

Then you should not start the transfer, or you should suspend or end it. Record that decision and consider redesigning the processing to keep the data in Europe.

How often should I review a transfer assessment?

Review it at planned intervals and whenever a trigger occurs, such as a legal change in the destination country, a new sub-processor or a change in the data transferred.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.