Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Cross-Border Transfers

Article 49 Derogations

Also known as: Derogations for specific situations, Article 49 GDPR derogations, GDPR transfer derogations
Simply put

Article 49 derogations are a set of specific exceptions under the EU General Data Protection Regulation (GDPR) that permit personal data to be transferred to a country outside the EU/EEA (a 'third country') or to an international organisation in particular situations. They are intended to be used only as a last resort, when the usual transfer safeguards are not available. Examples of the situations they cover include a transfer based on the individual's explicit consent or one that is necessary for a specific contract.

Formal definition

Article 49 of the GDPR provides derogations that allow a transfer, or a set of transfers, of personal data to a third country or an international organisation in the absence of an adequacy decision and in the absence of appropriate safeguards (such as standard contractual clauses or binding corporate rules). Under EDPB Guidelines 2/2018, these derogations are interpreted restrictively and are regarded as a last-resort basis for transfer rather than a routine mechanism; each transfer must satisfy the specific conditions of a listed derogation (for example, explicit consent, necessity for the performance of a contract, or other enumerated situations). Related recitals inform the interpretation of these conditions. This entry summarises the concept only and does not reproduce the full statutory conditions, their limitations, or evolving EDPB interpretation; readers should verify the current text of Article 49, the associated recitals, and the applicable EDPB guidance against the latest authoritative sources, as GDPR provisions and guidance may be updated. This is informational and not legal advice; application to specific transfers requires professional judgment.

Why it matters

Transfers of personal data outside the EU/EEA are one of the more heavily scrutinised areas of GDPR compliance, and Article 49 derogations occupy a distinctive place within the transfer framework. The GDPR establishes a hierarchy for lawful transfers: first, transfers to countries covered by an adequacy decision; second, transfers made subject to appropriate safeguards such as standard contractual clauses or binding corporate rules; and only then, in the absence of both, the derogations set out in Article 49. Understanding that Article 49 sits at the bottom of this hierarchy matters because organisations sometimes reach for consent or contractual necessity as a convenient default, when in practice these derogations are intended as a last-resort basis rather than a routine mechanism.

The European Data Protection Board addresses this directly in its Guidelines 2/2018, which interpret the derogations restrictively. Treating a derogation as a general-purpose transfer tool—for example, relying on explicit consent to underpin large-scale, systematic, or repetitive transfers—risks mischaracterising the legal basis and exposing the transfer to challenge. Because each derogation carries its own specific conditions, a transfer that does not genuinely satisfy those conditions may be unlawful even if the organisation believed it had a valid footing.

For this reason, Article 49 is often most relevant precisely when the usual safeguards are unavailable or impractical, and where the transfer is narrow, occasional, or tied to a concrete situation such as a particular contract or the individual's explicit consent. Readers should treat this entry as informational only; whether a given transfer qualifies under a specific derogation is fact-specific and depends on the current text of Article 49, its associated recitals, and the applicable EDPB guidance, all of which should be verified against the latest authoritative sources.

Who it's relevant to

Data protection officers and privacy teams
DPOs and privacy professionals assessing cross-border data flows need to understand where Article 49 sits in the transfer hierarchy—below adequacy decisions and appropriate safeguards. This helps them avoid defaulting to derogations such as consent or contractual necessity where a more appropriate safeguard exists, and to document why a derogation is genuinely available in a given case.
Legal counsel advising on international transfers
In-house and external counsel structuring transfers to third countries or international organisations must evaluate whether the specific conditions of a listed derogation are met, and account for the EDPB's restrictive, last-resort interpretation under Guidelines 2/2018. This entry is informational and not a substitute for legal advice tailored to a particular transfer.
Compliance officers and auditors
Those reviewing an organisation's transfer arrangements can use an understanding of Article 49 to test whether reliance on a derogation is appropriate or whether it is being used to cover systematic or repetitive transfers that should instead rest on appropriate safeguards. They should verify the current statutory text and guidance, as GDPR provisions and EDPB interpretation may change.
Organisations transferring EU/EEA personal data abroad
Businesses that move personal data outside the EU/EEA—particularly where no adequacy decision or standard contractual clauses apply—may occasionally need to rely on an Article 49 derogation for a specific, non-routine transfer. Understanding the narrow, last-resort nature of these derogations is important before relying on one.

Inside Article 49 Derogations

Derogations for Specific Situations
Article 49 of the GDPR provides a set of exceptions permitting transfers of personal data to a third country or international organisation in the absence of an adequacy decision or appropriate safeguards. These derogations apply to specific, defined situations rather than as a general basis for routine or systematic transfers.
Explicit Consent
One derogation permits a transfer where the data subject has explicitly consented to the proposed transfer after having been informed of the possible risks arising from the absence of an adequacy decision and appropriate safeguards. The heightened 'explicit' standard and the requirement to inform of risks distinguish this from ordinary consent.
Contractual Necessity
Derogations exist where a transfer is necessary for the performance of a contract between the data subject and the controller, or for the implementation of pre-contractual measures taken at the data subject's request, as well as for contracts concluded in the interest of the data subject between the controller and another party.
Important Reasons of Public Interest
A transfer may be permitted where it is necessary for important reasons of public interest, which must be recognised in Union or Member State law. The scope of what qualifies is generally interpreted narrowly and is subject to jurisdictional definition.
Legal Claims and Vital Interests
Further derogations cover transfers necessary for the establishment, exercise, or defence of legal claims, and transfers necessary to protect the vital interests of the data subject or of other persons where the data subject is physically or legally incapable of giving consent.
Public Register Transfers
A derogation addresses transfers made from a register intended to provide information to the public, subject to the conditions laid down in law for consultation of that register.
Compelling Legitimate Interests (Residual Derogation)
Where no other derogation or safeguard applies, a limited residual ground may permit a non-repetitive transfer concerning a limited number of data subjects, subject to strict conditions including assessment of the transfer, suitable safeguards, and notification to the supervisory authority. This ground is generally treated as a last resort of narrow scope.

Common questions

Answers to the questions practitioners most commonly ask about Article 49 Derogations.

Can Article 49 derogations be used as a routine basis for regular international data transfers?
Generally no. The derogations under Article 49 of the GDPR are intended for specific, exceptional situations rather than for systematic or repetitive transfers. Regulatory guidance has consistently treated them as a last resort, to be relied upon only where an appropriate safeguard (such as standard contractual clauses or binding corporate rules) and an adequacy decision are not available. Using a derogation to structure ongoing, large-scale transfer operations would in most cases fall outside their intended scope. Application to a particular transfer pattern requires case-specific analysis, and you should verify the current supervisory guidance against the latest authoritative sources.
Does relying on a derogation mean the other GDPR obligations no longer apply to the transfer?
No. A derogation addresses only the lawful basis for transferring personal data to a third country in the absence of an adequacy decision or appropriate safeguards. It does not remove the controller's or processor's other obligations under the GDPR, such as having a lawful basis for the processing itself, meeting transparency and information duties, observing data minimisation, and maintaining records. A derogation is a narrow exception to the transfer restriction, not a general exemption from the Regulation. How the full set of obligations applies depends on the facts and calls for professional judgment.
How should an organisation document its reliance on an Article 49 derogation?
As a general matter, an organisation should be able to demonstrate why a derogation applies and why appropriate safeguards and an adequacy decision were not available. This typically involves recording the specific derogation relied upon, the factual circumstances that bring the transfer within it, and the assessment supporting that conclusion. Certain derogations carry additional documentation or notification expectations. Because record-keeping expectations are shaped by supervisory guidance and may evolve, verify the specific requirements against the current official text and applicable authority guidance.
Which derogation applies when a transfer is necessary to perform a contract with the data subject?
The GDPR provides derogations covering transfers necessary for the performance of a contract between the data subject and the controller, and for pre-contractual steps taken at the data subject's request, as well as for contracts concluded in the data subject's interest between the controller and a third party. The key qualifier is necessity: the transfer must be genuinely required to perform or conclude the contract, not merely convenient. Whether a given transfer meets that necessity threshold is fact-specific, and interpretations of necessity should be checked against current guidance.
What conditions attach to relying on the data subject's explicit consent for a transfer?
Where consent is used as a derogation, it generally must be explicit and informed, meaning the data subject is told about the specific transfer and the possible risks arising from the absence of an adequacy decision and appropriate safeguards. Consent that does not meet the GDPR's standards for valid consent, or that is not specific to the transfer, would in most cases be insufficient. Consent may also be withdrawn, which affects its reliability for ongoing arrangements. The precise conditions should be confirmed against the current text and supervisory guidance.
Is there a narrow derogation for occasional transfers based on compelling legitimate interests, and what limits it?
The GDPR contains a further, tightly constrained basis sometimes described as the compelling-legitimate-interests derogation, which is generally treated as available only where no other derogation or safeguard applies. It is typically limited to transfers that are not repetitive, concern a limited number of data subjects, and are subject to an assessment of the interests involved and suitable safeguards, with certain notification expectations toward the supervisory authority. Because this basis is intended to be exceptional and its practical use narrow, confirm the applicable conditions and any evolving interpretation against the latest authoritative sources; application to specific circumstances requires professional judgment.

Common misconceptions

Article 49 derogations can be used as a routine, ongoing basis for international data transfers.
The derogations are generally intended for specific, occasional situations rather than repetitive or systematic transfers. Supervisory authorities have generally interpreted them restrictively, and for regular transfers organisations are typically expected to rely on an adequacy decision or appropriate safeguards instead. Readers should verify current guidance and the authoritative text.
Any form of data subject consent satisfies the Article 49 consent derogation.
The provision requires 'explicit' consent given after the data subject has been informed of the specific risks arising from the absence of an adequacy decision and appropriate safeguards. This is a higher bar than ordinary consent and cannot be assumed from generic terms acceptance.
Article 49 is a global rule that governs all cross-border data transfers.
Article 49 is a provision of the EU GDPR and governs transfers of personal data out of the EU/EEA under that regulation. Other jurisdictions, including the United Kingdom under its own regime and the United States, address transfers through different instruments. Application depends on the applicable legal framework.

Best practices

Treat Article 49 derogations as exceptional grounds and, wherever a transfer is repetitive or systematic, prioritise an adequacy decision or appropriate safeguards over reliance on a derogation.
Document the specific derogation relied upon for each transfer and the factual basis showing that its conditions are met, given that these grounds are fact-specific and interpreted narrowly.
Where relying on explicit consent, ensure data subjects are clearly informed of the risks arising from the absence of an adequacy decision and appropriate safeguards, and record that the consent meets the explicit standard.
Assess whether the residual 'compelling legitimate interests' ground genuinely applies only as a last resort, and observe its stricter conditions including limited scope, suitable safeguards, and notification to the relevant supervisory authority.
Consult the current authoritative GDPR text and applicable supervisory authority guidance before relying on any derogation, as interpretations and enforcement practice continue to evolve.
Obtain professional judgement for particular circumstances, since this entry is informational and application of Article 49 to a specific transfer depends on the facts and the applicable jurisdiction.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.