Onward Transfer
An onward transfer happens when personal data that has already been sent from one organization to another is then passed along again to a further recipient, often in a different country. In a data protection context, it typically describes the situation where a party who has received personal data transfers that data to an additional third party. Whether such a transfer is permitted generally depends on the safeguards and conditions attached to the original transfer.
In the context of international data transfers, an onward transfer refers to a further transfer of personal data occurring after the data have first been transferred from an exporter to a recipient (for example, a data importer located outside the exporter's jurisdiction), where that recipient subsequently transfers the same data to an additional third party. Under EU law, the concept is relevant to the transfer regime addressed in the GDPR (including provisions governing transfers to third countries and international organizations), where the safeguards relied upon for the initial transfer are generally expected to extend to, and constrain, any subsequent onward transfer. The precise obligations depend on the transfer mechanism used and the facts of the specific arrangement; the term describes the further movement of data and is distinct from the initial transfer itself. Readers should verify requirements against the current authoritative text applicable in the relevant jurisdiction, as transfer rules and their interpretation continue to evolve. This entry is informational and does not constitute legal advice; application to particular circumstances requires professional judgment.
Why it matters
Onward transfers are a recurring point of legal exposure in international data flows because the safeguards attached to an initial transfer can be undermined if the recipient forwards the data further without equivalent protection. When personal data leaves an exporter for a recipient outside the exporter's jurisdiction, the conditions relied upon for that first transfer are generally expected to follow the data and constrain any subsequent movement. If they do not, data can end up in the hands of a further third party — potentially in a jurisdiction with weaker protections — outside the scope of the original safeguards.
For organizations subject to the EU regime, the onward transfer concept is directly relevant to how the GDPR addresses transfers to third countries and international organizations. The specific obligations depend on which transfer mechanism was used for the initial transfer and on the facts of the particular arrangement, so the same data flow can be permissible or problematic depending on the contractual and legal architecture behind it. This makes onward transfers a matter of careful mapping and documentation rather than a one-time assessment at the point of the first transfer.
Because transfer rules and their interpretation continue to evolve across jurisdictions, and because requirements differ by mechanism and by the parties involved, treating an onward transfer as automatically covered by the initial arrangement is a common source of risk. Readers should verify the applicable obligations against the current authoritative text for the relevant jurisdiction rather than assuming that clearance of the first transfer settles the question for every subsequent one.
Who it's relevant to
Inside Onward Transfer
Common questions
Answers to the questions practitioners most commonly ask about Onward Transfer.

