Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Cross-Border Transfers

Onward Transfer

Also known as: Onward Transfers, Onward Transfer Arrangement
Simply put

An onward transfer happens when personal data that has already been sent from one organization to another is then passed along again to a further recipient, often in a different country. In a data protection context, it typically describes the situation where a party who has received personal data transfers that data to an additional third party. Whether such a transfer is permitted generally depends on the safeguards and conditions attached to the original transfer.

Formal definition

In the context of international data transfers, an onward transfer refers to a further transfer of personal data occurring after the data have first been transferred from an exporter to a recipient (for example, a data importer located outside the exporter's jurisdiction), where that recipient subsequently transfers the same data to an additional third party. Under EU law, the concept is relevant to the transfer regime addressed in the GDPR (including provisions governing transfers to third countries and international organizations), where the safeguards relied upon for the initial transfer are generally expected to extend to, and constrain, any subsequent onward transfer. The precise obligations depend on the transfer mechanism used and the facts of the specific arrangement; the term describes the further movement of data and is distinct from the initial transfer itself. Readers should verify requirements against the current authoritative text applicable in the relevant jurisdiction, as transfer rules and their interpretation continue to evolve. This entry is informational and does not constitute legal advice; application to particular circumstances requires professional judgment.

Why it matters

Onward transfers are a recurring point of legal exposure in international data flows because the safeguards attached to an initial transfer can be undermined if the recipient forwards the data further without equivalent protection. When personal data leaves an exporter for a recipient outside the exporter's jurisdiction, the conditions relied upon for that first transfer are generally expected to follow the data and constrain any subsequent movement. If they do not, data can end up in the hands of a further third party — potentially in a jurisdiction with weaker protections — outside the scope of the original safeguards.

For organizations subject to the EU regime, the onward transfer concept is directly relevant to how the GDPR addresses transfers to third countries and international organizations. The specific obligations depend on which transfer mechanism was used for the initial transfer and on the facts of the particular arrangement, so the same data flow can be permissible or problematic depending on the contractual and legal architecture behind it. This makes onward transfers a matter of careful mapping and documentation rather than a one-time assessment at the point of the first transfer.

Because transfer rules and their interpretation continue to evolve across jurisdictions, and because requirements differ by mechanism and by the parties involved, treating an onward transfer as automatically covered by the initial arrangement is a common source of risk. Readers should verify the applicable obligations against the current authoritative text for the relevant jurisdiction rather than assuming that clearance of the first transfer settles the question for every subsequent one.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for mapping data flows and maintaining transfer records need to identify not only initial transfers but any subsequent movement of the same data to further recipients. Onward transfers require confirming that the safeguards relied upon for the first transfer extend to any downstream party, which involves tracing where data originated and where it is stored.
Data importers and recipients outside the exporter's jurisdiction
A recipient who wishes to pass received personal data to an additional third party is generally constrained by the conditions attached to the original transfer. Recipients should understand that receiving data does not by itself authorize further onward transfer, and that the permissibility depends on the mechanism and terms governing the initial transfer.
Legal counsel and contract drafters
Because the obligations for an onward transfer depend on the transfer mechanism used and the facts of the arrangement, counsel drafting or reviewing data transfer agreements need to address how safeguards flow through to subsequent recipients. Requirements differ across jurisdictions and continue to evolve, so drafting should be checked against the current authoritative text applicable in the relevant jurisdiction.
Compliance and audit functions
Teams assessing an organization's international transfer practices should treat onward transfers as a distinct checkpoint rather than assuming they are covered by clearance of the initial transfer. This includes verifying documentation of the data flow and the safeguards intended to constrain any further movement of the data.

Inside Onward Transfer

Definition of Onward Transfer
The subsequent transfer of personal data by a recipient to a further recipient, following an initial transfer from the original data exporter. It describes the second (and later) link in a chain of transfers rather than the original cross-border movement of data.
Chain of Accountability
The concept generally requires that protections applied to the initial transfer continue to attach to the data as it moves to further recipients. Each link in the chain may carry obligations to ensure the data remains subject to comparable safeguards, though the precise allocation of responsibility is fact-specific.
Transfer Mechanisms and Safeguards
Onward transfers commonly rely on the same categories of safeguards used for the original transfer, such as contractual commitments imposed on the further recipient. The applicable mechanism depends on the legal basis governing the original transfer and the jurisdictions involved.
Jurisdictional Context
The meaning and requirements of onward transfer differ across regimes. It features in EU data protection law governing transfers of personal data outside the EEA and in other frameworks addressing cross-border data flows. Readers should identify which regime applies to their specific arrangement, as obligations are not universal.
Role Distinctions
Whether a party making an onward transfer acts as a controller or a processor affects its obligations. The distinction between these roles should be assessed separately for each party in the transfer chain, as it shapes the responsibilities that apply.

Common questions

Answers to the questions practitioners most commonly ask about Onward Transfer.

Is onward transfer the same thing as the initial transfer of data from an original exporter to a recipient?
No. Onward transfer generally refers to a subsequent transfer, where a recipient who has already received personal data passes it on to a further recipient, rather than the first transfer from the original exporter. The distinction matters because the party making an onward transfer typically inherits obligations to ensure that continued protection travels with the data. The specific mechanisms and responsibilities attaching to an onward transfer differ from those governing the initial transfer, and the exact requirements depend on the jurisdiction, the transfer instrument relied upon, and the roles of the parties involved. Readers should verify the applicable requirements against the current authoritative text.
Does using an approved transfer mechanism for the first transfer automatically cover any later onward transfers?
Not necessarily. Relying on a recognized mechanism for an initial transfer does not, on its own, guarantee that every subsequent onward transfer is covered. In most cases the onward transfer must itself satisfy a valid basis and ensure that an equivalent level of protection continues to apply. Whether additional safeguards, contractual terms, or conditions are required generally depends on the mechanism used, the jurisdictions involved, and the nature of the further recipient. Because interpretations and enforcement practice in this area continue to evolve, readers should confirm the position against the latest official guidance and the specific instrument they rely on.
How should an organization document onward transfers within its records?
As a general practice, organizations map where personal data flows after the initial transfer, identifying each further recipient, the purpose, and the safeguard relied upon for the onward step. Maintaining records that trace these subsequent flows helps demonstrate accountability and supports responses to audits or regulatory inquiries. The precise documentation expected varies by jurisdiction, by the role of the party (for example, controller or processor), and by the transfer instrument in use. This entry does not prescribe a specific record format, and organizations should align their documentation with the requirements applicable to their circumstances and verify these against current authoritative sources.
What contractual terms are commonly used to govern onward transfers?
Contracts governing onward transfers commonly include provisions requiring the recipient to ensure that any further recipient is bound to an equivalent level of protection, along with conditions on purpose limitation and, in some cases, notification or consent. Where standard contractual clauses or similar instruments are used, they may contain specific terms addressing onward transfers. The applicable terms depend on the mechanism chosen, the jurisdictions involved, and the relationship between the parties. This entry does not reproduce or endorse particular clause wording; readers should consult the current official text of the relevant instrument and apply professional judgment to their specific arrangements.
Who bears responsibility when an onward transfer fails to maintain adequate protection?
Responsibility generally depends on the roles of the parties and the safeguards in place. In many arrangements, the party making the onward transfer retains obligations to ensure continued protection, and liability may attach to that party if protection is not maintained. Allocation of responsibility is fact-specific and shaped by the applicable jurisdiction, the controller or processor status of each party, and the contractual terms agreed. This entry describes the concept qualitatively rather than assigning liability in any particular case, and determining responsibility for a specific situation requires professional judgment and reference to the governing legal framework.
What conditions typically need to be assessed before permitting an onward transfer?
Before permitting an onward transfer, organizations commonly assess whether a valid basis exists for the further transfer, whether the further recipient can ensure an equivalent level of protection, and whether the transfer is consistent with the original purpose and any conditions imposed at the initial transfer. The specific factors to evaluate vary by jurisdiction, data category, and the transfer mechanism relied upon, and enforcement practice may diverge from the literal text of applicable rules. This entry outlines the general nature of these considerations and does not substitute for verification against the current authoritative source or for professional judgment applied to particular circumstances.

Common misconceptions

Once data has been transferred abroad under a valid mechanism, it can be passed on freely to any further recipient.
Protections generally must continue to follow the data. Onward transfers to further recipients typically require their own safeguards, and the original safeguard covering the first transfer does not automatically authorize unrestricted subsequent transfers. The specific requirements depend on the applicable regime and should be verified against the current official text.
Onward transfer and the original cross-border transfer are the same thing.
They are distinct links in a transfer chain. The original transfer is the initial movement of data from the exporter to a recipient, while an onward transfer is the recipient's subsequent transfer of that data to a further party. Each may carry its own obligations.
Rules on onward transfer are uniform across jurisdictions.
Requirements differ across the EU, the United States, the United Kingdom, and other jurisdictions, and interpretations continue to evolve. The obligations attaching to an onward transfer depend on which regime governs the arrangement.

Best practices

Map the full chain of transfers, identifying each recipient and further recipient, so that no onward transfer occurs without a documented basis and appropriate safeguards.
Determine the role of each party in the chain (controller or processor) and confirm which regime governs the arrangement before authorizing any onward transfer.
Ensure that safeguards applied to the original transfer are contractually extended to further recipients, rather than assuming existing protections automatically carry over.
Impose written commitments on further recipients requiring them to maintain comparable protections and to seek authorization before making additional onward transfers.
Verify the applicable requirements against the latest authoritative source for the relevant jurisdiction, as rules and interpretations are periodically amended and continue to evolve.
Seek professional judgment for fact-specific arrangements, treating this entry as informational rather than as guidance for a particular situation.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.