Third Country Transfer
A third country transfer is the movement of personal data to a country or territory outside the sending jurisdiction's protected area, such as outside the European Economic Area (EEA) under EU rules or outside the UK under UK rules. Because the receiving country may not offer the same level of legal protection for personal data, such transfers are generally permitted only where certain conditions are met. What counts as a 'third country' depends on which legal regime applies, so the same destination may be treated differently under EU and UK law.
Under the EU General Data Protection Regulation (GDPR), a third country transfer refers to the transfer of personal data to a country or international organisation outside the European Economic Area (EEA); under UK data protection law, a 'third country' is a country or territory outside the UK. Some guidance frames the concept broadly, treating a transfer as occurring where a party in a non-EEA country can potentially gain access to the data, though the precise threshold for what constitutes a 'transfer' can vary and continues to be interpreted through regulatory guidance and case law. Such transfers are typically assessed in a layered manner: the transfer must first satisfy the general lawfulness requirements applicable to any processing, and then must additionally rely on a permitted transfer mechanism. The primary mechanism is an adequacy decision, by which the relevant authority (for example, the European Commission for the EU) determines that the destination provides an adequate level of protection; in the absence of adequacy, other safeguards or derogations may apply. This entry does not detail those specific alternative mechanisms, sector-specific rules (such as the separate regime for law enforcement processing), or the differing lists of adequate countries under each regime; adequacy determinations and transfer rules are periodically amended, and their application to particular circumstances requires professional judgment and verification against current authoritative texts.
Why it matters
Third country transfers sit at the intersection of global business operations and data protection law. Modern organisations routinely rely on cloud services, group companies, and vendors located outside their home jurisdiction, and as the EDPB notes, transfers of personal data to countries outside the EEA are often essential in view of international trade or cooperation. The core concern is that once personal data leaves the sending jurisdiction's protected area, it may fall under a legal regime that does not offer the same level of protection. For this reason such transfers are generally permitted only where specific conditions are satisfied, and getting this wrong can expose an organisation to regulatory scrutiny and to challenges over the lawfulness of its data flows.
A recurring source of difficulty is that the term is regime-specific. Under EU law a third country is one outside the EEA, while under UK data protection law a third country is a country or territory outside the UK. The same destination may therefore be treated differently depending on which legal framework applies, and an organisation operating across both the EU and the UK cannot assume that a single analysis covers both. Because adequacy determinations and transfer rules are periodically amended, an arrangement that is compliant today may need to be reassessed if the underlying decisions or guidance change.
Who it's relevant to
Inside Third Country Transfer
Common questions
Answers to the questions practitioners most commonly ask about Third Country Transfer.
