Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Cross-Border Transfers

Third Country Transfer

Also known as: International Data Transfer, Third-Country Transfer, Cross-Border Data Transfer to a Third Country
Simply put

A third country transfer is the movement of personal data to a country or territory outside the sending jurisdiction's protected area, such as outside the European Economic Area (EEA) under EU rules or outside the UK under UK rules. Because the receiving country may not offer the same level of legal protection for personal data, such transfers are generally permitted only where certain conditions are met. What counts as a 'third country' depends on which legal regime applies, so the same destination may be treated differently under EU and UK law.

Formal definition

Under the EU General Data Protection Regulation (GDPR), a third country transfer refers to the transfer of personal data to a country or international organisation outside the European Economic Area (EEA); under UK data protection law, a 'third country' is a country or territory outside the UK. Some guidance frames the concept broadly, treating a transfer as occurring where a party in a non-EEA country can potentially gain access to the data, though the precise threshold for what constitutes a 'transfer' can vary and continues to be interpreted through regulatory guidance and case law. Such transfers are typically assessed in a layered manner: the transfer must first satisfy the general lawfulness requirements applicable to any processing, and then must additionally rely on a permitted transfer mechanism. The primary mechanism is an adequacy decision, by which the relevant authority (for example, the European Commission for the EU) determines that the destination provides an adequate level of protection; in the absence of adequacy, other safeguards or derogations may apply. This entry does not detail those specific alternative mechanisms, sector-specific rules (such as the separate regime for law enforcement processing), or the differing lists of adequate countries under each regime; adequacy determinations and transfer rules are periodically amended, and their application to particular circumstances requires professional judgment and verification against current authoritative texts.

Why it matters

Third country transfers sit at the intersection of global business operations and data protection law. Modern organisations routinely rely on cloud services, group companies, and vendors located outside their home jurisdiction, and as the EDPB notes, transfers of personal data to countries outside the EEA are often essential in view of international trade or cooperation. The core concern is that once personal data leaves the sending jurisdiction's protected area, it may fall under a legal regime that does not offer the same level of protection. For this reason such transfers are generally permitted only where specific conditions are satisfied, and getting this wrong can expose an organisation to regulatory scrutiny and to challenges over the lawfulness of its data flows.

A recurring source of difficulty is that the term is regime-specific. Under EU law a third country is one outside the EEA, while under UK data protection law a third country is a country or territory outside the UK. The same destination may therefore be treated differently depending on which legal framework applies, and an organisation operating across both the EU and the UK cannot assume that a single analysis covers both. Because adequacy determinations and transfer rules are periodically amended, an arrangement that is compliant today may need to be reassessed if the underlying decisions or guidance change.

Who it's relevant to

Data protection officers and privacy specialists
Those responsible for mapping and governing data flows need to identify when personal data leaves the protected area and to confirm that each transfer relies on a permitted route. Because the definition of a third country differs between the EU and UK regimes, practitioners operating across both must assess transfers under each framework separately rather than assuming a single conclusion applies.
Legal counsel and compliance officers
Counsel advising on vendor contracts, intra-group arrangements, and cross-border operations must determine whether an adequacy decision covers the destination and, where it does not, whether alternative safeguards or derogations are available. Given that adequacy determinations are periodically amended, ongoing review is required rather than a one-time assessment. Application to particular circumstances calls for professional judgment.
Procurement and IT teams managing cloud and vendor services
Teams selecting cloud providers and processors need to understand that a transfer may be treated as occurring where a party outside the protected area can potentially gain access to personal data, not only where data is physically relocated. This informs due diligence on where services and support functions are located.
Auditors and assessors
Those evaluating an organisation's data protection posture should verify that international transfers have been analysed under the correct regime, that reliance on adequacy or other mechanisms is documented, and that the position has been checked against current authoritative texts, since transfer rules and adequacy lists change over time.

Inside Third Country Transfer

Definition of Third Country
Under EU data protection law, a 'third country' generally refers to any jurisdiction outside the European Economic Area (EEA). A transfer to such a country is treated as a restricted transfer subject to specific safeguards. Note that whether a particular territory counts as a third country can depend on evolving political arrangements, so readers should verify current status against official EU sources.
Restricted Transfer Trigger
A third country transfer is engaged when personal data subject to EU rules is transmitted to, or made accessible from, a country outside the EEA. This includes not only physical transmission but also remote access, which may itself constitute a transfer depending on the circumstances.
Adequacy Decision
A mechanism whereby the European Commission determines that a third country ensures a level of data protection considered essentially equivalent to that under EU law. Where an adequacy decision is in force, transfers to that country may proceed without additional safeguards. Adequacy decisions can be adopted, amended, or withdrawn over time and should be verified against the current official list.
Appropriate Safeguards
In the absence of adequacy, transfers generally require appropriate safeguards, which may include Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other recognised instruments. The available mechanisms and their approved versions change, so the applicable text should be confirmed against the latest authoritative source.
Supplementary Measures
Depending on the destination country's laws and practices, additional technical, contractual, or organizational measures may be needed alongside a transfer mechanism to address risks such as government access. The need for and adequacy of such measures is fact-specific and assessed case by case.
Derogations for Specific Situations
Limited exceptions may permit a transfer without adequacy or standard safeguards, for example where based on explicit consent or contractual necessity. These are generally interpreted narrowly and are not intended as a routine basis for systematic transfers.

Common questions

Answers to the questions practitioners most commonly ask about Third Country Transfer.

Does a 'third country' just mean any country outside your own?
No. In the context of EU data protection law, a 'third country' means a country outside the European Economic Area (EEA), not simply any country other than your own. The term is defined relative to the EEA as a bloc, so transfers between EEA member states are not third country transfers, while a transfer from one non-EEA country to another may or may not fall under this concept depending on which regime applies. Because the same phrase can carry different meanings under other jurisdictions' laws, readers should confirm the applicable definition against the relevant legal text rather than assuming a universal meaning.
If a country has been recognized as providing adequate protection, does that mean no further compliance steps are needed for transfers there?
Not entirely. An adequacy recognition generally allows personal data to flow to the recognized destination without an additional transfer mechanism such as standard contractual clauses, but it does not remove the other obligations that apply to any processing of personal data. Controllers and processors generally remain responsible for lawful basis, transparency, data subject rights, security, and accountability regardless of the destination. Adequacy determinations can also be limited in scope, subject to conditions, or reviewed and withdrawn over time, so their status should be verified against the current official position rather than treated as permanent.
What transfer mechanisms are commonly available when a destination lacks an adequacy recognition?
Where no adequacy recognition applies, organizations generally rely on one of the appropriate safeguards or derogations set out in the applicable law. Commonly used safeguards include standard contractual clauses and binding corporate rules, and in some cases approved codes of conduct or certification mechanisms. Certain limited derogations may apply to specific situations. The precise list, conditions, and approved forms differ by jurisdiction and change over time, so the available mechanisms and their current versions should be verified against the relevant official source before implementation.
Is a signed standard contractual clause sufficient on its own to legitimize a transfer?
In most cases it is not treated as sufficient on its own. Following evolving regulatory and case-law expectations, organizations relying on contractual safeguards are generally expected to assess whether the law and practice in the destination undermine the protections in the contract, and to apply supplementary measures where needed. This assessment is fact-specific and depends on the data, the parties, and the destination's legal environment. Because interpretation and enforcement practice in this area continue to develop, the current requirements should be confirmed against authoritative guidance and applied with professional judgment.
How does onward transfer to a further country affect compliance?
Onward transfers, where data received in one destination is transferred again to another, generally need their own basis and safeguards rather than being covered automatically by the original transfer. Transfer mechanisms commonly include provisions addressing onward transfers, and the party making the further transfer typically bears responsibility for ensuring continued protection. The specific obligations depend on the mechanism used and the jurisdictions involved, so the applicable requirements should be verified against the current text of the relevant mechanism and law.
What should organizations document to demonstrate accountability for a third country transfer?
Documentation practices generally include identifying the transfer, the destination, the parties and their roles, the legal mechanism relied upon, and, where applicable, any assessment of the destination's protections and the supplementary measures adopted. Maintaining records that show how the transfer was evaluated and justified supports the accountability expectations found in many data protection regimes. The exact expectations vary by jurisdiction and by the mechanism in use, and enforcement practice may diverge from the text, so documentation approaches should be aligned with current authoritative guidance and tailored to the specific circumstances.

Common misconceptions

A third country transfer only occurs when data is physically sent abroad.
Making personal data accessible from outside the EEA, such as through remote access by staff or support providers in a non-EEA country, may itself constitute a restricted transfer, even where the data is not moved in the traditional sense.
Signing Standard Contractual Clauses is always sufficient to legitimise a transfer.
SCCs are one recognised safeguard, but in some cases they must be accompanied by a case-specific assessment of the destination country's legal environment and by supplementary measures. Reliance on a mechanism alone, without that assessment, may not be adequate.
The concepts of 'third country transfer' and jurisdictional restrictions are the same across all regimes.
The 'third country' terminology and its safeguard framework derive primarily from EU data protection law and apply to transfers outside the EEA. Other jurisdictions, such as the United States or the United Kingdom, address cross-border data flows differently, and their requirements should not be assumed to mirror the EU approach.

Best practices

Map data flows to identify where personal data leaves the EEA or becomes accessible from outside it, including remote access by processors, sub-processors, and support functions.
Check whether the destination country is covered by a current adequacy decision before selecting a transfer mechanism, and verify status against the official EU list, as adequacy can be granted or withdrawn.
Where adequacy does not apply, select an appropriate safeguard such as Standard Contractual Clauses or Binding Corporate Rules, and confirm you are using the latest approved version of the relevant instrument.
Conduct a documented, case-specific assessment of the destination country's laws and practices, and implement supplementary technical, contractual, or organizational measures where the risk analysis indicates they are needed.
Treat derogations for specific situations as narrow exceptions rather than a routine basis for ongoing or bulk transfers, and document the justification when relied upon.
Periodically review transfer arrangements against the latest authoritative sources, since regulations, adequacy decisions, and approved mechanisms change; engage qualified professional judgment for application to specific circumstances.
Promotional banner for the Penetration Report Template Kit