Transfer Impact Assessment
A Transfer Impact Assessment (TIA) is a case-by-case evaluation an organisation carries out before sending personal data to another country, to check whether that data will still be adequately protected once it arrives. It looks at both the laws of the destination country and how those laws work in practice, alongside any contractual safeguards used for the transfer. The TIA became a widely expected step following the Schrems II ruling of the Court of Justice of the European Union.
Under the EU General Data Protection Regulation (GDPR), a Transfer Impact Assessment is a documented, case-by-case evaluation performed by the party relying on an Article 46 transfer tool (such as Standard Contractual Clauses) to assess whether the level of protection guaranteed by EU law is met in practice for a given international transfer. Following the Court of Justice's Schrems II ruling, the assessment examines the legal framework and practical application of the law in the destination jurisdiction, the sufficiency of foreign protections, and whether supplementary measures are needed to address any gaps. A TIA is a compliance analysis rather than a certification or an approval mechanism, and its precise methodology is not fixed by the GDPR text; supervisory authorities such as the CNIL have published guidance identifying the steps and structuring how the analysis can be carried out. Scope here is limited to GDPR-governed transfers; requirements, terminology, and expectations may differ in other jurisdictions such as the United Kingdom, and readers should verify against the current authoritative texts and guidance, as interpretation and enforcement practice continue to evolve.
Why it matters
The Transfer Impact Assessment gained prominence because the Court of Justice of the European Union's Schrems II ruling made clear that relying on an Article 46 transfer tool, such as Standard Contractual Clauses, is not sufficient on its own. The exporting party must also verify that the personal data will actually receive a level of protection essentially equivalent to that guaranteed under EU law once it reaches the destination country. Where the destination's legal framework or its practical application falls short, the organisation may need supplementary measures to close the gap, or may need to reconsider the transfer altogether. The TIA is the analytical step that documents this evaluation.
For organisations subject to the GDPR, the practical consequence is that cross-border transfers can no longer be treated as a routine box-ticking exercise. A signed set of Standard Contractual Clauses does not, by itself, demonstrate compliance; the accompanying case-by-case assessment is what shows that the exporter considered the specific laws and conditions of the destination jurisdiction. Because the assessment is fact-specific, its outcome can differ from one transfer to another depending on the data category, the recipient, and the jurisdiction involved.
It is worth emphasising what a TIA is not. It is a compliance analysis, not a certification, an approval, or a guarantee of lawfulness, and no supervisory authority issues a stamp of validity for a completed TIA. Its methodology is not prescribed in fixed terms by the GDPR text itself, though supervisory authorities such as France's CNIL have published guidance identifying the steps and structuring how the analysis can be carried out. Because interpretation and enforcement practice continue to evolve, and because expectations differ in jurisdictions such as the United Kingdom, organisations should verify their approach against the current authoritative guidance rather than treating any single template as definitive.
Who it's relevant to
Inside TIA
Common questions
Answers to the questions practitioners most commonly ask about TIA.

