Outbound Wiki

Third-country data transfers

How to handle prospect data sent to or accessed from countries outside the European Economic Area by outbound tools and service providers.

Treat every outbound system as a data-flow question. Before approving a vendor, map which organisation receives or can access prospect data, where it operates, and which route covers the handoff. An EEA organisation can make a transfer when it shares data with a non-EEA controller or processor, even if the recipient is already subject to the GDPR.1 If a processor or sub-processor exports the data, the controller remains responsible for transfer compliance.2

The transfer check

Run the check in this order. Stop if you cannot explain who receives the data, where the handoff goes, and which safeguards cover it.

  1. Map the route.

Start with the record, the handoff, and the destination. A third country is any country outside the EEA.3 The GDPR contains specific provisions for transfers outside the EEA, aimed at giving transferred data the same level of protection it has within the EEA.45

Record where each field is stored, which organisation receives it, and where people can access it. Ask:

  • Where is prospect data stored?
  • Which legal entity receives it?
  • From which countries can staff or support teams access it?
  • Which subcontractors or internal divisions can process it?
  • Does any part of the route leave the EEA?

"The vendor's cloud" is not enough. Keep asking until you have a country and a receiving organisation for each handoff.

  1. Apply the transfer screen.

Use the transfer test before discussing contract language. The EDPB identifies three cumulative criteria for a transfer outside the EEA.6

First, ask whether a controller or processor is subject to the GDPR for the processing in question.7 Then ask whether that party discloses the data, or otherwise makes it available, to another controller or processor.8 Treat the screen as cumulative. A positive answer to one question does not settle the route.

Keep the analysis tied to the actual movement of data. A prospect's direct and self-initiated provision of personal information to an organisation outside the EEA is not a transfer.9 That does not answer what happens when your organisation sends a prospect record to an outbound service.

  1. Set responsibility and instructions.

Assign responsibility before accepting a vendor's explanation of its paperwork. The Chapter V transfer rules apply to processors as well as controllers.10

Ask who decides the purpose and means of processing, who sends the data, and who appoints each sub-processor. A processor is responsible when it initiates a transfer, usually to a sub-processor.11 If the arrangement includes joint controllers, allocate transfer responsibilities between them.12

The contract should specify the requirements for transfers to third countries or international organisations, taking account of Chapter V.13 If your instructions prohibit third-country transfers or disclosures, the processor cannot appoint a third-country sub-processor or process the data in a non-EU division.14 Put that restriction in the instructions, then check whether the vendor's actual route follows it.

  1. Check adequacy first.

Once you know the destination, check the available routes in a fixed order. The first consideration for a transfer to a third country is whether an adequacy decision exists.15

An adequacy decision means that the European Commission has determined that the third country or international organisation ensures an adequate level of data protection.16 Ask the vendor to identify the destination covered by the decision and the receiving organisation to which it applies.

If no adequacy decision covers the route, ask which safeguard permits the transfer. Transfers outside the EU or EEA are permitted only when specific safeguards are in place.17 Standard Contractual Clauses, Binding Corporate Rules, Codes of Conduct, and Certification Mechanisms must be in place for the specified cross-border transfers.18 Derogations may apply only in very specific circumstances.19 Treat a derogation as an escalation point, record the facts, and do not accept it as a routine vendor answer.

  1. Test the safeguard against the contract.

A safeguard is useful only if it covers the route you mapped. Read the contract alongside the vendor's answers and check each destination, receiving organisation, and processing activity.

Ask:

  • Which safeguard covers this specific destination?
  • Which contract clause addresses the transfer?
  • Does the clause cover storage, access, support, and sub-processors?
  • What do the processing instructions permit or prohibit?
  • If the vendor says the recipient is already subject to the GDPR, which transfer mechanism applies?

The current Standard Contractual Clauses apply only where the importer is not subject to the GDPR.20 If a vendor says it uses SCCs, check that they apply before treating the answer as complete.

  1. Check for other territorial rules.

Finish by checking whether another country's law affects the route. Laws in other territories may impose specific restrictions on international data transfers.21 Ask the vendor and your privacy contact whether the destination adds requirements beyond the route you have assessed.

Move on only when your record names the data, route, receiving organisation, destination, safeguard, and contract instruction. Escalate when one of those pieces is missing or when the vendor's answer changes depending on whether it is describing storage, access, or a sub-processor.

Questions to use on a vendor call

Use short questions that require a country-by-country answer. The aim is to turn a broad compliance statement into a route you can check.

  • Which legal entity receives the prospect records after they leave our environment?
  • In which countries are the records stored?
  • In which countries can the records be accessed for support, maintenance, or operations?
  • Which other organisations or internal divisions can process them?
  • Does any other organisation initiate a transfer from the service?
  • Is the destination covered by an adequacy decision?
  • If it is not, which safeguard covers the transfer?
  • Where does the contract address the transfer requirements?
  • Can our processing instructions prohibit transfers to a particular destination?
  • What changes if a new sub-processor or access location is introduced?

Listen for precise answers that separate the vendor's contracting entity from the places where data is stored or accessed. If the answer remains at the level of "global infrastructure" or "standard compliance," return to the route and ask for the receiving entity, country, and safeguard.

What not to do

Keep these mistakes out of the approval record.

  • Do not treat a broad contractual exception as permission to transfer personal data. Such an exception does not override the GDPR's transfer restrictions or count as the controller's instruction to transfer.22
  • Do not approve a route because a vendor says it has a European office. Identify the receiving organisation and the countries where the data can be accessed.
  • Do not treat a processor's export as someone else's compliance problem. The controller remains responsible for ensuring transfer compliance when a processor or sub-processor acts as the exporter.2
  • Do not assume that another country's rules are irrelevant once the GDPR route is documented. Other territories may impose their own restrictions.21
  • Do not wait for a breach or complaint before checking the transfer file. Restricted transfers are likely to receive regulatory scrutiny in either situation.23

Use the record during approval and revisit it whenever the vendor describes a new access location, receiving organisation, or sub-processor.

Sources

  1. 1
    “An EEA controller or processor sharing personal data with a non-EEA controller or processor engages in a transfer, regardless of whether or not the receiving entity is subject to the GDPR.”
  2. 2
    “If a (sub-)processor acts as the data exporter, controllers are still responsible for ensuring compliance with GDPR transfer obligations, in addition to the data exporter.”
  3. 3
    “with a third country being any country outside the European Economic Area (the “EEA”).”
  4. 4
    “The GDPR contains specific provisions for such transfers.”
  5. 5
    “With these provisions, the GDPR aims to guarantee an equivalent level of protection to personal data being transferred to the one they enjoy within the EEA.”
  6. 6
    “However, the EDPB has identified the following three cumulative criteria to identify a transfer outside the EEA:”
  7. 7
    “a controller or a processor is subject to the GDPR for the given processing;”
  8. 8
    “this controller or processor discloses by transmission or otherwise makes personal data available to another organisation (data controller or processor);”
  9. 9
    “It is not a transfer when a data subject provides personal information “directly and on his/her own initiative” to an organization outside the European Economic Area (“EEA”).”
  10. 10
    “the rules on transfers of data to third countries (Chapter V) apply to processors as well as controllers.”
  11. 11
    “A processor will be responsible when they initiate the transfer, usually to a sub-processor.”
  12. 12
    “Transfers of data to third countries (Chapter V)”
  13. 13
    “The contract should specify the requirements for transfers to third countries or international organisations, taking into account the provisions of Chapter V of the GDPR.”
  14. 14
    “If the instructions by the controller do not allow for transfers or disclosures to third countries, the processor will not be allowed to assign the processing to a sub-processor in a third country, nor will he be allowed to have the data processed in one of his non-EU divisions.”
  15. 15
    “The first thing to consider when transferring personal data to a third country is if there is an “adequacy decision”.”
  16. 16
    “An adequacy decision means that the European Commission has decided that a third country or an international organisation ensures an adequate level of data protection.”
  17. 17
    “Data transfers outside of the EU/EEA are only permitted when specific safeguards are in place.”
  18. 18
    “Standard Contractual Clauses, Binding Corporate Rules, and Codes of Conduct and Certification Mechanisms must be in place.”
  19. 19
    “Derogations may be permitted in very specific circumstances.”
  20. 20
    “The current set of Standard Contractual Clauses (“SCCs”) apply only where the importer is not subject to the GDPR.”
  21. 21
    “Also please be aware there may be specific restrictions in place under laws in other territories around the world.”
  22. 22
    “Such an exception is, however, without prejudice to the GDPR's transfer restrictions and cannot be interpreted as an "instruction" of the controller to transfer personal data.”
  23. 23
    “It’s an area likely to come under regulatory scrutiny, in the event of a breach or should a complaint be raised.”