Cross-Border Data Transfer
Definition
Cross-Border Data Transfer
A cross-border data transfer is the movement of personal data from one country to another, including remote access from abroad to data that never physically moves. Access counts as transfer in most modern privacy regimes, which surprises many outsourcing buyers.
Offshore delivery is built on such transfers — every ticket viewed from another country, and every record processed at an offshore site, is a transfer requiring a lawful basis.
The law offers a short menu of routes. An adequacy finding, an approved safeguard such as model clauses or internal corporate rules, or a narrow derogation for specific situations.
Choosing a route is not the end of the work — several regimes require the exporter to assess conditions in the destination country before relying on any safeguard at all.
Key takeaways
- Remote access from another country is a transfer, even if the data stays put.
- Adequacy, approved safeguards and narrow derogations are the three routes available.
- Derogations are for occasional cases and cannot carry routine offshore delivery.
- The chosen route must be documented, not merely assumed from a signed agreement.
How it works
Transfers are governed by a general principle first and a route second. The exporter identifies the destination, selects a lawful basis and records why that basis is adequate for the processing involved.
The hierarchy is explicit in law. Where no adequacy decision applies, a transfer may proceed subject to appropriate safeguards, including “binding corporate rules” and standard data protection clauses specified by the regulator.
| Route | When it applies | Suitable for routine offshore work |
|---|---|---|
| Adequacy finding | Destination assessed as adequate | Yes, and simplest |
| Standard clauses | No adequacy, contract-based safeguard | Yes, most common |
| Binding corporate rules | Intra-group transfers only | Yes, within one group |
| Certification or code | Approved scheme in place | Rarely used in practice |
| Derogation | Consent, contract necessity, legal claims | No, occasional use only |
The bottom row is the one buyers misuse — derogations are drafted for exceptional cases, and the law restricts the residual route to transfers that are “not repetitive” and affect a limited number of people.
Regulators expect a documented judgement, not a signature. UK guidance explains what a transfer risk assessment is and notes it “is now referred to in UK legislation as a ‘data protection test'”.
Supplementary measures can close the remaining gap. European guidance sets out measures that “supplement transfer tools to ensure compliance with the EU level of protection” where the destination falls short.
Examples
Every offshore outsourcing arrangement involves transfers, and most buyers underestimate how many. The four cases below show where they arise and how they are lawfully handled.
A European retailer sends customer service to a provider in Asia. Standard clauses cover the flow, and the GDPR outsourcing assessment records why they are sufficient.
A buyer keeps all data in one region but allows overnight support from abroad. That remote access is a transfer, and it needed its own documented basis.
A multinational moves employee data between group companies in six countries. Internal corporate rules cover the whole group, which avoids separate agreements for each pair.
A buyer relies on consent for routine offshore processing and is told it cannot. Consent is a derogation, and derogations do not support continuous delivery.
Related terms
Transfers interact with contracts, chains of suppliers and national regimes. The entries below separate the act of moving data from the instruments that permit it.
- Data processing agreement: the contract governing the processing, into which transfer terms are built.
- Sub-processor clause: each onward step in the chain is a fresh transfer needing its own basis.
- Offshore outsourcing: the delivery model in which almost every workflow depends on lawful transfers.
- ePrivacy Regulation: a parallel regime covering communications data alongside general privacy law.
- Philippine data privacy: the destination-country regime for a very large share of transfers.
- Nearshore Latin America: a region where adequacy status varies country by country.
FAQ
Does remote access count as a transfer?
Yes, in most regimes. Allowing someone abroad to view or work on data makes it available in that country, which is treated as a transfer.
What is an adequacy decision?
A formal finding that a destination country offers a sufficient level of protection. Where one applies, transfers proceed without an additional safeguard.
Can consent be used for offshore delivery?
Not for routine processing. Consent is a derogation intended for occasional transfers, and it can be withdrawn at any time.
Do standard clauses alone make a transfer lawful?
Usually not by themselves. Several regimes require a documented assessment of the destination and, where needed, supplementary technical measures.
Does the chain of sub-processors matter?
Very much. Each onward transfer needs its own lawful basis, and a chain is only as compliant as its weakest link.
What should be documented?
The destination, the route relied on, the assessment supporting it and any supplementary measures. Regulators ask for the reasoning, not just the signature.
Understand how offshore delivery models handle data at Outsource Accelerator.







Independent




