International Data Transfers Under GDPR: France Compliance Guide

Data transfer under GDPR in France requires the right legal mechanism, risk assessment, and safeguards. Learn how adequacy decisions, SCCs, Schrems II, TIAs, CNIL guidance, cloud services, and subprocessors shape compliant international transfers in practice.

Data transfer GDPR France illustrated with international personal data flows, compliance checks, cloud systems, databases, and cross-border transfer safeguards under GDPR.

Organisations in France routinely transfer personal data across borders through cloud services, global HR systems, SaaS platforms, customer databases, analytics tools and group-company infrastructure. These transfers are often underestimated because data may appear to remain hosted in Europe while being accessed, supported or otherwise processed from another country.

Managing data transfer under GDPR in France requires organisations to identify transfers outside the EEA, determine the correct legal mechanism and assess whether personal data will receive an essentially equivalent level of protection.

GDPR Chapter V provides the core framework. Depending on the destination and circumstances, organisations may need to consider adequacy decisions, Standard Contractual Clauses (SCCs), Schrems II requirements, Transfer Impact Assessments, supplementary measures, US transfer mechanisms and processor or subprocessor arrangements.

CNIL expectations, accurate documentation and ongoing monitoring are also central to effective compliance.

International transfers are not automatically prohibited under GDPR. They are permitted where the applicable transfer conditions are satisfied and the organisation can demonstrate that appropriate safeguards and accountability measures are in place.

What Counts as an International Data Transfer Under GDPR?

An international transfer issue can arise when personal data protected by the General Data Protection Regulation, Regulation (EU) 2016/679 is made available to a separate controller or processor located in a third country or international organisation.

The analysis should not focus only on the physical location of the server. Transfers can also occur through remote access or onward processing. Examples include a non-EEA support team accessing an EU system, employee records being shared with an overseas parent company, use of a non-EEA SaaS provider, engagement of an international processor or access by a foreign subcontractor.

France Versus the EEA

GDPR Chapter V, particularly Articles 44 to 49, governs transfers outside the European Economic Area, not simply transfers outside France.

A transfer from France to Germany or Spain therefore differs from a transfer from France to the United States, India or another third country.

Hosting in Europe Does Not Always Eliminate Transfer Risk

A provider may host data in France while support staff access it from outside the EEA, logs are processed globally, backups are replicated abroad or non-EEA subprocessors receive access.

Organisations should therefore map actual data flows, access locations and processing relationships rather than rely solely on marketing claims such as “EU hosting.”

The GDPR International Transfer Framework

GDPR does not rely on a single method for transferring personal data outside the EEA. Instead, Chapter V provides several legal pathways depending on the destination, relationship and circumstances of the transfer.

The main mechanisms include adequacy decisions under Article 45, appropriate safeguards under Article 46, Binding Corporate Rules for certain intra-group transfers and limited derogations under Article 49. The European Commission provides an official overview of these rules on international data transfers.

Follow a Hierarchy Rather Than Choosing a Mechanism Randomly

Organisations should first determine whether the destination is covered by a valid adequacy decision.

If no adequacy decision applies, the next step is to assess whether an Article 46 safeguard can be used, such as Standard Contractual Clauses or Binding Corporate Rules.

Article 49 derogations should generally be treated as exceptional mechanisms for specific circumstances rather than as the default basis for routine or repetitive business transfers.

The Transfer Mechanism Is Only One Part of Compliance

A valid transfer mechanism does not make the wider processing operation automatically compliant.

Organisations must still satisfy general GDPR requirements relating to lawfulness, transparency, purpose limitation, data minimisation, security, processor governance and accountability.

For example, signing SCCs does not make an excessive, insecure or otherwise unlawful processing activity compliant. The transfer mechanism addresses the international-transfer element, while the underlying processing must independently satisfy the rest of the GDPR.

Data transfer GDPR France infographic showing the decision path for international transfers, including EEA checks, adequacy decisions, SCCs, BCRs, TIAs, supplementary safeguards, and Article 49 derogations.

Adequacy Decisions Explained

Under Article 45 of GDPR, the European Commission may determine that a third country, territory, specified sector or international organisation provides an adequate level of protection for personal data.

Where a valid adequacy decision applies, personal data can generally be transferred to the covered destination without using a separate Article 46 mechanism such as Standard Contractual Clauses or Binding Corporate Rules. The European Commission maintains the current list of adequacy decisions.

What Adequacy Does Not Mean

An adequacy decision does not remove the organisation’s wider GDPR responsibilities.

The controller must still assess whether the underlying processing is lawful, whether the recipient actually falls within the scope of the adequacy decision, whether appropriate processor arrangements are in place and whether the personal data being transferred is necessary for the stated purpose.

Adequacy addresses the international-transfer mechanism. It does not make unrelated GDPR requirements disappear.

Check Current Status

Adequacy decisions should not be treated as permanent assumptions. They may be reviewed, renewed, amended or affected by legal and regulatory developments.

Organisations should therefore maintain an up-to-date record of which destinations and recipients are covered and periodically verify that the transfer basis remains valid.

This is especially important for recurring transfers and long-term supplier relationships, where an outdated “safe country” classification could leave the organisation relying on an obsolete transfer assessment.

Data Protection Officer (DPO) Training

Build Practical GDPR and Data Protection Expertise

Strengthen your understanding of GDPR governance, data protection responsibilities, privacy risk management, and DPO oversight. Develop practical knowledge to support stronger compliance decisions and responsible handling of personal data across your organisation.

Explore DPO Training →

Schrems II Explained

Schrems II remains one of the most important judgments shaping international data transfers under GDPR. On 16 July 2020, the Court of Justice of the European Union issued its decision in Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems.

The judgment had two major consequences. First, it invalidated the former EU-US Privacy Shield adequacy decision. Second, it confirmed that Standard Contractual Clauses can remain a valid transfer mechanism, but organisations cannot rely on SCCs mechanically.

Data exporters must assess whether the laws and practices of the destination country allow the safeguards contained in the SCCs to provide an essentially equivalent level of protection in practice. Where those safeguards are insufficient, additional measures may be required.

Schrems II Did Not Ban International Transfers

Schrems II did not create a general prohibition on transfers to the United States or other third countries.

Instead, it required organisations using mechanisms such as SCCs to examine the specific transfer context and determine whether third-country laws or government-access practices could undermine the contractual protections being relied upon.

Why Schrems II Still Matters

The judgment remains central to Transfer Impact Assessments, supplementary measures, SCC implementation, vendor due diligence and government-access risk assessments.

The later EU-US Data Privacy Framework changed the legal basis available for certain US transfers, but it did not make Schrems II irrelevant. Organisations relying on Article 46 safeguards must still assess whether their chosen transfer mechanism provides effective protection in the circumstances of the transfer.

Standard Contractual Clauses Explained

Standard Contractual Clauses, or SCCs, are contractual clauses adopted by the European Commission that can provide appropriate safeguards under Article 46 of GDPR for certain transfers of personal data to recipients outside the EEA.

The Commission adopted the current modernised SCCs in June 2021. These clauses are designed to address different transfer relationships and incorporate requirements shaped by GDPR and the Schrems II judgment. The official framework is available through the European Commission’s Standard Contractual Clauses for international transfers.

The SCC Modular Structure

The modern SCCs use different modules depending on the GDPR roles of the exporter and importer.

Transfer relationship

SCC module

Controller to controller

Module 1

Controller to processor

Module 2

Processor to processor

Module 3

Processor to controller

Module 4

Organisations should select the correct module based on the parties’ actual GDPR roles rather than relying only on contractual labels.

Completing SCCs Correctly

SCCs must be completed carefully. Relevant information includes the parties, transfer description, categories of personal data, data subjects, processing purposes, retention arrangements, security measures, competent supervisory authority and subprocessor details where applicable.

Incomplete or generic annexes can weaken the organisation’s ability to demonstrate that the transfer has been properly assessed.

Do SCCs Automatically Make a Transfer Lawful?

No. Signing SCCs does not automatically make every international transfer compliant.

Organisations must still assess the transfer context, including relevant third-country laws and practices. Where the SCCs do not provide sufficient protection on their own, supplementary technical, contractual or organisational safeguards may be required.

What Is a Transfer Impact Assessment?

A Transfer Impact Assessment, or TIA, evaluates whether personal data transferred outside the EEA using an Article 46 mechanism will receive protection that is essentially equivalent to the level guaranteed under EU law.

The CNIL published the final version of its practical TIA guide on 9 July 2025. The CNIL guidance provides a methodology for assessing the transfer, the destination country’s laws and practices, and whether supplementary measures are needed.

When Is a TIA Required?

According to the CNIL, an exporter subject to GDPR, whether acting as controller or processor, must carry out a TIA before transferring personal data outside the EEA where the transfer relies on an Article 46 tool such as SCCs or Binding Corporate Rules. The importer should assist with the assessment.

The main exceptions are transfers covered by a valid adequacy decision and transfers relying on an applicable Article 49 derogation. The official CNIL Transfer Impact Assessment guide explains this framework.

What the TIA Should Assess

The process starts by describing the transfer and identifying the legal transfer mechanism. The exporter should then assess the laws and practices of the destination country that could affect the effectiveness of those safeguards, including potential government access.

Next, assess whether supplementary technical, contractual or organisational measures are necessary. The decision should be documented and reassessed periodically as laws, practices or transfer circumstances change.

The Importer Must Cooperate

Exporters often need information from vendors or group entities about government-access requests, technical architecture, data locations, encryption, transparency practices and internal policies.

Unsupported assurances such as “we comply with GDPR” are not enough. The assessment should rely on evidence capable of supporting the exporter’s documented conclusion.

Supplementary Measures After Schrems II

Supplementary measures may be necessary where the transfer mechanism used under Article 46 does not provide sufficient protection on its own in the specific circumstances of an international transfer.

Following Schrems II, organisations should assess whether additional technical, contractual or organisational safeguards can bring protection to an essentially equivalent level. The EDPB’s official Recommendations 01/2020 on supplementary measures provide a structured methodology for this assessment.

Technical Measures

Technical safeguards may include strong encryption, effective control of encryption keys, pseudonymisation, data minimisation and split processing.

Encryption is most useful where the threat being addressed cannot realistically bypass it. For example, protection may be weakened if the data importer or authorities in the destination country can obtain both the encrypted data and the keys needed to decrypt it.

Contractual and Organisational Safeguards

Additional measures can include government-access notification commitments, transparency obligations, procedures for challenging disclosure requests, internal access restrictions and documented security policies.

However, contractual promises cannot neutralise conflicting third-country law on their own. They should support, not replace, effective technical and organisational protections.

When Supplementary Measures Are Insufficient

If the organisation cannot establish effective protection after assessing the transfer and available safeguards, it may need to suspend the transfer, restructure the processing, change providers or adopt a different technical architecture.

The objective is not to accumulate safeguards, but to demonstrate that the measures actually address the identified transfer risk.

EU-US Data Transfers After Schrems II

The European Commission adopted the EU-US Data Privacy Framework adequacy decision on 10 July 2023. Where a US recipient participates in and is covered by the framework, personal data can be transferred from the EEA based on that adequacy decision without relying on SCCs for that covered transfer.

Verify the Recipient

Organisations should not assume that every US company is automatically covered. Before relying on the framework, verify that the recipient is an active participant and confirm that the relevant type of data and processing activity fall within the scope of its certification. The official Data Privacy Framework list distinguishes active and inactive participants and provides certification details.

What if the US Recipient Is Not Covered?

Other GDPR transfer mechanisms may still be available. For example, organisations may be able to rely on SCCs where the legal conditions are met. In that situation, the exporter should complete the required transfer assessment and consider supplementary safeguards where necessary rather than treating the Data Privacy Framework as a blanket solution for all US transfers.

Keep US Transfers Under Review

US transfer arrangements should be monitored over time. Relevant changes include the recipient’s certification status, the transfer mechanism being used, regulatory developments and major court decisions that could affect the framework.

The European Commission’s official EU-US data transfer framework should be used as a primary reference for the current legal position. The Commission also conducts periodic reviews of the framework’s functioning.

Binding Corporate Rules

Binding Corporate Rules, or BCRs, are an Article 46 transfer mechanism designed primarily for international transfers of personal data within multinational corporate groups or groups of enterprises engaged in a joint economic activity.

They can be particularly useful where personal data moves regularly between affiliated entities across several jurisdictions. Instead of managing each recurring intra-group transfer through separate contractual arrangements, BCRs create a broader governance framework covering how personal data is protected across the group.

Why BCRs Differ from SCCs

Standard Contractual Clauses are contractual tools used for specific transfer relationships between data exporters and importers.

BCRs operate differently. They establish group-wide rules governing international data transfers and require approval through the applicable supervisory-authority process before they can be relied upon as a transfer mechanism.

Because BCR implementation involves significant governance, documentation, coordination and regulatory review, it is generally more resource-intensive than using SCCs.

For large multinational groups with frequent internal transfers, that investment may be justified. For an organisation making only occasional international transfers, however, SCCs or another appropriate mechanism will usually be more practical.

Article 49 Derogations

GDPR Article 49 provides a limited set of derogations that may permit international data transfers in specific circumstances where an adequacy decision or Article 46 safeguard is not available.

Depending on the situation, these can include explicit consent, necessity for the performance or conclusion of certain contracts, important reasons of public interest, establishment or defence of legal claims, protection of vital interests and certain transfers from public registers.

These derogations are subject to specific legal conditions and should be applied carefully.

Do Not Use Derogations as Routine Transfer Mechanisms

Article 49 derogations are not intended to replace adequacy decisions, SCCs, Binding Corporate Rules or other Article 46 safeguards for normal, systematic or repetitive business transfers.

For example, an organisation should not rely on employee consent as a convenient basis for a recurring global HR transfer without first assessing whether the consent is genuinely explicit, informed and freely given, and whether the relevant Article 49 conditions are satisfied.

In practice, organisations should document why a derogation applies, limit its use to the specific circumstances allowed by GDPR and avoid treating Article 49 as a general alternative to structured international transfer mechanisms.

Processor and Subprocessor Transfers

Processors frequently create international transfer exposure through the subprocessors they use to deliver services. Common examples include cloud hosting, technical support, analytics, security monitoring, customer service and software infrastructure.

For French organisations, this means the transfer analysis should extend beyond the primary vendor. A processor may be established in the EEA while relying on subprocessors or support teams located elsewhere.

Review the Complete Processing Chain

Organisations should know where the processor is established, which subprocessors are involved, where personal data can be accessed, which transfer mechanism applies to each relevant transfer and how changes to the processing chain are communicated.

This is particularly important where multiple vendors participate in the same service.

Article 28 and Chapter V Work Together

A compliant Article 28 data processing agreement does not remove the need to comply with GDPR Chapter V where personal data is transferred outside the EEA.

Likewise, having SCCs in place does not replace the processor-contract requirements that govern processing instructions, confidentiality, security and subprocessor use. Both sets of obligations must be addressed.

Subprocessor Changes

Organisations should establish a review process for new countries, new vendors, changed transfer mechanisms and material changes in processing.

This is especially important for cloud and SaaS providers, where subprocessor lists may change over time and create new transfer risks that were not present during the original assessment.

International Transfers Through Cloud Services

Cloud architecture can make international data transfers difficult to identify because personal data may move through several technical and operational layers even when the primary hosting location is in Europe.

Organisations should review more than the main data centre. Relevant transfer points may include disaster-recovery environments, backups, technical support locations, security operations, subprocessors, telemetry services and administrative access.

EU Data Residency Is Not the Whole Analysis

An EU-hosted cloud service may still involve an international transfer where personal data is made available to a separate recipient outside the EEA.

For example, a provider may store production data in France while allowing non-EEA support personnel to access the environment, processing logs through a global security platform or relying on overseas subprocessors.

The correct assessment should therefore follow the actual data flow and access model rather than rely only on an “EU data residency” commitment.

Procurement Questions

Before onboarding a cloud provider, organisations should determine where data is stored, where support personnel are located, which subprocessors are involved and which transfer mechanisms apply.

Procurement and privacy teams should also confirm whether SCCs are available where required, how the provider supports Transfer Impact Assessments, what information it provides about government-access requests and how changes to subprocessors or data locations are communicated.

Building these questions into supplier onboarding helps identify transfer risks before the cloud service becomes operational.

Data Transfer Mapping and Records

Organisations cannot manage international data transfers effectively without knowing where those transfers occur. A strong compliance programme should therefore begin with existing GDPR documentation and expand it into a clear picture of cross-border data flows.

Useful starting points include records of processing activities, processor and subprocessor lists, cloud inventories, HR platforms, customer systems, marketing tools, security services and group-company data flows. These sources can help identify transfers that may otherwise remain hidden inside routine business processes.

Build a Transfer Register

For each material transfer, record the data exporter and importer, countries involved, GDPR roles, processing purpose, categories of personal data, affected individuals, transfer mechanism, TIA status, supplementary measures and next review date.

The register should also identify which processor or subprocessor relationship supports the transfer and where supporting contracts or assessments are stored.

Prioritise Critical Transfers

Where resources are limited, organisations should prioritise transfers that present the highest privacy or regulatory risk.

This may include transfers involving sensitive data, large data volumes, children, employees, health information, systematic monitoring or destinations presenting greater legal or government-access concerns.

A current transfer register creates a practical foundation for reviewing SCCs, completing TIAs, monitoring subprocessors and demonstrating accountability to internal stakeholders or supervisory authorities.

The DPO's Role in International Data Transfers

The Data Protection Officer should provide independent advice and monitoring on international data transfers rather than personally owning every operational decision.

Relevant DPO activities may include reviewing transfer inventories, advising on the appropriate transfer mechanism, reviewing Transfer Impact Assessments, monitoring vendor assessments, advising on supplementary measures and checking whether transfer documentation remains current and complete.

The DPO should also help ensure that transfer decisions are consistent with wider GDPR principles, including accountability, transparency, security and processor governance.

Procurement and Legal Teams Also Matter

International transfers are inherently cross-functional. Procurement may manage supplier onboarding, IT may understand system architecture and access locations, security may assess encryption and other technical safeguards, while legal teams may review SCCs and contractual terms.

The DPO's role is to connect these activities to GDPR requirements and challenge gaps where necessary.

Escalate High-Risk Transfers

Some transfers should receive enhanced review before approval. Examples include transfers involving sensitive data, complex destination-country laws, major outsourcing arrangements, significant government-access concerns or situations where effective supplementary measures cannot be implemented.

Clear escalation criteria help prevent high-risk transfers from being approved through routine procurement processes without sufficient privacy assessment.

Practical Data Transfer Compliance Process

A practical international data transfer programme should follow a consistent sequence so that legal mechanisms, risk assessments and operational controls remain connected.

Step 1: Map Transfers

Identify personal data leaving the EEA or being made accessible to separate recipients outside the EEA. Include remote access, cloud services, subprocessors and intra-group transfers.

Step 2: Verify GDPR Roles

Confirm whether each party acts as controller, processor or subprocessor for the relevant processing activity.

Step 3: Identify the Transfer Mechanism

Check first whether a valid adequacy decision applies. If not, consider Article 46 safeguards such as SCCs or Binding Corporate Rules.

Step 4: Complete a TIA Where Required

Assess the destination country's legal environment, government-access risks and the practical circumstances of the transfer.

Step 5: Introduce Supplementary Measures

Where necessary, add technical, organisational or contractual safeguards capable of addressing identified risks.

Step 6: Complete Documentation

Finalise SCC annexes, processor contracts, transfer records, TIAs, supplementary-measure assessments and approval evidence.

Step 7: Inform Data Subjects Where Required

Ensure privacy notices accurately describe relevant international transfers and the safeguards relied upon.

Step 8: Monitor Changes

Review changes in countries, subprocessors, provider terms, adequacy decisions, court judgments, government access practices, and technical architecture.

Step 9: Suspend Transfers Where Protection Becomes Inadequate

Define escalation and suspension procedures in advance. If effective protection can no longer be demonstrated, the organisation should be prepared to pause the transfer, change the provider or redesign the processing arrangement.

This sequence helps turn GDPR Chapter V requirements into a repeatable operational process rather than a one-time contractual exercise.

Data transfer GDPR France infographic showing a six-step compliance roadmap to map transfers, verify roles, select safeguards, assess TIAs, protect data, monitor changes, and review or suspend transfers.

GDPR International Data Transfer Checklist

Use this compact checklist to confirm that international data transfers are identified, legally supported and documented.

Mapping and scope: Have all international transfers been identified? Does the review include remote access, cloud providers, subprocessors, SaaS platforms, group-company transfers and overseas support teams? Are the exporter, importer and countries involved clearly recorded?

Mechanism and assessment: Is each transfer covered by a valid adequacy decision, SCCs, Binding Corporate Rules or an applicable Article 49 derogation? Has a Transfer Impact Assessment been completed where required? Where risks remain, are supplementary technical, contractual or organisational measures effective?

Contracts and evidence: Are SCCs completed with accurate annexes? Are Article 28 processor terms in place where required? Are importer and subprocessor commitments documented? Can the organisation demonstrate why the selected transfer mechanism and safeguards are appropriate?

Monitoring: Does each material transfer have a review date? Are changes in recipients, processing locations, destination-country law, adequacy status, subprocessors and technical architecture monitored?

A strong checklist should lead to current evidence. If a transfer cannot be supported by valid documentation and effective safeguards, it should be escalated for remediation before continuing.

Common International Data Transfer Mistakes

Assuming No Transfer Occurs Because Data Is Hosted in Europe

EU hosting does not automatically eliminate international transfer risk. Better approach: review remote access, overseas support teams, subprocessors, backups and other processing locations.

Signing SCCs Without Completing a Transfer Assessment

SCCs are not a complete compliance solution by themselves. Better approach: assess the transfer context, destination-country laws and practical risks where required.

Relying on Outdated SCCs or Privacy Shield References

Old contractual language or references to the former EU-US Privacy Shield can create serious compliance gaps. Better approach: use current European Commission transfer mechanisms.

Treating All US Companies as Covered by the Data Privacy Framework

Not every US recipient participates in the framework. Better approach: verify the organisation’s active certification and relevant coverage.

Using Article 49 Derogations for Routine Transfers

Derogations are not intended as a default mechanism for repetitive business transfers. Better approach: use them only where the specific legal conditions are genuinely satisfied.

Completing a TIA Once and Never Reviewing It

Transfer risks can change. Better approach: reassess material changes in laws, providers, subprocessors and processing.

Allowing Procurement to Sign International Contracts Without Privacy Review

Supplier onboarding can create hidden transfer exposure. Better approach: build international transfer assessment into procurement and contract approval.

Build Stronger Data Protection Expertise

Turn GDPR Transfer Rules into Practical Compliance Decisions

International data transfers require more than adding contractual clauses to supplier agreements. Privacy professionals need to understand GDPR roles, transfer mechanisms, Transfer Impact Assessments, processor relationships, risk evaluation and regulatory expectations.

The French Compliance Institute’s Data Protection Officer (DPO) Training helps professionals build practical knowledge of GDPR governance, data-protection responsibilities and compliance processes.

This knowledge can support stronger oversight of international transfers, cloud providers, processors, subprocessors and cross-border data flows.

The training should form part of a wider professional development and compliance framework rather than be treated as a guarantee of GDPR compliance or universal DPO competence.

Conclusion

International transfers of personal data are permitted under GDPR, but organisations must identify each transfer and apply the correct Chapter V mechanism.

Adequacy decisions can simplify covered transfers, while SCCs and other Article 46 safeguards require closer assessment. Schrems II remains relevant because organisations must consider whether destination-country laws and practices could undermine contractual protections. For French organisations, CNIL guidance on Transfer Impact Assessments provides a practical structure for documenting that analysis.

Cloud providers and subprocessors require particular attention because access and processing may occur across multiple jurisdictions.

Organizations should maintain a current transfer register, complete SCCs accurately, document TIAs, implement effective supplementary measures where necessary, and reassess transfers when circumstances change.

Organizations that combine accurate data-flow mapping, appropriate transfer mechanisms, and documented risk assessments will be better positioned to demonstrate compliant international data transfers under GDPR.

Frequently Asked Questions

Yes. Personal data can be transferred outside France. Transfers within the European Economic Area generally do not require a separate GDPR Chapter V transfer mechanism. Transfers to recipients outside the EEA must comply with the applicable international transfer requirements, including adequacy decisions, appropriate safeguards or a valid derogation.

No. GDPR does not prohibit international data transfers. Organisations may transfer personal data outside the EEA where the conditions in Chapter V are satisfied. The correct mechanism depends on the destination, recipient, GDPR roles and circumstances of the transfer.

Schrems II invalidated the former EU-US Privacy Shield and reinforced the need to assess whether Article 46 safeguards work effectively in the destination country. Organisations relying on mechanisms such as SCCs must consider whether local laws or practices could undermine the protection provided.

Yes. SCCs remain a valid GDPR transfer mechanism. However, exporters cannot rely on them mechanically. They may need to assess destination-country laws and practices through a Transfer Impact Assessment and introduce supplementary safeguards where contractual protections are insufficient.

A Transfer Impact Assessment evaluates whether personal data transferred using an Article 46 mechanism will receive protection that is essentially equivalent to EU standards. It considers the transfer mechanism, the destination-country legal environment, practical government access risks, and any supplementary measures required.

No. Under CNIL guidance, TIAs are particularly relevant where a transfer relies on an Article 46 safeguard such as SCCs or Binding Corporate Rules. Transfers covered by a valid adequacy decision or certain applicable Article 49 derogations follow different transfer requirements.

Yes. Transfers to the United States may rely on the EU-US Data Privacy Framework where the recipient is properly certified and covered. Where it is not, another valid mechanism, such as SCCs, may be available subject to the required assessment.

Generally no. Where a valid Article 45 adequacy decision covers the destination and recipient, that decision provides the Chapter V basis for the transfer. Organisations must still comply with the wider GDPR requirements governing the underlying processing.

A French DPO should start with the organisation’s international transfer inventory, processor and subprocessor chain, countries involved and transfer mechanisms being used. Particular attention should be given to transfers relying on SCCs where no current, documented TIA or supplementary-measure assessment exists.