Restaurant Food Safety Checklist: What Managers Should Check in France
Restaurant food safety is an everyday management responsibility. Controls can weaken during a busy service, when a delivery arrives late, equipment fails, a recipe changes...
Data transfer under GDPR in France requires the right legal mechanism, risk assessment, and safeguards. Learn how adequacy decisions, SCCs, Schrems II, TIAs, CNIL guidance, cloud services, and subprocessors shape compliant international transfers in practice.
Organisations in France routinely transfer personal data across borders through cloud services, global HR systems, SaaS platforms, customer databases, analytics tools and group-company infrastructure. These transfers are often underestimated because data may appear to remain hosted in Europe while being accessed, supported or otherwise processed from another country.
Managing data transfer under GDPR in France requires organisations to identify transfers outside the EEA, determine the correct legal mechanism and assess whether personal data will receive an essentially equivalent level of protection.
GDPR Chapter V provides the core framework. Depending on the destination and circumstances, organisations may need to consider adequacy decisions, Standard Contractual Clauses (SCCs), Schrems II requirements, Transfer Impact Assessments, supplementary measures, US transfer mechanisms and processor or subprocessor arrangements.
CNIL expectations, accurate documentation and ongoing monitoring are also central to effective compliance.
International transfers are not automatically prohibited under GDPR. They are permitted where the applicable transfer conditions are satisfied and the organisation can demonstrate that appropriate safeguards and accountability measures are in place.
An international transfer issue can arise when personal data protected by the General Data Protection Regulation, Regulation (EU) 2016/679 is made available to a separate controller or processor located in a third country or international organisation.
The analysis should not focus only on the physical location of the server. Transfers can also occur through remote access or onward processing. Examples include a non-EEA support team accessing an EU system, employee records being shared with an overseas parent company, use of a non-EEA SaaS provider, engagement of an international processor or access by a foreign subcontractor.
GDPR Chapter V, particularly Articles 44 to 49, governs transfers outside the European Economic Area, not simply transfers outside France.
A transfer from France to Germany or Spain therefore differs from a transfer from France to the United States, India or another third country.
A provider may host data in France while support staff access it from outside the EEA, logs are processed globally, backups are replicated abroad or non-EEA subprocessors receive access.
Organisations should therefore map actual data flows, access locations and processing relationships rather than rely solely on marketing claims such as “EU hosting.”
GDPR does not rely on a single method for transferring personal data outside the EEA. Instead, Chapter V provides several legal pathways depending on the destination, relationship and circumstances of the transfer.
The main mechanisms include adequacy decisions under Article 45, appropriate safeguards under Article 46, Binding Corporate Rules for certain intra-group transfers and limited derogations under Article 49. The European Commission provides an official overview of these rules on international data transfers.
Organisations should first determine whether the destination is covered by a valid adequacy decision.
If no adequacy decision applies, the next step is to assess whether an Article 46 safeguard can be used, such as Standard Contractual Clauses or Binding Corporate Rules.
Article 49 derogations should generally be treated as exceptional mechanisms for specific circumstances rather than as the default basis for routine or repetitive business transfers.
A valid transfer mechanism does not make the wider processing operation automatically compliant.
Organisations must still satisfy general GDPR requirements relating to lawfulness, transparency, purpose limitation, data minimisation, security, processor governance and accountability.
For example, signing SCCs does not make an excessive, insecure or otherwise unlawful processing activity compliant. The transfer mechanism addresses the international-transfer element, while the underlying processing must independently satisfy the rest of the GDPR.

Under Article 45 of GDPR, the European Commission may determine that a third country, territory, specified sector or international organisation provides an adequate level of protection for personal data.
Where a valid adequacy decision applies, personal data can generally be transferred to the covered destination without using a separate Article 46 mechanism such as Standard Contractual Clauses or Binding Corporate Rules. The European Commission maintains the current list of adequacy decisions.
An adequacy decision does not remove the organisation’s wider GDPR responsibilities.
The controller must still assess whether the underlying processing is lawful, whether the recipient actually falls within the scope of the adequacy decision, whether appropriate processor arrangements are in place and whether the personal data being transferred is necessary for the stated purpose.
Adequacy addresses the international-transfer mechanism. It does not make unrelated GDPR requirements disappear.
Adequacy decisions should not be treated as permanent assumptions. They may be reviewed, renewed, amended or affected by legal and regulatory developments.
Organisations should therefore maintain an up-to-date record of which destinations and recipients are covered and periodically verify that the transfer basis remains valid.
This is especially important for recurring transfers and long-term supplier relationships, where an outdated “safe country” classification could leave the organisation relying on an obsolete transfer assessment.
Build Practical GDPR and Data Protection Expertise
Strengthen your understanding of GDPR governance, data protection responsibilities, privacy risk management, and DPO oversight. Develop practical knowledge to support stronger compliance decisions and responsible handling of personal data across your organisation.
Explore DPO Training →Schrems II remains one of the most important judgments shaping international data transfers under GDPR. On 16 July 2020, the Court of Justice of the European Union issued its decision in Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems.
The judgment had two major consequences. First, it invalidated the former EU-US Privacy Shield adequacy decision. Second, it confirmed that Standard Contractual Clauses can remain a valid transfer mechanism, but organisations cannot rely on SCCs mechanically.
Data exporters must assess whether the laws and practices of the destination country allow the safeguards contained in the SCCs to provide an essentially equivalent level of protection in practice. Where those safeguards are insufficient, additional measures may be required.
Schrems II did not create a general prohibition on transfers to the United States or other third countries.
Instead, it required organisations using mechanisms such as SCCs to examine the specific transfer context and determine whether third-country laws or government-access practices could undermine the contractual protections being relied upon.
The judgment remains central to Transfer Impact Assessments, supplementary measures, SCC implementation, vendor due diligence and government-access risk assessments.
The later EU-US Data Privacy Framework changed the legal basis available for certain US transfers, but it did not make Schrems II irrelevant. Organisations relying on Article 46 safeguards must still assess whether their chosen transfer mechanism provides effective protection in the circumstances of the transfer.
Standard Contractual Clauses, or SCCs, are contractual clauses adopted by the European Commission that can provide appropriate safeguards under Article 46 of GDPR for certain transfers of personal data to recipients outside the EEA.
The Commission adopted the current modernised SCCs in June 2021. These clauses are designed to address different transfer relationships and incorporate requirements shaped by GDPR and the Schrems II judgment. The official framework is available through the European Commission’s Standard Contractual Clauses for international transfers.
The modern SCCs use different modules depending on the GDPR roles of the exporter and importer.
|
Transfer relationship |
SCC module |
|
Controller to controller |
Module 1 |
|
Controller to processor |
Module 2 |
|
Processor to processor |
Module 3 |
|
Processor to controller |
Module 4 |
Organisations should select the correct module based on the parties’ actual GDPR roles rather than relying only on contractual labels.
SCCs must be completed carefully. Relevant information includes the parties, transfer description, categories of personal data, data subjects, processing purposes, retention arrangements, security measures, competent supervisory authority and subprocessor details where applicable.
Incomplete or generic annexes can weaken the organisation’s ability to demonstrate that the transfer has been properly assessed.
No. Signing SCCs does not automatically make every international transfer compliant.
Organisations must still assess the transfer context, including relevant third-country laws and practices. Where the SCCs do not provide sufficient protection on their own, supplementary technical, contractual or organisational safeguards may be required.
A Transfer Impact Assessment, or TIA, evaluates whether personal data transferred outside the EEA using an Article 46 mechanism will receive protection that is essentially equivalent to the level guaranteed under EU law.
The CNIL published the final version of its practical TIA guide on 9 July 2025. The CNIL guidance provides a methodology for assessing the transfer, the destination country’s laws and practices, and whether supplementary measures are needed.
According to the CNIL, an exporter subject to GDPR, whether acting as controller or processor, must carry out a TIA before transferring personal data outside the EEA where the transfer relies on an Article 46 tool such as SCCs or Binding Corporate Rules. The importer should assist with the assessment.
The main exceptions are transfers covered by a valid adequacy decision and transfers relying on an applicable Article 49 derogation. The official CNIL Transfer Impact Assessment guide explains this framework.
The process starts by describing the transfer and identifying the legal transfer mechanism. The exporter should then assess the laws and practices of the destination country that could affect the effectiveness of those safeguards, including potential government access.
Next, assess whether supplementary technical, contractual or organisational measures are necessary. The decision should be documented and reassessed periodically as laws, practices or transfer circumstances change.
Exporters often need information from vendors or group entities about government-access requests, technical architecture, data locations, encryption, transparency practices and internal policies.
Unsupported assurances such as “we comply with GDPR” are not enough. The assessment should rely on evidence capable of supporting the exporter’s documented conclusion.
Supplementary measures may be necessary where the transfer mechanism used under Article 46 does not provide sufficient protection on its own in the specific circumstances of an international transfer.
Following Schrems II, organisations should assess whether additional technical, contractual or organisational safeguards can bring protection to an essentially equivalent level. The EDPB’s official Recommendations 01/2020 on supplementary measures provide a structured methodology for this assessment.
Technical safeguards may include strong encryption, effective control of encryption keys, pseudonymisation, data minimisation and split processing.
Encryption is most useful where the threat being addressed cannot realistically bypass it. For example, protection may be weakened if the data importer or authorities in the destination country can obtain both the encrypted data and the keys needed to decrypt it.
Additional measures can include government-access notification commitments, transparency obligations, procedures for challenging disclosure requests, internal access restrictions and documented security policies.
However, contractual promises cannot neutralise conflicting third-country law on their own. They should support, not replace, effective technical and organisational protections.
If the organisation cannot establish effective protection after assessing the transfer and available safeguards, it may need to suspend the transfer, restructure the processing, change providers or adopt a different technical architecture.
The objective is not to accumulate safeguards, but to demonstrate that the measures actually address the identified transfer risk.
The European Commission adopted the EU-US Data Privacy Framework adequacy decision on 10 July 2023. Where a US recipient participates in and is covered by the framework, personal data can be transferred from the EEA based on that adequacy decision without relying on SCCs for that covered transfer.
Organisations should not assume that every US company is automatically covered. Before relying on the framework, verify that the recipient is an active participant and confirm that the relevant type of data and processing activity fall within the scope of its certification. The official Data Privacy Framework list distinguishes active and inactive participants and provides certification details.
Other GDPR transfer mechanisms may still be available. For example, organisations may be able to rely on SCCs where the legal conditions are met. In that situation, the exporter should complete the required transfer assessment and consider supplementary safeguards where necessary rather than treating the Data Privacy Framework as a blanket solution for all US transfers.
US transfer arrangements should be monitored over time. Relevant changes include the recipient’s certification status, the transfer mechanism being used, regulatory developments and major court decisions that could affect the framework.
The European Commission’s official EU-US data transfer framework should be used as a primary reference for the current legal position. The Commission also conducts periodic reviews of the framework’s functioning.
Binding Corporate Rules, or BCRs, are an Article 46 transfer mechanism designed primarily for international transfers of personal data within multinational corporate groups or groups of enterprises engaged in a joint economic activity.
They can be particularly useful where personal data moves regularly between affiliated entities across several jurisdictions. Instead of managing each recurring intra-group transfer through separate contractual arrangements, BCRs create a broader governance framework covering how personal data is protected across the group.
Standard Contractual Clauses are contractual tools used for specific transfer relationships between data exporters and importers.
BCRs operate differently. They establish group-wide rules governing international data transfers and require approval through the applicable supervisory-authority process before they can be relied upon as a transfer mechanism.
Because BCR implementation involves significant governance, documentation, coordination and regulatory review, it is generally more resource-intensive than using SCCs.
For large multinational groups with frequent internal transfers, that investment may be justified. For an organisation making only occasional international transfers, however, SCCs or another appropriate mechanism will usually be more practical.
GDPR Article 49 provides a limited set of derogations that may permit international data transfers in specific circumstances where an adequacy decision or Article 46 safeguard is not available.
Depending on the situation, these can include explicit consent, necessity for the performance or conclusion of certain contracts, important reasons of public interest, establishment or defence of legal claims, protection of vital interests and certain transfers from public registers.
These derogations are subject to specific legal conditions and should be applied carefully.
Article 49 derogations are not intended to replace adequacy decisions, SCCs, Binding Corporate Rules or other Article 46 safeguards for normal, systematic or repetitive business transfers.
For example, an organisation should not rely on employee consent as a convenient basis for a recurring global HR transfer without first assessing whether the consent is genuinely explicit, informed and freely given, and whether the relevant Article 49 conditions are satisfied.
In practice, organisations should document why a derogation applies, limit its use to the specific circumstances allowed by GDPR and avoid treating Article 49 as a general alternative to structured international transfer mechanisms.
Processors frequently create international transfer exposure through the subprocessors they use to deliver services. Common examples include cloud hosting, technical support, analytics, security monitoring, customer service and software infrastructure.
For French organisations, this means the transfer analysis should extend beyond the primary vendor. A processor may be established in the EEA while relying on subprocessors or support teams located elsewhere.
Organisations should know where the processor is established, which subprocessors are involved, where personal data can be accessed, which transfer mechanism applies to each relevant transfer and how changes to the processing chain are communicated.
This is particularly important where multiple vendors participate in the same service.
A compliant Article 28 data processing agreement does not remove the need to comply with GDPR Chapter V where personal data is transferred outside the EEA.
Likewise, having SCCs in place does not replace the processor-contract requirements that govern processing instructions, confidentiality, security and subprocessor use. Both sets of obligations must be addressed.
Organisations should establish a review process for new countries, new vendors, changed transfer mechanisms and material changes in processing.
This is especially important for cloud and SaaS providers, where subprocessor lists may change over time and create new transfer risks that were not present during the original assessment.
Cloud architecture can make international data transfers difficult to identify because personal data may move through several technical and operational layers even when the primary hosting location is in Europe.
Organisations should review more than the main data centre. Relevant transfer points may include disaster-recovery environments, backups, technical support locations, security operations, subprocessors, telemetry services and administrative access.
An EU-hosted cloud service may still involve an international transfer where personal data is made available to a separate recipient outside the EEA.
For example, a provider may store production data in France while allowing non-EEA support personnel to access the environment, processing logs through a global security platform or relying on overseas subprocessors.
The correct assessment should therefore follow the actual data flow and access model rather than rely only on an “EU data residency” commitment.
Before onboarding a cloud provider, organisations should determine where data is stored, where support personnel are located, which subprocessors are involved and which transfer mechanisms apply.
Procurement and privacy teams should also confirm whether SCCs are available where required, how the provider supports Transfer Impact Assessments, what information it provides about government-access requests and how changes to subprocessors or data locations are communicated.
Building these questions into supplier onboarding helps identify transfer risks before the cloud service becomes operational.
Organisations cannot manage international data transfers effectively without knowing where those transfers occur. A strong compliance programme should therefore begin with existing GDPR documentation and expand it into a clear picture of cross-border data flows.
Useful starting points include records of processing activities, processor and subprocessor lists, cloud inventories, HR platforms, customer systems, marketing tools, security services and group-company data flows. These sources can help identify transfers that may otherwise remain hidden inside routine business processes.
For each material transfer, record the data exporter and importer, countries involved, GDPR roles, processing purpose, categories of personal data, affected individuals, transfer mechanism, TIA status, supplementary measures and next review date.
The register should also identify which processor or subprocessor relationship supports the transfer and where supporting contracts or assessments are stored.
Where resources are limited, organisations should prioritise transfers that present the highest privacy or regulatory risk.
This may include transfers involving sensitive data, large data volumes, children, employees, health information, systematic monitoring or destinations presenting greater legal or government-access concerns.
A current transfer register creates a practical foundation for reviewing SCCs, completing TIAs, monitoring subprocessors and demonstrating accountability to internal stakeholders or supervisory authorities.
The Data Protection Officer should provide independent advice and monitoring on international data transfers rather than personally owning every operational decision.
Relevant DPO activities may include reviewing transfer inventories, advising on the appropriate transfer mechanism, reviewing Transfer Impact Assessments, monitoring vendor assessments, advising on supplementary measures and checking whether transfer documentation remains current and complete.
The DPO should also help ensure that transfer decisions are consistent with wider GDPR principles, including accountability, transparency, security and processor governance.
International transfers are inherently cross-functional. Procurement may manage supplier onboarding, IT may understand system architecture and access locations, security may assess encryption and other technical safeguards, while legal teams may review SCCs and contractual terms.
The DPO's role is to connect these activities to GDPR requirements and challenge gaps where necessary.
Some transfers should receive enhanced review before approval. Examples include transfers involving sensitive data, complex destination-country laws, major outsourcing arrangements, significant government-access concerns or situations where effective supplementary measures cannot be implemented.
Clear escalation criteria help prevent high-risk transfers from being approved through routine procurement processes without sufficient privacy assessment.
A practical international data transfer programme should follow a consistent sequence so that legal mechanisms, risk assessments and operational controls remain connected.
Identify personal data leaving the EEA or being made accessible to separate recipients outside the EEA. Include remote access, cloud services, subprocessors and intra-group transfers.
Confirm whether each party acts as controller, processor or subprocessor for the relevant processing activity.
Check first whether a valid adequacy decision applies. If not, consider Article 46 safeguards such as SCCs or Binding Corporate Rules.
Assess the destination country's legal environment, government-access risks and the practical circumstances of the transfer.
Where necessary, add technical, organisational or contractual safeguards capable of addressing identified risks.
Finalise SCC annexes, processor contracts, transfer records, TIAs, supplementary-measure assessments and approval evidence.
Ensure privacy notices accurately describe relevant international transfers and the safeguards relied upon.
Review changes in countries, subprocessors, provider terms, adequacy decisions, court judgments, government access practices, and technical architecture.
Define escalation and suspension procedures in advance. If effective protection can no longer be demonstrated, the organisation should be prepared to pause the transfer, change the provider or redesign the processing arrangement.
This sequence helps turn GDPR Chapter V requirements into a repeatable operational process rather than a one-time contractual exercise.

Use this compact checklist to confirm that international data transfers are identified, legally supported and documented.
Mapping and scope: Have all international transfers been identified? Does the review include remote access, cloud providers, subprocessors, SaaS platforms, group-company transfers and overseas support teams? Are the exporter, importer and countries involved clearly recorded?
Mechanism and assessment: Is each transfer covered by a valid adequacy decision, SCCs, Binding Corporate Rules or an applicable Article 49 derogation? Has a Transfer Impact Assessment been completed where required? Where risks remain, are supplementary technical, contractual or organisational measures effective?
Contracts and evidence: Are SCCs completed with accurate annexes? Are Article 28 processor terms in place where required? Are importer and subprocessor commitments documented? Can the organisation demonstrate why the selected transfer mechanism and safeguards are appropriate?
Monitoring: Does each material transfer have a review date? Are changes in recipients, processing locations, destination-country law, adequacy status, subprocessors and technical architecture monitored?
A strong checklist should lead to current evidence. If a transfer cannot be supported by valid documentation and effective safeguards, it should be escalated for remediation before continuing.
EU hosting does not automatically eliminate international transfer risk. Better approach: review remote access, overseas support teams, subprocessors, backups and other processing locations.
SCCs are not a complete compliance solution by themselves. Better approach: assess the transfer context, destination-country laws and practical risks where required.
Old contractual language or references to the former EU-US Privacy Shield can create serious compliance gaps. Better approach: use current European Commission transfer mechanisms.
Not every US recipient participates in the framework. Better approach: verify the organisation’s active certification and relevant coverage.
Derogations are not intended as a default mechanism for repetitive business transfers. Better approach: use them only where the specific legal conditions are genuinely satisfied.
Transfer risks can change. Better approach: reassess material changes in laws, providers, subprocessors and processing.
Supplier onboarding can create hidden transfer exposure. Better approach: build international transfer assessment into procurement and contract approval.
International data transfers require more than adding contractual clauses to supplier agreements. Privacy professionals need to understand GDPR roles, transfer mechanisms, Transfer Impact Assessments, processor relationships, risk evaluation and regulatory expectations.
The French Compliance Institute’s Data Protection Officer (DPO) Training helps professionals build practical knowledge of GDPR governance, data-protection responsibilities and compliance processes.
This knowledge can support stronger oversight of international transfers, cloud providers, processors, subprocessors and cross-border data flows.
The training should form part of a wider professional development and compliance framework rather than be treated as a guarantee of GDPR compliance or universal DPO competence.
International transfers of personal data are permitted under GDPR, but organisations must identify each transfer and apply the correct Chapter V mechanism.
Adequacy decisions can simplify covered transfers, while SCCs and other Article 46 safeguards require closer assessment. Schrems II remains relevant because organisations must consider whether destination-country laws and practices could undermine contractual protections. For French organisations, CNIL guidance on Transfer Impact Assessments provides a practical structure for documenting that analysis.
Cloud providers and subprocessors require particular attention because access and processing may occur across multiple jurisdictions.
Organizations should maintain a current transfer register, complete SCCs accurately, document TIAs, implement effective supplementary measures where necessary, and reassess transfers when circumstances change.
Organizations that combine accurate data-flow mapping, appropriate transfer mechanisms, and documented risk assessments will be better positioned to demonstrate compliant international data transfers under GDPR.