Skip to content
compliancebase
GDPRChapter V — General Principle for International Transfers

Article 44

General Principle for International Transfers

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Transfer personal data outside the EEA only when GDPR transfer conditions preserve the level of protection across onward transfers.

Points of focus

  • Map remote access and vendor processing that constitute transfers
  • Use an available Chapter V transfer mechanism
  • Control onward transfers through contracts and oversight

Implementation notes

Model hosting, support access, telemetry routing, and vendor administration as transfer paths; block unapproved regions and tie subprocessor changes to transfer review before data flows. Operationalize map remote access and vendor processing that constitute transfers in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain transfer inventory linked to subprocessors and hosting regions with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that data is hosted in europe but routinely accessed by support staff in a third country Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample transfer inventory linked to subprocessors and hosting regions with dates and named reviewers. Be ready to walk through how you detect and correct: data is hosted in europe but routinely accessed by support staff in a third country

Evidence auditors typically request:

  • Transfer inventory linked to subprocessors and hosting regions
  • Transfer mechanism and supplementary-measures record
  • Remote-access and onward-transfer review

Common gaps

  • Data is hosted in Europe but routinely accessed by support staff in a third country
  • A processor adds an onward subprocessor outside the approved transfer chain

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 44This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

General Principle for International Transfers applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — map remote access and vendor processing that constitute transfers — with evidence stored where auditors and customers can sample it.

Lead with transfer inventory linked to subprocessors and hosting regions and pair it with transfer mechanism and supplementary-measures record. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because data is hosted in europe but routinely accessed by support staff in a third country Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above