Skip to content
compliancebase
GDPRChapter V — Transfers Subject to Appropriate Safeguards

Article 46

Transfers Subject to Appropriate Safeguards

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Use appropriate safeguards and enforceable rights for transfers without an adequacy decision, such as standard contractual clauses with necessary supplementary measures.

Points of focus

  • Select a valid safeguard for each non-adequate destination
  • Assess destination-law and practical access risks
  • Implement contractual, technical, and organisational supplementary measures

Implementation notes

Generate transfer assessments from the Article 30 inventory, verify SCC roles and modules, evaluate government-access exposure, and keep encryption keys and access approvals under effective control. Operationalize select a valid safeguard for each non-adequate destination in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain executed standard contractual clauses and module selection with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that standard clauses are signed but no destination-specific assessment is performed Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample executed standard contractual clauses and module selection with dates and named reviewers. Be ready to walk through how you detect and correct: standard clauses are signed but no destination-specific assessment is performed

Evidence auditors typically request:

  • Executed standard contractual clauses and module selection
  • Transfer impact assessment tied to actual data flows
  • Encryption, access-control, and challenge-policy evidence

Common gaps

  • Standard clauses are signed but no destination-specific assessment is performed
  • Encryption is claimed as supplementary protection while the importer controls the keys

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 46This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Transfers Subject to Appropriate Safeguards applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — select a valid safeguard for each non-adequate destination — with evidence stored where auditors and customers can sample it.

Lead with executed standard contractual clauses and module selection and pair it with transfer impact assessment tied to actual data flows. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because standard clauses are signed but no destination-specific assessment is performed Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above