Article 46
Transfers Subject to Appropriate Safeguards
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Use appropriate safeguards and enforceable rights for transfers without an adequacy decision, such as standard contractual clauses with necessary supplementary measures.
Points of focus
- Select a valid safeguard for each non-adequate destination
- Assess destination-law and practical access risks
- Implement contractual, technical, and organisational supplementary measures
Implementation notes
Generate transfer assessments from the Article 30 inventory, verify SCC roles and modules, evaluate government-access exposure, and keep encryption keys and access approvals under effective control. Operationalize select a valid safeguard for each non-adequate destination in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain executed standard contractual clauses and module selection with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that standard clauses are signed but no destination-specific assessment is performed Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample executed standard contractual clauses and module selection with dates and named reviewers. Be ready to walk through how you detect and correct: standard clauses are signed but no destination-specific assessment is performed
Evidence auditors typically request:
- Executed standard contractual clauses and module selection
- Transfer impact assessment tied to actual data flows
- Encryption, access-control, and challenge-policy evidence
Common gaps
- Standard clauses are signed but no destination-specific assessment is performed
- Encryption is claimed as supplementary protection while the importer controls the keys
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 46 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 46: Regulation (EU) 2016/679, Article 46 — Transfers Subject to Appropriate Safeguards