Personal data, including employee data, can be transferred outside the European Economic Area (EEA). But only under the conditions of Chapter V of the GDPR (Article 44 GDPR). The order is always the same. First, check whether the European Commission has adopted an adequacy decision for the recipient’s country. If not, you need appropriate safeguards, most often standard contractual clauses (SCCs), and, as the EDPB says, a written assessment of the destination country’s law. The derogations in Article 49 GDPR are only for specific, occasional cases.
The hardest part may not be the contract, but the question whether a transfer takes place at all. Our partners at Privacio (in Lithuanian) explain step by step how to put SCCs in place. Here we cover what the law requires, where mistakes are made and what they can lead to.
What counts as a transfer
The GDPR does not define a transfer. The European Data Protection Board (EDPB), in its Guidelines 05/2021, sets three criteria. The data is sent by a controller or processor that is subject to the GDPR. It sends the data, or otherwise makes it available, to another controller or processor. That recipient is in a third country.
Two practical rules follow. First, remote access from a third country is a transfer, even if the data is only displayed on a screen, for example during technical support. The same applies to storage in a cloud outside the EEA. Second, your own employee who logs in to company systems while on a business trip does not make a transfer, because the employee is not a separate controller. But the EDPB points out that such processing outside the EU can still carry higher risks, so the controller must assess them and apply appropriate security measures (Article 32(1) GDPR).
One company asked exactly this: the software vendor comes from a non-EU country, but the servers are in Spain. Is that a transfer? The answer depends not on where the server is, but on who your processor is and where it is. If the processor is a company in a third country and it accesses the data, for example to provide technical support, the EDPB treats this as a transfer to a processor in a third country. If the processor is an EU company in a non-EU group and nobody outside the EU accesses the data, there is no transfer. But before engaging it, you must assess whether third-country authorities can demand the data from it, because a processor must provide sufficient guarantees of compliance (Article 28(1) GDPR).
Employee data and group systems
The same rules apply to employee data. One example is an international group whose HR system is run in another country. The EDPB describes exactly this example: an EU subsidiary sends employee data to its parent company in a third country, to be stored in a centralised HR database. That is a transfer.
When we drafted internal rules for such a company, we asked the client a specific question: is any employee data transferred outside the EEA, and if so, to which countries, what data, to whom and why? Without that answer, neither the privacy notice nor the records of processing can be prepared correctly.
Common ownership does not justify a transfer. Inside a group the same Chapter V rules apply as with an outside vendor. If the recipient’s country has an adequacy decision, that is enough. If not, you need standard data protection clauses (Article 46(2)(c) GDPR) or approved binding corporate rules (Article 46(2)(b) GDPR).
Relying on employee consent is risky. Article 49(1)(a) GDPR requires explicit consent given after the person has been informed of the risks of the transfer. In employment, consent is rarely free, as we explain in our article on employee consent.
What safeguards are required
Adequacy decision. If the Commission has decided that a country ensures an adequate level of protection, no specific authorisation is needed (Article 45(1) GDPR). The Commission publishes the list in the Official Journal and on its website (Article 45(8) GDPR). A decision can also be partial. For example, the decision on the EU–US Data Privacy Framework applies only to organisations included in the list kept by the US Department of Commerce (Article 1 of Decision (EU) 2023/1795). For a US vendor not on the list, this decision does not apply. Employee data needs one more check: an organisation that wants the framework to cover HR data transferred from the EU must state this in its self-certification (Annex I to Decision (EU) 2023/1795).
Appropriate safeguards. Without an adequacy decision, you may transfer only if you have put appropriate safeguards in place and enforceable data subject rights and effective legal remedies are available (Article 46(1) GDPR). The most common safeguard is standard data protection clauses adopted by the Commission (Article 46(2)(c) GDPR).
Signing SCCs is not enough. The EDPB Recommendations 01/2020 state that the exporter must itself assess whether the law and practice of the destination country prevent the safeguards from working. Where needed, it must add supplementary measures. This assessment must be done with due diligence and documented thoroughly. If no supplementary measure can ensure protection, the transfer must be avoided or suspended.
Derogations. Article 49 GDPR allows a transfer without an adequacy decision and without an Article 46 safeguard (such as SCCs) only in specific cases, for example where it is necessary to perform a contract with the person concerned (Article 49(1)(b) GDPR). The EDPB stresses that derogations cannot become the rule. The last derogation, based on compelling legitimate interests, applies only where no Article 45 or 46 tool and no other derogation is available. The transfer must be non-repetitive, concern a limited number of people and be necessary for those interests, and the person’s interests or rights must not override them. The controller must assess all the circumstances, put safeguards in place and document this in the records of processing (Article 49(1), second subparagraph, and Article 49(6) GDPR). Both the supervisory authority and the person concerned must be informed (Article 49(1), second subparagraph, GDPR). Public authorities exercising their public powers cannot use this derogation (Article 49(3) GDPR).
Documents. The transfer must be stated in the privacy notice (Article 13(1)(f) GDPR) and in the records of processing, including the name of the country (Article 30(1)(e) GDPR). The data processing agreement must say that the processor transfers data only on the controller’s documented instructions, unless EU or Member State law requires otherwise; in that case the processor informs the controller in advance, unless that law prohibits such notice on important grounds of public interest (Article 28(3)(a) GDPR). When a data processing agreement is required is covered in Data processing agreement: when required and the risk without one.
What to check along the vendor chain
Signing with a Lithuanian or other EU company does not mean its sub-processors operate in the EU. The GDPR requirements tell you what you need to know about each vendor:
- which group companies and sub-processors take part in the processing, and in which country each one is (Article 30(1)(e) GDPR);
- what each step of the transfer relies on: an adequacy decision or an Article 46 tool such as SCCs (Article 44 GDPR);
- whether an assessment of the destination country’s law has been done for each vendor that receives data under SCCs or another Article 46 tool (EDPB Recommendations 01/2020);
- whether sub-processors were engaged with the controller’s prior specific or general written authorisation (Article 28(2) GDPR).
Contract partners ask these questions too: is data transferred outside the EEA, and which cloud is used. You need a written answer to them. How to tell a controller, a processor and joint controllers apart is covered in Sharing data with a partner: controller, processor or joint controller.
What happens when it goes wrong
Breaches of the transfer rules fall into the highest fine band: up to 20 million euros or, for an undertaking, up to 4 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(c) GDPR).
Another measure can hurt more. The supervisory authority can order the suspension of data flows to a recipient in a third country (Article 58(2)(j) GDPR). That means a system your HR or customer service uses every day would have to be replaced in a hurry.
One possible mistake is documents that are wrong. For example, the privacy notice says no data leaves the EEA, while the vendor’s support team logs in from a third country. This breaches the duty to inform, and the statement itself shows in writing that the chain was never checked.
An adequacy decision is not permanent. The Commission can repeal, amend or suspend it (Article 45(5) GDPR). The same vendors then need another instrument.
When to call a lawyer
- when you choose a vendor that operates outside the EEA itself or through sub-processors;
- when your group centralises an HR, customer or accounting system in another country;
- when the recipient’s country has no adequacy decision and its law needs to be assessed;
- when you are considering an Article 49 GDPR derogation;
- when a partner, a client or VDAI asks you to explain where the data goes.
Frequently asked questions
If the servers are in the EU, is there no transfer?
Not necessarily. The EDPB treats remote access from a third country as a transfer when another controller or processor accesses the data, even if the data is only viewed on a screen, for example during technical support. So you need to know not only where the server is, but also which companies – the vendor and its sub-processors – access the data and in which countries they are.
Can employee data be transferred on the basis of their consent?
Only in exceptional cases. Article 49(1)(a) GDPR requires explicit consent after the person has been informed of the risks, and employee consent is rarely free. A regular transfer, such as a group HR system, needs an adequacy decision or an Article 46 safeguard, most often SCCs or binding corporate rules.
Does a US vendor need SCCs?
It depends on whether the vendor is included in the EU–US Data Privacy Framework list. If it is, the transfer can rely on Commission Decision (EU) 2023/1795. For employee data that is not enough: the vendor’s certification must also cover HR data. If the vendor is not listed, or its certification does not cover this data, you need an Article 46 GDPR safeguard, most often SCCs, and a transfer assessment.
How to start
List the systems and vendors that process employee or customer data, and mark those whose group or sub-processors operate outside the EEA. Send us that list and your current data processing agreements. We will tell you where transfers take place, which instrument is missing and what to correct in your documents.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and consultations.