Policy Register

International data transfer policy

On what basis personal data may leave the jurisdiction, which safeguards are used, and how each transfer is assessed and recorded.

How the register reads it

Also calledtransfer impact assessment, standard contractual clauses
FamilyPrivacy
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Folds intoThe regimes accept it folded into the data protection policy; when neither is listed, the gap is counted once, under the parent.
Expected ownerThe data protection officer or privacy lead.
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenGDPR is ticked and no line resolves to it or to its parent (ISO 27701 requires it too, inside a parent document, so it does not list it separately).
TemplateCross border data transfer policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27701:2025

ISO 27701 A.1.5.2 Identify basis for PII transfer between jurisdictions

The organization must identify and document the basis on which personal data is transferred between jurisdictions, documenting compliance with the legislation and regulation that applies depending on the jurisdiction or international organization the data goes to and comes from, and being aware that some jurisdictions require transfer agreements to be reviewed by a designated supervisory authority.

Evidence an auditor accepts: Transfer register naming origin, destination and the documented basis for each transfer; the transfer instruments themselves, such as contractual clauses or binding rules; assessment of destination jurisdiction requirements
Common gap: Transfers identified only where data physically moves, missing remote access from another jurisdiction, which is itself a transfer
Source: ISO/IEC 27701:2025
ISO 27701 A.1.5.4 Records of transfer of PII

The organization must record transfers of personal data to and from third parties and ensure cooperation with those parties to support future requests arising from its obligations to individuals, which includes transfers from third parties of data modified as a result of controllers managing their obligations and transfers to third parties implementing legitimate individual requests such as erasure after consent withdrawal, holding a policy defining the retention period of these records and applying data minimisation so only the strictly needed information is retained.

Evidence an auditor accepts: Transfer log covering transfers both to and from third parties; documented cooperation arrangements supporting later individual requests; retention policy for the transfer records themselves
Common gap: Only outbound transfers recorded, so data flowing back after a third party correction is untracked
Source: ISO/IEC 27701:2025

GDPR (Regulation (EU) 2016/679)

GDPR Art. 44 General principle for transfers

Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

Evidence an auditor accepts: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; the onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; evidence that remote access from a third country was assessed as a transfer alongside physical movement of data
Common gap: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 46 Transfers subject to appropriate safeguards

In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

Evidence an auditor accepts: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; the transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; the supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place
Common gap: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
Source: GDPR (Regulation (EU) 2016/679)

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Data subject rights procedure · Legitimate interests assessment