International data transfer policy
On what basis personal data may leave the jurisdiction, which safeguards are used, and how each transfer is assessed and recorded.
How the register reads it
| Also called | transfer impact assessment, standard contractual clauses |
|---|---|
| Family | Privacy |
| Document type | Policy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Folds into | The regimes accept it folded into the data protection policy; when neither is listed, the gap is counted once, under the parent. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | GDPR is ticked and no line resolves to it or to its parent (ISO 27701 requires it too, inside a parent document, so it does not list it separately). |
| Template | Cross border data transfer policy. |
Which standards require it, and what each expects it to contain
4 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.5.2 Identify basis for PII transfer between jurisdictionsThe organization must identify and document the basis on which personal data is transferred between jurisdictions, documenting compliance with the legislation and regulation that applies depending on the jurisdiction or international organization the data goes to and comes from, and being aware that some jurisdictions require transfer agreements to be reviewed by a designated supervisory authority.
Common gap: Transfers identified only where data physically moves, missing remote access from another jurisdiction, which is itself a transfer
Source: ISO/IEC 27701:2025
ISO 27701 A.1.5.4 Records of transfer of PIIThe organization must record transfers of personal data to and from third parties and ensure cooperation with those parties to support future requests arising from its obligations to individuals, which includes transfers from third parties of data modified as a result of controllers managing their obligations and transfers to third parties implementing legitimate individual requests such as erasure after consent withdrawal, holding a policy defining the retention period of these records and applying data minimisation so only the strictly needed information is retained.
Common gap: Only outbound transfers recorded, so data flowing back after a third party correction is untracked
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 44 General principle for transfersTransfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.
Common gap: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 46 Transfers subject to appropriate safeguardsIn the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.
Common gap: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerData subject rights procedure · Legitimate interests assessment