Data Transfers outside of the EU/EEA

As a non-EU Data Controller and responsible for the data, what are your options? 

The use of IOT has facilitated exchanges between organizations worldwide and consequently increased the number of personal data transfers. The entry into force of the General Data Protection Regulation EU n°2016 /679 (‘the GDPR’) created the free flow of data within the European Union and the European Economic Area (GDPR, art. 1). The free flow of data principle is to ensure a fair playing field within all the EU/EEA territory and to promote the creation of an EU single market. 

In contrast, the transfer of personal data outside of the EU/EEA territory is strictly regulated. Such transfers are allowed only if a sufficient and appropriate level of data protection is ensured. 

A controller or a processor that intends to transfer personal data to a third country must use one of the tools provided by the GDPR to ensure such level of data protection (GDPR, art. 44-49). The goal of the rules is to ensure personal data remains efficiently protected in countries not governed by the GDPR, where the law may be less strict. 

What are these tools? 

Adequacy decision (GDPR, art. 45) 

Some third countries may be considered “adequate” by the European Commission, meaning that the data protection laws applicable in these countries are essentially equivalent to those of the EU. As a result, data importers located in an adequate country can receive data from the EU/EEA without any additional action or approval from a Data Protection Authority. The Privacy Shield is considered as a sectoral adequacy decision. 

The former Privacy Shield has been invalidated by the Court of Justice of the EU in 2020. It was replaced by the EU–U.S. Data Privacy Framework (DPF) in July 2023, which is considered a sectoral adequacy decision for certified U.S. organizations. 

Appropriate safeguards (GDPR, art. 46-47) 

The second tool is akin to the conclusion of a contract between the data sender and the data recipient. In this case, the GDPR provides different types of additional safeguards: 

  1. Contractual clauses, such as the European Commission’s Standard Contractual Clauses (SCCs – 2021/914), which include modular formats for various transfer scenarios, but also clauses provided by Data Protection Authorities or tailored (“ad hoc”) clauses; 
  1. Binding Corporate Rules (BCRs), designed for transfers within multinational corporate groups; 
  1. Code of Conduct or Certification mechanisms, in combination with enforceable commitments to apply appropriate safeguards. 

Since the “Schrems II” decision of July 2020, these safeguards must be supplemented by a Transfer Impact Assessment (TIA) to assess the legal environment of the recipient country. 

Derogations (GDPR, art. 49) 

When it is not possible to implement effective safeguards, the data exporter may apply one of the derogations listed in Article 49. These include the data subject’s explicit consent or the necessity of the transfer for contract performance. Derogations must be interpreted restrictively, as they allow data transfers to countries where no adequate level of protection can be guaranteed. 

The European Data Protection Board (EDPB) recommends a three-step approach: 

  1. Check for an adequacy decision; 
  1. Consider appropriate safeguards; 
  1. Use a derogation only as a last resort. 

Although no Code of Conduct for the clinical sector has yet been formally approved by the European Data Protection Board (EDPB), the European CRO Federation (EUCROF) has submitted a sector-specific GDPR Code of Conduct for Contract Research Organizations. As of August 2025, this Code is still under review, but it already serves as a reference for data protection compliance in the clinical research field. 

What if the recipient country is not covered by an adequacy decision? 

The SCCs adopted in 2021 now offer greater flexibility, including modules allowing for use by non-EU data exporters, making them the preferred mechanism for many organizations. 

However, some tools may still not be feasible in every context: 

  • Code of Conducts and certifications are not yet available in many sectors, including clinical research — although the EUCROF Code of Conduct is progressing toward formal approval; 
  • Binding Corporate Rules can be difficult to implement when the parties are not part of the same corporate group; 
  • Derogations are limited in use and not designed for repetitive, large-scale transfers. 

 Can Ad-Hoc Clauses be used? 

In theory, yes. Tailored contractual clauses may be submitted to the competent supervisory authority for approval under Article 46(3)(a). These ad hoc clauses must: 

  • Ensure data subjects’ rights are enforceable and 
  • Provide effective legal remedies. 

Once submitted, they are: 

  • First reviewed by the EDPB, which may issue an opinion, 
  • Then approved (or rejected) by the national DPA, taking into account the EDPB opinion. 

The GDPR’s consistency mechanism (art. 63) encourages authorities to align decisions, which should ease the approval of ad hoc clauses already endorsed by the EDPB. 

However, in practice, the use of ad hoc clauses remains rare due to the heavy administrative process involved and the availability of SCCs. 

Specific Notes for the Clinical Research Sector 

In the context of clinical trials and global research collaborations: 

  • SCCs (2021) combined with a TIA are today the most viable and operational option for transferring personal data to countries lacking adequacy decisions. 
  • There is still no sector-wide approved code of conduct for clinical trials, but the EUCROF Code of Conduct for CROs is widely recognized and awaits formal endorsement by the EDPB. 
  • Binding Corporate Rules may be available only to large international groups such as global CROs or laboratory networks. 

Conclusion  

As of August 2025, a non-EU controller seeking to receive or transfer personal data from the EU/EEA should: 

  • Check if the country benefits from an adequacy decision (e.g. via the DPF for U.S. entities), 
  • Use the 2021 SCCs, with a Transfer Impact Assessment, 
  • Consider ad hoc clauses only where SCCs are not suitable, 
  • Avoid relying on derogations as a routine measure. 

SCCs combined with documented TIAs are the current gold standard for lawful data transfers outside the EU/EEA in the absence of adequacy.  

Whether you are a sponsor, a CRO or a laboratory, we can support you in defining a compliant international data transfer strategy from drafting robust SCC packages and TIAs to preparing for future adherence to sectoral Codes of Conduct such as the EUCROF Code. 

Our team regularly assists organizations in implementing practical, regulator-proof solutions tailored to the reality of global clinical operations. 

A controller or a processor which intends to transfer personal data to a third country should use one of the tools provided by the GDPR to ensure such level of data protection (GDPR, art. 44-49). The goal of the rules provided by the Regulation is to enable the data to be still efficiently protected in countries not governed by the GDPR and where the law may be less strict.

[/vc_row]

Prev post
Next post
Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)