GDPR
Chapter V - Transfers of Personal Data

GDPR GDPR-Art.44: General principle for transfers

Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 64 controls across 49 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 4 controls

  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 7.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.2 Countries and international organizations to which PII can be transferred
  • EGY-PDPL-Art.14 Cross-border transfer adequacy and licensing
  • EGY-PDPL-Art.15 Derogations from the cross-border protection level
  • EGY-PDPL-Art.16 Disclosure to controllers/processors abroad under licence

APPI · 2 controls

  • APPI-A28 Provision to Third Parties in Foreign Countries
  • APPI-A31 Provision of Personally Referable Information

C5 (Germany) · 2 controls

  • C5-COS-07 Documentation of the network topology
  • C5-PSS-12 Locations of Data Processing and Storage
  • CAYDPA-P8 Eighth Principle - International Transfer
  • CAYDPA-Sch4 Schedule 4 - Transfers to Which the Eighth Principle Does Not Apply

FedRAMP High · 2 controls

  • CM-12 Information Location (CM-12)
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))

FedRAMP Moderate · 2 controls

  • CM-12 Information Location (CM-12)
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • PMF-D.3 Onward Transfer Accountability
  • AL-DPA-12 International Data Transfers
  • 5.9 5.9 International transfers of HR and monitoring data: adequacy preferred, minimum data, limited group access
  • AUCDR-PS-8 Privacy Safeguard 8 - Overseas disclosure of CDR data
  • MYHR-CUD-4 Records not held or taken outside Australia
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer

Bahrain PDPL · 1 control

  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BM-PIPA-15 Transfer of personal information to an overseas third party
  • BN-PDPO-s24 Transfer of personal data outside Brunei Darussalam
  • SD134-13 Cross-Border Transfer
  • CSL-Art37 CII Data Localization and Cross-Border Assessment - Art. 37
  • DSL-Art31 Cross-Border Transfer of Important Data (Art. 31)
  • PIPL-Art39 Notice and Separate Consent for Cross-Border
  • CDR-PS-8 Privacy Safeguard 8: Overseas Disclosure of CDR Data
  • DK-502-§14 Transfers of personal data to third countries
  • DUAA-P5-TRANSFERS International transfers data protection test

EU Data Act · 1 control

  • DA-Art.32 International governmental access and transfer (Article 32)
  • DGA-Art.31 International access and transfer (Article 31)
  • EST-IKS-§46-50 Transmission of personal data to third countries and international organisations
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • s81 s 81 Transfer directly to other third-country recipients only exceptionally and with purpose instructions

ISO 27001:2022 · 1 control

  • 5.14 Information transfer

ISO 27002:2022 · 1 control

  • 5.14 Information transfer
  • RO-LAW190-012 International Data Transfers
  • CIA-TRANS-11 Cross border transfer of credit information
  • ZDPA-06 Cross-Border Data Transfers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter V - Transfers of Personal Data

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.44 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 64 it maps to, and the evidence behind each claim, over MCP and REST.