GDPR
Chapter V - Transfers of Personal Data

GDPR GDPR-Art.45: Transfers on the basis of an adequacy decision

Personal data may be transferred to a third country, a territory, one or more specified sectors within a third country, or an international organisation where the Commission has decided that it ensures an adequate level of protection, and such a transfer requires no specific authorisation. Adequacy decisions carry a defined territorial and sectoral scope, provide for periodic review at least every four years, and may be repealed, amended or suspended by the Commission. Relying on adequacy therefore requires confirming that the specific recipient and data fall inside the scope of a decision that is in force at the time of the transfer, and monitoring for amendment, suspension or repeal of that decision.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 80 controls across 59 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing

ISO 27701:2019 · 2 controls

  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 8.5.1 Basis for PII transfer between jurisdictions
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • CH-FADP-24 Cross-border transfer safeguards
  • FADP-10 Cross-Border Disclosure (Articles 16-18)

APPI · 1 control

  • APPI-A28 Provision to Third Parties in Foreign Countries
  • AUCDR-PS-8 Privacy Safeguard 8 - Overseas disclosure of CDR data
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • AZ-DPA-12 Article 13 - Cross-border transfer

Bahrain PDPL · 1 control

  • BB-DPA-17 Section 24 - Appropriate Safeguards
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • s78 s 78 Transfer to third countries only to competent bodies with adequacy, and control onward transfers
  • ICP-25 Supervisory Cooperation and Coordination
  • INCDPA-Processor-Contracts-DPA-Subprocessor-Audit-Confidentiality-EndOfContract Indiana CDPA Processor Contracts - Data Processing Agreement (DPA) + Required Provisions + Subprocessor Approval + Confidentiality + End of Contract Deletion + Audit Rights + Assistance
  • IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity

LGPD · 1 control

  • LGPD-BR-Cross-Border-International-Transfer-Article-33-Adequacy-SCC-BCR-ANPD-Approval-Mercosur-RIPD Brazil LGPD Cross-Border + Article 33 + Adequacy + SCC + BCR + Mercosur + RIPD

Liechtenstein DPA · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Scope-SS-584-Singapore-Standards-Council-IMDA-SAC-3-Tier-2013-2015-2020-2024-Certification MTCS Scope + SS 584 + Singapore Standards Council + IMDA + SAC + 3-Tier Framework + Certification

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Mauritius DPA · 1 control

  • MU-DPA-Enforcement-Commissioner-Section-41-43-MUR-200K-5-Year-Prison-ICT-Appeal-Tribunal-Supreme-Court Mauritius DPA Enforcement + Commissioner + Section 41 + Section 43 + MUR 200K + 5 Year Prison + ICT Appeal Tribunal + Supreme Court

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Enforcement-INAI-Articles-63-64-67-320K-Days-Minimum-Wage-3-Year-Prison-TFJA-Recurso-Revision-SCJN Mexico LFPDPPP Enforcement + INAI + Articles 63-64-67 + 320K Days Minimum Wage + 3 Year Prison + TFJA + Recurso de Revision + SCJN
  • MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification
  • MT-CDPA-Processor-Contract-Security-MCA-30-14-2809-30-14-2811-Pseudonymisation-De-Identification Montana CDPA Processor + MCA 30-14-2809 + Security + Pseudonymisation + MCA 30-14-2811 + De-Identification

NIST SP 800-122 · 1 control

  • NISTSP122-7 PII Sharing, Cross-Border Transfers, and Third-Party Agreements
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-7 Cross-Border Transfer of Personal Data under NDPR Section 2.7-CBT
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs

PDPA Singapore · 1 control

  • PDPASG-6 Transfer Limitation, Cross-Border Safeguards, and Data Intermediary Oversight

PDPA Thailand · 1 control

  • PDPATH-6 Cross-Border Transfer and Processor Engagement

POPIA · 1 control

  • POPIASA-6 Transborder Information Flows, Direct Marketing
  • NORWAY-6 International Transfers and Processor Agreements

Privacy Act 2020 · 1 control

  • NZPRV-5 IPP 11-12 Disclosure, Cross-Border Disclosure (Schedule 8)

Qatar DPL · 1 control

  • QATAR-6 Cross-Border Transfer and Processor Management
  • RCEPEC-2 Cross-Border Transfer, Computing Facilities, Localization (12.14-15)

Saudi Arabia PDPL · 1 control

  • SA-PDPL-24 Cross-border transfer safeguards
  • IM8-CLD.4 Cloud Data Sovereignty

South Korea ISMS-P · 1 control

  • ISMSP-PI-04 Cross-Border Transfer

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Taiwan PDPA · 1 control

  • TAIWAN-4 DPIA, Privacy by Design
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • UK-DPA18-LE-03 International Transfers (Law Enforcement)
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP
  • UZB-DPL-11 Cross Border Data Transfers

Vietnam PDPD · 1 control

  • VIETNAMPDP-3 Data Subject Rights

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-4 Privacy Notice and DPIA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter V - Transfers of Personal Data

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.45 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 80 it maps to, and the evidence behind each claim, over MCP and REST.