GDPR
Chapter V - Transfers of Personal Data

GDPR GDPR-Art.46: Transfers subject to appropriate safeguards

In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 16 controls across 14 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 2 controls

  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 8.5.1 Basis for PII transfer between jurisdictions
  • PMF-D.3 Onward Transfer Accountability
  • CBPR-PR-46 Mechanisms with processors to meet obligations

APPI · 1 control

  • APPI-A28 Provision to Third Parties in Foreign Countries
  • AL-DPA-12 International Data Transfers
  • AUCDR-PS-8 Privacy Safeguard 8 - Overseas disclosure of CDR data
  • MYHR-CUD-4 Records not held or taken outside Australia
  • APP-8 APP 8 - Cross-border disclosure of personal information
  • PIPL-Art38 Cross-Border Transfer Legal Mechanisms
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • s79 s 79 Without adequacy, transfer on appropriate safeguards, document it and report annually
  • RO-LAW190-012 International Data Transfers

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter V - Transfers of Personal Data

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.46 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.