GDPR
Chapter V - Transfers of Personal Data

GDPR GDPR-Art.49: Derogations for specific situations

In the absence of an adequacy decision and of appropriate safeguards, a transfer to a third country or an international organisation may take place only on one of the Article 49(1) conditions: the data subject's explicit consent after being informed of the possible risks arising from the absence of adequacy and safeguards; necessity for the performance of a contract with the data subject or pre-contractual measures at their request; necessity for a contract concluded in the data subject's interest between the controller and another person; important reasons of public interest recognised in Union or Member State law; the establishment, exercise or defence of legal claims; protection of the vital interests of a person incapable of giving consent; or a transfer from a register which by law is intended to provide information to the public, limited to the conditions for consultation. Where none of these applies, a transfer may take place only where it is not repetitive, concerns a limited number of data subjects, is necessary for compelling legitimate interests of the controller not overridden by the data subject's interests or rights, and the controller has assessed all the circumstances and provided suitable safeguards on the basis of that assessment, informed the supervisory authority of the transfer, and informed the data subject of the transfer and of the compelling legitimate interests pursued. The controller or processor must document that assessment and those safeguards in the Article 30 records. Points (a), (b) and (c) are not available to public authorities exercising their public powers.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 7 controls across 5 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 2 controls

  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A28 Provision to Third Parties in Foreign Countries
  • PMF-D.3 Onward Transfer Accountability
  • UAE-PDPL-Art.22_23_24 Cross-border data transfers (UAE PDPL Articles 22-24)
  • s80 s 80 Transfer without safeguards only on the listed necessity grounds and document it

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter V - Transfers of Personal Data

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.49 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.