Every time your website loads a US analytics script, your CRM syncs to a server in Virginia, or your support tool routes a ticket through a data centre outside Europe, you are making an international data transfer. Most organisations make hundreds of them a day without ever calling them that — and international transfers are one of the most heavily litigated corners of GDPR.
This guide explains how transfers actually work in 2026: the mechanisms that make them lawful, the assessment regulators expect you to have done, and where the genuine risk sits. It is the missing context behind questions like "is GA4 legal in the EU?" — because the answer almost always turns on a transfer.
What Counts as a Transfer
A "transfer" under Chapter V of the GDPR is any movement of personal data to a country outside the European Economic Area — or any access to that data from outside it. That last part surprises people. If a support engineer in a third country can view EU customer records stored on an EU server, that remote access is itself a transfer.
You do not have to export a database to trigger the rules. Embedding a third-party script, using a US-headquartered SaaS tool, or granting a global team access to a shared system all count. The question is never whether you transfer data — it is whether each transfer has a lawful basis.
The 2016-and-onward Backstory in One Paragraph
Chapter V says you may only transfer personal data outside the EEA if the destination offers "essentially equivalent" protection. In 2020, the Court of Justice's Schrems II ruling struck down the EU-US Privacy Shield because US surveillance law did not meet that bar, and it put every organisation relying on it into breach overnight. That decision still shapes the entire field: it is why transfers now demand documented diligence rather than a box tick.
The Three Ways to Transfer Lawfully
There are three main routes to a compliant transfer. Most organisations use a mix.
1. Adequacy Decisions
The European Commission can declare that a country provides adequate protection, allowing transfers to flow freely — no extra safeguards required. Countries with adequacy include the UK, Switzerland, Japan, Canada (commercial organisations), and others.
The one that matters most for the average business is the EU-US Data Privacy Framework (DPF), adopted in July 2023. It is a partial adequacy decision: transfers to US companies that are self-certified under the DPF are treated as adequate. This is what gives tools like Google Analytics a valid transfer basis again — but only where the specific US recipient is actually certified. Adequacy for the US is company-by-company, not country-wide.
2. Standard Contractual Clauses (SCCs)
Where there is no adequacy decision, the workhorse mechanism is Standard Contractual Clauses — pre-approved contract templates published by the Commission (the modernised 2021 set) that bind the data importer to EU-level protections. You sign them with the recipient and, in principle, the transfer is safeguarded.
But Schrems II added a condition: SCCs alone are not enough if the destination's laws would undermine them in practice. Which brings us to the step most organisations skip.
3. Derogations (the narrow exceptions)
Article 49 allows occasional transfers on the basis of explicit consent, contractual necessity, or important public interest. These are meant for one-off, non-repetitive situations — booking a hotel abroad, say — not for routing your entire analytics stack through a derogation. Treat them as the exception, never the architecture.
The Step Everyone Forgets: The Transfer Impact Assessment
If you rely on SCCs (or Binding Corporate Rules), Schrems II requires you to assess whether the destination country's laws actually let the importer honour them — and to add "supplementary measures" if they don't. That assessment is the Transfer Impact Assessment (TIA).
A TIA documents:
- What data is transferred, to whom, and why
- Where it goes and under which legal mechanism
- The legal environment of the destination — particularly government access and surveillance powers
- Supplementary measures you have added (encryption in transit and at rest, pseudonymisation, contractual and organisational controls)
The TIA is the single most commonly missing document in transfer compliance. Plenty of organisations have signed SCCs and stopped there, unaware that the assessment behind them is the part regulators actually ask to see. Signed clauses without a TIA are a paper trail that stops one step short of the finish line.
Why the DPF Is Not a Reason to Relax
The Data Privacy Framework resolved the immediate crisis, but it rests on the same foundation its predecessors did — and both Safe Harbor and Privacy Shield were annulled by the courts. The DPF now faces its own legal challenge (the Latombe case), echoing that history. No one can promise it will survive.
Prudent organisations therefore treat the DPF as valid today while keeping a fallback ready: SCCs plus a current TIA for their key US processors, so that if the framework is weakened they are not scrambling into breach a second time. Resilience here means not depending on a single mechanism you cannot control.
Where the Hidden Transfers Are
The transfers you documented are rarely the problem. The dangerous ones are the transfers you never noticed you were making — the third-party trackers, pixels, fonts, and embeds that quietly ship visitor data to servers around the world on every page load.
You cannot assess a transfer you do not know is happening. Each undisclosed US tracker on your site is an undocumented transfer with no mechanism, no TIA, and no entry in your records — exactly the gap our guide on hidden third-party trackers digs into.
Find the transfers hiding on your own site. Our free Website Privacy Scanner loads your pages like a real browser and lists every third-party domain that receives data — including the ones sending it outside the EU. It is the fastest way to turn "I think we're covered" into an actual list. A detailed report with a prioritised fix guide is available for a small one-off fee.
A Practical Transfer Checklist
To keep international transfers defensible in 2026:
- Map your transfers. You cannot govern what you have not inventoried. List every tool, embed, and recipient that moves or accesses EU data from outside the EEA.
- Match each to a mechanism. Adequacy/DPF, SCCs, or a genuine Article 49 derogation. If a transfer has none, fix or stop it.
- Verify DPF certification for each US recipient you rely on — do not assume it.
- Run a TIA for every SCC-based transfer, with real supplementary measures.
- Disclose transfers in your privacy policy: which categories of recipient, which countries, which safeguard.
- Keep a fallback for DPF-dependent transfers in case the framework is annulled.
- Re-check periodically. New tools add new transfers; adequacy decisions and court rulings change the ground under you.
The Bottom Line
International transfers are not an edge case for multinationals — they happen every time a European visitor's data touches a non-EU server, which for most websites is constantly. Compliance in 2026 means knowing where your data goes, having a valid mechanism for each destination, and being able to show the assessment behind it.
Start with visibility. Scan your site to see which third parties are receiving your visitors' data and where it is going, then read our companion guide on GA4 and GDPR for the most common transfer question of all. To see how regulators are treating transfer failures in practice, browse our enforcement monitor.


