What is a data transfer?
A data transfer occurs when personal data is disclosed, sent, made available or remotely accessed by another party or from another jurisdiction. Transfers can take place through cloud hosting, support access, integrations, email, file sharing, outsourcing, corporate-group systems and vendor platforms. Data does not always need to be physically moved; remote access from another country can be relevant.
The parties involved may include controllers, processors, joint controllers, sub-processors and independent recipients. Understanding their roles is essential because contracts, transparency and legal safeguards depend on the relationship.
Why are international transfers regulated?
Privacy protections may differ between jurisdictions, and foreign laws may allow access or limit individual remedies. Transfer rules seek to preserve an appropriate level of protection when data leaves the original legal environment.
Organisations should consider the nature of the data, purpose, recipient, destination, onward transfers and technical controls. Sensitive or large-scale data generally requires more detailed assessment.
How are transfers documented?
A data map should identify the exporter, importer, countries, data categories, affected people, purpose, systems, access method and transfer mechanism. Contracts and vendor records should match the real flow, including support and sub-processors.
Where required, organisations may use adequacy decisions, standard contractual clauses, binding corporate rules or other recognised mechanisms. The selected mechanism may need a transfer impact assessment and supplementary safeguards.
How should transfers be managed over time?
New sub-processors, hosting changes, remote-support arrangements and acquisitions can alter the transfer. Organisations should monitor provider notices and review whether the original assessment remains accurate. Offboarding should address deletion and removal of remote access.
Data minimisation, encryption, regional processing and access controls can reduce exposure, but the complete legal and operational context should be evaluated.
Frequently asked questions
Is viewing data from another country a transfer?
It can be. Remote access may make data available in the other jurisdiction even when the storage location does not change.
Is sending data to a processor a transfer?
Yes, it is a disclosure to another party and may also be an international transfer depending on location and access.
Do standard contractual clauses automatically make a transfer lawful?
Not always. The organisation may need to assess practical enforceability, destination-country risks and supplementary measures.
Does anonymised data require a transfer mechanism?
Genuinely anonymised data may fall outside personal-data transfer rules, but the anonymisation must be effective and documented.
Who owns the transfer assessment?
The controller or responsible organisation should coordinate legal, privacy, security, procurement and vendor input and maintain the evidence.



