GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-015 Data Transfer Controls

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Personal and sensitive data transferred outside the organisation (including to processors, sub-processors, and across international borders) is governed by documented transfer rules. Cross-border transfers to countries without an adequacy decision are only made using approved safeguards (e.g. Standard Contractual Clauses, Binding Corporate Rules). All data transfers are authorised and logged.

Rationale

Unauthorised international data transfers are a significant GDPR enforcement priority. Products with multi-region architectures or sub-processors in non-adequate countries need an explicit transfer mechanism on each route.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
Data Act Cloud Provider (EU)stablerequiredrole duty

Art. 32(1) extends the transfer question to non-personal data held in the Union, which no privacy control in the library reads. The provider owes all adequate technical, organisational and legal measures, contracts included, to prevent an international or third-country governmental access or transfer that would conflict with Union or Member State law.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (12)

DSP-10Sensitive Data Transferfull
DSP-13Personal Data Sub-processingpartial
DSP-10Sensitive Data Transferfull
DSP-13Personal Data Sub-processingpartial
DORA-Art.30.2.bLocations of service provision and data processinginformative
EU-DA-Art.28.1.aJurisdiction of the ICT Infrastructureinformative
EU-DA-Art.32.1Measures Preventing Unlawful Third-Country Accessinformative
GDPR-Art.44General Principle for Transfers to Third Countriesfull
GDPR-Art.45Transfers on the Basis of an Adequacy Decisionfull
GDPR-Art.46Transfers Subject to Appropriate Safeguardsfull
GDPR-Art.49Derogations for Specific Transfer Situationsinformative
5.14Information transferfull

Evidence (2)

contractdocumentmanual

Standard Contractual Clauses (SCCs) or other approved transfer mechanisms executed with all third parties receiving personal data in non-adequate countries.

Example: Executed EU SCCs (2021 EC SCCs, Module 1 or 2 as applicable) with key US or non-EEA sub-processors (e.g. AWS, Stripe, Salesforce), signed copies filed in the contract repository, with transfer impact assessment (TIA) attached where required

Test: Request the executed SCCs or other transfer safeguards for all transfers to non-adequate countries. Verify: (1) SCCs are executed for every identified cross-border transfer to non-adequate countries, (2) SCCs use the current 2021 EC standard clauses (pre-2021 Schrems II-invalidated clauses are not in use), (3) a TIA is documented for any transfer to a country with broad government surveillance laws, (4) no transfer is relying solely on derogations (Art.49) for routine processing.

recorddocumentmanual

Data transfer log or authorised transfer register documenting approved cross-border and third-party data transfers with mechanism and approval status.

Example: Data Transfer Register (Confluence / OneTrust), listing each authorised transfer with: destination country, recipient name, data categories transferred, transfer mechanism used (SCC / adequacy / BCR), date approved, and responsible owner

Test: Request the data transfer register. Verify: (1) all cross-border transfers identified in the RoPA are present, (2) each transfer has a documented mechanism, (3) no transfers are marked 'no mechanism' or 'TBC', (4) register has been reviewed within the last 12 months.

Questions (2)

boolean

Are all cross-border transfers of personal data to countries without an EU adequacy decision governed by an approved transfer mechanism such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)?

The 2021 EC SCCs must be used for transfers under the GDPR. Pre-2021 SCCs invalidated post-Schrems II are not acceptable. A Transfer Impact Assessment should accompany transfers to high-risk jurisdictions.

multi

Which transfer mechanism(s) does your organisation rely upon for international transfers of personal data?

EU Standard Contractual Clauses (2021 SCCs)Adequacy decision for the destination countryBinding Corporate Rules (BCRs)UK International Data Transfer Agreement (IDTA)Derogations under GDPR Article 49 (e.g. explicit consent, performance of a contract)Transfers have not been assessed for cross-border implicationsNone of the above

Most providers rely on 2021 SCCs for transfers to the US and other non-adequate countries. Sole reliance on Article 49 derogations for routine processing is not permitted under GDPR.