Review this workflow before sending personal data from the EEA to a third country or international organisation without relying only on a contract label.
It keeps adequacy checks, SCC module selection, Clause 14 assessment, importer evidence, supplementary measures, and stop-transfer decisions in one auditable transfer record.
Use this workflow for a GDPR Chapter V transfer impact assessment () where personal data is made available to a separate recipient in a third country or international organisation. It helps the team decide whether an adequacy decision covers the transfer, whether standard contractual clauses (SCCs) are available, and whether supplementary measures can make the selected transfer tool effective after Schrems II.
1
Section 1
Start with the transfer route
Open one transfer record for each distinct exporter, importer, destination country, transfer tool, data set, and processing purpose. Do not group unrelated vendors or destinations into one generic because the SCC assessment depends on the transfer's specific circumstances.
Before choosing a transfer tool, confirm that Chapter V applies. EDPB Guidelines 05/2021 use three cumulative criteria: an exporter is subject to the GDPR for the processing; the exporter transmits or otherwise makes the personal data available to a different controller, joint controller, or processor; and that importer is in a third country or is an international organisation. The importer's own GDPR status does not remove Chapter V.
First decide whether the destination is covered by a current adequacy decision for the relevant recipient and sector. If it is, record the adequacy route and keep evidence that the recipient actually falls inside the decision. If it is not, move to the Article 46 transfer-tool review. If there is no separate importer, Chapter V may not apply, but the processing still needs the GDPR security, accountability, and risk controls that fit the overseas access.
Record the exporter, importer, onward recipients, destination country, storage location, transmission channel, and whether the recipient is a controller, processor, or sub-processor.
Identify the personal data categories, data-subject groups, special-category or criminal-offence data, transfer frequency, retention period, and business purpose.
Check whether an adequacy decision applies to the destination and recipient type; for the United States, record whether the organisation participates in the EU-US Data Privacy Framework if that is the claimed route.
If adequacy does not cover the transfer, identify the Article 46 tool, usually the 2021 SCCs, and preserve the reason Article 49 derogations were not used as the operating basis.
Where the transfer uses SCCs, the contract package should identify the right module and complete the appendices before the team signs off the transfer assessment. Empty annexes, generic security descriptions, or missing onward-transfer details make the assessment hard to defend.
The 2021 SCCs use a modular structure for different transfer scenarios. The workflow should therefore tie the selected module to the actual exporter/importer roles, then attach the transfer details, technical and organisational measures, sub-processor information where relevant, and competent supervisory authority details. Also confirm that the clauses are available for the transfer: Decision (EU) 2021/914 states that these SCCs may be used only where the importer's processing is not within the territorial scope of the GDPR.
Select the SCC module that matches the transfer: controller-to-controller, controller-to-processor, processor-to-processor, or processor-to-controller.
Complete Annex I with parties, transfer description, categories of personal data, data subjects, purposes, retention, recipients, and competent supervisory authority.
Complete Annex II with specific technical and organisational measures for this transfer, not a generic security-policy reference.
Complete Annex III where sub-processors are part of the chosen module and authorisation model.
Record who can approve SCC signature, who can update annexes, and who receives importer notices about inability to comply or public-authority access requests.
The must determine whether the chosen Article 46 tool can work effectively for this transfer in the destination country or whether local laws and practices undermine the protection promised by the SCCs.
Schrems II and the SCCs require a case-by-case assessment. The record should cover the transfer facts, the destination-country laws and practices relevant to the importer and data, the importer evidence, and any safeguards already in place.
Use the EDPB sequence: know the transfers, verify the transfer tool, assess destination laws and practices, identify supplementary measures if needed, take required procedural steps, and re-evaluate at appropriate intervals.
For Clause 14, record the transfer circumstances, processing-chain length, transmission channels, recipient type, purpose, data categories and format, sector, storage location, relevant destination-country laws and practices, and existing safeguards.
Ask the importer for objective, reliable, relevant, verifiable, and lawfully shareable information about public-authority access risks, prior requests where usable, challenge procedures, transparency limits, and technical controls.
Do not treat absence of past access requests as decisive by itself; corroborate it with public or otherwise accessible information where the assessment relies on importer experience.
Have legal or privacy leadership approve the assessment report, including the sources checked, people involved, dates of checks, conclusion, and residual risk.
Record an explicit transfer decision and the evidence behind it. A transfer can proceed under SCCs only when the team can explain why the SCCs, together with any supplementary measures, ensure the required level of protection for that transfer.
If destination laws or practices prevent the importer from complying and effective supplementary measures cannot close the gap, the record should say that the transfer must not start or must be suspended or ended. Article 49 derogations are exceptions for specific situations, not a routine replacement for adequacy or Article 46 safeguards; document the exact condition and any additional requirements before relying on one.
Does signing the SCCs complete the transfer review?
No. The parties must select the correct module, complete the applicable annexes, and document the Clause 14 assessment before concluding the SCCs. They must also operate the clauses after signature, including importer notices, public-authority request handling, review of changed laws or practices, and suspension or termination when compliance can no longer be ensured.
Can the exporter rely only on the importer's lack of government-access requests?
No. Importer experience can be relevant only when it is lawfully shareable and assessed with objective, reliable, relevant, verifiable, and accessible information. An absence of prior requests is not decisive by itself, and the file should explain the period covered, the importer's legal limits on disclosure, and the public or otherwise accessible information used to corroborate the conclusion.
When must the transfer be stopped?
Do not start, or suspend or end, the transfer when the selected tool cannot provide effective protection and no supplementary measure closes the identified gap. The same escalation applies when the importer later reports that it cannot comply with the SCCs or when a legal, factual, or control change invalidates the approved assessment.
Proceed under adequacy only when the adequacy decision covers the destination, recipient, sector, and transfer facts recorded for the workflow.
Proceed under SCCs without extra measures only when the documents why the destination laws and practices do not undermine the SCCs for this transfer.
Proceed under SCCs with supplementary measures only when the measures are specific, effective for the identified risk, and do not contradict the SCCs.
Use technical, contractual, and organisational measures as needed, but record why each measure works for the actual data, importer, destination law, and processing purpose.
Suspend, end, or do not start the transfer when no effective supplementary measure can ensure the required level of protection, or when the importer can no longer comply with the SCCs.
Worked patterns help reviewers test the logic, but they do not replace the facts of the actual transfer. Use the same sequence in every case: identify the exporter and separate importer, map the data and onward recipients, check adequacy, select the available Article 46 tool, assess laws and practices, test supplementary measures, and record the operating decision.
A vendor's security certification, data-processing agreement, or statement that it has never received a government request may support part of the evidence file. None of those items establishes the Chapter V route or resolves Clause 14 by itself.
US recipient claiming the EU-US Data Privacy Framework: verify current participation and that the recipient and transferred data fall within the listed certification. Record a separate route for any non-participating recipient or onward transfer.
EEA controller using a non-adequate-country SaaS processor: use Module 2 when the roles and territorial-scope conditions fit, complete Annexes I and II, assess the importer and subprocessors, and test whether the service needs plaintext access. Encryption at rest does not prevent importer or authority access when the importer controls decryption.
EEA processor appointing a third-country sub-processor: assess Module 3 when it fits, record the controller's documented instructions and Article 28 authorisation path, complete the sub-processing details, and follow every onward recipient and support location.
Employee abroad accessing the same employer's systems: first apply the separate-importer test. Access by an employee acting within the same controller is not automatically a Chapter V transfer, but the controller still needs appropriate access, security, purpose, and accountability controls for the overseas processing.
Importer cannot comply after approval: capture the notice, stop affected access or flows, assess return or deletion, notify the required internal owners and counterparties, and document whether a lawful alternative route exists before resuming.
A useful transfer record lets privacy, legal, vendor-management, and security teams reconstruct the decision without searching email threads. Keep the evidence close to the vendor or system record so it is updated when the service, country, subprocessors, or data categories change.
Reopen the workflow when the transfer facts change, the importer reports an inability to comply, there is a new or changed public-authority access risk, supplementary measures stop working, SCC annexes change, or adequacy coverage changes.
Transfer map: exporter, importer, onward recipients, countries, systems, purposes, data categories, data-subject categories, frequency, retention, and storage locations.
Adequacy evidence: decision relied on, scope match, recipient participation evidence where relevant, and date the scope was checked.
SCC evidence: signed module, completed Annex I, Annex II, Annex III where relevant, competent supervisory authority entry, and owner for annex updates.
evidence: laws and practices assessed, importer materials, public or accessible corroborating sources, practical-experience analysis if used, approver, dates, conclusion, and next review trigger.
Supplementary-measure evidence: measure owner, implementation proof, control test, importer commitment, residual risk, and stop-transfer condition.
Operational evidence: process for public-authority request notices, challenge steps, inability-to-comply notices, suspension decisions, termination, return, and deletion.
How this workflow was prepared and should be qualified
Sorena AI assembled this workflow from the GDPR, Commission Implementing Decision (EU) 2021/914, the Commission adequacy and SCC materials, EDPB Guidelines 05/2021, EDPB Recommendations 01/2020, and the Schrems II judgment. The transfer test, module fields, assessment factors, evidence list, and stop-transfer outcomes were mapped to those sources.
AI assisted with source comparison, drafting, and organisation. No named human privacy or legal reviewer is claimed. Before approving a transfer, confirm the current adequacy scope, the parties' actual roles, the importer's territorial-scope position, the destination laws and practices, the completed SCC text and annexes, and any national rules or professional advice required for the case.
Source review current as of 25 July 2026. This revision added a featured definition, inline explanations of the other transfer terms, the Chapter V transfer test, worked transfer patterns, direct answers for common approval questions, and an explicit review-method qualification. The page date reflects those substantive changes.
This workflow helps structure GDPR transfer records
Sorena can help convert SCC packages, importer evidence, TIA conclusions, and supplementary-measure controls into reusable transfer records for GDPR work.
Supports the separate-importer test, including the employee-within-the-same-controller example, and confirms that the importer's own GDPR status does not remove Chapter V.
"another controller, joint controller or processor"