Skip to main content
Problem areas in international data transfers
Back to all Insights

Insights · IT security

Problem areas in international data transfers

Published
15 April 2024
Reading time
5 min read

Share this article

European data protection law does not make it easy for companies to send data to third countries. The Transfer Impact Assessment (TIA) is intended to help reduce the risks of breaching EU data protection law.

The facts actually sound fairly straightforward: “Data transfers between EU Member States and the contracting states of the European Economic Area (EEA) within the scope of the General Data Protection Regulation (GDPR) must be treated in the same way under data protection law as domestic data traffic. Data transfers to third countries outside the EU and EEA must also meet the special conditions of Chapter 5 of the GDPR.”

This is stated in the information on “Datenschutz und Telekommunikation” published by the Federal Commissioner for Data Protection and Freedom of Information (BfDI). Anyone looking for Chapter 5 in the GDPR will find it under the heading “Transfers of personal data to third countries or international organisations”. Companies must therefore guarantee compliance with the GDPR requirements for personal data. These often quite extensive questions are intended to be answered in a “Data Transfer Impact Assessment” (DTIA) or “Transfer Impact Assessment” (TIA) (see also “Data Transfer Impact Assessment (TIA): Aber wie?”).

Where does TIA fit in?

Dr Markus Hülper, data protection expert at CLARIUS LEGAL, sums it up: “The core issue is the transfer of personal data from the EU to ‘unsafe third countries’. Under the case law of the Court of Justice of the European Union, this ultimately requires a risk assessment of data exports to these countries. Exactly how this assessment is to be structured has not yet been conclusively clarified.”

At least the EU Member States have already agreed on the penalties. “The European supervisory authorities may impose fines for violations of the General Data Protection Regulation (GDPR). These may amount to up to EUR 20 million or, in the case of companies, up to 4 per cent of worldwide annual revenue,” states the German Federal Data Protection Commissioner’s press release “Einheitliche Regeln für Datenschutzbußgelder in Europa”.

Data means potential risks

As part of the risk assessment, companies must evaluate the level of data protection in third countries. It is questionable, however, whether companies in Germany can use their own employees to provide the detailed legal knowledge required about local data protection law and the ability of government authorities to access the data.

In 2021, the European Data Protection Board (EDPB) published recommendations on exporting data to third countries. These provide for a highly extensive and complex review process that small and medium-sized enterprises (SMEs), in particular, can scarcely manage in practice.

Finding the right answers

The problem should be resolved quickly, as there is a concern that many contracts could otherwise fail. Some data exporters from the EU address the issue by sending data importers comprehensive questionnaires on the current state of data protection in the third country. Response rates to such questionnaires are low because of the complexity of the questions. Companies often cannot improve this unsatisfactory situation on their own. The recognised data protection experts at CLARIUS LEGAL can provide support here.

Data Transfer Impact Assessment (TIA): but how?

There are no statutory requirements governing how a TIA is to be conducted and documented. Data protection supervisory authorities provide general guidance, but no template for conducting one.

Administrative data must first be recorded, and questions such as the following must be asked and answered:

  • Which controller or processor initiates the processing in a third country, and is therefore the data exporter?
  • Who is the controller or (sub-)processor in the third country (data importer)?
  • In which third country does the processing take place?

The planned processing must then be described. In a manner comparable to the information in the records of processing activities (Article 30 GDPR), the following must be described:

  • Context and purpose of processing in a third country
  • Groups of data subjects
  • Categories of personal data transferred
  • Legal basis of the processing itself

In accordance with the Schrems II judgment, the legal position in the third country must be assessed, i.e. whether the level of data protection in that country is essentially equivalent to the level of protection in the EU and whether data subjects have enforceable rights and effective legal remedies that meet the requirements of the GDPR and the EU Charter of Fundamental Rights. The questions to be answered therefore include:

  • Does the third country or region of the third country have legislation that serves to protect data?
  • Do the rules apply equally to citizens or residents of the third country and to people who are not citizens or residents of that country?
  • Is the data importer subject to these laws?
  • Do these rules also protect the data exporter’s data affected by the processing in the third country?
  • Do these rules grant the persons affected by the processing in the third country enforceable rights and effective legal remedies, so that the third country provides a level of protection essentially equivalent to that guaranteed in the Union by the GDPR read in the light of the Charter?
  • Are there laws or practices in the third country that can compel the data importer to grant third parties, such as public authorities, access to the data?

Source: “Datenverarbeitung in einem Drittland: Data Transfer Impact Assessment (TIA) – eine Einführung ins Thema”, Berufsverband der Datenschutzbeauftragten Deutschlands (BvD) e. V.

In practice, this extensive catalogue requires considerable effort and detailed care from the companies concerned. Experienced personnel are needed for this task. Medium-sized companies in particular are likely to find it difficult to assign their own employees to this extensive, highly specialised task. Uncertainty is also especially pronounced in legally critical areas. Many companies therefore draw on external support to help resolve their problems with Data Transfer Impact Assessments. If you too would like to rely on proven and experienced data protection expertise, please send us a no-obligation enquiry.

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email