Skip to content
HexaTransfer
Back to blog
GDPR & Compliance

Cross-Border Data Transfer Rules for File Sharing

Navigate cross-border data transfer regulations when sharing files internationally, including SCCs, adequacy decisions, and transfer impact assessments.

Cross-border file transfers from the EU to third countries require one of the Chapter V transfer tools under GDPR Articles 44-50: an adequacy decision (Article 45), Standard Contractual Clauses (Article 46), Binding Corporate Rules (Article 47), or a derogation (Article 49). Since Schrems II invalidated Privacy Shield in July 2020, every SCC-based transfer also needs a Transfer Impact Assessment documenting whether the destination country's surveillance laws undermine the protection. Get this wrong and you face fines up to 4% of global revenue plus injunctions stopping the data flow.

The adequacy decisions you can rely on

The European Commission has declared the following third countries adequate as of 2026: Andorra, Argentina, Canada (commercial operators only), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom, United States (DPF-certified entities only), and Uruguay. Transfers to these destinations need no additional Article 46 safeguards. For everywhere else — India, Brazil, China, Australia outside specific frameworks, most of Africa and Latin America — you need SCCs plus a TIA. The adequacy list updates; check the Commission's official register before relying on it.

Standard Contractual Clauses: the four modules

Commission Implementing Decision 2021/914 (June 2021) introduced the current SCCs with four modules. Module 1: controller to controller (sharing an exported .csv with a partner in Brazil). Module 2: controller to processor (using a US-based transfer service that isn't DPF-certified). Module 3: processor to processor (your DPA processor uses a sub-processor outside the EEA). Module 4: processor to controller (exporting data back from a processor to a third-country controller). Pick the right module — the wrong one is as invalid as none.

Transfer Impact Assessments after Schrems II

The CJEU's Schrems II ruling (C-311/18, July 2020) requires exporters to verify that the importer can actually comply with SCC commitments given local surveillance law. The EDPB Recommendations 01/2020 (adopted June 2021) lay out six steps: (1) map transfers, (2) identify the transfer tool, (3) assess effectiveness in the destination country, (4) identify supplementary measures, (5) procedural steps, (6) re-evaluate at intervals. For US transfers, the laws of concern are FISA Section 702 and Executive Order 12333. For Chinese transfers, the National Intelligence Law of 2017 and the Data Security Law of 2021.

Supplementary measures that actually work

The EDPB classifies supplementary measures as technical, contractual, and organizational. Only technical measures withstand the most aggressive surveillance. Ciphertext-in-transit with keys held only by the data exporter (client-side E2EE) means the importer holds only encrypted blobs useless to foreign authorities. Pseudonymization where re-identification keys stay in the EEA is equivalent for most use cases. Contractual measures — notify-of-access clauses, transparency reports — matter but don't defeat compelled disclosure. Organizational measures (access controls, training) are table stakes, not solutions.

The EU-US Data Privacy Framework

The EU-US DPF, effective July 2023 after the Commission's adequacy decision, restores a simplified path for US transfers to certified entities. Companies self-certify annually via the US Department of Commerce, commit to the DPF Principles, and submit to FTC enforcement. Over 2,500 US companies had certified by early 2026, including most major SaaS vendors. For DPF-certified recipients, no SCCs and no TIA are needed. Verify certification at dataprivacyframework.gov before each transfer; certifications lapse, and post-lapse transfers fall back to SCC requirements.

Binding Corporate Rules for intra-group transfers

BCRs under Article 47 are internal codes of conduct binding all companies within a corporate group, approved by a lead supervisory authority after consultation with all concerned authorities. Approval takes 18-36 months and costs EUR 100-300k in legal fees. Once approved, BCRs cover all intra-group transfers — so a German HQ can freely send personnel files to subsidiaries in Singapore, Mexico, and Nigeria. BCRs don't help with third-party processors; for those, SCCs remain the tool. Roughly 120 groups held approved BCRs as of 2025.

Article 49 derogations for edge cases

Article 49 allows transfers without Article 46 safeguards in specific situations: explicit consent with risk disclosure (49(1)(a)), transfer necessary for contract performance (49(1)(b)), important reasons of public interest (49(1)(d)), establishment or defense of legal claims (49(1)(e)), vital interests (49(1)(f)), and transfers from a public register (49(1)(g)). The EDPB Guidelines 2/2018 stress these are narrow exceptions — "occasional and non-repetitive." Using 49(1)(a) consent for ongoing customer file transfers is non-compliant. Using 49(1)(e) to send a case file to opposing counsel in the US for litigation is fine.

Country-specific rules beyond the GDPR

China's Personal Information Protection Law (PIPL, November 2021) requires a security assessment by the CAC for high-volume or sensitive-data exports. Russia's data localization law (242-FZ, September 2015) requires personal data of Russian citizens to be stored first on Russian soil. Brazil's LGPD (August 2020) has its own adequacy framework. India's Digital Personal Data Protection Act (August 2023, rules pending) will restrict transfers to countries blacklisted by the central government. File transfers touching these jurisdictions need local counsel — GDPR compliance alone isn't enough.

Practical architecture for cross-border compliance

A clean cross-border file transfer architecture: (1) encrypt client-side with keys the provider can't access, so the foreign provider holds only ciphertext; (2) pin file storage and metadata to EU regions (OVH Gravelines, AWS Frankfurt with explicit no-replication, Scaleway Paris); (3) log every transfer with destination country and lawful basis; (4) expire files automatically after 7-30 days to minimize residency risk; (5) maintain a live sub-processor register with jurisdictions. Services like HexaTransfer implement these patterns out of the box — EU-only storage, client-side AES-256-GCM, 7-day expiry.

Keeping records under Article 30(1)(e)

Article 30(1)(e) requires controllers to document, for each processing activity involving international transfers, the third country and the safeguards relied upon. The register entry for a transfer service should read: "File deliverables to client partners, transfers to US (DPF-certified) and UK (adequate), SCCs Module 2 for non-certified sub-processors, TIA dated [date] reviewed annually." Keep TIAs in version control; supervisory authorities inspect the history during investigations, not just the current version.

Design the transfer path before the first byte moves. Try it at hexatransfer.com — free, no account, 10 GB max.

Send large files securely with end-to-end encryption

Transfer files up to 10 GB for free with end-to-end encryption. No account required. Your files are encrypted in your browser before upload — no one else can read them.

Send a file