International Data Transfers & Adequacy Decisions

Confused about GDPR jargon? No problem! Our glossary breaks down all the key terms and definitions you need to understand the language of data privacy and compliance. This glossary will grow as we continue to add new terms and explanations, making it an essential reference for everyone.

Adequacy Decision

EU Commission decision confirming that a non-EU country ensures adequate data protection, allowing data transfers without additional safeguards (Article 45).

Binding Corporate Rules (BCRs)

Internal, regulator-approved rules that let a multinational group transfer personal data between its own entities across borders (Article 47).

Cross-Border Processing

Processing that affects individuals in multiple EU countries or involves data transferred across borders (Article 4(23)).

Data Localization

A legal or policy requirement that certain personal data be stored and processed within a specific country or region, rather than transferred abroad (Articles 44–49).

One-Stop-Shop Mechanism

A GDPR system letting an organisation operating in several EU countries deal with a single lead supervisory authority instead of one per country (Article 56).

Standard Contractual Clauses (SCCs)

Pre-approved legal agreements for GDPR-compliant data transfers outside the EU (Articles 46(2)(c), 46(5)).

Third Country

Any country outside the EU/EEA — sending personal data there triggers extra GDPR safeguards (Articles 44–46).

Transfer Impact Assessment (TIA)

An assessment carried out before transferring personal data to a third country under SCCs, checking whether the destination’s laws actually protect the data in practice — a post-Schrems II requirement (Articles 44–46).