International Data Transfers: GDPR Compliance in the Global Cloud
Cross-border data transfer compliance: Standard Contractual Clauses, Transfer Impact Assessments, EU-US Data Privacy Framework, and Binding Corporate Rules for multinational groups.
Does this apply to your business?
Do you know exactly what personal data your company transfers to vendors outside the EEA and what legal safeguard covers each transfer?
Do your cloud provider contracts (AWS, Google, Microsoft, Salesforce) include the 2021 SCCs and an up-to-date Transfer Impact Assessment?
Have you assessed whether the EU-US Data Privacy Framework is sufficient for your US transfers, or whether additional safeguards are needed?
Are all international transfers documented in your records of processing activities with the applicable safeguard referenced?
0 of 4 questions answered
Our international data transfer audit and remediation process
International transfer mapping
We identify all personal data flows outside the EEA: cloud providers, SaaS platforms, foreign subsidiaries, marketing and analytics vendors, and any other processor located outside the EU.
Existing safeguard verification
We audit the current safeguard for each transfer: adequacy decision coverage, SCCs implemented and updated to the 2021 version, or alternative mechanisms valid under Article 46 GDPR.
Transfer Impact Assessment (TIA)
We conduct TIAs for SCC-based transfers: assessment of the destination country's legal framework, likelihood of government access, and effectiveness of the safeguards in that specific context.
Safeguard implementation and documentation
We implement the 2021 SCCs in processor contracts, negotiate necessary addenda with vendors, and document the transfer inventory in the records of processing activities.
The challenge
Any company using cloud services, SaaS platforms, or vendors outside the European Economic Area is making international personal data transfers. The Schrems II judgment invalidated the Privacy Shield in 2020 and exposed thousands of Spanish companies transferring data to the US without valid safeguards. Many remain in the same position: using outdated standard clauses, without the Transfer Impact Assessment the AEPD requires, or with no safeguard at all.
Our solution
We audit all your company's international data transfers, verify the safeguard applicable to each one, and remediate gaps: implementation of the updated 2021 Standard Contractual Clauses, Transfer Impact Assessments (TIAs), advisory on the EU-US Data Privacy Framework, and design of Binding Corporate Rules for multinational groups.
International transfers of personal data — any transmission of personal data to a country or international organisation outside the European Economic Area (EEA) — are regulated by Chapter V of the EU General Data Protection Regulation (GDPR, Articles 44–49). A transfer can only take place if the destination country benefits from an adequacy decision (Article 45), or if the exporter implements appropriate safeguards such as Standard Contractual Clauses (SCCs — Commission Decision 2021/914), Binding Corporate Rules (BCRs), or a Transfer Impact Assessment (TIA) confirming equivalent protection. The EU-US Data Privacy Framework (Commission Decision 2023/1795) currently provides an adequacy basis for transfers to certified US organisations. The Court of Justice of the EU's Schrems II judgment (Case C-311/18, July 2020) invalidated the previous Privacy Shield and requires case-by-case assessment of third-country legal systems for all SCCs-based transfers.
The globalisation of technology services has made international personal data transfers a daily reality for the vast majority of Spanish businesses, regardless of size. Using any US cloud service, CRM platform, analytics tool, or management software with non-EEA servers involves international transfers regulated by Chapter V of the GDPR. The problem is that many organisations make these transfers without valid safeguards — and without knowing it.
The Schrems II Legacy
The CJEU’s Schrems II judgment was a watershed moment whose full implications have still not been absorbed by the Spanish business community. The invalidation of the Privacy Shield and the requirement to conduct a Transfer Impact Assessment to verify that SCCs are practically effective in the destination country transformed a relatively straightforward exercise into a more complex legal and technical analysis. Companies that simply copied and pasted the 2021 SCCs into their vendor contracts without conducting the corresponding TIA remain non-compliant.
The 2021 SCCs introduced modular clauses covering four processing scenarios (controller-to-controller, controller-to-processor, processor-to-controller, and processor-to-processor), replacing the three previous sets of clauses. This structural change means that organisations reviewing their international transfer contracts need to verify not only that new SCCs are in place, but that the correct module and addendum are used for each specific transfer relationship.
What the Audit Reveals
Complete mapping of international transfers is the indispensable starting point. In our experience, organisations typically identify 30 to 50 percent more transfers than they initially believed they were making: sub-processors that the primary vendor uses in third countries, technical support tools with remote access from outside the EEA, or backup solutions in non-European cloud regions that the provider activates by default. Each of these flows requires its own safeguard — sub-processor transfers are covered by the main processor’s SCCs only if those SCCs specifically authorise sub-processing and impose equivalent obligations down the chain.
For multinational groups, Binding Corporate Rules are the structural solution that allows intra-group transfers to be managed coherently without executing SCCs with each group entity individually. The approval process is complex, but the result is a legally robust instrument recognised by all European supervisory authorities. In a context where regulatory compliance is increasingly a competitive differentiator, an auditable and documented international transfer system is a genuine asset in due diligence processes and institutional client relationships.
The EU-US Data Privacy Framework: Current Status and Risk
The EU-US Data Privacy Framework (DPF), adopted in July 2023, provides an adequacy basis for transfers to US organisations that have self-certified to the DPF programme administered by the US Department of Commerce. It is currently the operative legal basis for the majority of EU-US transfers in standard cloud and SaaS contracts. However, the DPF is subject to the same legal challenges that invalidated the Privacy Shield and Safe Harbor before it: a third Schrems challenge is considered likely. Organisations that have structured their entire US transfer programme on the DPF adequacy decision should maintain a secondary SCCs-based framework in reserve. Our transfer audit service includes a DPF resilience assessment as standard — identifying which transfers rely exclusively on the adequacy decision and designing fallback safeguards for each.
Transfer Impact Assessments: The Practical Methodology
A Transfer Impact Assessment (TIA) is required for all transfers based on Standard Contractual Clauses where the destination country lacks an adequacy decision. The TIA must assess whether the laws and practices of the destination country — particularly government access powers — permit effective enforcement of the SCCs’ data protection obligations. For high-volume transfers to jurisdictions with documented surveillance concerns, the TIA must be completed to a standard that can withstand AEPD scrutiny. We conduct TIAs using a documented methodology aligned with the EDPB’s Recommendations 01/2020 on transfers.
Sub-Processor Chains and Controller Liability
The most under-managed dimension of international transfers is the sub-processor chain. When an organisation contracts with a primary processor that itself uses sub-processors in third countries, the original controller is responsible for ensuring that each link in the chain is covered by appropriate safeguards. Many organisations are unaware of the sub-processors their primary vendors use, or have not verified that onward transfer agreements include the required SCC clauses. The outsourced DPO service integrates this sub-processor monitoring function as an ongoing obligation, not a one-time audit.
International Transfers in M&A and Corporate Transactions
International data transfer compliance is an increasingly significant component of due diligence in corporate transactions. A target company that has been making unprotected transfers to US cloud vendors for years represents a regulatory liability that must be quantified in the deal. Transfer compliance audits as part of M&A due diligence are a standard component of our privacy advisory service for transactions involving European data-intensive businesses. Our impact assessment service integrates the DPIA dimension of these transfers for any processing activities that also require a risk assessment under Article 35 GDPR.
The EU-US Data Privacy Framework: Current Status and Risk
The EU-US Data Privacy Framework (DPF), adopted in July 2023, provides an adequacy basis for transfers to US organisations that have self-certified to the DPF programme administered by the US Department of Commerce. It is currently the operative legal basis for the majority of EU-US transfers in standard cloud and SaaS contracts. However, the DPF is subject to the same legal challenges that invalidated the Privacy Shield and Safe Harbor before it: a third Schrems challenge is considered likely. Organisations that have structured their entire US transfer programme on the DPF adequacy decision should maintain a secondary SCCs-based framework in reserve. Our transfer audit service includes a DPF resilience assessment as standard — identifying which transfers rely exclusively on the adequacy decision and designing fallback safeguards for each.
Transfer Impact Assessments: The Practical Methodology
A Transfer Impact Assessment (TIA) is required for all transfers based on Standard Contractual Clauses where the destination country lacks an adequacy decision. The TIA must assess whether the laws and practices of the destination country — particularly government access powers — permit effective enforcement of the SCCs’ data protection obligations. For high-volume transfers to jurisdictions with documented surveillance concerns, the TIA must be completed to a standard that can withstand AEPD scrutiny. We conduct TIAs using a documented methodology aligned with the EDPB’s Recommendations 01/2020 on transfers.
Sub-Processor Chains and Controller Liability
The most under-managed dimension of international transfers is the sub-processor chain. When an organisation contracts with a primary processor that itself uses sub-processors in third countries, the original controller is responsible for ensuring that each link in the chain is covered by appropriate safeguards. Many organisations are unaware of the sub-processors their primary vendors use, or have not verified that onward transfer agreements include the required SCC clauses. The outsourced DPO service integrates this sub-processor monitoring function as an ongoing obligation, not a one-time audit.
International Transfers in M&A and Corporate Transactions
International data transfer compliance is an increasingly significant component of due diligence in corporate transactions. A target company that has been making unprotected transfers to US cloud vendors for years represents a regulatory liability that must be quantified in the deal. Transfer compliance audits as part of M&A due diligence are a standard component of our privacy advisory service for transactions involving European data-intensive businesses. Our impact assessment service integrates the DPIA dimension of these transfers for any processing activities that also require a risk assessment under Article 35 GDPR.
Real results in international data transfer compliance
An internal audit revealed we were transferring European customer data to US servers without valid SCCs or TIAs. BMC resolved the entire situation in three months: new contracts with all vendors, complete TIAs, and an updated transfer register. We now know exactly what safeguard covers every data flow.
Experienced team with local insight and international reach
What our international data transfer service includes
International Transfer Audit
Complete mapping of all personal data flows outside the EEA: cloud providers, SaaS platforms, subsidiaries, sub-processors, and any other recipient in third countries.
Standard Contractual Clauses Implementation
Review, update, and implementation of the 2021 SCCs in all processor contracts with entities located outside the EEA.
Transfer Impact Assessment (TIA)
Analysis of the destination country's legal framework and assessment of safeguard effectiveness in the context of that country's government access laws.
EU-US Data Privacy Framework Advisory
Guidance on the US adequacy decision, certification verification for vendors, and alternative safeguard strategy in the event of future invalidation.
Binding Corporate Rules
Design and management of the BCR approval process for multinational groups with systematic intra-group transfer requirements.
Results that speak for themselves
Reference guides
Post-Brexit: your British company operating in Spain with the right structure
post-Brexit advisory for UK companies operating in Spain: entity structuring, customs and VAT, work permits for British nationals, UK-Spain tax treaty optimisation and data protection compliance.
View guideComprehensive legal services for businesses
Comprehensive legal advisory for businesses: commercial, employment, contracts, regulatory compliance, and dispute resolution. A dedicated legal team to protect your company.
View guideBuy property in Spain with confidence — and without the horror stories
Buying property in Spain as a non-resident involves legal checks, tax obligations, and title risks that many buyers discover too late. BMC protects your investment from offer to deed.
View guideThe collective agreement that governs your workforce: understand it and negotiate from strength
How collective agreements work in Spain: hierarchy of agreements, company-level vs sector agreements, ultra-actividad, inaplicacion (opt-out), and negotiation strategy for employers after the 2021 labour reform.
View guideYour commercial lease agreement: get the clauses right before you sign
Expert legal guidance on commercial lease agreements in Spain under the LAU: key clauses, rent reviews, subleasing, termination rights, VAT implications and tenant and landlord protections.
View guideCorporate lawyer for construction: protect your contracts and your rights
Corporate legal advisory for construction companies and developers in Spain: construction contracts, UTEs, joint ventures, interim valuation disputes, claims for defects, and debt recovery.
View guideAnalysis and perspectives
Frequently asked questions about international data transfers under GDPR
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
International Data Transfers
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Anti-Money Laundering (AML)
AML/CFT compliance programme for entities subject to Spain's Law 10/2010: policies, procedures, training, and SEPBLAC liaison.
Saber másCommercial Law
Expert commercial law advisory to safeguard your business operations and protect your corporate interests.
Saber másCybersecurity Audit
Security posture assessment, compliance audits (ENS, ISO 27001, NIS2), vulnerability assessment, penetration testing management, and third-party risk evaluation.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másKey terms
Data Protection Officer (DPO)
A Data Protection Officer (DPO) is a designated individual responsible for overseeing an…
Read definitionPrivacy by Design
A GDPR principle (Article 25) requiring data protection to be integrated into the design of…
Read definitionStandard Contractual Clauses (SCCs)
Model contracts adopted by the European Commission that provide adequate safeguards for transferring…
Read definition