Privacy education, consultancy & implementation, in 50+ jurisdictions.enquiry@vedhacon.com
Guidance and examples adapt to your selection.↑↓ to browse, ↵ to apply
Not sure where to start?Check your readiness in 10 minutes

Eighteen questions, eight domains, a prioritised list of gaps. Nothing leaves your browser.

Begin the assessment
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
International transfers · Practical guide

Reading a transfer clause without falling asleep

Start with the real data flow, identify the legal route, then test whether the contract, assessment and operating controls describe and protect that same flow.

Vedhacon Transfer & Vendor practice10 min read

Transfer clauses are long because they combine legal mechanism, data-processing terms, destination risk and operational promises. Reading from page one often hides the central question: does this document describe the transfer that actually occurs?

Write the data flow in one sentence before reviewing the clause. If the contract describes a different flow, that is the first finding.

Start with the transfer map

Record who exports and imports the data, their roles, the people and data involved, purpose, originating and destination countries, storage locations, remote-access locations, sub-processors, frequency, retention and return or deletion. Include support access and onward transfers, not only the primary hosting region.

Minimum transfer-map fields
FieldQuestionEvidence
Parties and rolesWho exports, imports and determines purposes?Contract, RoPA and processing instructions
People and dataWhose data and which categories move?Data inventory and annex
Purpose and frequencyWhy, how often and through which interfaces?Architecture and service description
Locations and accessWhere is data stored and from where can it be accessed?Hosting, support and sub-processor records
Onward transfersWhich parties and countries receive data next?Sub-processor list and transfer chain
LifecycleHow long is data retained, returned or deleted?Retention rule and exit plan

Identify the legal route

Common transfer routes to assess
RegimePossible routeReview point
EU GDPRAdequacy decision, Article 46 safeguard such as 2021 SCCs, BCRs, or a limited Article 49 derogation.Confirm the destination, scope, roles, correct route and whether destination-law assessment is required.
UK GDPRAdequacy regulation, UK IDTA, UK Addendum to EU SCCs, BCRs, or a limited exception.Use the UK instrument and complete the required transfer risk assessment or data protection test.
India DPDP ActTransfers permitted subject to countries or territories restricted by Central Government notification.Check current restrictions, sectoral localisation rules, contracts and any applicable directions or higher protections.
Other jurisdictionsLocal adequacy, contracts, certification, consent or regulator approval depending on law.Do not assume EU SCCs automatically satisfy another country’s transfer rules.
Derogations are not routine architecture

EU and UK exceptions for specific situations should not be treated as a convenient substitute for an appropriate recurring transfer mechanism. Confirm the conditions and document why the route fits the actual transfer.

Select the correct EU SCC module

The four 2021 EU SCC modules
ModuleExporterImporterTypical check
1ControllerControllerEach party has independent purposes and transparency duties.
2ControllerProcessorProcessing instructions and Article 28 obligations align.
3ProcessorProcessorThe upstream controller and processing chain are correctly identified.
4ProcessorControllerThe importer’s controller role and applicable GDPR scope are understood.

Complete the annexes. Describe data, people, purposes, frequency, retention, competent authority, technical and organisational measures and sub-processors precisely. Blank or generic annexes can make a formally signed instrument operationally unreliable.

Assess destination law and practice

Where the chosen safeguard requires it, assess whether laws and practices in the destination could prevent the importer from complying with the instrument. Document the importer’s experience where relevant, the type of data and access, likely government-access scenarios, applicable safeguards and objective information used.

A practical destination-risk assessment
QuestionEvidencePossible response
Could public authorities lawfully seek the data?Applicable laws, importer input and authoritative materialLimit data, change architecture or add safeguards
Can the importer notify and challenge requests?Policy, legal constraints and historical transparencyContract commitments and escalation procedure
Is data intelligible to the importer or authorities?Encryption design, key control and access modelStrong encryption or pseudonymisation with keys retained separately
Is access necessary for the service?Support model, privilege and workflowRemove standing access; use approved, logged sessions
Do residual risks remain?Assessment of effectiveness and limitationsApprove, redesign, suspend or select another provider

Read the operational clauses

Clauses that determine whether safeguards work
Clause areaWhat to confirm
Instructions and purposeProcessing is limited to documented instructions and the service purpose.
SecurityMeasures match the actual data and risk; changes cannot silently reduce protection.
Sub-processorsCurrent list, countries, advance notice, objection process and equivalent obligations.
Government requestsNotification where lawful, review, challenge where appropriate, minimum disclosure and records.
Incident responseNotification timing and content allow the exporter to meet its own deadlines.
Rights and cooperationImporter supports rights, complaints, audits and regulator enquiries.
Audit and evidenceRelevant reports, remediation, access to information and escalation are available.
Return and deletionTimeline, format, copies, backups, sub-processors and deletion confirmation.
Suspension and terminationExporter can suspend transfers when safeguards cannot be met.
Liability and precedenceCommercial terms do not undermine mandatory clauses or practical remedies.

Follow onward transfers

The primary hosting country is only the start. Support centres, group companies, telemetry providers, content delivery, security services and sub-processors may create additional transfers. Require the chain to use an appropriate route and equivalent protection, and maintain a current record of countries and parties.

Change control
  • Receive advance notice of new sub-processors and countries.
  • Assess material changes before the transfer begins.
  • Record objections, remediation and decisions.
  • Update the RoPA, transfer inventory, privacy notice and risk assessment.
  • Verify deletion by departing sub-processors.

Apply India’s model carefully

Section 16 of India’s DPDP Act allows the Central Government to restrict transfers to notified countries or territories. The Act also preserves laws that provide a higher degree of protection or restriction, so sectoral localisation or storage duties may continue to apply.

Do not read the absence of an SCC-style mechanism as absence of diligence. Confirm current government notifications and commencement, map destination and onward access, protect the data contractually, assess security and sectoral rules, and retain evidence of the decision.

Red flags

  • The contract references obsolete EU clauses or leaves the SCC module blank.
  • Annexes use generic descriptions that do not match the service or data flow.
  • The UK transfer uses EU SCCs without the required UK instrument.
  • No transfer assessment exists where the route requires one.
  • The importer will not identify sub-processors, countries or remote support locations.
  • Government-access promises are absolute despite legal restrictions, or absent entirely.
  • Security measures can be reduced unilaterally.
  • Return and deletion omit backups, logs and sub-processors.
  • Liability, governing-law or precedence wording conflicts with mandatory safeguards.

Keep a transfer evidence pack

  • The approved transfer map and data-flow description.
  • The mechanism decision and applicability analysis.
  • Signed clauses with correct modules and completed annexes.
  • The transfer risk assessment and supplementary measures.
  • Current sub-processor, country and remote-access records.
  • Security evidence, government-request policy and transparency information.
  • Change notices, objections and approvals.
  • Exit, return and deletion evidence.

References and scope

  • Regulation (EU) 2016/679 (GDPR), Chapter V, Articles 44–49.
  • Commission Implementing Decision (EU) 2021/914 on standard contractual clauses.
  • European Data Protection Board recommendations on measures supplementing transfer tools.
  • UK Information Commissioner guidance on the IDTA, UK Addendum and transfer risk assessment.
  • Digital Personal Data Protection Act, 2023 (India), section 16, together with current notifications, commencement and applicable sectoral rules.

General information for practitioners, not legal advice. Transfer requirements depend on roles, destinations, scope, mechanism, sector and current government or regulator decisions. Verify official texts and obtain qualified advice for the transfer concerned.