You can't audit what you haven't mapped. Cross-border data transfers are a key focus of GDPR enforcement, yet many organizations treat transfer mechanisms as a one-time paperwork exercise. With supervisory authorities sharpening their focus on Chapter V compliance and the ePrivacy Regulation still looming, it's time to ensure your transfer framework actually works.
This checklist covers the operational controls you need before your next regulatory review. It assumes you're already transferring personal data outside the European Economic Area and need to confirm your current mechanisms meet supervisory authority expectations.
Prerequisites
Before you start, gather these materials:
- Your complete data flow inventory (all systems that send personal data outside the EEA)
- Current Standard Contractual Clauses or Binding Corporate Rules documentation
- Your most recent Transfer Impact Assessment for each destination country
- Documentation of any supplementary measures you've implemented
- Records of data subject notifications regarding international transfers
If you don't have a Transfer Impact Assessment for every non-EEA destination, stop here. You're not ready for this checklist. Complete your TIAs first, following the European Data Protection Board's recommendations on supplementary measures.
Transfer Mechanism Verification
1. Confirm Your Legal Basis for Each Transfer Route
Check that every cross-border data flow relies on a valid Chapter V GDPR mechanism. Adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, and derogations each have specific scope limits.
What good looks like: You can produce a matrix showing each transfer route, its legal basis, the specific GDPR article authorizing it, and the date you last verified that basis remains valid. No transfer occurs without a documented mechanism.
2. Verify Standard Contractual Clauses Match Current Commission Templates
The European Commission updated SCCs in June 2021. If you're still using pre-2021 clauses, you're non-compliant. Check every contract.
What good looks like: All SCCs use the 2021 Commission templates. You've completed Module selection based on actual controller/processor relationships. The UK Addendum is attached where you transfer data from the UK. Each SCC is signed by both parties with dates clearly visible.
3. Document Your Transfer Impact Assessment for Each Non-Adequate Country
Article 46 mechanisms require you to assess whether the destination country's laws undermine the transfer safeguards. This isn't optional. You need a written assessment for each jurisdiction, updated when local laws change.
What good looks like: Each TIA identifies specific surveillance laws in the destination country, evaluates their impact on your data categories, and documents why your supplementary measures provide essential equivalence. You've dated each assessment and assigned an owner responsible for monitoring legal developments.
4. Implement and Test Supplementary Measures
If your TIA identified risks, you must add technical or organizational safeguards. Encryption, pseudonymization, and contractual commitments are common choices, but they must actually reduce the identified risk.
What good looks like: Your supplementary measures directly address the gaps your TIA identified. If you're using encryption, keys are held only in the EEA and your data importer cannot access plaintext. If you're relying on contractual commitments, you've verified the importer can legally honor them under local law.
5. Maintain Current Data Importer Contact Details and Escalation Paths
When a supervisory authority questions a transfer, you need to reach your importer immediately. Outdated contacts create compliance gaps.
What good looks like: You have current email addresses and phone numbers for each data importer's Chief Privacy Officer (CPO). You've tested these contacts in the past six months. Your breach response plan includes notification procedures for cross-border incidents.
Data Subject Rights Across Borders
6. Verify Data Subjects Can Exercise Rights Regardless of Data Location
Transferring data doesn't suspend GDPR rights. Your data subjects must be able to access, rectify, or erase their data even when it sits in a third country.
What good looks like: Your DSAR process explicitly covers data held by importers. You've tested end-to-end fulfillment with at least one importer. Response times meet the one-month GDPR deadline even when data retrieval requires coordination across time zones.
7. Document Data Subject Notification of Transfers
Articles 13 and 14 require you to inform data subjects about international transfers, including the safeguards you use. This goes in your privacy notice, but it must be specific.
What good looks like: Your privacy notice names destination countries (or regions), identifies the transfer mechanism, and explains where data subjects can obtain copies of safeguards or adequacy decisions. Generic statements like "we may transfer data internationally" don't satisfy this requirement.
Common Mistakes
Treating adequacy decisions as permanent. The EU-U.S. Privacy Shield was invalidated in 2020. Adequacy decisions can be suspended or withdrawn. Monitor EDPB announcements and have a backup mechanism ready.
Assuming encryption alone satisfies supplementary measure requirements. Encryption protects data in transit and at rest, but if your importer needs to process the data, they'll decrypt it. That exposes it to local access laws. Your TIA must account for this.
Using derogations as a routine transfer mechanism. Article 49 derogations (like consent or contract necessity) are for occasional, non-repetitive transfers. If you're moving employee data to your U.S. payroll provider every month, you can't rely on derogations. You need SCCs or BCRs.
Failing to update SCCs when processing relationships change. If your processor becomes a sub-processor, or you start acting as a joint controller, your SCC module selection changes. Review annually.
Next Steps
If you found gaps, prioritize transfers involving special category data or large volumes of personal data. These attract supervisory authority attention first.
For any transfer lacking a valid mechanism, suspend it until you've implemented proper safeguards. Yes, this may disrupt operations. The alternative is enforcement action.
Schedule quarterly reviews of your transfer inventory. Data flows change faster than contracts. New SaaS tools, cloud migrations, and vendor changes all create new transfer routes that need Chapter V compliance.
Finally, assign someone to monitor ePrivacy Regulation developments. When it passes, it will add consent and cookie requirements that affect how you collect the data you're transferring. Your cross-border compliance framework needs to account for both collection and transfer rules, and right now, you're working with an incomplete picture of where EU privacy law is heading.



