Chapter V GDPR
Chapter V of the EU General Data Protection Regulation (GDPR) contains the rules that apply when personal data is sent from the European Economic Area to a country outside it or to an international organisation. It sets out the conditions that must be met before such a transfer can lawfully take place. It does not, on its own, describe every step of how to make a transfer work in practice, and separate treatment applies under the UK GDPR and other regimes.
Chapter V of the EU GDPR establishes the legal framework governing transfers of personal data to third countries or international organisations. It begins with a general principle for transfers and then provides the recognised bases on which a transfer may proceed, including transfers made on the basis of an adequacy decision (Article 45) and other mechanisms addressed within the chapter. Per the European Data Protection Board, personal data may only be transferred outside the EEA in compliance with the conditions laid down in Chapter V. This entry identifies the scope and structure of the chapter; it does not exhaustively enumerate every transfer mechanism, procedural safeguard, or supplementary measure, and the specific article-level requirements should be consulted directly. The UK GDPR maintains a structurally analogous but separately administered regime, and its adequacy and transfer determinations are made independently of the EU. Whether a given data flow constitutes a 'transfer' triggering Chapter V obligations is itself a fact-specific question. Out of scope here: enforcement outcomes, the mechanics of specific safeguards, retention rules, and treatment under non-GDPR frameworks.
Why it matters
Chapter V of the EU GDPR governs one of the most operationally consequential aspects of data protection: whether personal data can lawfully leave the European Economic Area at all. The European Data Protection Board is explicit that personal data may only be transferred outside the EEA in compliance with the conditions laid down in Chapter V. This means that ordinary business activities that appear routine, such as using a cloud provider with infrastructure outside the EEA, engaging an overseas support vendor, or consolidating personnel records in a global system, can each raise Chapter V questions before the data ever moves. Getting this wrong exposes organisations to regulatory scrutiny, and the chapter functions as a gatekeeper rather than a formality.
Who it's relevant to
Inside Chapter V GDPR
Common questions
Answers to the questions practitioners most commonly ask about Chapter V GDPR.