Codes of Conduct for Transfers
A code of conduct for transfers is a set of binding rules that organizations outside the EU can voluntarily sign up to, promising to protect personal data they receive from the EU. It is one of the mechanisms recognized under the EU GDPR for legitimizing transfers of personal data to countries that do not have an adequacy decision. As of 30 August 2026, no code of conduct intended specifically for use as a transfer tool has yet been finally approved in either the EU or the UK, so in practice this mechanism is not yet operational.
Under the EU GDPR framework, an approved code of conduct may serve as a tool to provide appropriate safeguards for transfers of personal data to third countries, provided the importing controller or processor located outside the EU (and not otherwise subject to the GDPR) makes binding and enforceable commitments to apply the code's safeguards, including with respect to data subject rights. The EDPB set out its interpretation of how such codes may function as transfer tools in Guidelines 04/2021 on Codes of Conduct as tools for transfers (adopted following public consultation, dated 22 February 2022). The mechanism is distinct from other transfer instruments such as standard contractual clauses or binding corporate rules, and adherence must be accompanied by demonstrable, enforceable commitments rather than stated intent. This entry addresses only the general nature of codes of conduct as transfer tools; it does not cover the detailed accreditation of monitoring bodies, the approval and registration procedure, supplementary measures that may be required following a transfer risk assessment, retention obligations, or enforcement consequences. Treatment differs under the UK GDPR and other regimes, which are separate legal instruments. As of 30 August 2026, no code of conduct intended specifically for use as a transfer tool has been finally approved in either the EU or the UK.
Why it matters
For organizations that move personal data out of the EU to countries lacking an adequacy decision, the EU GDPR offers a defined set of transfer mechanisms, and codes of conduct are one of them. Their significance is largely prospective: a code of conduct approved as a transfer tool would allow an importing controller or processor outside the EU, one not otherwise subject to the GDPR, to demonstrate appropriate safeguards through binding, enforceable commitments rather than by negotiating standard contractual clauses or establishing binding corporate rules. This could offer a sector-tailored, scalable route to compliant transfers for groups of similarly situated organizations.
Who it's relevant to
Inside Codes of Conduct for Transfers
Common questions
Answers to the questions practitioners most commonly ask about Codes of Conduct for Transfers.