Skip to main content
Category: International Data Transfers

Codes of Conduct for Transfers

Also known as: Codes of Conduct as Tools for Transfers, Transfer Codes of Conduct
Simply put

A code of conduct for transfers is a set of binding rules that organizations outside the EU can voluntarily sign up to, promising to protect personal data they receive from the EU. It is one of the mechanisms recognized under the EU GDPR for legitimizing transfers of personal data to countries that do not have an adequacy decision. As of 30 August 2026, no code of conduct intended specifically for use as a transfer tool has yet been finally approved in either the EU or the UK, so in practice this mechanism is not yet operational.

Formal definition

Under the EU GDPR framework, an approved code of conduct may serve as a tool to provide appropriate safeguards for transfers of personal data to third countries, provided the importing controller or processor located outside the EU (and not otherwise subject to the GDPR) makes binding and enforceable commitments to apply the code's safeguards, including with respect to data subject rights. The EDPB set out its interpretation of how such codes may function as transfer tools in Guidelines 04/2021 on Codes of Conduct as tools for transfers (adopted following public consultation, dated 22 February 2022). The mechanism is distinct from other transfer instruments such as standard contractual clauses or binding corporate rules, and adherence must be accompanied by demonstrable, enforceable commitments rather than stated intent. This entry addresses only the general nature of codes of conduct as transfer tools; it does not cover the detailed accreditation of monitoring bodies, the approval and registration procedure, supplementary measures that may be required following a transfer risk assessment, retention obligations, or enforcement consequences. Treatment differs under the UK GDPR and other regimes, which are separate legal instruments. As of 30 August 2026, no code of conduct intended specifically for use as a transfer tool has been finally approved in either the EU or the UK.

Why it matters

For organizations that move personal data out of the EU to countries lacking an adequacy decision, the EU GDPR offers a defined set of transfer mechanisms, and codes of conduct are one of them. Their significance is largely prospective: a code of conduct approved as a transfer tool would allow an importing controller or processor outside the EU, one not otherwise subject to the GDPR, to demonstrate appropriate safeguards through binding, enforceable commitments rather than by negotiating standard contractual clauses or establishing binding corporate rules. This could offer a sector-tailored, scalable route to compliant transfers for groups of similarly situated organizations.

Who it's relevant to

Data protection officers and privacy leads at EU exporters
DPOs and privacy leads assessing lawful transfer routes should be aware that codes of conduct are a recognized transfer mechanism under the EU GDPR in principle, but that none has been finally approved for this purpose as of 30 August 2026. In the near term, restricted transfers must continue to rely on other valid mechanisms, and this option should be monitored rather than planned around.
Data importers outside the EU
Codes of conduct intended for transfers are designed to be used by importing controllers and processors that are not otherwise subject to the GDPR. Such importers would provide safeguards by adhering to an approved code and making binding, enforceable commitments, including on data subject rights. Because no such code has yet been finally approved, importers cannot currently rely on this route and should use other recognized instruments.
Industry associations and code owners
Sector bodies considering developing a code of conduct as a transfer tool should consult the EDPB's Guidelines 04/2021 for the interpretive framework. They should note that the accreditation of monitoring bodies and the approval and registration procedures are outside the scope of this entry, and that no transfer-specific code has reached final approval in the EU or UK as of 30 August 2026.
Legal and compliance advisors
Advisors structuring cross-border data flows should distinguish codes of conduct from standard contractual clauses and binding corporate rules, and should avoid presenting them as an available transfer mechanism at present. Treatment differs under the UK GDPR and other regimes, and any advice should account for the current absence of finally approved transfer codes and the need for demonstrable, enforceable commitments.

Inside Codes of Conduct for Transfers

Approved code of conduct as a transfer mechanism
Under the EU GDPR, an approved code of conduct can, in principle, serve as a lawful basis for transferring personal data to controllers or processors outside the EEA, provided it is combined with binding and enforceable commitments by the recipient in the third country. The UK GDPR contains an analogous framework. The scope of this entry is limited to the code-of-conduct mechanism itself and does not cover other transfer tools such as standard contractual clauses, binding corporate rules, or adequacy decisions.
Binding and enforceable commitments
For a code of conduct to function as a transfer tool, the data importer in the third country generally must make binding and enforceable commitments to apply the appropriate safeguards set out in the code, including as regards data subjects' rights. Merely adhering to a code that addresses domestic processing is not sufficient to legitimize a transfer.
Monitoring body
Codes of conduct generally require an accredited monitoring body to oversee and enforce compliance by adhering parties. For a code used as a transfer tool, this monitoring function extends to the commitments made by importers, and non-compliance can lead to suspension or exclusion from the code.
Approval and competent authority involvement
A code of conduct must be approved by the competent supervisory authority (and, where relevant, involve the European Data Protection Board for the EU or the Information Commissioner's Office for the UK) before it can operate as a transfer mechanism. As of 30 August 2026, no codes of conduct intended specifically for use as transfer tools have yet been finally approved in either the EU or the UK, so this remains a mechanism available in the regulatory framework rather than an established one in practice.
Accountability and demonstrable evidence
Reliance on a code of conduct as a transfer tool requires the transferring party to be able to demonstrate that the code has been approved for that purpose, that the importer's commitments are binding and enforceable, and that monitoring arrangements are in place. Stated adherence alone does not satisfy the accountability principle.

Common questions

Answers to the questions practitioners most commonly ask about Codes of Conduct for Transfers.

Does an approved code of conduct automatically make an international data transfer lawful?
No. A code of conduct is one of the transfer mechanisms recognised under the EU GDPR (and, separately, contemplated under the UK GDPR), but adherence to a code does not by itself guarantee a lawful transfer. The code must be approved for that purpose and must include binding and enforceable commitments from the recipient in the third country to apply appropriate safeguards, including as to data subject rights. As of 30 August 2026, no codes of conduct intended specifically for use as transfer tools have yet been finally approved in either the EU or the UK, so in practice this mechanism is not yet available for reliance. Whether any given transfer is lawful still depends on the full context, including any need for supplementary measures. This answer does not address the mechanics of other transfer tools such as standard contractual clauses or adequacy.
Is a code of conduct for transfers the same as binding corporate rules?
No, though the two are sometimes conflated because both are enforceable transfer safeguards. Binding corporate rules generally apply within a single corporate group or group of enterprises engaged in a joint economic activity, whereas a code of conduct is typically prepared by an association or body representing a category of controllers or processors and may be adhered to by parties outside a single group. They follow different approval pathways and involve different monitoring arrangements. As of 30 August 2026, no transfer-specific codes of conduct have been finally approved in the EU or the UK, whereas binding corporate rules have an established approval track record. This answer does not cover the detailed approval procedure for either mechanism.
Who is responsible for monitoring compliance with a code of conduct used for transfers?
Under the EU GDPR framework, monitoring of an approved code by controllers or processors that are not public authorities is generally carried out by a body accredited for that purpose by the competent supervisory authority, in addition to and without prejudice to the supervisory authority's own tasks and powers. That monitoring body is typically expected to take action, such as suspension or exclusion, where a member infringes the code. The recipient's binding and enforceable commitments remain central to the transfer safeguard. This answer does not describe accreditation criteria in detail, and note that no such transfer-specific codes had been finally approved in the EU or UK as of 30 August 2026.
If our organisation wants to rely on a code of conduct for transfers, what practical steps are involved?
In general terms, the organisation would first need an approved code that is designed and approved for use as a transfer tool, then formally adhere to it, and ensure that the third-country recipient makes binding and enforceable commitments to apply the safeguards. The organisation should retain demonstrable evidence of adherence and of the recipient's commitments, since accountability under the framework requires evidence rather than stated intent. Because, as of 30 August 2026, no transfer-specific codes had been finally approved in the EU or the UK, organisations planning around this mechanism should confirm current availability before relying on it and typically consider alternative transfer tools in the interim. This answer does not cover the specifics of any particular sector code.
Does the recipient in the third country have any obligations under a code of conduct transfer mechanism?
Yes. A defining feature of this mechanism in the EU GDPR framework is that the controller or processor in the third country must make binding and enforceable commitments, via contractual or other legally binding instruments, to apply the appropriate safeguards, including as to data subject rights. Without such commitments from the recipient, the code alone does not provide the safeguard. The precise allocation of obligations depends on whether the recipient acts as a controller or processor and on the terms of the code. This answer does not set out the full text of any commitment or the enforcement route available to data subjects.
How does a code of conduct for transfers differ from a code of conduct used for general compliance?
A code of conduct can serve broader purposes, such as helping specify how the applicable rules apply within a sector or demonstrating aspects of compliance, without being intended as a transfer tool. Only a code that is specifically approved for use as a transfer mechanism, together with binding and enforceable recipient commitments, can support international transfers on that basis. Organisations should not assume that membership of any sector code enables transfers. As noted, no transfer-specific codes had been finally approved in the EU or the UK as of 30 August 2026. This answer does not address the general approval process for non-transfer codes.

Common misconceptions

Any approved code of conduct can be used to legitimize international data transfers.
A general code of conduct addressing domestic or intra-EEA processing does not, by itself, serve as a transfer tool. Only a code specifically approved for transfer purposes, combined with binding and enforceable commitments by the importer, can perform that function. As of 30 August 2026, no such transfer-specific codes have been finally approved in either the EU or the UK.
Codes of conduct are already a common, established alternative to standard contractual clauses for transfers.
While the EU GDPR and UK GDPR frameworks provide for codes of conduct as a potential transfer mechanism, none intended specifically as transfer tools have been finally approved in the EU or UK as of 30 August 2026. In practice, organizations continue to rely predominantly on other mechanisms; the code-of-conduct route remains largely theoretical at present.
Adhering to a code of conduct removes the need for any monitoring or ongoing oversight.
Codes of conduct generally require an accredited monitoring body and impose ongoing enforcement, including the possibility of suspension or exclusion for non-compliance. Adherence is not a one-time formality and the transferring party must still be able to demonstrate compliance.

Best practices

Confirm whether a given code of conduct has actually been approved for use specifically as a transfer tool before relying on it, recognizing that as of 30 August 2026 none have been finally approved in the EU or the UK.
Do not treat adherence to a general processing code of conduct as sufficient to legitimize an international transfer; verify that transfer-specific safeguards and binding importer commitments are present.
Where a transfer-specific code becomes available, ensure the third-country importer provides binding and enforceable commitments to apply the safeguards, and retain evidence of those commitments.
Verify that an accredited monitoring body is in place and understand the consequences of non-compliance, including potential suspension or exclusion.
Continue to evaluate established transfer mechanisms as primary options given the current absence of finally approved transfer codes, and reassess as the regulatory landscape develops.
Maintain demonstrable, documented evidence of the chosen transfer basis and its approval status to satisfy the accountability principle, rather than relying on stated adherence alone.