Data Exporter
A data exporter is the party that sends personal data to another organization or jurisdiction, typically in the context of a cross-border transfer. In addition to arranging the transfer, the data exporter carries ongoing responsibilities, such as checking whether the legal basis relied on for the transfer remains valid. Note that the same phrase is also used commercially for unrelated software tools that extract data from a platform, which is a different concept entirely.
In the context of international data transfers, a data exporter is the entity that transfers personal data to a recipient in another jurisdiction or organization, frequently as part of a cross-border transfer arrangement. According to the European Data Protection Board, data exporters bear ongoing accountability obligations, including monitoring whether adequacy decisions relevant to their transfers remain in force and are not being revoked. This entry defines the role at a conceptual level and does not detail the specific transfer mechanisms (such as standard contractual clauses or supplementary measures), the allocation of obligations between data exporter and data importer, or the differing treatment of the term across regimes; the cited responsibilities reflect the EU/EEA framework as described by the EDPB and should not be assumed to apply identically in other jurisdictions. The commercial software products that share the name 'Data Exporter' are unrelated data-extraction tools and are out of scope for this definition.
Why it matters
The data exporter role sits at the center of cross-border transfer accountability. When personal data leaves one jurisdiction for another, the exporter is generally the party that must ensure a valid legal basis for that transfer exists and continues to exist over time. This is not a one-time gatekeeping decision made at the point of transfer; under the EU/EEA framework as described by the European Data Protection Board, data exporters carry ongoing obligations, including monitoring whether adequacy decisions relevant to their transfers remain in force and are not in the process of being revoked. Treating the transfer as a completed formality, rather than a relationship requiring continued oversight, is a common source of exposure.
Because adequacy determinations and the legal landscape around them can change, the exporter's monitoring duty is what keeps a transfer defensible over its lifetime. Accountability here requires demonstrable evidence that the exporter has assessed and continues to assess the validity of its chosen basis, not merely a stated intention to comply. This entry describes the role conceptually and does not cover the specific transfer mechanisms, the allocation of obligations between exporter and importer, or how the term is treated outside the EU/EEA; those matters typically differ by jurisdiction and implementation and should be assessed separately.
A practical hazard worth flagging is naming. The phrase "data exporter" is also used commercially for unrelated software products that extract data from a platform into files or databases. Conflating the data protection role with such a tool can cause real confusion in procurement, documentation, and internal communications, so practitioners should confirm which meaning is intended in any given context.
Who it's relevant to
Inside Data Exporter
Common questions
Answers to the questions practitioners most commonly ask about Data Exporter.