Data Importer
A data importer is the party that receives personal data sent by a data exporter, typically when that data crosses from one country into another. The importer is usually located in the destination country and takes on obligations for handling the transferred data. This term relates specifically to international data transfer arrangements, not to the general technical process of importing data into a software application.
In the context of EU GDPR cross-border transfer instruments, a data importer is generally understood as a controller or processor located in a third country (outside the transferring jurisdiction) that receives personal data from a data exporter. The specific role and obligations of the importer depend on the transfer mechanism and the underlying contractual arrangement; for example, in certain standard contractual clause modules the data importer is characterised as the processor who agrees to receive personal data from the exporter for processing on the exporter's behalf, while in other configurations the importer may act as a controller. The precise obligations, safeguards, and liability allocation are set out in the governing transfer instrument and are distinct from the term's unrelated use in software engineering, where 'data import' refers to the automated or semi-automated ingestion of external data into an application. This entry defines the role only; it does not address the mechanics, adequacy conditions, or supplementary measures required to lawfully effect a transfer, nor does it cover UK GDPR, CCPA/CPRA, or other regimes where treatment may differ.
Why it matters
The data importer designation matters because it determines which party in a cross-border transfer arrangement carries specific handling obligations for personal data once it leaves the transferring jurisdiction. Under EU GDPR transfer instruments, the importer is the entity located in a third country that receives personal data from the data exporter, and the governing transfer instrument allocates safeguards and liability between the two parties. Misidentifying who the importer is, or failing to bind that party to enforceable commitments, can leave transferred data without the protections the transfer mechanism is meant to guarantee.
Who it's relevant to
Inside Data Importer
Common questions
Answers to the questions practitioners most commonly ask about Data Importer.