Supplementary Measures
Supplementary measures are additional safeguards that an organization may need to put in place when transferring personal data from the European Economic Area to a country outside it, on top of a transfer tool such as Standard Contractual Clauses. They are intended to fill gaps in protection that arise where the laws or practices of the destination country do not offer protection equivalent to that under EU law. The specific measures required depend on the outcome of a case-by-case assessment of the transfer and the destination country.
Under the European Data Protection Board's Recommendations 01/2020, supplementary measures are technical, contractual, or organizational measures adopted to compensate for gaps in protection arising from the laws or practices of a third country, so that transferred personal data continues to receive protection essentially equivalent to that guaranteed within the EU. They arise in the transfer assessment methodology that follows the Schrems II ruling, where an exporter relying on an Article 46 GDPR transfer tool (for example, Standard Contractual Clauses) must assess the third country's legal environment and, at the step of adopting supplementary measures, determine whether additional safeguards are needed to make the transfer lawful. The exporter bears the accountability for identifying and implementing effective measures; per the SCC framework, the importer's role is generally to assist the exporter in assessing the need for and designing such measures and to follow the exporter's instructions. Where no effective supplementary measure can bring the transfer up to the required standard, the transfer should generally not proceed on that basis. This entry defines the concept and allocates roles; it does not cover the full transfer-assessment methodology, adequacy decisions, derogations, the detailed catalogue of example measures, or the treatment of international transfers under regimes other than EU/UK GDPR, all of which are out of scope here and differ by jurisdiction and implementation.
Why it matters
Supplementary measures matter because a transfer tool such as Standard Contractual Clauses is, on its own, no longer treated as sufficient to legitimize every transfer of personal data out of the European Economic Area. Following the Court of Justice of the European Union's Schrems II ruling, an exporter cannot simply sign the clauses and proceed; it must assess whether the destination country's laws and practices could undermine the protections the clauses promise, and where they do, it must consider additional safeguards. Supplementary measures are the mechanism for closing that gap so that transferred data continues to receive protection essentially equivalent to that guaranteed within the EU.
The accountability dimension is what makes this a live compliance obligation rather than a paper exercise. Under the EDPB's Recommendations 01/2020, the exporter bears responsibility for identifying and implementing effective measures and, generally, for documenting the assessment that led to them. Stated intent is not enough; the framework expects demonstrable evidence that the transfer was assessed and that any measures adopted are genuinely capable of remedying the identified shortfalls. Where no effective measure can bring the transfer up to the required standard, the transfer should generally not proceed on that basis, which can force organizations to re-architect data flows or reconsider vendor relationships.
This entry does not resolve which specific measures suffice in a given case. That determination is fact-specific and depends on the nature of the data, the transfer, and the legal environment of the destination country, and it typically requires legal and technical analysis rather than a generic checklist.
Who it's relevant to
Inside Supplementary Measures
Common questions
Answers to the questions practitioners most commonly ask about Supplementary Measures.