Skip to main content
Category: International Data Transfers

Supplementary Measures

Also known as: Supplementary Measures for International Transfers
Simply put

Supplementary measures are additional safeguards that an organization may need to put in place when transferring personal data from the European Economic Area to a country outside it, on top of a transfer tool such as Standard Contractual Clauses. They are intended to fill gaps in protection that arise where the laws or practices of the destination country do not offer protection equivalent to that under EU law. The specific measures required depend on the outcome of a case-by-case assessment of the transfer and the destination country.

Formal definition

Under the European Data Protection Board's Recommendations 01/2020, supplementary measures are technical, contractual, or organizational measures adopted to compensate for gaps in protection arising from the laws or practices of a third country, so that transferred personal data continues to receive protection essentially equivalent to that guaranteed within the EU. They arise in the transfer assessment methodology that follows the Schrems II ruling, where an exporter relying on an Article 46 GDPR transfer tool (for example, Standard Contractual Clauses) must assess the third country's legal environment and, at the step of adopting supplementary measures, determine whether additional safeguards are needed to make the transfer lawful. The exporter bears the accountability for identifying and implementing effective measures; per the SCC framework, the importer's role is generally to assist the exporter in assessing the need for and designing such measures and to follow the exporter's instructions. Where no effective supplementary measure can bring the transfer up to the required standard, the transfer should generally not proceed on that basis. This entry defines the concept and allocates roles; it does not cover the full transfer-assessment methodology, adequacy decisions, derogations, the detailed catalogue of example measures, or the treatment of international transfers under regimes other than EU/UK GDPR, all of which are out of scope here and differ by jurisdiction and implementation.

Why it matters

Supplementary measures matter because a transfer tool such as Standard Contractual Clauses is, on its own, no longer treated as sufficient to legitimize every transfer of personal data out of the European Economic Area. Following the Court of Justice of the European Union's Schrems II ruling, an exporter cannot simply sign the clauses and proceed; it must assess whether the destination country's laws and practices could undermine the protections the clauses promise, and where they do, it must consider additional safeguards. Supplementary measures are the mechanism for closing that gap so that transferred data continues to receive protection essentially equivalent to that guaranteed within the EU.

The accountability dimension is what makes this a live compliance obligation rather than a paper exercise. Under the EDPB's Recommendations 01/2020, the exporter bears responsibility for identifying and implementing effective measures and, generally, for documenting the assessment that led to them. Stated intent is not enough; the framework expects demonstrable evidence that the transfer was assessed and that any measures adopted are genuinely capable of remedying the identified shortfalls. Where no effective measure can bring the transfer up to the required standard, the transfer should generally not proceed on that basis, which can force organizations to re-architect data flows or reconsider vendor relationships.

This entry does not resolve which specific measures suffice in a given case. That determination is fact-specific and depends on the nature of the data, the transfer, and the legal environment of the destination country, and it typically requires legal and technical analysis rather than a generic checklist.

Who it's relevant to

Data protection officers and privacy leads
DPOs and privacy teams overseeing EEA-origin transfers need to understand where supplementary measures fit within the post-Schrems II assessment methodology and to ensure that any measures adopted are documented as demonstrable evidence, not merely stated intent. This entry defines the concept and role allocation but does not provide the full assessment methodology or a definitive catalogue of measures.
Data exporters (controllers and processors sending data out of the EEA)
Exporters relying on an Article 46 GDPR transfer tool such as Standard Contractual Clauses bear the accountability for assessing the third country's legal environment and for identifying and implementing effective supplementary measures. Where no effective measure can bring the transfer up to the required standard, the transfer should generally not proceed on that basis.
Data importers in third countries
Importers should understand that, under the SCC framework, their role is generally to assist the exporter in assessing the need for and designing supplementary measures and to follow the exporter's instructions, rather than to make the transfer determination themselves.
Legal, procurement, and vendor management teams
Those negotiating cross-border data arrangements need to recognize that a signed transfer tool may not be sufficient on its own and that the case-by-case assessment can require additional contractual, technical, or organizational safeguards. Specific measures, adequacy decisions, and derogations are out of scope here and require dedicated legal analysis by jurisdiction.

Inside Supplementary Measures

Contextual Concept
Supplementary measures are additional safeguards considered on top of a chosen cross-border transfer mechanism, most prominently in the context of EU GDPR transfers relying on standard contractual clauses or similar instruments. The concept gained prominence in EU data protection practice following judicial scrutiny of transfers to third countries. Treatment under the UK GDPR is broadly analogous but is administered separately, and this framing does not automatically map to other regimes such as the CCPA and CPRA or HIPAA.
Transfer Impact Assessment Linkage
Supplementary measures are typically identified as an output of an assessment of the destination jurisdiction's laws and practices. The exporter generally evaluates whether the transfer mechanism alone provides an essentially equivalent level of protection, and where gaps are found, considers supplementary measures to address them. The specifics of assessment methodology are out of scope for this entry.
Technical Measures
Technical safeguards such as strong encryption or pseudonymization may be considered as supplementary measures. Note that encryption or tokenization does not, on its own, render data non-personal; pseudonymized data remains personal data because re-identification is generally possible with additional information. The effectiveness of any technical measure depends on the specific threat model, key management, and implementation.
Contractual Measures
Additional contractual commitments between exporter and importer, such as transparency obligations, notification requirements regarding access requests, or commitments to challenge disproportionate demands. Contractual measures alone may be insufficient where local law can compel the importer regardless of contract terms.
Organizational Measures
Policies, internal governance, access controls, documentation of handling of government access requests, and staff procedures that reinforce the protection of transferred data. These sit at the overlap of data governance and information security but should not be treated as a substitute for technical or legal safeguards where those are required.
Accountability Element
Under an accountability-based framing, the data exporter (typically acting as controller, though a processor may also be involved) is generally expected to document the reasoning behind selected measures and to be able to demonstrate that reasoning with evidence, not merely assert that measures are adequate.

Common questions

Answers to the questions practitioners most commonly ask about Supplementary Measures.

Do standard contractual clauses on their own make a cross-border transfer lawful?
Not necessarily. Standard contractual clauses are a transfer mechanism, but following the case law that reshaped EU and UK transfer practice, the transferring party is generally expected to assess whether the law and practice in the destination country undermine the protection the clauses promise. Where that assessment identifies gaps, supplementary measures may be needed in addition to the contractual mechanism. The clauses and the supplementary measures serve different functions and neither substitutes for the other. This entry does not cover the full mechanics of any specific transfer mechanism or the details of any particular jurisdiction's laws.
Are supplementary measures always technical controls like encryption?
No. Supplementary measures are commonly grouped into technical, contractual, and organizational categories, and an effective approach often combines them. Technical measures such as strong encryption or certain forms of pseudonymization are frequently emphasized because they can remain effective even where local law would otherwise compel access, but they are not the only option and are not always sufficient on their own. Importantly, applying encryption or pseudonymization does not render data non-personal, so these measures reduce risk rather than remove the data from scope. The suitability of any measure depends on the specific transfer, the data involved, and the identified risks.
How do we decide which supplementary measures are appropriate for a given transfer?
The choice generally follows from a transfer risk assessment that examines the nature of the data, the parties involved, the transfer mechanism relied upon, and the law and practice of the destination country. The measures selected should address the specific risks that assessment identifies rather than being applied as a generic checklist. Where no combination of measures can bring the transfer to the required level of protection, the transfer may need to be suspended or not proceed. This entry does not prescribe measures for any particular scenario, as appropriateness is context-dependent.
Who is responsible for identifying and implementing supplementary measures?
Accountability for the transfer generally rests with the party exporting the data, who is typically the controller in the arrangement, though the specific allocation depends on the roles and the contract. The importing party often bears obligations to cooperate, to be transparent about relevant local laws and access requests, and to implement agreed measures on its side. Under accountability principles, the exporting party should be able to demonstrate the reasoning and the measures with documented evidence, not merely assert that protection is adequate. This entry does not resolve controller and processor allocation for any specific arrangement.
What documentation should we retain to demonstrate supplementary measures were considered?
Because accountability frameworks generally require demonstrable evidence rather than stated intent, organizations typically retain the transfer risk assessment, the analysis of destination-country law and practice, the rationale for the measures chosen or rejected, and records of the measures actually implemented and reviewed. Keeping this evidence current matters because the underlying legal and practical conditions can change. This entry does not specify retention periods or the format any regulator requires, which vary by jurisdiction and context.
How often should supplementary measures be reviewed once in place?
Supplementary measures are generally treated as ongoing rather than one-time obligations, since the effectiveness of a given measure can be affected by changes in the destination country's law or practice, changes in the processing, or new access requests. A periodic review, together with reassessment when circumstances materially change, is a common approach. If a review indicates that the measures no longer provide the required protection, the transfer may need to be adjusted, supplemented further, or suspended. This entry does not set a fixed review interval, as this depends on the risk profile and applicable requirements.

Common misconceptions

Adopting a transfer mechanism such as standard contractual clauses automatically makes supplementary measures unnecessary.
In most cases involving EU or UK GDPR transfers, the mechanism is a starting point, not a conclusion. Where an assessment of the destination jurisdiction reveals that the mechanism alone does not ensure essentially equivalent protection, supplementary measures are generally considered. Whether they are needed depends on context and jurisdiction.
Encrypting or tokenizing the data removes it from scope so no further measures are required.
Encryption and tokenization can be effective supplementary technical measures in some scenarios, but they do not make data non-personal. Pseudonymized or encrypted data typically remains personal data, and the adequacy of such measures depends on the threat model and factors such as who controls the keys.
Contractual promises alone are sufficient supplementary measures in every case.
Contractual measures may be inadequate on their own where the importer can be legally compelled to disclose data regardless of contractual terms. In such situations, technical and organizational measures are generally considered alongside contractual ones, and the combination must be assessed for actual effectiveness.

Best practices

Treat supplementary measures as the output of a documented assessment of the destination jurisdiction, and retain that assessment as demonstrable evidence rather than relying on stated intent.
Scope your analysis to the applicable regime, distinguishing EU GDPR from UK GDPR treatment, and do not assume the same approach applies to CCPA and CPRA, HIPAA, or other frameworks.
Combine technical, contractual, and organizational measures where appropriate, and avoid relying on any single category as a guaranteed solution.
Where technical measures such as encryption or pseudonymization are used, document the threat model and key control arrangements, and do not treat the data as non-personal as a result.
Clearly assign roles, identifying whether the exporter acts as controller or processor and which party bears which obligation, and record the accountability rationale.
Review and re-validate supplementary measures periodically or when destination-jurisdiction conditions change, since the adequacy of measures is context-dependent and not fixed.