Skip to main content
Category: International Data Transfers

Trans-Atlantic Data Flows

Also known as: Transatlantic Data Flows, EU-U.S. Data Flows
Simply put

Trans-Atlantic data flows refer to the movement of personal data between the European Union (and related jurisdictions such as the United Kingdom) and the United States. Because these regions have different data protection regimes, transfers require a recognized legal basis so that personal data continues to be protected once it leaves its home jurisdiction. Governments on both sides have negotiated frameworks intended to provide a lawful and stable footing for these transfers, which underpin significant economic activity between the regions.

Formal definition

Trans-Atlantic data flows describe transfers of personal data from the European Economic Area, and separately from the United Kingdom, to the United States, which under the EU GDPR (and the UK GDPR) is treated as a third country requiring an approved transfer mechanism. Historically, the legal basis for such transfers has been provided through adequacy-style arrangements negotiated between the EU and the U.S., the most recent being the EU-U.S. Data Privacy Framework, alongside alternative mechanisms available under the GDPR where no adequacy determination applies. The validity of these arrangements has been shaped by litigation before EU courts (notably the Schrems line of cases) and remains subject to ongoing legal challenge and review. The UK maintains its own transfer regime and any UK-specific extension is assessed separately from the EU's determination. This entry defines the concept and does not detail the operational mechanics of specific transfer mechanisms (for example, standard contractual clauses or binding corporate rules), certification or self-attestation requirements, redress procedures, retention rules, or enforcement outcomes, each of which is governed by the applicable instrument and differs by jurisdiction. Note that treatment under other regimes, such as the CCPA and CPRA or sector-specific U.S. laws, differs and is not addressed here.

Why it matters

Trans-Atlantic data flows sit at the intersection of two divergent legal regimes: the EU GDPR (and separately the UK GDPR), which treat the United States as a third country requiring an approved transfer mechanism, and a U.S. framework built from sector-specific and state laws. For any organization that stores EU or UK personal data on U.S.-based infrastructure, uses U.S. cloud or SaaS providers, or shares data with a U.S. parent or affiliate, the lawfulness of that movement depends on maintaining a recognized legal basis. When a transfer mechanism is invalidated or called into question, the affected transfers do not become lawful by default; controllers and processors must identify an alternative basis or halt the transfer.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads overseeing organizations that transfer EU or UK personal data to the United States need to confirm and document the legal basis relied upon, whether that is the EU-U.S. Data Privacy Framework or an alternative GDPR mechanism. Because the EU and UK regimes are assessed separately, they should verify that the basis relied upon actually covers the relevant flow. This entry does not address the operational requirements of any specific mechanism, which must be reviewed against the applicable instrument.
Legal and Compliance Teams
Legal and compliance functions should track the litigation and review history affecting these arrangements, including the Schrems line of cases and the September 2025 General Court decision confirming the Data Privacy Framework's validity, while recognizing that such determinations remain open to further challenge. Contingency planning for the possible narrowing or invalidation of a mechanism is generally prudent rather than optional.
Data Governance and Information Security Leads
Governance leads maintaining data catalogs and lineage need visibility into where personal data physically resides and moves, since a lawful transfer basis cannot be demonstrated without knowing which flows reach the United States. This is a governance concern distinct from, though overlapping with, the security controls applied to the data in transit and at rest; a valid transfer mechanism and strong security controls address different obligations and neither substitutes for the other.
Procurement and Vendor Management
Teams onboarding U.S.-based cloud providers, SaaS vendors, or sub-processors should confirm the transfer basis a vendor relies on and whether it covers both EU and, where relevant, UK data. Vendor reliance on a particular framework should be documented as part of accountability evidence, and contracts should anticipate the possibility that a mechanism may be reviewed or withdrawn.

Inside Trans-Atlantic Data Flows

Transfer Mechanism
A legal basis relied upon to move personal data from one jurisdiction to another, such as an adequacy determination, standard contractual clauses, or a certification framework. Under the EU GDPR and UK GDPR, transfers of personal data outside the respective jurisdiction generally require such a mechanism. The specific mechanisms recognized differ between the EU and UK regimes, and treatment varies elsewhere.
Adequacy Determination
A formal finding by a competent authority that a third country, territory, or framework provides a level of protection considered comparable to that of the originating regime. Where an adequacy determination applies, transfers may generally proceed without additional safeguards, though the scope and conditions of any given determination should be confirmed rather than assumed.
Standard Contractual Clauses (SCCs)
Pre-approved contractual terms used to provide safeguards for transfers where no adequacy determination applies. The EU and UK maintain their own respective sets of clauses, which are not interchangeable. SCCs typically allocate obligations between exporting and importing parties and may require accompanying assessment of the destination's legal environment.
Transfer Impact Assessment
An evaluation, associated in particular with EU GDPR practice, of whether the protections in the destination jurisdiction and the safeguards in place are sufficient in light of local laws and the circumstances of the transfer. Whether and how such an assessment is required depends on the mechanism relied upon and the applicable regime.
Roles of the Parties
The exporting party (often a data controller, and sometimes a data processor) and the importing party each bear distinct obligations under the applicable transfer mechanism. Accountability for lawful transfer generally rests with the controller, but processors may carry their own contractual and statutory duties. The specific allocation should be documented and demonstrable.

Common questions

Answers to the questions practitioners most commonly ask about Trans-Atlantic Data Flows.

Does the existence of an adequacy decision or framework mean my organization can transfer personal data to the United States without any further steps?
Not necessarily. An adequacy decision or a framework such as the EU-U.S. Data Privacy Framework generally provides a transfer mechanism only for data flows that fall within its specific scope and, where relevant, only to recipients that have self-certified or otherwise qualified under it. Transfers outside that scope typically still require a separate lawful transfer mechanism. Adequacy also does not remove your other obligations as a controller or processor, including having a lawful basis for the processing itself, honoring data subject rights, and meeting security and accountability requirements. This entry does not cover the current legal status, scope, or conditions of any specific framework, which can change and should be verified against the relevant regulator's guidance.
If I encrypt or pseudonymize personal data before sending it across a border, does that mean the transfer is no longer regulated?
Generally no. Encryption and pseudonymization are risk-reduction and security measures; they do not, on their own, take data outside the scope of data protection law. Pseudonymized data is typically still personal data because it can be re-linked to individuals, and encrypted data remains personal data to any party who can decrypt it. These measures can be relevant supplementary safeguards that support a transfer mechanism, particularly where a transfer risk assessment identifies concerns, but they do not by themselves constitute a lawful basis for a cross-border transfer. This entry does not address when a given technique would be sufficient as a supplementary measure in a specific case.
How do I decide which transfer mechanism to rely on for a specific data flow?
The choice generally depends on the origin jurisdiction, the destination, the nature of the parties, and the type of data. In broad terms, you first check whether the destination is covered by an adequacy decision or an applicable framework; if not, you consider contractual mechanisms such as standard contractual clauses or binding corporate rules, or, in narrower circumstances, specific derogations. The appropriate mechanism differs between the EU GDPR and the UK GDPR, and other regimes address international transfers on their own terms. This entry does not prescribe a mechanism for any particular scenario, and you should confirm the current options with the applicable regulator's guidance and qualified counsel.
What is a transfer risk assessment, and when should I carry one out?
A transfer risk assessment is an evaluation, typically performed when relying on a contractual mechanism such as standard contractual clauses, of whether the legal and practical circumstances in the destination provide a level of protection broadly consistent with the exporting jurisdiction's standard, and of what supplementary measures may be needed. It generally considers factors such as the destination's laws affecting access to data and the practical context of the transfer. As a governance matter, the assessment and its supporting rationale should be documented as demonstrable evidence rather than stated intent. This entry does not set out the specific methodology, required factors, or thresholds, which depend on jurisdiction and current regulatory guidance.
How should responsibilities for a cross-border transfer be allocated between a data controller and a data processor?
Responsibility generally follows the roles. A controller typically determines the purposes and means of processing and bears primary accountability for ensuring a valid transfer mechanism is in place and for the underlying lawful basis. A processor generally acts on the controller's documented instructions and, where it engages sub-processors located in other jurisdictions, must ensure appropriate transfer safeguards are addressed, usually reflected in the processing contract. Onward transfers by processors or sub-processors are a common area of accountability gaps. This entry does not cover the detailed contractual terms required in any specific regime or the full scope of processor obligations.
What documentation should we maintain to demonstrate that cross-border transfers are handled appropriately?
From a governance and accountability perspective, organizations generally maintain evidence such as records that identify their transfers and destinations, the transfer mechanism relied on for each, any executed contractual instruments, and any transfer risk assessments and supplementary measures adopted. Under some regimes, transfers may also need to be reflected in records of processing activities; note that such records are an accountability obligation and not the same thing as a data inventory tool. Accountability generally requires demonstrable, maintained evidence rather than merely stated policy. This entry does not specify retention periods, exact record contents, or the documentation requirements of any particular jurisdiction.

Common misconceptions

The EU GDPR and UK GDPR treat trans-Atlantic transfers identically, so a single mechanism satisfies both.
The EU and UK operate distinct regimes with their own adequacy determinations and their own sets of standard contractual clauses. A mechanism valid under one does not automatically satisfy the other, and organizations transferring under both regimes generally need to address each separately.
Encrypting or tokenizing data before transfer means it is no longer personal data, so transfer rules do not apply.
Encryption and tokenization are safeguards, not means of rendering data non-personal. Where the data can be re-identified or linked back to individuals, it typically remains personal data and the applicable transfer requirements continue to apply. Such measures may support a transfer mechanism but do not remove the underlying obligation.
Once an adequacy determination or transfer framework exists, no further compliance work is needed.
The scope, conditions, and continued validity of an adequacy determination or framework should be confirmed and monitored, and it may not cover every category of data or every recipient. Reliance on it is context-dependent and does not by itself guarantee compliance for all processing associated with the transfer.

Best practices

Identify the applicable regime or regimes for each transfer separately, treating EU GDPR and UK GDPR requirements as distinct rather than assuming a single mechanism covers both.
Confirm the current scope and conditions of any adequacy determination or transfer framework you rely upon, rather than assuming it covers all data categories, recipients, or processing activities.
Where standard contractual clauses are used, use the set appropriate to the applicable regime and ensure the obligations allocated to exporting and importing parties are documented and demonstrable.
Document the roles of the parties involved, distinguishing controller and processor responsibilities, and retain evidence of how accountability for the transfer is met rather than relying on stated intent.
Treat encryption, tokenization, and similar measures as supporting safeguards, and continue to apply transfer requirements where the data remains capable of identifying individuals.
Where a transfer impact assessment is relevant to the mechanism relied upon, conduct and record it, and review transfers periodically as the legal environment or the arrangement changes.