Privacy Designยฎ
Knowledge Base โ†’ Frameworks & law โ†’ ๐ŸŒ International Transfers & TIA Matrix

๐ŸŒ International Transfers & TIA Matrix

International data transfers, transfer impact assessments (TIAs), adequacy and SCCs. See also the China / CAC repository.

<WRAP center round important 90%> โš ๏ธ NOT LEGAL ADVICE โ€” decision-support only. This matrix is a simplified, generalised aid for spotting which transfer mechanism likely applies. It is not a legal opinion and must not be relied on for a specific transfer without verifying the current primary law and taking qualified advice. Data-protection transfer law changes frequently; entries can be out of date the moment they are written.

Table A โ€” Exporter regimes (the “from” axis)

Exporter Model Free to Otherwise need Assessment Localisation
EU/EEA (GDPR Ch. V) Adequacy + SCCs EC adequacy list (incl. US via DPF) SCCs 2021/914 ยท BCRs ยท Art. 49 TIA (Schrems II) No
UK (UK GDPR) Adequacy + IDTA UK regs (โ‰ˆEU + UKโ€“US Data Bridge) IDTA / EU SCCs+Addendum ยท BCRs ยท derogations TRA No
Switzerland (revFADP) Adequacy + CH-SCCs FDPIC list + Swissโ€“US DPF EU SCCs + FDPIC amend. ยท BCRs ยท derogations TIA No
Brazil (LGPD) Adequacy + SCCs ANPD list (nascent) ANPD SCCs ยท BCRs ยท specific clauses โ€” No
Canada (PIPEDA; Quรฉbec Law 25) Accountability โ€” Comparable-protection contract; org stays accountable. Quรฉbec Law 25: privacy-impact assessment required before transferring PI outside Quรฉbec Assessment (Quรฉbec PIA) No
China (PIPL) Approval / mechanism โ€” CAC security assessment / certification / standard contract; 2024 exemptions PIPIA Yes (CIIO, “important data”)
India (DPDPA + DPDP Rules 2025) ๐Ÿ”ถ Negative list All (none restricted yet) Nothing extra now; govt may blacklist; fully operational ~mid-2027 โ€” Sectoral (RBI)
Indonesia (PDP Law 27/2022) ๐Ÿ”ถ Tiered Equal-or-higher protection Else binding safeguards; else consent; implementing GR pending; extraterritorial โ€” Sectoral (public / electronic-system data, GR 71/2019)
Japan (APPI) Adequacy-equiv. Japan list (EEA, UK) Consent / equivalent-measures contract + oversight โ€” No
Malaysia (PDPA amended 2024/25) Comparable-protection + TIA โ€” Destination “substantially similar”/adequate via TIA; SCC/BCR/cert; or consent/contract; 5-day notice Yes (TIA) No
South Korea (PIPA 2023) Consent + alternatives EU (PIPC-recognised, Sep 2025) Consent / contract+safeguards+notice / PIPC-cert / recognised country; SCC/BCR + Overseas-Transfer Impact Assessment planned H1 2026 Impact-type No
Taiwan (PDPA amended Nov 2025 โ†’ PDPC) Permitted unless restricted โ€” No dedicated CBDT statute yet; PDPC may restrict (Art. 21); sector/national-security bans emerging (PII to China/HK/Macao); assertive enforcement โ€” Sector
UAE (Federal PDPL 45/2021 + DIFC/ADGM) ๐Ÿ”ถ Adequacy + mechanisms (fragmented) Federal list pending; DIFC/ADGM own lists Federal: adequate country / contract / consent / necessity (regs not gazetted); health data must stay in UAE absent approval; financial-sector controls. DIFC & ADGM: GDPR-like + own SCCs DIFC/ADGM yes Health + free-zone/sector
Australia (APP 8) Accountability โ€” Reasonable steps + comparable protection; exporter stays liable; consent Reasonable-steps Health/sector
Russia Localisation โ€” Roskomnadzor consent/registration; strict โ€” Yes (citizens’ data)
Singapore (PDPA s.26) Comparable-protection + accountability โ€” Recipient bound by legally enforceable obligations (contract/BCR/APEC-CBPR cert) ensuring comparable protection; or consent; or contract necessity; or data in transit/public Comparable-protection assessment No
South Africa (POPIA s.72) Adequacy-or-safeguards + accountability โ€” Recipient bound by law/BCR/agreement with adequate protection + onward-transfer limits; or consent; or contract necessity/benefit Adequacy assessment No
Turkey (KVKK Art. 9, amended Jun 2024) Adequacy + safeguards (GDPR-aligned) Board adequacy decisions (list nascent) Board standard contract (notify Board โ‰ค5 business days) / BCRs / int’l agreement / undertaking+authorisation; explicit-consent & other derogations for one-off Adequacy/safeguards assessment No
Costa Rica (Law 8968; reform Bill 23097 ๐Ÿ”ถ) Consent-based + adequate-protection โ€” Data-subject consent; transfer to a non-adequate country without a valid derogation = “very serious” offence; guarantee adequate protection. GDPR-aligned reform (Bill 23097) pending Adequacy/consent check No
Most other countries Light / none โ€” Often consent/contract or no restriction โ€” Varies

Table B โ€” PERSONAL DATA transfer โ€” destination buckets from an EU/EEA exporter (UK/CH โ‰ˆ same)

These buckets are the EU/EEA exporter view (adequacy is an EU concept). For any other exporter, that country’s own regime governs โ€” see Table A.

Bucket Countries Adequate? Mechanism Verdict
Adequate โ†’ free UK, CH, Japan, South Korea, Canada (comm.), NZ, Israel, Argentina, Uruguay, Andorra, Faroe, Guernsey, IoM, Jersey โœ… none Free
US โ€” DPF-certified ๐Ÿ”ถ US importer self-certified to DPF โœ… (partial) DPF OK if certified (verify scope)
Mechanism-achievable (SCC + TIA) Australia, Taiwan, UAE (esp. DIFC/ADGM), Malaysia, Indonesia, Brazil, Singapore, South Africa, Turkey, Costa Rica, most LatAm/SE-Asia โŒ SCCs + TIA (+ measures) OK, case-by-case
High-risk / broad state access US (non-DPF), China, Russia, India โŒ SCCs + TIA + strong measures / local mechanism Problematic โ€” measures or block
Localisation / approval China (CIIO/important data), Russia, Indonesia/India (sectoral) โŒ Local pre-clearance + export mechanism Restricted
No mechanism one-off flows โ€” Art. 49 derogation Occasional only

Table C โ€” SYSTEM ACCESS (remote admin/support) โ€” EU/EEA as exporter / source of the remote access โ€” mitigation lens

Same mechanism as Table B, but technical measures change the residual risk. The decisive question: does the third-country admin need PLAINTEXT personal data?

Situation Mitigations Residual risk Verdict
Adequate destination n/a Low Free โ€” normal access controls
Non-adequate, importer sees only ciphertext/pseudonymised (keys held in exporter country) Strong encryption (exporter-held keys), pseudonymisation, no-download, JIT/ephemeral access, logging Neutralised (EDPB Rec 01/2020 UC 1โ€“3) OK
Non-adequate, importer needs plaintext Access controls help but don’t neutralise Medium Case-by-case (per destination risk)
High-risk destination, plaintext admin Encryption fails if cleartext needed (EDPB UC 6/7) High Avoid โ€” restrict to encrypted-only ops or relocate access
High-risk destination, encrypted-only ops E2E enc + exporter-held keys + confidential computing Low / neutralised OK if admin never needs cleartext
Localisation regime โ€” โ€” Local rules govern even remote access

Table D โ€” SYSTEM SUPPORT OUT OF INDIA (Indian team remotely supporting your systems)

Perspective: India as the location of the remote support/access, supporting a controller elsewhere (e.g. an EU/EEA exporter). If Indian staff can reach personal data, that access is a transfer to India (EDPB 05/2021). India (DPDPA) does not restrict inbound access, but the Indian entity is usually a processor / data-fiduciary with its own contract & security duties; India is not EU-adequate (broad state access โ†’ factor into the TIA). RBI payment-data localisation applies if payment data is in scope.

Support scenario Transfer? EU-exporter mechanism India-side (DPDPA) Mitigations / notes Verdict
No access to personal data (infra/OS/network only, or ciphertext-only with keys held outside India) No personal-data transfer None (Ch. V not triggered) Contract + security good practice RBAC; encryption (keys outside India); no-download; screen-only/JIT; logging; beware PII in metadata/config/logs/tickets OK โ€” document the no-PII scoping
Possible / incidental access (admin could technically reach PII; break-glass only) Treat as a transfer (mere possibility can count) SCCs + TIA โ€” or neutralise the access Processor contract; security Prefer to eliminate access (encryption + keys outside India โ†’ back to row 1); else SCC+TIA + measures SCC+TIA, or neutralise
Actual access to personal data (plaintext) (L2/L3 support, data fixes, content ops) Yes โ€” transfer to India SCCs + TIA + supplementary measures Valid processor contract required (DPDPA); security safeguards; breach cooperation; onward transfer follows DPDPA negative-list Encryption can’t neutralise plaintext (EDPB UC 6/7); minimise/pseudonymise; heightened scrutiny for sensitive/large-scale; consider EU-side handling for sensitive data SCC+TIA + measures; high scrutiny

Table E โ€” US DOJ Data Security Program (EO 14117) โ€” bulk-sensitive-data export controls ๐Ÿ”ถ

A US-outbound national-security control (28 CFR Part 202; EO 14117; final rule effective 8 Apr 2025, affirmative compliance obligations from 6 Oct 2025, reporting/enforcement phasing through 2026). Separate from the privacy/adequacy analysis โ€” it turns on the recipient being a country of concern (China incl. HK/Macau, Cuba, Iran, North Korea, Russia, Venezuela) or a covered person (entities โ‰ฅ50% owned by / organised in a CoC; their employees/contractors; individuals resident in a CoC). Covers bulk US sensitive personal data (genomic/‘omic, biometric, precise geolocation, health, financial, identifiers) and US government-related data (any volume). Cross-link: offshoring to India (Table D) is not a CoC โ€” but a support provider that is a covered person (e.g. โ‰ฅ50% CoC-owned, or CoC-resident staff) can trigger this.

Scenario DSP category Outcome What’s required Notes
Data brokerage / sale of bulk US sensitive personal data to a CoC or covered person Prohibited transaction Prohibited โ€” (not permitted) Core prohibition; incl. onward-transfer & knowingly directing
US government-related data (precise geolocation of sensitive gov sites; data on gov/military personnel) to CoC/covered person Prohibited Prohibited โ€” any volume โ€” No bulk threshold
Human genomic / ‘omic / biospecimen data to CoC/covered person Prohibited Prohibited โ€” Lowest thresholds; especially sensitive
Vendor / employment / investment agreement giving a covered person access to bulk US sensitive data (e.g. an offshore support/dev team that is a covered person) Restricted transaction Allowed only if compliant CISA security requirements + data-compliance program + due diligence + annual audit + (2026) reporting The key offshoring case โ€” access = a covered data transaction
Below bulk threshold, rule-compliant de-identification, or an exempt transaction (intra-corporate group, financial services, telecom, US-gov, FDA/clinical) Out of scope / exempt No DSP restriction Document the exemption/threshold Still check other laws (privacy, export controls)

Table F โ€” HEALTH & special-category data (overlay on Tables Aโ€“C)

Health data is special-category (GDPR Art. 9). A transfer must satisfy an Art. 9(2) condition on top of the Chapter V mechanism, and the TIA must treat it as sensitive โ€” plaintext exposure to a high-risk state generally cannot be neutralised by encryption (EDPB Rec 01/2020 UC 6/7). Watch EU secondary-use rules (EHDS) and national health-hosting regimes (e.g. FR HDS) that can require EU/EEA hosting.

Cross-cutting frameworks

Topic Rule / effect on transfers
GDPR Art. 9 โ€” special category + stacking Needs an Art. 9(2) condition in addition to an Art. 6 basis and a Chapter V transfer tool; the transfer mechanism does not itself legitimise the sensitive-data processing.
GDPR Art. 9(4) โ€” national add-ons Member States may keep/introduce further conditions on health/genetic/biometric data โ€” the hook for the national hosting/localisation rules below.
EDPB Rec 01/2020 โ€” encryption is no cure for plaintext Storage-only encryption / pseudonymisation (UC 1โ€“3) can be effective; transfer to a processor in a high-risk state that needs cleartext (UC 6/7) has no effective technical measure.
EHDS โ€” Reg. (EU) 2025/327 ๐Ÿ”ถ In force 26 Mar 2025 (secondary-use from 2029). Secondary-use analysis must occur in an HDAB-controlled secure processing environment (Art. 73); third countries join HealthData@EU only from 2035 on equivalence. Member States may require primary-use EHR storage in the EU.
France โ€” HDS + SecNumCloud / “cloud au centre” ๐Ÿ”ถ Hosting others’ patient data needs HDS certification (CSP L.1111-8). State doctrine requires particularly sensitive State/public-sector data on ANSSI SecNumCloud-qualified cloud. Health Data Hub mid-migration Azure โ†’ Scaleway (target end-2026/2027).
Germany โ€” ยง203 StGB + Land / church laws Medical secrecy; the 2017 amendment permits disclosure to external IT/cloud providers under conditions. Public hospitals are additionally bound by Land hospital laws; confessional hospitals by church data-protection law (KDG/DSG-EKD).
US โ€” HIPAA/HITECH + EO 14117 ๐Ÿ”ถ HIPAA has no localisation; PHI may go offshore with Security-Rule safeguards + a Business Associate Agreement. DOJ Data Security Program (EO 14117; 28 CFR Part 202) restricts bulk health & human-genomic data to countries of concern; enforcement ramps up 6 Oct 2026.
China โ€” PIPL + Human Genetic Resources ๐Ÿ”ถ Health/genetic = sensitive PI (PIPL: separate consent + a CAC export route). Human genetic resources are separately gated by the HGR Regulation (MOST/HGRAC approval) โ€” not a substitute for PIPL export compliance.

Per-regime health specifics

“Public-body extras” = where public vs private hospitals diverge. The split bites at: FR SecNumCloud / “cloud au centre” (State/public sector), German Land hospital laws (+ church law for confessional hospitals), and public-scope localisation (Indonesia GR 71/2019, Russia public bodies, EHDS Health Data Access Bodies). UAE, Australia (MHR), Russia, China and US HIPAA/EO 14117 apply by data type / actor role regardless of public vs private.

Regime Health-data specifics Health localisation Public-body extras
EU/EEA ๐Ÿ”ถ Art. 9(2) condition on top of Ch. V; EHDS routes secondary use into HDAB secure environments EHDS secondary-use; optional national EHR storage-in-EU Public bodies / Health Data Access Bodies carry EHDS secure-processing duties
UK Special category (Art. 9) + transfer tool; no statutory health localisation No (NHS residency expectations in practice) NHS: DSPT + residency/procurement expectations
Switzerland Sensitive personal data (revFADP); adequacy/safeguards No โ€”
Brazil Sensitive (LGPD); ANPD adequacy/SCCs No โ€”
Canada / Quรฉbec ๐Ÿ”ถ No general health localisation; Quรฉbec Law 25 PIA before any transfer of PI outside Quรฉbec No (Quรฉbec PIA before export) Public bodies + Quรฉbec health-info sector: extra constraints
China ๐Ÿ”ถ Health/genetic = sensitive PI (PIPL + CAC route); HGR Regulation gates genetic/biospecimen export PIPL route + HGR approval (genetic) โ€”
India ๐Ÿ”ถ No health localisation in the final DPDP Act / Rules 2025; conditional free-flow No โ€”
Indonesia ๐Ÿ”ถ Tiered PDP-Law regime; GR 71/2019 forces PUBLIC operators to localise Public-sector (GR 71/2019) โ€” catches state/public hospitals State/public hospitals must localise; private may offshore
Japan Requires-special-care information (APPI); adequacy/consent/equivalent-measures No โ€”
Malaysia Sensitive (PDPA); TIA / comparable-protection No โ€”
South Korea Sensitive information (PIPA); consent/statutory basis (EU-adequate) No โ€”
Taiwan ๐Ÿ”ถ Sensitive (PDPA); PDPC may restrict; no dedicated CBDT statute yet No โ€”
UAE ๐Ÿ”ถ HARD localisation: Law 2/2019 Art. 13 โ€” health data must stay in UAE absent approval Yes โ€” must stay in UAE (Law 2/2019) โ€”
Australia My Health Records Act s.77 โ€” MHR data must stay in Australia (not waivable); other health via APP 8 Yes โ€” MHR data must stay in Australia (s.77) โ€”
Russia 152-FZ citizen-data localisation catches health (no carve-out) Yes (152-FZ โ€” includes health) โ€”
Singapore Personal data (PDPA s.26); comparable-protection No โ€”
South Africa Special personal information (POPIA s.72) No โ€”
Turkey Special-category (KVKK); adequacy / standard-contract (2024 reform) No โ€”
Costa Rica ๐Ÿ”ถ Sensitive (Law 8968); consent / adequate protection No โ€”
Most other Health = “sensitive” โ†’ tighter conditions, often local approval; some hard localisation (UAE, AU MHR) or sovereign-cloud Varies Public bodies often face extra residency / procurement rules

Sources


The interactive TIA matrix tool on privacydesign.ch is generated from the machine-readable block below. Edit the block to update the tool (the daily site sync regenerates it). Keep the YAML valid.

Machine-readable matrix omitted here โ€” use the interactive TIA matrix tool.