๐ International Transfers & TIA Matrix
International data transfers, transfer impact assessments (TIAs), adequacy and SCCs. See also the China / CAC repository.
<WRAP center round important 90%> โ ๏ธ NOT LEGAL ADVICE โ decision-support only. This matrix is a simplified, generalised aid for spotting which transfer mechanism likely applies. It is not a legal opinion and must not be relied on for a specific transfer without verifying the current primary law and taking qualified advice. Data-protection transfer law changes frequently; entries can be out of date the moment they are written.
- As of: 2026-09-07. Re-verify every entry against the primary source before use.
- Volatile items (๐ถ): EUโUS DPF (subject to ongoing litigation), India DPDP Rules (phasing in to ~2027, no restricted-country list yet), UAE federal implementing regulations (not yet gazetted), Indonesia implementing GR (pending), Taiwan PDPC (operationalising the Nov-2025 amendment).
- Scope limits: buckets are generalisations; a destination’s real risk depends on the specific data, recipient, purpose, sector and government-access exposure. Sub-national/sector rules (e.g. US state laws, DIFC/ADGM vs UAE mainland, RBI localisation) can override the country-level view.
- “Access = transfer”: remote access to personal data from a third country is itself a transfer (EDPB Guidelines 05/2021).
- The exporter’s law sets the conditions (Table A), evaluated per transfer. One data flow can trigger several regimes at once.
- Cross-checked (2026-09) against DLA Piper Data Protection Laws of the World, Linklaters Data Protected, and Chambers Global Practice Guides 2026.
Table A โ Exporter regimes (the “from” axis)
| Exporter | Model | Free to | Otherwise need | Assessment | Localisation |
|---|---|---|---|---|---|
| EU/EEA (GDPR Ch. V) | Adequacy + SCCs | EC adequacy list (incl. US via DPF) | SCCs 2021/914 ยท BCRs ยท Art. 49 | TIA (Schrems II) | No |
| UK (UK GDPR) | Adequacy + IDTA | UK regs (โEU + UKโUS Data Bridge) | IDTA / EU SCCs+Addendum ยท BCRs ยท derogations | TRA | No |
| Switzerland (revFADP) | Adequacy + CH-SCCs | FDPIC list + SwissโUS DPF | EU SCCs + FDPIC amend. ยท BCRs ยท derogations | TIA | No |
| Brazil (LGPD) | Adequacy + SCCs | ANPD list (nascent) | ANPD SCCs ยท BCRs ยท specific clauses | โ | No |
| Canada (PIPEDA; Quรฉbec Law 25) | Accountability | โ | Comparable-protection contract; org stays accountable. Quรฉbec Law 25: privacy-impact assessment required before transferring PI outside Quรฉbec | Assessment (Quรฉbec PIA) | No |
| China (PIPL) | Approval / mechanism | โ | CAC security assessment / certification / standard contract; 2024 exemptions | PIPIA | Yes (CIIO, “important data”) |
| India (DPDPA + DPDP Rules 2025) ๐ถ | Negative list | All (none restricted yet) | Nothing extra now; govt may blacklist; fully operational ~mid-2027 | โ | Sectoral (RBI) |
| Indonesia (PDP Law 27/2022) ๐ถ | Tiered | Equal-or-higher protection | Else binding safeguards; else consent; implementing GR pending; extraterritorial | โ | Sectoral (public / electronic-system data, GR 71/2019) |
| Japan (APPI) | Adequacy-equiv. | Japan list (EEA, UK) | Consent / equivalent-measures contract + oversight | โ | No |
| Malaysia (PDPA amended 2024/25) | Comparable-protection + TIA | โ | Destination “substantially similar”/adequate via TIA; SCC/BCR/cert; or consent/contract; 5-day notice | Yes (TIA) | No |
| South Korea (PIPA 2023) | Consent + alternatives | EU (PIPC-recognised, Sep 2025) | Consent / contract+safeguards+notice / PIPC-cert / recognised country; SCC/BCR + Overseas-Transfer Impact Assessment planned H1 2026 | Impact-type | No |
| Taiwan (PDPA amended Nov 2025 โ PDPC) | Permitted unless restricted | โ | No dedicated CBDT statute yet; PDPC may restrict (Art. 21); sector/national-security bans emerging (PII to China/HK/Macao); assertive enforcement | โ | Sector |
| UAE (Federal PDPL 45/2021 + DIFC/ADGM) ๐ถ | Adequacy + mechanisms (fragmented) | Federal list pending; DIFC/ADGM own lists | Federal: adequate country / contract / consent / necessity (regs not gazetted); health data must stay in UAE absent approval; financial-sector controls. DIFC & ADGM: GDPR-like + own SCCs | DIFC/ADGM yes | Health + free-zone/sector |
| Australia (APP 8) | Accountability | โ | Reasonable steps + comparable protection; exporter stays liable; consent | Reasonable-steps | Health/sector |
| Russia | Localisation | โ | Roskomnadzor consent/registration; strict | โ | Yes (citizens’ data) |
| Singapore (PDPA s.26) | Comparable-protection + accountability | โ | Recipient bound by legally enforceable obligations (contract/BCR/APEC-CBPR cert) ensuring comparable protection; or consent; or contract necessity; or data in transit/public | Comparable-protection assessment | No |
| South Africa (POPIA s.72) | Adequacy-or-safeguards + accountability | โ | Recipient bound by law/BCR/agreement with adequate protection + onward-transfer limits; or consent; or contract necessity/benefit | Adequacy assessment | No |
| Turkey (KVKK Art. 9, amended Jun 2024) | Adequacy + safeguards (GDPR-aligned) | Board adequacy decisions (list nascent) | Board standard contract (notify Board โค5 business days) / BCRs / int’l agreement / undertaking+authorisation; explicit-consent & other derogations for one-off | Adequacy/safeguards assessment | No |
| Costa Rica (Law 8968; reform Bill 23097 ๐ถ) | Consent-based + adequate-protection | โ | Data-subject consent; transfer to a non-adequate country without a valid derogation = “very serious” offence; guarantee adequate protection. GDPR-aligned reform (Bill 23097) pending | Adequacy/consent check | No |
| Most other countries | Light / none | โ | Often consent/contract or no restriction | โ | Varies |
Table B โ PERSONAL DATA transfer โ destination buckets from an EU/EEA exporter (UK/CH โ same)
These buckets are the EU/EEA exporter view (adequacy is an EU concept). For any other exporter, that country’s own regime governs โ see Table A.
| Bucket | Countries | Adequate? | Mechanism | Verdict |
|---|---|---|---|---|
| Adequate โ free | UK, CH, Japan, South Korea, Canada (comm.), NZ, Israel, Argentina, Uruguay, Andorra, Faroe, Guernsey, IoM, Jersey | โ | none | Free |
| US โ DPF-certified ๐ถ | US importer self-certified to DPF | โ (partial) | DPF | OK if certified (verify scope) |
| Mechanism-achievable (SCC + TIA) | Australia, Taiwan, UAE (esp. DIFC/ADGM), Malaysia, Indonesia, Brazil, Singapore, South Africa, Turkey, Costa Rica, most LatAm/SE-Asia | โ | SCCs + TIA (+ measures) | OK, case-by-case |
| High-risk / broad state access | US (non-DPF), China, Russia, India | โ | SCCs + TIA + strong measures / local mechanism | Problematic โ measures or block |
| Localisation / approval | China (CIIO/important data), Russia, Indonesia/India (sectoral) | โ | Local pre-clearance + export mechanism | Restricted |
| No mechanism | one-off flows | โ | Art. 49 derogation | Occasional only |
Table C โ SYSTEM ACCESS (remote admin/support) โ EU/EEA as exporter / source of the remote access โ mitigation lens
Same mechanism as Table B, but technical measures change the residual risk. The decisive question: does the third-country admin need PLAINTEXT personal data?
| Situation | Mitigations | Residual risk | Verdict |
|---|---|---|---|
| Adequate destination | n/a | Low | Free โ normal access controls |
| Non-adequate, importer sees only ciphertext/pseudonymised (keys held in exporter country) | Strong encryption (exporter-held keys), pseudonymisation, no-download, JIT/ephemeral access, logging | Neutralised (EDPB Rec 01/2020 UC 1โ3) | OK |
| Non-adequate, importer needs plaintext | Access controls help but don’t neutralise | Medium | Case-by-case (per destination risk) |
| High-risk destination, plaintext admin | Encryption fails if cleartext needed (EDPB UC 6/7) | High | Avoid โ restrict to encrypted-only ops or relocate access |
| High-risk destination, encrypted-only ops | E2E enc + exporter-held keys + confidential computing | Low / neutralised | OK if admin never needs cleartext |
| Localisation regime | โ | โ | Local rules govern even remote access |
Table D โ SYSTEM SUPPORT OUT OF INDIA (Indian team remotely supporting your systems)
Perspective: India as the location of the remote support/access, supporting a controller elsewhere (e.g. an EU/EEA exporter). If Indian staff can reach personal data, that access is a transfer to India (EDPB 05/2021). India (DPDPA) does not restrict inbound access, but the Indian entity is usually a processor / data-fiduciary with its own contract & security duties; India is not EU-adequate (broad state access โ factor into the TIA). RBI payment-data localisation applies if payment data is in scope.
| Support scenario | Transfer? | EU-exporter mechanism | India-side (DPDPA) | Mitigations / notes | Verdict |
|---|---|---|---|---|---|
| No access to personal data (infra/OS/network only, or ciphertext-only with keys held outside India) | No personal-data transfer | None (Ch. V not triggered) | Contract + security good practice | RBAC; encryption (keys outside India); no-download; screen-only/JIT; logging; beware PII in metadata/config/logs/tickets | OK โ document the no-PII scoping |
| Possible / incidental access (admin could technically reach PII; break-glass only) | Treat as a transfer (mere possibility can count) | SCCs + TIA โ or neutralise the access | Processor contract; security | Prefer to eliminate access (encryption + keys outside India โ back to row 1); else SCC+TIA + measures | SCC+TIA, or neutralise |
| Actual access to personal data (plaintext) (L2/L3 support, data fixes, content ops) | Yes โ transfer to India | SCCs + TIA + supplementary measures | Valid processor contract required (DPDPA); security safeguards; breach cooperation; onward transfer follows DPDPA negative-list | Encryption can’t neutralise plaintext (EDPB UC 6/7); minimise/pseudonymise; heightened scrutiny for sensitive/large-scale; consider EU-side handling for sensitive data | SCC+TIA + measures; high scrutiny |
Table E โ US DOJ Data Security Program (EO 14117) โ bulk-sensitive-data export controls ๐ถ
A US-outbound national-security control (28 CFR Part 202; EO 14117; final rule effective 8 Apr 2025, affirmative compliance obligations from 6 Oct 2025, reporting/enforcement phasing through 2026). Separate from the privacy/adequacy analysis โ it turns on the recipient being a country of concern (China incl. HK/Macau, Cuba, Iran, North Korea, Russia, Venezuela) or a covered person (entities โฅ50% owned by / organised in a CoC; their employees/contractors; individuals resident in a CoC). Covers bulk US sensitive personal data (genomic/‘omic, biometric, precise geolocation, health, financial, identifiers) and US government-related data (any volume). Cross-link: offshoring to India (Table D) is not a CoC โ but a support provider that is a covered person (e.g. โฅ50% CoC-owned, or CoC-resident staff) can trigger this.
| Scenario | DSP category | Outcome | What’s required | Notes |
|---|---|---|---|---|
| Data brokerage / sale of bulk US sensitive personal data to a CoC or covered person | Prohibited transaction | Prohibited | โ (not permitted) | Core prohibition; incl. onward-transfer & knowingly directing |
| US government-related data (precise geolocation of sensitive gov sites; data on gov/military personnel) to CoC/covered person | Prohibited | Prohibited โ any volume | โ | No bulk threshold |
| Human genomic / ‘omic / biospecimen data to CoC/covered person | Prohibited | Prohibited | โ | Lowest thresholds; especially sensitive |
| Vendor / employment / investment agreement giving a covered person access to bulk US sensitive data (e.g. an offshore support/dev team that is a covered person) | Restricted transaction | Allowed only if compliant | CISA security requirements + data-compliance program + due diligence + annual audit + (2026) reporting | The key offshoring case โ access = a covered data transaction |
| Below bulk threshold, rule-compliant de-identification, or an exempt transaction (intra-corporate group, financial services, telecom, US-gov, FDA/clinical) | Out of scope / exempt | No DSP restriction | Document the exemption/threshold | Still check other laws (privacy, export controls) |
Table F โ HEALTH & special-category data (overlay on Tables AโC)
Health data is special-category (GDPR Art. 9). A transfer must satisfy an Art. 9(2) condition on top of the Chapter V mechanism, and the TIA must treat it as sensitive โ plaintext exposure to a high-risk state generally cannot be neutralised by encryption (EDPB Rec 01/2020 UC 6/7). Watch EU secondary-use rules (EHDS) and national health-hosting regimes (e.g. FR HDS) that can require EU/EEA hosting.
Cross-cutting frameworks
| Topic | Rule / effect on transfers |
|---|---|
| GDPR Art. 9 โ special category + stacking | Needs an Art. 9(2) condition in addition to an Art. 6 basis and a Chapter V transfer tool; the transfer mechanism does not itself legitimise the sensitive-data processing. |
| GDPR Art. 9(4) โ national add-ons | Member States may keep/introduce further conditions on health/genetic/biometric data โ the hook for the national hosting/localisation rules below. |
| EDPB Rec 01/2020 โ encryption is no cure for plaintext | Storage-only encryption / pseudonymisation (UC 1โ3) can be effective; transfer to a processor in a high-risk state that needs cleartext (UC 6/7) has no effective technical measure. |
| EHDS โ Reg. (EU) 2025/327 ๐ถ | In force 26 Mar 2025 (secondary-use from 2029). Secondary-use analysis must occur in an HDAB-controlled secure processing environment (Art. 73); third countries join HealthData@EU only from 2035 on equivalence. Member States may require primary-use EHR storage in the EU. |
| France โ HDS + SecNumCloud / “cloud au centre” ๐ถ | Hosting others’ patient data needs HDS certification (CSP L.1111-8). State doctrine requires particularly sensitive State/public-sector data on ANSSI SecNumCloud-qualified cloud. Health Data Hub mid-migration Azure โ Scaleway (target end-2026/2027). |
| Germany โ ยง203 StGB + Land / church laws | Medical secrecy; the 2017 amendment permits disclosure to external IT/cloud providers under conditions. Public hospitals are additionally bound by Land hospital laws; confessional hospitals by church data-protection law (KDG/DSG-EKD). |
| US โ HIPAA/HITECH + EO 14117 ๐ถ | HIPAA has no localisation; PHI may go offshore with Security-Rule safeguards + a Business Associate Agreement. DOJ Data Security Program (EO 14117; 28 CFR Part 202) restricts bulk health & human-genomic data to countries of concern; enforcement ramps up 6 Oct 2026. |
| China โ PIPL + Human Genetic Resources ๐ถ | Health/genetic = sensitive PI (PIPL: separate consent + a CAC export route). Human genetic resources are separately gated by the HGR Regulation (MOST/HGRAC approval) โ not a substitute for PIPL export compliance. |
Per-regime health specifics
“Public-body extras” = where public vs private hospitals diverge. The split bites at: FR SecNumCloud / “cloud au centre” (State/public sector), German Land hospital laws (+ church law for confessional hospitals), and public-scope localisation (Indonesia GR 71/2019, Russia public bodies, EHDS Health Data Access Bodies). UAE, Australia (MHR), Russia, China and US HIPAA/EO 14117 apply by data type / actor role regardless of public vs private.
| Regime | Health-data specifics | Health localisation | Public-body extras |
|---|---|---|---|
| EU/EEA ๐ถ | Art. 9(2) condition on top of Ch. V; EHDS routes secondary use into HDAB secure environments | EHDS secondary-use; optional national EHR storage-in-EU | Public bodies / Health Data Access Bodies carry EHDS secure-processing duties |
| UK | Special category (Art. 9) + transfer tool; no statutory health localisation | No (NHS residency expectations in practice) | NHS: DSPT + residency/procurement expectations |
| Switzerland | Sensitive personal data (revFADP); adequacy/safeguards | No | โ |
| Brazil | Sensitive (LGPD); ANPD adequacy/SCCs | No | โ |
| Canada / Quรฉbec ๐ถ | No general health localisation; Quรฉbec Law 25 PIA before any transfer of PI outside Quรฉbec | No (Quรฉbec PIA before export) | Public bodies + Quรฉbec health-info sector: extra constraints |
| China ๐ถ | Health/genetic = sensitive PI (PIPL + CAC route); HGR Regulation gates genetic/biospecimen export | PIPL route + HGR approval (genetic) | โ |
| India ๐ถ | No health localisation in the final DPDP Act / Rules 2025; conditional free-flow | No | โ |
| Indonesia ๐ถ | Tiered PDP-Law regime; GR 71/2019 forces PUBLIC operators to localise | Public-sector (GR 71/2019) โ catches state/public hospitals | State/public hospitals must localise; private may offshore |
| Japan | Requires-special-care information (APPI); adequacy/consent/equivalent-measures | No | โ |
| Malaysia | Sensitive (PDPA); TIA / comparable-protection | No | โ |
| South Korea | Sensitive information (PIPA); consent/statutory basis (EU-adequate) | No | โ |
| Taiwan ๐ถ | Sensitive (PDPA); PDPC may restrict; no dedicated CBDT statute yet | No | โ |
| UAE ๐ถ | HARD localisation: Law 2/2019 Art. 13 โ health data must stay in UAE absent approval | Yes โ must stay in UAE (Law 2/2019) | โ |
| Australia | My Health Records Act s.77 โ MHR data must stay in Australia (not waivable); other health via APP 8 | Yes โ MHR data must stay in Australia (s.77) | โ |
| Russia | 152-FZ citizen-data localisation catches health (no carve-out) | Yes (152-FZ โ includes health) | โ |
| Singapore | Personal data (PDPA s.26); comparable-protection | No | โ |
| South Africa | Special personal information (POPIA s.72) | No | โ |
| Turkey | Special-category (KVKK); adequacy / standard-contract (2024 reform) | No | โ |
| Costa Rica ๐ถ | Sensitive (Law 8968); consent / adequate protection | No | โ |
| Most other | Health = “sensitive” โ tighter conditions, often local approval; some hard localisation (UAE, AU MHR) or sovereign-cloud | Varies | Public bodies often face extra residency / procurement rules |
Sources
- EC โ adequacy decisions
- EC โ EUโUS data transfers (DPF)
- India โ DPDP Rule 15 (transfers)
- Malaysia โ CBDT guidelines 2025
- Indonesia โ PDP Law transfer requirements
- Taiwan โ PDPA 2025 amendment / PDPC
- UAE โ PDPL (DLA Piper)
- DLA Piper โ Data Protection Laws of the World
- Linklaters โ Data Protected
- Chambers โ Data Protection & Privacy 2026
- US DOJ NSD โ Data Security Program (EO 14117)
- 28 CFR Part 202 (eCFR)
- EHDS โ Regulation (EU) 2025/327
- EDPB Recommendations 01/2020 (supplementary measures)
- France โ HDS hosting (CSP Art. L.1111-8, Lรฉgifrance)
- Germany โ ยง203 StGB (professional secrecy)
- Australia โ My Health Records Act 2012 (s.77)
- US HHS โ HIPAA Business Associates
The interactive TIA matrix tool on privacydesign.ch is generated from the machine-readable block below. Edit the block to update the tool (the daily site sync regenerates it). Keep the YAML valid.
Machine-readable matrix omitted here โ use the interactive TIA matrix tool.