Cross-Border Data Transfer
What is Cross-Border Data Transfer?
The movement of personal data from one jurisdiction to another. Cross-border transfers are regulated under GDPR, LGPD, and other privacy laws and typically require adequate safeguards such as Standard Contractual Clauses or Binding Corporate Rules.
Terms that appear alongside cross-border data transfer
Each of these is named in at least one of the same controls as cross-border data transfer. The number is how many controls name both.
- consent 6 shared controls
- certification 6 shared controls
- standard contractual clauses 6 shared controls
- binding corporate rules 6 shared controls
- gdpr 5 shared controls
- authorisation 5 shared controls
- data subject 5 shared controls
- cybersecurity 4 shared controls
Frameworks that govern cross-border data transfer
What the standards actually require on cross-border data transfer
Requirements naming cross-border data transfer across 6 standards, quoted from the control text.
Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection;
UAE-PDPL-Art.22_23_24 · Cross-border data transfers (UAE PDPL Articles 22-24) →Transfers outside Thailand require destination country to have adequate protection, or one of the exceptions, including binding corporate rules or standard contractual clauses approved by PDPC.
Section 28 · Cross-Border Data Transfer →Store personal data, financial data, government data, and CII operational data on servers physically located in Myanmar per data localisation provisions in the 2025 Cybersecurity Law and supporting regulations.
MMCL-4 · Data Localisation and Cross-Border Data Transfer Controls →Conduct cross-border data transfers per NDPA Section 41(CBT) using adequate level of protection mechanisms including: countries on NDPC Whitelist (adequacy) + Binding Corporate Rules (BCR) approved by NDPC + Standard Contractual Clauses approved by NDPC + expl...
NG-NDPA-7 · Cross-Border Data Transfers and International Cooperation →Personal data may be transferred abroad only if the destination ensures an adequate level of protection or where contractual safeguards, binding corporate rules, or other approved mechanisms apply.
CH-FADP-07 · Cross border data transfers →Transfers of personal data to foreign states may be carried out provided that the receiving state ensures adequate protection of rights of data subjects. Transfers to states without adequate protection require consent or other specified grounds.
UZB-DPL-11 · Cross Border Data Transfers →Questions people ask about cross-border data transfer
What is Cross-Border Data Transfer?
Why is Cross-Border Data Transfer important for compliance?
Which compliance frameworks address Cross-Border Data Transfer?
Where can I learn more about Cross-Border Data Transfer?
See how Cross-Border Data Transfer applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.