Skip to content

Cross-Border Data Transfer

What is Cross-Border Data Transfer?

The movement of personal data from one jurisdiction to another. Cross-border transfers are regulated under GDPR, LGPD, and other privacy laws and typically require adequate safeguards such as Standard Contractual Clauses or Binding Corporate Rules.

Privacy

Each of these is named in at least one of the same controls as cross-border data transfer. The number is how many controls name both.

What the standards actually require on cross-border data transfer

Requirements naming cross-border data transfer across 6 standards, quoted from the control text.

Article 22 (CROSS-BORDER TRANSFER) - personal data may be transferred OUTSIDE the UAE only where: (a) ADEQUACY - the UAE Data Office determines that the third country provides an adequate level of protection;

UAE-PDPL-Art.22_23_24 · Cross-border data transfers (UAE PDPL Articles 22-24)
PDPA Thailand2 controls

Transfers outside Thailand require destination country to have adequate protection, or one of the exceptions, including binding corporate rules or standard contractual clauses approved by PDPC.

Section 28 · Cross-Border Data Transfer

Store personal data, financial data, government data, and CII operational data on servers physically located in Myanmar per data localisation provisions in the 2025 Cybersecurity Law and supporting regulations.

MMCL-4 · Data Localisation and Cross-Border Data Transfer Controls

Conduct cross-border data transfers per NDPA Section 41(CBT) using adequate level of protection mechanisms including: countries on NDPC Whitelist (adequacy) + Binding Corporate Rules (BCR) approved by NDPC + Standard Contractual Clauses approved by NDPC + expl...

NG-NDPA-7 · Cross-Border Data Transfers and International Cooperation

Personal data may be transferred abroad only if the destination ensures an adequate level of protection or where contractual safeguards, binding corporate rules, or other approved mechanisms apply.

CH-FADP-07 · Cross border data transfers

Transfers of personal data to foreign states may be carried out provided that the receiving state ensures adequate protection of rights of data subjects. Transfers to states without adequate protection require consent or other specified grounds.

UZB-DPL-11 · Cross Border Data Transfers

Questions people ask about cross-border data transfer

What is Cross-Border Data Transfer?
The movement of personal data from one jurisdiction to another. Cross-border transfers are regulated under GDPR, LGPD, and other privacy laws and typically require adequate safeguards such as Standard Contractual Clauses or Binding Corporate Rules.
Why is Cross-Border Data Transfer important for compliance?
Cross-Border Data Transfer is a key concept in Privacy. Understanding cross-border data transfer helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Cross-Border Data Transfer?
Cross-Border Data Transfer appears in the requirement text of Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL), PDPA Thailand, Myanmar Cybersecurity Law (2023), Nigeria Data Protection Act 2023 (NDPA), Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023). Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Cross-Border Data Transfer?
Explore our compliance framework pages to see how cross-border data transfer applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Cross-Border Data Transfer applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.