You've mapped your processing activities. Your processor agreements reference Article 28. Your transfer impact assessments are marked "complete." Then an employee of your EEA-based processor boards a flight to New York with a laptop containing personal data your organization controls. You're now facing a compliance scenario most transfer frameworks don't explicitly address.
This isn't about vendor selection or Standard Contractual Clauses. It's about whether the temporary physical movement of data by a processor's employee constitutes a transfer requiring Article 46 safeguards, and what your obligations are as a controller when it happens.
The Decision You're Facing
Does your processor's employee traveling outside the EEA with personal data on their device trigger GDPR Chapter V transfer requirements? And if so, what mechanism protects you?
The answer depends on three factors: the nature of data access during travel, the processor's operational control over that access, and whether the data becomes accessible to third-country authorities or entities while the employee is abroad.
Key Factors That Affect Your Choice
Factor 1: Access vs. Presence
The physical location of a device matters less than whether the data becomes subject to third-country jurisdiction. If your processor's employee carries encrypted data they can't decrypt or access during travel, you're in different territory than if they're actively processing customer records from a hotel in Singapore.
Factor 2: Controller Instructions
Article 28(3)(a) requires processors to process only on documented instructions from the controller. If your processing agreement doesn't explicitly authorize cross-border data access during business travel, your processor may be exceeding their mandate when an employee opens that laptop abroad.
Factor 3: Third-Country Access Risk
The Schrems II decision established that transfers occur when personal data becomes subject to third-country laws that permit government access without adequate safeguards. An employee working from a jurisdiction with expansive surveillance powers creates exposure even if no local entity touches the data.
Path A: Treat It as a Transfer Requiring Article 46 Safeguards
Choose this path when:
- The processor's employee will actively access, modify, or process personal data while outside the EEA.
- The destination country has laws permitting government access to data on devices or in cloud storage.
- The employee's work involves sensitive categories of data or large volumes of records.
- Your organization's risk tolerance demands documented transfer mechanisms for any cross-border data movement.
Implementation requirements:
You'll need Standard Contractual Clauses with your processor that explicitly cover employee travel scenarios. Your processing agreement should include an annex listing approved third countries for business travel and require advance notice for travel to non-approved jurisdictions.
Conduct a transfer impact assessment for each destination country where processor employees regularly travel. Document whether local laws create risks that SCCs alone can't mitigate. If they do, implement supplementary measures: device-level encryption that remains secure against lawful access demands, prohibition on cloud sync during travel, or restriction of data access to view-only mode.
Update your Article 30 processing records to reflect these transfers. When your DPA asks about third-country transfers, "our processor's employees sometimes travel" without documentation won't satisfy them.
What this path protects:
You create an auditable trail showing you've assessed transfer risks and implemented appropriate safeguards. If a processor employee's device is seized at a border or subject to lawful access demands, you can demonstrate you anticipated the risk and took steps to mitigate it.
Path B: Treat It as Processor Operations Not Requiring Transfer Safeguards
Choose this path when:
- Data remains encrypted with keys held only in the EEA, making it inaccessible during travel.
- The processor's employee carries data solely for disaster recovery or system maintenance purposes with no active processing.
- Travel is brief and incidental to the processing relationship.
- Your processing agreement already grants the processor discretion over operational details like employee location.
Implementation requirements:
Even if you don't treat this as a formal transfer, document your reasoning. Your Article 30 records should note that processor employees may travel internationally but can't access data outside the EEA due to technical controls.
Require your processor to maintain policies restricting data access during international travel. This might include automatic VPN requirements that route all data access through EEA servers, prohibition on downloading data to local devices, or mandatory use of virtual desktop infrastructure that keeps data processing in the EEA regardless of employee location.
Verify these controls during your Article 28 audits. Ask your processor to demonstrate that an employee in Tokyo can't decrypt or process personal data without connecting through EEA infrastructure.
What this path protects:
You avoid the administrative burden of treating every business trip as a transfer event while maintaining that the data processing itself never leaves EEA jurisdiction. This works when you can demonstrate technical controls that make the employee's physical location irrelevant to data access.
Path C: Prohibit Travel With Data Entirely
Choose this path when:
- You process special categories of data under Article 9 where transfer risks are unacceptable.
- Your processor handles data for public authorities or critical infrastructure where security requirements are heightened.
- The administrative cost of documenting and safeguarding travel scenarios exceeds the business benefit.
- Your risk assessment shows no supplementary measure adequately addresses third-country access risks.
Implementation requirements:
Amend your processing agreement to explicitly prohibit processor employees from traveling outside the EEA with any device containing personal data or credentials that grant access to personal data. Require the processor to implement technical controls: geofencing that disables data access from non-EEA IP addresses, device management that wipes data when a device crosses certain borders, or complete segregation of international-travel devices from data processing systems.
This path requires the most processor cooperation. You're constraining their operational flexibility, which may affect pricing or service delivery. Build this requirement into vendor selection rather than trying to retrofit it onto existing relationships.
What this path protects:
You eliminate transfer risk entirely for this processing relationship. When your transfer impact assessment for a particular processor shows unmitigable risks, prohibition may be your only compliant option.
Summary Matrix
| Factor | Path A: Transfer | Path B: Processor Ops | Path C: Prohibition |
|---|---|---|---|
| Documentation | SCCs + TIA + Article 30 records | Processor policies + audit verification | Processing agreement amendment + technical controls |
| Processor Burden | Advance notice + country restrictions | VPN/encryption requirements | Significant operational constraint |
| Your Risk | Mitigated through safeguards | Low if technical controls verified | Eliminated |
| Audit Defensibility | High (documented assessment) | Medium (depends on control verification) | High (clear prohibition) |
| Best For | Active processing during travel | Encrypted/inaccessible data | Special categories or high-risk data |
Your processor's employee travel policy isn't a footnote to your processing agreement. It's a transfer scenario that requires the same rigorous assessment you'd apply to any cross-border data flow. The path you choose depends on how your processor's employees access data, where they travel, and what your transfer impact assessment reveals about third-country risks.
Document your choice. When your processor says "our team needs to visit the Singapore office next month," you should already know which path applies and what safeguards you require.





