Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Laws and Regulations

International Data Transfer

Also known as: Cross-Border Data Transfer, Restricted Transfer, Transfer to Third Countries
Simply put

An international data transfer occurs when personal data is moved from one country to another, for example when an organisation sends information about individuals to a service provider based abroad. Under EU and UK data protection law, such transfers to countries outside the European Economic Area (or, for the UK, outside the UK) are subject to specific rules designed to ensure the data remains protected. These rules may be relevant to cookie and tracking activities where personal data ends up being processed in another country, though the details depend on the specific arrangement.

Formal definition

An international (or cross-border) data transfer refers to a transfer of personal data from a controller or processor in one jurisdiction to a recipient in a third country or international organisation. Under the GDPR and UK GDPR, transfers outside the EEA (or, respectively, outside the UK) are 'restricted' and generally require a lawful transfer mechanism. The primary mechanism is an adequacy decision, under which a receiving country is deemed to provide an equivalent level of protection; where no adequacy decision applies, organisations may rely on appropriate safeguards or on specific derogations, such as a transfer being necessary for important reasons of public interest recognised in law. The term 'transfer' is not precisely defined in the legislation and its scope can be a matter of interpretation; identifying whether a given data flow constitutes a restricted transfer, and selecting an appropriate mechanism, requires case-specific assessment. This entry addresses the general concept; the detailed conditions, available mechanisms, and supplementary measures vary between the EU and UK regimes and evolve with regulatory guidance.

Why it matters

For organisations using cookies, pixels, tags, and similar tracking technologies, personal data collected in a browser often does not stay within the country where the user is located. Analytics providers, advertising networks, and tag management or consent management vendors are frequently based abroad or route data through servers in other jurisdictions. Where this happens, the data flow may constitute a restricted transfer under EU or UK data protection law, bringing it within a distinct set of rules on top of the consent obligations that already apply to setting cookies and to processing the resulting personal data.

The practical significance is that consent to place a cookie, or a lawful basis for processing under the GDPR, does not by itself resolve the question of whether personal data may lawfully leave the EEA or the UK. Under the GDPR and UK GDPR, transfers to third countries are generally 'restricted' and require a lawful transfer mechanism, such as reliance on an adequacy decision or on appropriate safeguards. Overlooking this dimension can leave an otherwise well-managed cookie programme exposed, because the international element is governed separately and depends heavily on the specific arrangement between the parties.

The scope of what counts as a 'transfer' is itself a source of uncertainty. The term is not precisely defined in the legislation, and identifying whether a given cross-border data flow is a restricted transfer can be a matter of interpretation that requires case-specific assessment. Because the detailed conditions, available mechanisms, and any supplementary measures differ between the EU and UK regimes and continue to evolve with regulatory guidance, organisations should treat each cross-border data flow arising from their cookie and tracking activities as requiring its own analysis rather than assuming a single approach applies everywhere.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance need to map where personal data collected through cookies and trackers ultimately flows, determine whether any flow constitutes a restricted transfer under the EU or UK regime, and identify an appropriate transfer mechanism such as an adequacy decision or appropriate safeguards. Because the scope of 'transfer' can be a matter of interpretation, they should approach each arrangement on a case-specific basis.
Legal counsel and compliance teams
Counsel advising on vendor and processor arrangements should assess whether cross-border flows arising from tracking technologies fall within the restricted-transfer rules and which mechanism, if any, is available. They should also account for the differences between the EU and UK regimes and the evolving nature of regulatory guidance, rather than assuming a single approach is definitive.
Web developers and technical implementers
Developers configuring analytics tags, advertising pixels, SDKs, and consent management platforms are often the ones directing where data is sent. Understanding that data routed to providers based abroad may trigger international transfer obligations helps ensure that technical choices are surfaced to compliance colleagues for assessment before deployment.
Marketing and adtech teams
Teams selecting advertising, measurement, and attribution vendors should be aware that many such providers process data outside the EEA or UK, which may bring restricted-transfer rules into play in addition to consent requirements. This is a factor to raise with legal and privacy colleagues when evaluating new tools, as tooling alone does not resolve the transfer question.

Inside International Data Transfer

Cross-border transfer of personal data
An international data transfer occurs when personal data collected in one jurisdiction is sent to, accessed from, or stored in another. In the cookie context, this frequently happens when consent data, identifiers, or tracking information gathered through cookies, pixels, SDKs, or similar technologies is processed by vendors, analytics providers, or advertising partners located outside the originating jurisdiction.
Transfer mechanisms under the GDPR
Where data is transferred outside the EU/EEA, the GDPR generally requires a lawful transfer mechanism, such as an adequacy decision recognizing a destination country's protections, Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs). These mechanisms address the transfer itself and are separate from the consent required under the ePrivacy Directive to place or access cookies on a device.
Relationship to cookie consent
Consent to place non-essential cookies (governed in most EU jurisdictions by ePrivacy rules) is distinct from the legal basis and safeguards needed for any subsequent international transfer of the resulting personal data (governed by the GDPR). Obtaining cookie consent does not by itself satisfy transfer requirements, and vice versa.
Supplementary measures and transfer risk assessment
Following regulatory guidance in the EU, data exporters are generally expected to assess whether the law and practice in the destination country undermine the protections of the chosen transfer mechanism, and to apply supplementary measures (such as encryption or pseudonymization) where needed. The precise expectations continue to evolve with authority guidance.
Jurisdictional variation
Transfer obligations differ across regimes. The EU and UK operate their own adequacy and safeguard frameworks, and individual US state privacy laws (such as the CCPA/CPRA in California) generally do not impose the same style of cross-border transfer restrictions, relying instead on other mechanisms such as contractual terms and opt-out rights. Scope should always be identified before relying on any single rule.

Common questions

Answers to the questions practitioners most commonly ask about International Data Transfer.

Does obtaining valid cookie consent also authorize transferring the resulting personal data outside the EU?
No. Consent to the placing of and access to cookies under the ePrivacy rules, and consent to processing under the GDPR, are distinct from the separate legal basis required to transfer personal data internationally. Where cookie or tracking technologies cause personal data to flow to recipients outside the EEA (for example to advertising or analytics vendors based abroad), that transfer generally needs its own transfer mechanism under Chapter V of the GDPR. Valid consent for the cookie does not by itself satisfy the transfer requirements, and in most EU jurisdictions the two questions should be assessed separately.
Is data transferred to a US-based cookie or analytics vendor automatically unlawful?
Not necessarily. A transfer to a recipient outside the EEA is not inherently unlawful; it must instead rely on an appropriate transfer mechanism recognized under the GDPR, such as an adequacy decision, standard contractual clauses, or another lawful basis, and may require additional safeguards depending on the circumstances. The lawfulness depends on the specific mechanism used, the recipient, and the surrounding facts. This entry does not assess the current status of any particular framework or vendor, and organizations should check the prevailing adequacy position and guidance from the relevant data protection authority.
How do I identify which cookies and tracking technologies on my site trigger an international data transfer?
Start by mapping each cookie, pixel, SDK, tag, or similar technology to the vendor that receives the data and the location where that data is processed or accessible. A technical audit or scan can reveal the third parties involved, but it typically needs to be combined with vendor documentation and data processing agreements to confirm where processing occurs. Note that similar technologies beyond literal cookies, such as pixels, local storage, and device fingerprinting, can also involve transfers, so the review should not be limited to items labelled as cookies. The precise flows depend on facts specific to your configuration and are out of scope for a general definition.
What transfer mechanism should I use for a third-party tag that sends data abroad?
The appropriate mechanism depends on the destination and the recipient. Where an adequacy decision covers the destination, transfers may rely on that; otherwise, standard contractual clauses or another recognized Chapter V mechanism may be required, potentially supplemented by additional technical or organizational safeguards after a transfer risk assessment. This is a legal determination that varies with the facts, and the choice should be documented. This entry does not endorse any specific mechanism for any specific vendor, and legal advice may be needed for contested or complex cases.
Does my consent management platform handle international transfer compliance for me?
Generally not on its own. A CMP typically manages the collection, signalling, and logging of consent preferences for cookies and tracking technologies, but managing transfer mechanisms such as contractual safeguards and transfer risk assessments is usually a separate legal and organizational task. A CMP can support compliance, for example by helping suppress vendors until consent is given, but it does not replace the legal judgment required to establish a valid transfer basis. You should confirm what your specific platform does and does not cover.
What should I document to demonstrate accountability for cookie-related international transfers?
In most EU jurisdictions, accountability under the GDPR generally involves keeping records of the transfer mechanism relied on for each relevant vendor, any transfer risk assessment conducted, the categories of personal data involved, and the relevant contractual documentation, alongside consent records where consent is the basis for the underlying cookie or processing. The exact record-keeping expectations can vary by jurisdiction and by the guidance of the relevant supervisory authority, and the specific documentation required depends on your circumstances, so this list is illustrative rather than exhaustive.

Common misconceptions

Obtaining cookie consent means an international transfer of the data is automatically lawful.
Cookie consent under the ePrivacy Directive addresses placing and accessing information on a device. Any subsequent transfer of personal data outside the EU/EEA is governed separately by the GDPR and generally requires its own lawful basis and a valid transfer mechanism such as an adequacy decision, SCCs, or BCRs. The two obligations are distinct and neither automatically satisfies the other.
Using a consent management platform or a US-based analytics or advertising vendor resolves the transfer question.
A CMP supports consent collection and record-keeping but does not by itself establish a lawful transfer mechanism or guarantee compliance. Where a vendor processes data outside the originating jurisdiction, practitioners still need to identify an appropriate transfer safeguard and, in the EU, assess whether supplementary measures are required. Tools support compliance but do not replace legal judgment.
Transfer rules are the same everywhere, so one approach fits all jurisdictions.
Cross-border transfer obligations vary between the EU, the UK, and individual US states. The EU and UK apply adequacy and safeguard-based frameworks, while several US state laws generally rely on contractual and opt-out approaches rather than EU-style transfer restrictions. The geographic and legal scope of any requirement should be confirmed rather than assumed to be universal.

Best practices

Map where cookie-derived personal data flows, identifying every vendor, analytics provider, and advertising partner that receives or can access the data outside the originating jurisdiction.
Treat cookie consent and international transfer safeguards as separate compliance steps, ensuring both the ePrivacy consent requirement and the GDPR transfer mechanism are addressed where EU/EEA data is involved.
For transfers outside the EU/EEA, confirm an appropriate mechanism (adequacy decision, SCCs, or BCRs) is in place and documented for each recipient.
Where required under EU guidance, carry out a transfer risk assessment and apply supplementary measures such as encryption or pseudonymization, and revisit these as authority guidance evolves.
Confirm the geographic and legal scope of applicable rules before relying on any single approach, recognizing that EU, UK, and individual US state requirements differ.
Maintain records of consent and of transfer arrangements, and treat consent management platforms as support tools rather than a substitute for legal review of transfer obligations.
Promotional banner for the Penetration Report Template Kit