International Data Transfer
An international data transfer occurs when personal data is moved from one country to another, for example when an organisation sends information about individuals to a service provider based abroad. Under EU and UK data protection law, such transfers to countries outside the European Economic Area (or, for the UK, outside the UK) are subject to specific rules designed to ensure the data remains protected. These rules may be relevant to cookie and tracking activities where personal data ends up being processed in another country, though the details depend on the specific arrangement.
An international (or cross-border) data transfer refers to a transfer of personal data from a controller or processor in one jurisdiction to a recipient in a third country or international organisation. Under the GDPR and UK GDPR, transfers outside the EEA (or, respectively, outside the UK) are 'restricted' and generally require a lawful transfer mechanism. The primary mechanism is an adequacy decision, under which a receiving country is deemed to provide an equivalent level of protection; where no adequacy decision applies, organisations may rely on appropriate safeguards or on specific derogations, such as a transfer being necessary for important reasons of public interest recognised in law. The term 'transfer' is not precisely defined in the legislation and its scope can be a matter of interpretation; identifying whether a given data flow constitutes a restricted transfer, and selecting an appropriate mechanism, requires case-specific assessment. This entry addresses the general concept; the detailed conditions, available mechanisms, and supplementary measures vary between the EU and UK regimes and evolve with regulatory guidance.
Why it matters
For organisations using cookies, pixels, tags, and similar tracking technologies, personal data collected in a browser often does not stay within the country where the user is located. Analytics providers, advertising networks, and tag management or consent management vendors are frequently based abroad or route data through servers in other jurisdictions. Where this happens, the data flow may constitute a restricted transfer under EU or UK data protection law, bringing it within a distinct set of rules on top of the consent obligations that already apply to setting cookies and to processing the resulting personal data.
The practical significance is that consent to place a cookie, or a lawful basis for processing under the GDPR, does not by itself resolve the question of whether personal data may lawfully leave the EEA or the UK. Under the GDPR and UK GDPR, transfers to third countries are generally 'restricted' and require a lawful transfer mechanism, such as reliance on an adequacy decision or on appropriate safeguards. Overlooking this dimension can leave an otherwise well-managed cookie programme exposed, because the international element is governed separately and depends heavily on the specific arrangement between the parties.
The scope of what counts as a 'transfer' is itself a source of uncertainty. The term is not precisely defined in the legislation, and identifying whether a given cross-border data flow is a restricted transfer can be a matter of interpretation that requires case-specific assessment. Because the detailed conditions, available mechanisms, and any supplementary measures differ between the EU and UK regimes and continue to evolve with regulatory guidance, organisations should treat each cross-border data flow arising from their cookie and tracking activities as requiring its own analysis rather than assuming a single approach applies everywhere.
Who it's relevant to
Inside International Data Transfer
Common questions
Answers to the questions practitioners most commonly ask about International Data Transfer.
