International Data Transfers: GDPR Compliance in the Global Cloud
Cross-border data transfer compliance: Standard Contractual Clauses, Transfer Impact Assessments, EU-US Data Privacy Framework, and Binding Corporate Rules for multinational groups.
Does this apply to your business?
Do you know exactly what personal data your company transfers to vendors outside the EEA and what legal safeguard covers each transfer?
Do your cloud provider contracts (AWS, Google, Microsoft, Salesforce) include the 2021 SCCs and an up-to-date Transfer Impact Assessment?
Have you assessed whether the EU-US Data Privacy Framework is sufficient for your US transfers, or whether additional safeguards are needed?
Are all international transfers documented in your records of processing activities with the applicable safeguard referenced?
0 of 4 questions answered
Our international data transfer audit and remediation process
International transfer mapping
We identify all personal data flows outside the EEA: cloud providers, SaaS platforms, foreign subsidiaries, marketing and analytics vendors, and any other processor located outside the EU.
Existing safeguard verification
We audit the current safeguard for each transfer: adequacy decision coverage, SCCs implemented and updated to the 2021 version, or alternative mechanisms valid under Article 46 GDPR.
Transfer Impact Assessment (TIA)
We conduct TIAs for SCC-based transfers: assessment of the destination country's legal framework, likelihood of government access, and effectiveness of the safeguards in that specific context.
Safeguard implementation and documentation
We implement the 2021 SCCs in processor contracts, negotiate necessary addenda with vendors, and document the transfer inventory in the records of processing activities.
The challenge
Any company using cloud services, SaaS platforms, or vendors outside the European Economic Area is making international personal data transfers. The Schrems II judgment invalidated the Privacy Shield in 2020 and exposed thousands of Spanish companies transferring data to the US without valid safeguards. Many remain in the same position: using outdated standard clauses, without the Transfer Impact Assessment the AEPD requires, or with no safeguard at all.
Our solution
We audit all your company's international data transfers, verify the safeguard applicable to each one, and remediate gaps: implementation of the updated 2021 Standard Contractual Clauses, Transfer Impact Assessments (TIAs), advisory on the EU-US Data Privacy Framework, and design of Binding Corporate Rules for multinational groups.
International transfers of personal data — any transmission of personal data to a country or international organisation outside the European Economic Area (EEA) — are regulated by Chapter V of the EU General Data Protection Regulation (GDPR, Articles 44–49). A transfer can only take place if the destination country benefits from an adequacy decision (Article 45), or if the exporter implements appropriate safeguards such as Standard Contractual Clauses (SCCs — Commission Decision 2021/914), Binding Corporate Rules (BCRs), or a Transfer Impact Assessment (TIA) confirming equivalent protection. The EU-US Data Privacy Framework (Commission Decision 2023/1795) currently provides an adequacy basis for transfers to certified US organisations. The Court of Justice of the EU's Schrems II judgment (Case C-311/18, July 2020) invalidated the previous Privacy Shield and requires case-by-case assessment of third-country legal systems for all SCCs-based transfers.
The globalisation of technology services has made international personal data transfers a daily reality for the vast majority of Spanish businesses, regardless of size. Using any US cloud service, CRM platform, analytics tool, or management software with non-EEA servers involves international transfers regulated by Chapter V of the GDPR. The problem is that many organisations make these transfers without valid safeguards — and without knowing it.
The Schrems II Legacy
The CJEU’s Schrems II judgment was a watershed moment whose full implications have still not been absorbed by the Spanish business community. The invalidation of the Privacy Shield and the requirement to conduct a Transfer Impact Assessment to verify that SCCs are practically effective in the destination country transformed a relatively straightforward exercise into a more complex legal and technical analysis. Companies that simply copied and pasted the 2021 SCCs into their vendor contracts without conducting the corresponding TIA remain non-compliant.
The 2021 SCCs introduced modular clauses covering four processing scenarios (controller-to-controller, controller-to-processor, processor-to-controller, and processor-to-processor), replacing the three previous sets of clauses. This structural change means that organisations reviewing their international transfer contracts need to verify not only that new SCCs are in place, but that the correct module and addendum are used for each specific transfer relationship.
What the Audit Reveals
Complete mapping of international transfers is the indispensable starting point. In our experience, organisations typically identify 30 to 50 percent more transfers than they initially believed they were making: sub-processors that the primary vendor uses in third countries, technical support tools with remote access from outside the EEA, or backup solutions in non-European cloud regions that the provider activates by default. Each of these flows requires its own safeguard — sub-processor transfers are covered by the main processor’s SCCs only if those SCCs specifically authorise sub-processing and impose equivalent obligations down the chain.
For multinational groups, Binding Corporate Rules are the structural solution that allows intra-group transfers to be managed coherently without executing SCCs with each group entity individually. The approval process is complex, but the result is a legally robust instrument recognised by all European supervisory authorities. In a context where regulatory compliance is increasingly a competitive differentiator, an auditable and documented international transfer system is a genuine asset in due diligence processes and institutional client relationships.
Real results in international data transfer compliance
An internal audit revealed we were transferring European customer data to US servers without valid SCCs or TIAs. BMC resolved the entire situation in three months: new contracts with all vendors, complete TIAs, and an updated transfer register. We now know exactly what safeguard covers every data flow.
Experienced team with local insight and international reach
What our international data transfer service includes
International Transfer Audit
Complete mapping of all personal data flows outside the EEA: cloud providers, SaaS platforms, subsidiaries, sub-processors, and any other recipient in third countries.
Standard Contractual Clauses Implementation
Review, update, and implementation of the 2021 SCCs in all processor contracts with entities located outside the EEA.
Transfer Impact Assessment (TIA)
Analysis of the destination country's legal framework and assessment of safeguard effectiveness in the context of that country's government access laws.
EU-US Data Privacy Framework Advisory
Guidance on the US adequacy decision, certification verification for vendors, and alternative safeguard strategy in the event of future invalidation.
Binding Corporate Rules
Design and management of the BCR approval process for multinational groups with systematic intra-group transfer requirements.
Results that speak for themselves
Commercial debt portfolio recovery
92% portfolio recovery in 4 months, with out-of-court settlements in 78% of cases.
Comprehensive employment defense for industrial multinational
100% favorable outcomes: 5 advantageous conciliation agreements and 3 fully upheld court rulings.
GDPR compliance programme for a hospital group: from investigation to full compliance
AEPD investigation closed with no sanction. Full GDPR compliance achieved across all group centres within 6 months.
Analysis and perspectives
Frequently asked questions about international data transfers under GDPR
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
International Data Transfers
Legal
First step
Start with a free diagnostic
Our team of specialists, with deep knowledge of the Spanish and European market, will guide you from day one.
Request your diagnostic
You may also be interested in
Anti-Money Laundering (AML)
AML/CFT compliance programme for entities subject to Spain's Law 10/2010: policies, procedures, training, and SEPBLAC liaison.
Saber másCommercial Law
Expert commercial law advisory to safeguard your business operations and protect your corporate interests.
Saber másCybersecurity Audit
Security posture assessment, compliance audits (ENS, ISO 27001, NIS2), vulnerability assessment, penetration testing management, and third-party risk evaluation.
Saber másData Protection & Privacy
GDPR and LOPDGDD compliance, outsourced DPO, and comprehensive privacy management for businesses.
Saber másKey terms
Data Protection Officer (DPO)
A Data Protection Officer (DPO) is a designated individual responsible for overseeing an…
Read definitionPrivacy by Design
A GDPR principle (Article 25) requiring data protection to be integrated into the design of…
Read definitionStandard Contractual Clauses (SCCs)
Model contracts adopted by the European Commission that provide adequate safeguards for transferring…
Read definition