๐ International Transfer & TIA Matrix (interactive)
โ ๏ธ Not legal advice โ decision-support only. NOT LEGAL ADVICE. Simplified decision-support only. Verify every entry against current primary law and take qualified advice before relying on it for a specific transfer. Transfer law changes frequently; entries may be out of date.
As of 2026-09-07. Re-verify every entry against primary law. โAccess = transferโ (EDPB Guidelines 05/2021); the exporterโs law sets the conditions and one flow can trigger several regimes at once. ๐ถ = fast-moving, verify.
Pick an exporter (from) and a destination (to) for an at-a-glance transfer mechanism, plus the system-access (remote-admin) analysis โ then read the full tables below. The data is maintained in the wiki kb:transfers matrix and regenerated on each site sync, so it stays current without touching this page.
Quick check
Indicative only โ confirm against the tables below and primary law.
Table A โ Exporter regimes (the โfromโ axis)
| Exporter | Model | Free to | Otherwise need | Assessment | Localisation | Ref |
|---|---|---|---|---|---|---|
| EU/EEA (GDPR Ch. V) | Adequacy + SCCs | EC adequacy list (incl. US via DPF) | SCCs 2021/914 ยท BCRs ยท Art. 49 | TIA (Schrems II) | No | โ |
| UK (UK GDPR) | Adequacy + IDTA | UK regs (โEU + UKโUS Data Bridge) | IDTA / EU SCCs+Addendum ยท BCRs ยท derogations | TRA | No | โ |
| Switzerland (revFADP) | Adequacy + CH-SCCs | FDPIC list + SwissโUS DPF | EU SCCs + FDPIC amend. ยท BCRs ยท derogations | TIA | No | โ |
| Brazil (LGPD) | Adequacy + SCCs | ANPD list (nascent) | ANPD SCCs ยท BCRs ยท specific clauses | โ | No | โ |
| Canada (PIPEDA; Quebec Law 25) | Accountability | โ | Comparable-protection contract; org stays accountable. Quebec Law 25: privacy-impact assessment required before transferring PI outside Quebec | Assessment (Quebec PIA) | No | โ |
| China (PIPL) | Approval / mechanism | โ | CAC security assessment / certification / standard contract (filing); separate consent + specific export notice; 2024 exemptions | PIPIA | Yes (CIIO, important data) | โ |
| India (DPDPA + DPDP Rules 2025) ๐ถ | Negative list | All (none restricted yet) | Valid contract between fiduciary/processor; govt may blacklist; fully operational ~mid-2027 | โ | Sectoral (RBI payments) | โ |
| Indonesia (PDP Law 27/2022) ๐ถ | Tiered | Equal-or-higher protection | Else binding safeguards; else consent; implementing GR pending; extraterritorial effect | โ | Sectoral (public / electronic-system data, GR 71/2019) | โ |
| Japan (APPI) | Adequacy-equiv. | Japan list (EEA, UK) | Consent / equivalent-measures contract + oversight | โ | No | โ |
| Malaysia (PDPA amended 2024/25) | Comparable-protection + TIA | โ | TIA (substantially similar/adequate); SCC/BCR/cert; consent/contract; 5-day notice | Yes (TIA) | No | โ |
| South Korea (PIPA 2023) | Consent + alternatives | EU (PIPC-recognised equivalent, Sep 2025) | Consent / contract+safeguards+notice / PIPC-cert / PIPC-recognised country; SCC/BCR + Overseas-Transfer Impact Assessment planned H1 2026 | Impact-type | No | โ |
| Taiwan (PDPA amended Nov 2025 โ PDPC) ๐ถ | Permitted unless restricted | โ | No dedicated cross-border-transfer statute yet; PDPC may restrict (Art. 21); sector/national-security bans emerging (e.g. PII to China/HK/Macao); assertive enforcement | โ | Sector | โ |
| UAE (Federal PDPL 45/2021 + DIFC/ADGM) ๐ถ | Adequacy + mechanisms (fragmented) | Federal list pending; DIFC/ADGM own lists | Federal: adequate country / contract / consent / necessity (regs not gazetted); health data generally must stay in UAE absent approval; financial-sector controls. DIFC & ADGM: GDPR-like + own SCCs | DIFC/ADGM yes | Health data + free-zone/sector | โ |
| Australia (APP 8) | Accountability | โ | Reasonable steps + comparable protection (exporter stays liable, incl. intra-group); exception if recipient under substantially-similar law/binding scheme/BCRs; or consent | Reasonable-steps | Health/sector | โ |
| Russia | Localisation | โ | Roskomnadzor consent/registration; strict | โ | Yes (citizens' data) | |
| Singapore (PDPA s.26) | Comparable-protection + accountability | โ (no whitelist) | Recipient bound by legally enforceable obligations (contract/BCR/APEC-CBPR cert) ensuring comparable protection; or consent; or contract necessity; or data in transit/public | Comparable-protection assessment | No | โ |
| South Africa (POPIA s.72) | Adequacy-or-safeguards + accountability | โ (responsible party assesses adequacy) | Recipient bound by law/BCR/agreement with adequate protection + onward-transfer limits; or consent; or contract necessity/benefit | Adequacy assessment | No | โ |
| Turkey (KVKK Art. 9, amended Jun 2024) | Adequacy + safeguards (GDPR-aligned) | Board adequacy decisions (list nascent) | Board standard contract (notify Board <=5 business days) / BCRs / int'l agreement / undertaking+authorisation; explicit-consent & other derogations for one-off | Adequacy/safeguards assessment | No | โ |
| Costa Rica (Law 8968; reform Bill 23097) ๐ถ | Consent-based + adequate-protection | โ (no whitelist) | Data-subject consent; transfer to non-adequate country without valid derogation = very serious offence; guarantee adequate protection; GDPR-aligned reform (Bill 23097) pending | Adequacy/consent check | No | โ |
| Most other countries | Light / none | โ | Often consent/contract or no restriction | โ | Varies |
Table B โ Personal-data transfer, destination buckets โ from an EU/EEA exporter (UK/CH โ same)
Tables B and C are the EU/EEA-EXPORTER view (Table B = EU/EEA as data exporter; Table C = EU/EEA as the source/origin of the remote access). UK and Switzerland are broadly equivalent. For any other exporter, that exporter's own regime governs โ see Table A.
| Bucket | Countries | Adequate? | Mechanism | Verdict |
|---|---|---|---|---|
| Adequate โ free | United Kingdom, Switzerland, Japan, South Korea, Canada (commercial), New Zealand, Israel, Argentina, Uruguay, Andorra, Faroe Islands, Guernsey, Isle of Man, Jersey | yes | None (adequacy) | Free transfer |
| US โ DPF-certified ๐ถ | United States (DPF-certified importer) | partial | Data Privacy Framework | OK if importer is DPF-certified (verify scope) |
| Mechanism-achievable (SCC + TIA) | Australia, Taiwan, United Arab Emirates (DIFC/ADGM), Malaysia, Indonesia, Brazil, Singapore, South Africa, Turkey, Costa Rica, most Latin America / SE Asia (moderate risk) | no | SCCs + TIA (+ measures as risk dictates) | OK, case-by-case after TIA |
| High-risk / broad state access | United States (non-DPF), China, Russia, India | no | SCCs + TIA + strong supplementary measures, or local mechanism | Problematic โ robust measures or do not transfer |
| Localisation / approval | China (CIIO / important data), Russia, Indonesia (sectoral), India (sectoral) | no | Local pre-clearance (e.g. CAC) + export mechanism | Restricted โ local approval needed |
| No mechanism available | no | Art. 49 derogation (consent, contract necessity, legal claims) | Occasional / one-off only โ not for routine flows |
Table C โ System access (remote admin) โ EU/EEA as exporter / source of the remote access; mitigation lens
Does the third-country admin need to see PLAINTEXT personal data?
| Situation | Mitigations | Residual risk | Verdict |
|---|---|---|---|
| Adequate destination | n/a | Low | Free โ normal access controls |
| Non-adequate; importer sees only ciphertext/pseudonymised, keys held in exporter country | Strong encryption (exporter-held keys), pseudonymisation, no-download, JIT/ephemeral access, logging | Neutralised (EDPB Rec 01/2020 UC 1โ3) | OK |
| Non-adequate; importer needs plaintext | Access controls help but do not neutralise | Medium | Case-by-case (per destination risk) |
| High-risk destination; plaintext admin | Encryption fails if cleartext needed (EDPB UC 6/7) | High | Avoid โ encrypted-only ops or relocate access |
| High-risk destination; encrypted-only ops | E2E encryption + exporter-held keys + confidential computing | Low / neutralised | OK if admin never needs cleartext |
| Localisation regime | โ | โ | Local rules govern even remote access |
Table D โ System support out of India โ India as source of remote support
India as the LOCATION of the remote support/access, supporting a controller elsewhere (e.g. an EU/EEA exporter). If Indian staff can reach personal data, that access is a transfer to India (EDPB 05/2021). India (DPDPA) does not restrict inbound access, but the Indian entity is usually a processor/data-fiduciary with contract & security duties; India is not EU-adequate (broad state access -> factor into the TIA). RBI payment-data localisation applies if payment data is in scope.
| Support scenario | Transfer? | EU-exporter mechanism | India-side (DPDPA) | Mitigations / notes | Verdict |
|---|---|---|---|---|---|
| No access to personal data (infra/OS/network only, or ciphertext-only with keys held outside India) | No personal-data transfer | None (Ch. V not triggered) | Contract + security good practice | RBAC; encryption with keys outside India; no-download; screen-only/JIT; logging; beware PII in metadata/config/logs/tickets | OK โ document the no-PII scoping |
| Possible / incidental access (admin could technically reach PII; break-glass only) | Treat as a transfer (mere possibility of access can count) | SCCs + TIA โ or neutralise the access | Processor contract (DPDPA); security | Prefer to eliminate access (encryption + keys outside India -> back to row 1); else SCC+TIA + measures | SCC+TIA, or neutralise |
| Actual access to personal data (plaintext) โ L2/L3 support, data fixes, content ops | Yes โ transfer to India | SCCs + TIA + supplementary measures | Valid processor contract required (DPDPA); security safeguards; breach cooperation; onward transfer follows DPDPA negative-list | Encryption cannot neutralise plaintext (EDPB UC 6/7); minimise/pseudonymise; heightened scrutiny for sensitive/large-scale; consider EU-side handling for sensitive data | SCC+TIA + measures; high scrutiny |
Table E โ US DOJ Data Security Program (EO 14117) โ US-outbound bulk-sensitive-data export control ๐ถ
US-outbound national-security control (28 CFR Part 202; EO 14117; final rule effective 8 Apr 2025, affirmative compliance from 6 Oct 2025, reporting/enforcement phasing through 2026). Separate from the privacy/adequacy analysis; turns on the RECIPIENT being a country of concern (China incl. HK/Macau, Cuba, Iran, North Korea, Russia, Venezuela) or a covered person (entities >=50% owned by/organised in a CoC; their employees/contractors; individuals resident in a CoC). Covers bulk US sensitive personal data (genomic/omic, biometric, precise geolocation, health, financial, identifiers) and US government-related data (any volume). Cross-link: offshoring to India (Table D) is not a CoC, but a support provider that is a covered person can trigger this.
| Scenario | DSP category | Outcome | What's required | Notes |
|---|---|---|---|---|
| Data brokerage / sale of bulk US sensitive personal data to a CoC or covered person | Prohibited | Prohibited | โ (not permitted) | Core prohibition; incl. onward-transfer & knowingly directing |
| US government-related data (precise geolocation of sensitive gov sites; gov/military personnel data) to CoC/covered person | Prohibited | Prohibited โ any volume | โ | No bulk threshold |
| Human genomic / 'omic / biospecimen data to CoC/covered person | Prohibited | Prohibited | โ | Lowest thresholds; especially sensitive |
| Vendor / employment / investment agreement giving a covered person access to bulk US sensitive data (e.g. offshore support/dev team that is a covered person) | Restricted | Allowed only if compliant | CISA security requirements + data-compliance program + due diligence + annual audit + (2026) reporting | The key offshoring case โ access = a covered data transaction |
| Below bulk threshold, rule-compliant de-identification, or an exempt transaction (intra-corporate group, financial services, telecom, US-gov, FDA/clinical) | Out of scope / exempt | No DSP restriction | Document the exemption/threshold | Still check other laws (privacy, export controls) |
Sources
- EC โ adequacy decisions
- EC โ EUโUS DPF
- India โ DPDP Rule 15
- Malaysia โ CBDT guidelines 2025 (Mayer Brown)
- Indonesia โ PDP Law transfers (Makarim)
- Taiwan โ PDPA 2025 amendment
- UAE โ PDPL (DLA Piper)
- DLA Piper โ Data Protection Laws of the World
- Linklaters โ Data Protected
- Chambers โ Data Protection & Privacy 2026
- US DOJ NSD โ Data Security Program (EO 14117)
- 28 CFR Part 202 (eCFR)