Privacy Designยฎ
Knowledge Base โ†’ Frameworks & law โ†’ ๐ŸŒ International Transfer & TIA Matrix (interactive)

๐ŸŒ International Transfer & TIA Matrix (interactive)

โš ๏ธ Not legal advice โ€” decision-support only. NOT LEGAL ADVICE. Simplified decision-support only. Verify every entry against current primary law and take qualified advice before relying on it for a specific transfer. Transfer law changes frequently; entries may be out of date.

As of 2026-09-07. Re-verify every entry against primary law. โ€œAccess = transferโ€ (EDPB Guidelines 05/2021); the exporterโ€™s law sets the conditions and one flow can trigger several regimes at once. ๐Ÿ”ถ = fast-moving, verify.

Pick an exporter (from) and a destination (to) for an at-a-glance transfer mechanism, plus the system-access (remote-admin) analysis โ€” then read the full tables below. The data is maintained in the wiki kb:transfers matrix and regenerated on each site sync, so it stays current without touching this page.

Table A โ€” Exporter regimes (the โ€œfromโ€ axis)

ExporterModelFree toOtherwise needAssessmentLocalisationRef
EU/EEA (GDPR Ch. V)Adequacy + SCCsEC adequacy list (incl. US via DPF)SCCs 2021/914 ยท BCRs ยท Art. 49TIA (Schrems II)Noโ†—
UK (UK GDPR)Adequacy + IDTAUK regs (โ‰ˆEU + UKโ€“US Data Bridge)IDTA / EU SCCs+Addendum ยท BCRs ยท derogationsTRANoโ†—
Switzerland (revFADP)Adequacy + CH-SCCsFDPIC list + Swissโ€“US DPFEU SCCs + FDPIC amend. ยท BCRs ยท derogationsTIANoโ†—
Brazil (LGPD)Adequacy + SCCsANPD list (nascent)ANPD SCCs ยท BCRs ยท specific clausesโ€”Noโ†—
Canada (PIPEDA; Quebec Law 25)Accountabilityโ€”Comparable-protection contract; org stays accountable. Quebec Law 25: privacy-impact assessment required before transferring PI outside QuebecAssessment (Quebec PIA)Noโ†—
China (PIPL)Approval / mechanismโ€”CAC security assessment / certification / standard contract (filing); separate consent + specific export notice; 2024 exemptionsPIPIAYes (CIIO, important data)โ†—
India (DPDPA + DPDP Rules 2025) ๐Ÿ”ถNegative listAll (none restricted yet)Valid contract between fiduciary/processor; govt may blacklist; fully operational ~mid-2027โ€”Sectoral (RBI payments)โ†—
Indonesia (PDP Law 27/2022) ๐Ÿ”ถTieredEqual-or-higher protectionElse binding safeguards; else consent; implementing GR pending; extraterritorial effectโ€”Sectoral (public / electronic-system data, GR 71/2019)โ†—
Japan (APPI)Adequacy-equiv.Japan list (EEA, UK)Consent / equivalent-measures contract + oversightโ€”Noโ†—
Malaysia (PDPA amended 2024/25)Comparable-protection + TIAโ€”TIA (substantially similar/adequate); SCC/BCR/cert; consent/contract; 5-day noticeYes (TIA)Noโ†—
South Korea (PIPA 2023)Consent + alternativesEU (PIPC-recognised equivalent, Sep 2025)Consent / contract+safeguards+notice / PIPC-cert / PIPC-recognised country; SCC/BCR + Overseas-Transfer Impact Assessment planned H1 2026Impact-typeNoโ†—
Taiwan (PDPA amended Nov 2025 โ†’ PDPC) ๐Ÿ”ถPermitted unless restrictedโ€”No dedicated cross-border-transfer statute yet; PDPC may restrict (Art. 21); sector/national-security bans emerging (e.g. PII to China/HK/Macao); assertive enforcementโ€”Sectorโ†—
UAE (Federal PDPL 45/2021 + DIFC/ADGM) ๐Ÿ”ถAdequacy + mechanisms (fragmented)Federal list pending; DIFC/ADGM own listsFederal: adequate country / contract / consent / necessity (regs not gazetted); health data generally must stay in UAE absent approval; financial-sector controls. DIFC & ADGM: GDPR-like + own SCCsDIFC/ADGM yesHealth data + free-zone/sectorโ†—
Australia (APP 8)Accountabilityโ€”Reasonable steps + comparable protection (exporter stays liable, incl. intra-group); exception if recipient under substantially-similar law/binding scheme/BCRs; or consentReasonable-stepsHealth/sectorโ†—
RussiaLocalisationโ€”Roskomnadzor consent/registration; strictโ€”Yes (citizens' data)
Singapore (PDPA s.26)Comparable-protection + accountabilityโ€” (no whitelist)Recipient bound by legally enforceable obligations (contract/BCR/APEC-CBPR cert) ensuring comparable protection; or consent; or contract necessity; or data in transit/publicComparable-protection assessmentNoโ†—
South Africa (POPIA s.72)Adequacy-or-safeguards + accountabilityโ€” (responsible party assesses adequacy)Recipient bound by law/BCR/agreement with adequate protection + onward-transfer limits; or consent; or contract necessity/benefitAdequacy assessmentNoโ†—
Turkey (KVKK Art. 9, amended Jun 2024)Adequacy + safeguards (GDPR-aligned)Board adequacy decisions (list nascent)Board standard contract (notify Board <=5 business days) / BCRs / int'l agreement / undertaking+authorisation; explicit-consent & other derogations for one-offAdequacy/safeguards assessmentNoโ†—
Costa Rica (Law 8968; reform Bill 23097) ๐Ÿ”ถConsent-based + adequate-protectionโ€” (no whitelist)Data-subject consent; transfer to non-adequate country without valid derogation = very serious offence; guarantee adequate protection; GDPR-aligned reform (Bill 23097) pendingAdequacy/consent checkNoโ†—
Most other countriesLight / noneโ€”Often consent/contract or no restrictionโ€”Varies

Table B โ€” Personal-data transfer, destination buckets โ€” from an EU/EEA exporter (UK/CH โ‰ˆ same)

Tables B and C are the EU/EEA-EXPORTER view (Table B = EU/EEA as data exporter; Table C = EU/EEA as the source/origin of the remote access). UK and Switzerland are broadly equivalent. For any other exporter, that exporter's own regime governs โ€” see Table A.

BucketCountriesAdequate?MechanismVerdict
Adequate โ†’ freeUnited Kingdom, Switzerland, Japan, South Korea, Canada (commercial), New Zealand, Israel, Argentina, Uruguay, Andorra, Faroe Islands, Guernsey, Isle of Man, JerseyyesNone (adequacy)Free transfer
US โ€” DPF-certified ๐Ÿ”ถUnited States (DPF-certified importer)partialData Privacy FrameworkOK if importer is DPF-certified (verify scope)
Mechanism-achievable (SCC + TIA)Australia, Taiwan, United Arab Emirates (DIFC/ADGM), Malaysia, Indonesia, Brazil, Singapore, South Africa, Turkey, Costa Rica, most Latin America / SE Asia (moderate risk)noSCCs + TIA (+ measures as risk dictates)OK, case-by-case after TIA
High-risk / broad state accessUnited States (non-DPF), China, Russia, IndianoSCCs + TIA + strong supplementary measures, or local mechanismProblematic โ€” robust measures or do not transfer
Localisation / approvalChina (CIIO / important data), Russia, Indonesia (sectoral), India (sectoral)noLocal pre-clearance (e.g. CAC) + export mechanismRestricted โ€” local approval needed
No mechanism availablenoArt. 49 derogation (consent, contract necessity, legal claims)Occasional / one-off only โ€” not for routine flows

Table C โ€” System access (remote admin) โ€” EU/EEA as exporter / source of the remote access; mitigation lens

Does the third-country admin need to see PLAINTEXT personal data?

SituationMitigationsResidual riskVerdict
Adequate destinationn/aLowFree โ€” normal access controls
Non-adequate; importer sees only ciphertext/pseudonymised, keys held in exporter countryStrong encryption (exporter-held keys), pseudonymisation, no-download, JIT/ephemeral access, loggingNeutralised (EDPB Rec 01/2020 UC 1โ€“3)OK
Non-adequate; importer needs plaintextAccess controls help but do not neutraliseMediumCase-by-case (per destination risk)
High-risk destination; plaintext adminEncryption fails if cleartext needed (EDPB UC 6/7)HighAvoid โ€” encrypted-only ops or relocate access
High-risk destination; encrypted-only opsE2E encryption + exporter-held keys + confidential computingLow / neutralisedOK if admin never needs cleartext
Localisation regimeโ€”โ€”Local rules govern even remote access

Table D โ€” System support out of India โ€” India as source of remote support

India as the LOCATION of the remote support/access, supporting a controller elsewhere (e.g. an EU/EEA exporter). If Indian staff can reach personal data, that access is a transfer to India (EDPB 05/2021). India (DPDPA) does not restrict inbound access, but the Indian entity is usually a processor/data-fiduciary with contract & security duties; India is not EU-adequate (broad state access -> factor into the TIA). RBI payment-data localisation applies if payment data is in scope.

Support scenarioTransfer?EU-exporter mechanismIndia-side (DPDPA)Mitigations / notesVerdict
No access to personal data (infra/OS/network only, or ciphertext-only with keys held outside India)No personal-data transferNone (Ch. V not triggered)Contract + security good practiceRBAC; encryption with keys outside India; no-download; screen-only/JIT; logging; beware PII in metadata/config/logs/ticketsOK โ€” document the no-PII scoping
Possible / incidental access (admin could technically reach PII; break-glass only)Treat as a transfer (mere possibility of access can count)SCCs + TIA โ€” or neutralise the accessProcessor contract (DPDPA); securityPrefer to eliminate access (encryption + keys outside India -> back to row 1); else SCC+TIA + measuresSCC+TIA, or neutralise
Actual access to personal data (plaintext) โ€” L2/L3 support, data fixes, content opsYes โ€” transfer to IndiaSCCs + TIA + supplementary measuresValid processor contract required (DPDPA); security safeguards; breach cooperation; onward transfer follows DPDPA negative-listEncryption cannot neutralise plaintext (EDPB UC 6/7); minimise/pseudonymise; heightened scrutiny for sensitive/large-scale; consider EU-side handling for sensitive dataSCC+TIA + measures; high scrutiny

Table E โ€” US DOJ Data Security Program (EO 14117) โ€” US-outbound bulk-sensitive-data export control ๐Ÿ”ถ

US-outbound national-security control (28 CFR Part 202; EO 14117; final rule effective 8 Apr 2025, affirmative compliance from 6 Oct 2025, reporting/enforcement phasing through 2026). Separate from the privacy/adequacy analysis; turns on the RECIPIENT being a country of concern (China incl. HK/Macau, Cuba, Iran, North Korea, Russia, Venezuela) or a covered person (entities >=50% owned by/organised in a CoC; their employees/contractors; individuals resident in a CoC). Covers bulk US sensitive personal data (genomic/omic, biometric, precise geolocation, health, financial, identifiers) and US government-related data (any volume). Cross-link: offshoring to India (Table D) is not a CoC, but a support provider that is a covered person can trigger this.

ScenarioDSP categoryOutcomeWhat's requiredNotes
Data brokerage / sale of bulk US sensitive personal data to a CoC or covered personProhibitedProhibitedโ€” (not permitted)Core prohibition; incl. onward-transfer & knowingly directing
US government-related data (precise geolocation of sensitive gov sites; gov/military personnel data) to CoC/covered personProhibitedProhibited โ€” any volumeโ€”No bulk threshold
Human genomic / 'omic / biospecimen data to CoC/covered personProhibitedProhibitedโ€”Lowest thresholds; especially sensitive
Vendor / employment / investment agreement giving a covered person access to bulk US sensitive data (e.g. offshore support/dev team that is a covered person)RestrictedAllowed only if compliantCISA security requirements + data-compliance program + due diligence + annual audit + (2026) reportingThe key offshoring case โ€” access = a covered data transaction
Below bulk threshold, rule-compliant de-identification, or an exempt transaction (intra-corporate group, financial services, telecom, US-gov, FDA/clinical)Out of scope / exemptNo DSP restrictionDocument the exemption/thresholdStill check other laws (privacy, export controls)

Sources