Juridique

GDPR & International Data Transfers: Official EU Texts

The full text of the EU General Data Protection Regulation plus the key instruments for sending personal data outside the EU: the 2021 Standard Contractual Clauses, the Commission's Q&A on them, and the EU-US Data Privacy Framework adequacy decision. For DPOs, lawyers, SaaS vendors and compliance teams. Curated by Kopik from public sources: EUR-Lex / Publications Office of the EU and the European Commission (EU reuse).

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

This assistant answers questions on the EU General Data Protection Regulation (GDPR) and on the rules for sending personal data outside the European Union. It is meant for DPOs, lawyers, SaaS vendors and compliance teams who need answers grounded in the official wording. Its sources are the GDPR as published in the Official Journal, the 2021 Standard Contractual Clauses decision, the European Commission's Q&A on those clauses and the EU-US Data Privacy Framework adequacy decision.

Four official texts, one place to ask

The base contains Regulation (EU) 2016/679, the General Data Protection Regulation of 27 April 2016, in its Official Journal version.

It adds Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for transfers to third countries, together with the Commission's document "The New Standard Contractual Clauses: Questions and Answers".

The fourth text is Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework.

The general rule for transfers outside the EU

Article 44 of the GDPR sets the general principle: a transfer of personal data to a third country or an international organisation may only take place if the conditions of Chapter V are met by the controller and processor, including for onward transfers from that country to another one.

The aim stated in the Regulation is that the level of protection guaranteed by the GDPR is not undermined when data leave the Union.

In practice, Chapter V offers an adequacy decision by the Commission (Article 45), appropriate safeguards such as standard data protection clauses or binding corporate rules (Articles 46 and 47), and, in the absence of both, derogations for specific situations (Article 49).

How the Commission judges a country adequate

Under Article 45, a transfer may take place without any specific authorisation where the Commission has decided that a third country, a territory, one or more specified sectors within it, or an international organisation ensures an adequate level of protection.

The assessment looks in particular at the rule of law and respect for human rights, relevant legislation including on public security, national security and access of public authorities to personal data, effective and enforceable data subject rights, and effective administrative and judicial redress.

The Commission also considers whether one or more independent supervisory authorities exist and function effectively, and the international commitments the country has entered into in relation to the protection of personal data.

An adequacy decision must provide for a periodic review at least every four years. The Commission monitors developments on an ongoing basis and, where a country no longer ensures adequate protection, repeals, amends or suspends the decision, without retroactive effect.

Everyday GDPR deadlines and duties

Beyond transfers, the assistant covers the rest of the Regulation. A controller must act on a data subject's request without undue delay and in any event within one month of receipt.

A personal data breach must be notified to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless it is unlikely to result in a risk to individuals. A processor must notify its controller without undue delay.

When a breach is likely to result in a high risk to people's rights and freedoms, the controller must also inform the data subjects without undue delay.

Questions fréquentes

What are the maximum GDPR fines?

Article 83 sets two tiers. Some infringements can lead to fines of up to 10 000 000 EUR or, for an undertaking, up to 2 % of total worldwide annual turnover of the preceding financial year, whichever is higher. Others, and non-compliance with an order of a supervisory authority, can reach 20 000 000 EUR or 4 % of worldwide annual turnover, whichever is higher.

Can the one-month deadline for answering a data subject be extended?

Yes, by two further months where necessary, taking into account the complexity and number of requests. The controller must inform the person of the extension and the reasons for it within one month of receiving the request. If the controller decides not to act at all, it must say so within one month and mention the possibility of complaining to a supervisory authority.

What happens if a breach cannot be notified within 72 hours?

The notification can still be made, but it must be accompanied by the reasons for the delay. Article 33(4) adds that, where the information cannot all be provided at the same time, it may be provided in phases without undue further delay.

Who does the data protection officer report to?

The DPO reports directly to the highest management level of the controller or processor. The DPO must not receive instructions on how to carry out those tasks and cannot be dismissed or penalised for performing them.

How long does a supervisory authority have to answer a prior consultation?

Where the authority considers that intended high-risk processing would infringe the GDPR, it gives written advice within up to eight weeks of receiving the request. This period may be extended by six weeks for complex processing, and the controller must be informed of the extension within one month.

Is a transfer to an adequate country subject to other conditions?

Article 45 states that a transfer based on an adequacy decision does not require any specific authorisation. The other provisions of the GDPR still apply to the processing itself, and Article 44 extends the transfer conditions to onward transfers from that country to another third country or international organisation.

Can the assistant quote the exact article?

Yes. Answers are built from the official texts in the base, so you can ask for the article, recital or clause number and the wording behind an answer, then check it against the source.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-eu-gdpr-official-texts-data-transfers "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-eu-gdpr-official-texts-data-transfers": {
      "url": "https://kopik.io/api/mcp?base=eu-gdpr-official-texts-data-transfers",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-gdpr-official-texts-data-transfers/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.