International data transfer clause template clause
Updated: 21 September 2026
Please note: these example clauses are intended as a starting point, not as legal advice. Always adapt the text to your specific situation and have important contracts reviewed by a legal professional.
Clause text
Article [X] – Transfers of personal data outside the EEA
[X].1 General rule
Processor shall process the personal data it processes on behalf of Controller under this agreement solely within the European Economic Area, unless paragraph 2 provides otherwise.
[X].2 Permitted transfers
Transfer to a country outside the European Economic Area is permitted only where a valid basis for that transfer exists under Chapter V of the General Data Protection Regulation. Such a basis shall in any event include: an adequacy decision of the European Commission covering the country concerned, or the standard contractual clauses adopted by the European Commission, supplemented by the measures arising from the assessment referred to in paragraph 4.
[X].3 Register of processing locations
Processor shall maintain a current register of every country in which personal data is stored or processed, and of every country from which that data can be accessed, including access by support staff, remote administrators and sub-processors. Processor shall attach this register as an annex to this agreement, update it on every change, and resubmit it to Controller at least once every [number, e.g. 12] months.
[X].4 Assessment of the receiving country
Before any transfer made on the basis of standard contractual clauses, Processor shall assess the legal system of the receiving country, and in particular whether public authorities there can compel access to the data in a manner incompatible with Union law. Processor shall record that assessment in writing and make it available to Controller on first request.
[X].5 Supplementary measures
Where the assessment shows that the level of protection falls short, Processor shall implement supplementary measures before the transfer takes place. Such measures shall include at least: encryption with key management carried out exclusively within the European Economic Area, pseudonymisation of directly identifying data, and splitting data across processing locations such that the data held outside the European Economic Area is not identifiable on its own.
[X].6 Requests from authorities outside the EEA
Where Processor receives a request or order from an authority outside the European Economic Area to disclose personal data it processes on behalf of Controller, Processor shall notify Controller without delay, unless a legal prohibition prevents it from doing so. In that event Processor shall use its best efforts to challenge or narrow that prohibition through legal channels, and shall disclose no more data than it is demonstrably required to disclose.
[X].7 Loss of the legal basis
Where an adequacy decision lapses, or a competent court or supervisory authority rules that the basis relied upon no longer suffices, Processor shall suspend the transfer concerned within [number, e.g. 30] days, unless the parties agree an alternative basis in writing within that period.
[X].8 Consequences of breach
On breach of this Article, Controller may suspend the processing concerned with immediate effect. If the breach is not remedied within [number, e.g. 14] days of written notice of default, Controller may terminate this agreement in whole or in part, without prejudice to its right to compensation for the resulting loss.
What does this clause mean?
This clause settles a question that the standard data processing agreement usually disposes of in half a sentence: may your data leave European soil, and if so, on what terms. Chapter V of the GDPR permits transfers to countries outside the European Economic Area only where a basis for the transfer exists. The two bases that matter in practice are an adequacy decision of the European Commission for the country concerned, and the standard contractual clauses the Commission adopted in 2021.
The complication is that since the Schrems II judgment those standard clauses no longer suffice on their own. Each transfer has to be checked against the law of the receiving country to see whether the protection the clauses promise actually survives there. Paragraph 4 places that assessment with the party that can genuinely make it: your supplier, who knows which data centres it runs in and which subcontractors it uses.
Paragraph 3 is the most useful part of this article in practice, and the part least thought about at signature. Plenty of organisations know which country their cloud provider stores the data in, but not which countries that data can be reached from. A support desk on another continent looking into a customer environment is legally as much a transfer as a copy of the database. WorldCC (2025) reports that contract data sits scattered across 24 systems on average, and a transfer annex kept apart from the main contract is exactly the document nobody retrieves afterwards.
Paragraph 6 deserves separate attention, because it is the only provision that does any work at the moment things go wrong. A foreign authority demanding data rarely announces itself in advance. Without a notification duty and a best-efforts obligation, you learn of the demand once the data has already been handed over, and the only question left is who pays the fine.
When should you use this clause?
Include this article as soon as a supplier processes personal data on your behalf and does not expressly warrant that it does so entirely within the European Economic Area. In practice that touches almost every cloud application, CRM, payroll bureau, email platform and help desk with support staff outside Europe. Where a supplier demonstrably delivers wholly within the EEA, paragraphs 1 and 3 suffice as confirmation of that fact.
The article supplements rather than replaces the data processing clause, which governs the processing as a whole. If you also want to verify that the agreed terms are being honoured, pair it with an audit clause. And if you are thinking through the scenario in which the transfer has to stop, check whether your exit clause and your data portability terms actually make retrieving the data workable.
Loio (2026) calculates that 71% of contracts are never checked for compliance after signature. For transfer provisions that figure stings more than most, because the facts underneath the agreement really do shift: suppliers move workloads, take on new sub-processors and open support locations. Put the refresh interval from paragraph 3 into your contract management system as a task, not into an annex as an intention.
Customize these elements
- 1Ask for the country register in paragraph 3 before you sign, not after. A supplier that cannot produce it within a week does not have it either, and that on its own tells you something about the quality of its data governance.
- 2Distinguish storage from access. A supplier can truthfully state that the data sits in Frankfurt while remote administration happens from another continent. Paragraph 3 covers both, but only if you raise it explicitly during negotiation.
- 3Match the suspension period in paragraph 7 to what your organisation can absorb. Thirty days is reasonable for a peripheral application, but for a system your primary process depends on, suspension is not a real option. Agree a migration obligation on a longer timeline instead.
- 4State who bears the cost of the supplementary measures in paragraph 5. Encryption with key management inside the EEA is technically straightforward but rarely free, and that conversation belongs in the negotiation rather than in the year that follows.
- 5Check whether your [cyber insurance](/en/glossary/cyber-insurance/) covers regulatory fines and on what conditions. Many policies exclude them, or pay out only where the insured can show it had appropriate measures in place, and this article is precisely the kind of evidence asked for.
Sources
Manage all your contract deadlines automatically
Tracking Contracts alerts you well before every notice period. No spreadsheets, no missed renewals.
Start free month