Transfer Impact Assessment
A documented assessment of whether the law and practice of a third country could undermine the safeguards for a planned transfer of personal data and require supplementary measures.
A Transfer Impact Assessment (TIA) is a documented risk assessment for a planned transfer to a third country. It is not a separate transfer mechanism. Instead, it supports the assessment of whether the requirements of Article 44 GDPR and, in particular where standard contractual clauses are used, Article 46 GDPR can be met. The data protection glossary explains the related terms.
The TIA records the data, recipients, purposes, transfer route and transfer tool involved. It then examines whether the law and practice of the third country allow a level of protection that is essentially equivalent to that in the European Union. The Schrems II judgment and EDPB recommendations call for a risk-based assessment. If relevant gaps remain, the organisation must identify supplementary measures or refrain from making the transfer in that form. A processor assessment checklist helps with the related provider review.
The result should set out the assumptions, legal assessment, safeguards and remaining risks in a way that can be reviewed later. A TIA forms part of ongoing data protection governance: it should be revisited when the provider, transfer route or relevant law changes. It does not replace an adequacy decision or careful selection and ongoing monitoring of the transfer tool.
Learn more
Legal framework
General orientation, not individual advice.
-
International data transfer
An international data transfer is a transfer of personal data to a country outside the European Economic Area or to an international organisation subject to the specific requirements of Chapter V GDPR.
-
Standard contractual clauses
Standard contractual clauses are Commission-approved clauses that provide appropriate safeguards for certain transfers of personal data to third countries. Their choice and completion must fit the specific transfer.
-
Legal basis
A legal basis is the specific legal ground that makes processing personal data lawful. For most processing activities, one of the conditions in Article 6(1) GDPR must apply.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000