Privacy
Glossary

Transfer Impact Assessment

A documented assessment of whether the law and practice of a third country could undermine the safeguards for a planned transfer of personal data and require supplementary measures.

In brief

A Transfer Impact Assessment (TIA) is a documented risk assessment for a planned transfer to a third country. It is not a separate transfer mechanism. Instead, it supports the assessment of whether the requirements of Article 44 GDPR and, in particular where standard contractual clauses are used, Article 46 GDPR can be met. The data protection glossary explains the related terms.

The TIA records the data, recipients, purposes, transfer route and transfer tool involved. It then examines whether the law and practice of the third country allow a level of protection that is essentially equivalent to that in the European Union. The Schrems II judgment and EDPB recommendations call for a risk-based assessment. If relevant gaps remain, the organisation must identify supplementary measures or refrain from making the transfer in that form. A processor assessment checklist helps with the related provider review.

The result should set out the assumptions, legal assessment, safeguards and remaining risks in a way that can be reviewed later. A TIA forms part of ongoing data protection governance: it should be revisited when the provider, transfer route or relevant law changes. It does not replace an adequacy decision or careful selection and ongoing monitoring of the transfer tool.

General orientation, not individual advice.

Discuss your data protection matter

Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich