Українська
Увійти Замовити демо

All articles

Personal data outside the EEA: the GDPR rules in plain English

When may personal data go to the US or another country outside Europe? GDPR Articles 44 to 49 explained, with the US CLOUD Act alongside.

Published · 3 min read · Binadit

These articles are available in English, Dutch, German, French and Spanish.

Every company that uses Microsoft 365, Google Workspace, a US AI service or a US accounting package sends personal data outside Europe. The GDPR has a lot to say about that, in Chapter V. Here it is in plain English.

The basic rule: Article 44

Personal data may only go to a country outside the European Economic Area (the EU plus Iceland, Liechtenstein and Norway) if the level of protection is not undermined as a result. That also applies if the data is then passed on again. This is not about a form you fill in. It is about the protection that remains in practice.

There are three routes to meeting that rule.

Route 1: an adequacy decision (Article 45)

The European Commission can decide that a country, or part of it, offers an adequate level of protection. You may then send data there without additional arrangements. For the United States, such a decision has applied since 2023, but only to US companies that have joined the EU-US Data Privacy Framework.

The Commission must keep reviewing such a decision. If something fundamental changes in the other country, it can repeal or suspend it. That is exactly the question on the table now, after the Supreme Court ruling in Trump v. Slaughter.

Route 2: appropriate safeguards (Articles 46 and 47)

If there is no adequacy decision, the company can arrange safeguards itself. Usually this means Standard Contractual Clauses (SCCs) approved by the European Commission or, within an international group, Binding Corporate Rules (BCRs).

Since the Schrems II judgment in 2020, a contract alone is not enough. Anyone transferring data must assess whether the law in the other country allows those arrangements to work in practice, and take supplementary measures where needed. The strongest of these is encryption where the recipient does not hold the key. For ordinary cloud services that need to read your data to process it, such as mail and documents, that usually does not work.

Route 3: derogations (Article 49)

In specific situations a transfer is still allowed, for example with the explicit consent of the data subject or because it is necessary for a contract with that person. These are exceptions for occasional cases. They are not a basis for having all your mail and files processed by a US supplier every day.

The blocking rule: Article 48

Foreign authorities or courts sometimes demand data from companies. The US CLOUD Act, for example, requires US companies to hand over data they control, even if it sits on a server in Europe. Article 48 states that such a foreign order is not in itself a valid ground for disclosing data from the EU.

That does not solve the problem, though. A US company is then caught between two legal systems, and your data is caught in the middle. A European server location does not change that: what matters is who the supplier is, not where the disk is.

What about AI?

AI services add another layer. If you put personal data in a prompt, you are processing it for a purpose other than the one it was collected for. Free consumer versions often use input to train their models further; usually only business contracts rule that out. On top of that, the EU AI Act applies, with its own requirements per risk category. A European model on European infrastructure avoids most of these questions.

What this means for your company

The safest route is the simplest one: no transfers outside the EEA for the systems in which you work with personal data every day. Binadit Workspace runs entirely in the Netherlands, at a Dutch company with no US parent and no suppliers outside the EU. For mail, calendar, files, documents, meetings and chat, Chapter V of the GDPR then simply does not come into play. See Binadit Workspace.

Sources

  • General Data Protection Regulation, Chapter V (Articles 44 to 50): EUR-Lex
  • Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework: EUR-Lex
  • Court of Justice of the EU, Schrems II (C-311/18), 16 July 2020: Curia
  • Dutch Data Protection Authority (Autoriteit Persoonsgegevens) on transfers outside the EEA: autoriteitpersoonsgegevens.nl

This article is general information, not legal advice. For a specific situation, consult a lawyer.

Замовити демо Ціни