Skip to content

Privacy Hub · plain-language reference

← Privacy Hub

Cross-border transfer of personal data

Also known as: data export, foreign hosting, international data transfer, international transfer, offshore processing, overseas transfer, transborder data flow

A cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.

ZW_CDPA
EU_GDPR
GB_UK_GDPR
v3 · published 31 Jul 2026

Term explanation

At a glance

A cross-border transfer is not limited to emailing a database abroad. It may arise when an overseas supplier hosts data, a support team in another country accesses a system, a multinational shares a central database, or staff can download records from another location.

The precise legal boundary varies. Some frameworks focus on transfer outside a protected area or to a separate recipient; others use country-based language. Routing traffic through another country may be treated differently from storing or accessing it there.

In plain language

To be expanded during editorial review.

Why it matters

Data-protection rules can become harder to enforce once information moves across borders. The person may face weaker protections, unfamiliar legal access powers, limited complaint routes or multiple regulators. Transfer rules try to preserve an appropriate level of protection rather than banning all international services.

Using a reputable cloud provider does not settle compliance automatically. The organisation needs to understand the contracting entity, storage and backup locations, remote-support access, subprocessors, destination laws, security controls and onward transfers.

A practical example

A Zimbabwe retailer uses customer-support software hosted abroad. The supplier stores tickets overseas and permits global support access. The retailer should map the countries and subprocessors, assess the Zimbabwe transfer requirements, complete the relevant impact and adequacy work, and put the correct agreement and safeguards in place. EU or UK data requires separate analysis.

General principles

Start with a transfer map

List each data flow, the controller, exporter, recipient, processor status, countries or territories, data and people involved, purpose, frequency and storage/access model. Include administrative access and support, not only primary hosting. Check whether the same activity engages more than one legal framework.

Assess the route

The available route may depend on an official adequacy decision, recognised contractual safeguards, approved group rules, certification or a limited derogation such as necessity or explicit consent. These mechanisms are not interchangeable between jurisdictions. A safeguard with a familiar name should not be assumed valid everywhere.

Assess practical protection as well as paperwork: encryption, access controls, government-access exposure, incident handling, onward transfers, deletion, audit rights and the recipient’s ability to meet commitments. Record the assessment and approval before the transfer.

Transfers change over time

A compliant transfer can become outdated when a provider adds a subprocessor, moves a backup, changes remote-support locations, alters its contract or when law and official adequacy decisions change. Procurement should require advance notice of material changes and privacy owners should review the transfer register periodically. “Region selection” in a cloud dashboard does not prove that support, telemetry, disaster recovery and administrative access stay in that region.

Practical next steps

Create and maintain a transfer register. Assign an owner, identify the applicable lens, confirm the legal route, complete risk and adequacy assessments, approve the recipient and contract, provide required transparency, retain regulator correspondence and monitor changes. Pause a proposed transfer if the route or safeguards cannot be established.

Related terms: processor; recipient; adequacy; transfer impact assessment; consent; SCCs; BCRs; data localisation

Jurisdiction guidance

Select more lenses from the Hub landing page to compare across jurisdictions.

GLOBAL
Global baseline

No jurisdiction-specific guidance is published for this lens yet.

Sources & citations

Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.


Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.