Cross-border transfer of personal data
Also known as: data export, foreign hosting, international data transfer, international transfer, offshore processing, overseas transfer, transborder data flow
A cross-border transfer occurs when personal data is sent, stored, accessed or otherwise made available across national or regulatory borders in circumstances covered by the applicable law. It can arise through cloud hosting, overseas support, group-company access or an external processor. The destination, recipient, safeguards, purpose and transfer mechanism should be assessed before the transfer begins.
Term explanation
At a glance
A cross-border transfer is not limited to emailing a database abroad. It may arise when an overseas supplier hosts data, a support team in another country accesses a system, a multinational shares a central database, or staff can download records from another location.
The precise legal boundary varies. Some frameworks focus on transfer outside a protected area or to a separate recipient; others use country-based language. Routing traffic through another country may be treated differently from storing or accessing it there.
In plain language
To be expanded during editorial review.
Why it matters
Data-protection rules can become harder to enforce once information moves across borders. The person may face weaker protections, unfamiliar legal access powers, limited complaint routes or multiple regulators. Transfer rules try to preserve an appropriate level of protection rather than banning all international services.
Using a reputable cloud provider does not settle compliance automatically. The organisation needs to understand the contracting entity, storage and backup locations, remote-support access, subprocessors, destination laws, security controls and onward transfers.
A practical example
A Zimbabwe retailer uses customer-support software hosted abroad. The supplier stores tickets overseas and permits global support access. The retailer should map the countries and subprocessors, assess the Zimbabwe transfer requirements, complete the relevant impact and adequacy work, and put the correct agreement and safeguards in place. EU or UK data requires separate analysis.
General principles
Start with a transfer map
List each data flow, the controller, exporter, recipient, processor status, countries or territories, data and people involved, purpose, frequency and storage/access model. Include administrative access and support, not only primary hosting. Check whether the same activity engages more than one legal framework.
Assess the route
The available route may depend on an official adequacy decision, recognised contractual safeguards, approved group rules, certification or a limited derogation such as necessity or explicit consent. These mechanisms are not interchangeable between jurisdictions. A safeguard with a familiar name should not be assumed valid everywhere.
Assess practical protection as well as paperwork: encryption, access controls, government-access exposure, incident handling, onward transfers, deletion, audit rights and the recipient’s ability to meet commitments. Record the assessment and approval before the transfer.
Transfers change over time
A compliant transfer can become outdated when a provider adds a subprocessor, moves a backup, changes remote-support locations, alters its contract or when law and official adequacy decisions change. Procurement should require advance notice of material changes and privacy owners should review the transfer register periodically. “Region selection” in a cloud dashboard does not prove that support, telemetry, disaster recovery and administrative access stay in that region.
Practical next steps
Create and maintain a transfer register. Assign an owner, identify the applicable lens, confirm the legal route, complete risk and adequacy assessments, approve the recipient and contract, provide required transparency, retain regulator correspondence and monitor changes. Pause a proposed transfer if the route or safeguards cannot be established.
Related terms: processor; recipient; adequacy; transfer impact assessment; consent; SCCs; BCRs; data localisation
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Data processor — processor
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 4 of 2025 — Cross Border Data Transfers (CDPG-4-2025)
CDPG-4-2025 · cites · Read in the Legal Library
- CDPG 5 of 2024 — Cross Border Transfer (CDPG-5-2024)
CDPG-5-2024 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.