Article 46: Transfers subject to appropriate safeguards
Praxikon tracks Article 46 (Transfers subject to appropriate safeguards) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 46 govern?
Article 46 sets out how you may transfer personal data to a country outside the EU (a third country) or to an international organisation when the Commission has not adopted an adequacy decision for that country under Article 45. In that case a transfer is allowed only if the controller or processor provides appropriate safeguards and data subjects keep enforceable rights and effective legal remedies (paragraph 1). Paragraph 2 lists instruments you may use without any specific authorisation from the supervisory authority, such as standard data protection clauses adopted by the Commission, binding corporate rules under Article 47, and an approved code of conduct or certification combined with binding commitments. Paragraph 3 lists instruments that need authorisation from the competent supervisory authority, such as your own contractual clauses and administrative arrangements between public bodies; the supervisory authority applies the consistency mechanism of Article 63 for those (paragraph 4). The article exists because GDPR protection must not disappear once data leaves the EU: the safeguards have to compensate for the lack of protection in the third country (recital 108).
Key term: Appropriate safeguards: arrangements or rules that carry GDPR level protection with the data to a country outside the EU, so that data subjects keep enforceable rights there
Directly affects:controllerprocessordata subjectsupervisory authorityCommission
Praxikon’s reading of the text and the recitals; the official text below prevails.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
If you have data processed in a country without an adequacy decision, you first choose an instrument from paragraph 2, for example the Commission's standard data protection clauses or binding corporate rules for transfers within your own group (recital 110). If you want to use your own contractual clauses, you need prior authorisation from the supervisory authority (paragraph 3). You may include the standard clauses in a wider contract and add extra safeguards, as long as they do not contradict the standard clauses or prejudice the rights of data subjects (recital 109).
Processor
This article applies directly to you as well: a processor that moves data outside the EU, for example to a sub-processor, must itself provide appropriate safeguards (paragraph 1). You can include the standard clauses in the contract with that other processor (recital 109).
Data Protection Officer
You assess whether the chosen instrument fits the transfer and whether data subjects actually have enforceable rights and effective legal remedies (paragraph 1). You keep track of which transfers rely on paragraph 2 and which on paragraph 3, because paragraph 3 requires authorisation from the supervisory authority.
Data Subject
The article requires that you keep enforceable rights and effective legal remedies after the transfer, for example to seek administrative or judicial redress or to claim compensation (paragraph 1 and recital 108).
Compliance checklist
Related recitals
In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third country by way of appropriate safeguards for the data ...
(109)The possibility for the controller or processor to use standard data-protection clauses adopted by the Commission or by a supervisory authority should prevent controllers or processors neither from in...
(110)A group of undertakings, or a group of enterprises engaged in a joint economic activity, should be able to make use of approved binding corporate rules for its international transfers from the Union t...
Cross-references
Frequently asked questions
Connections
What connects to Article 46 GDPR
Case law
- Schrems II: Privacy Shield invalid, transfers under standard clauses only with essentially equivalent protection
2020-07-16 · final, Hof van Justitie van de EU (Grote kamer), Data Protection Commissioner tegen Facebook Ireland Ltd en Maximillian Schrems
Guidelines
- Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR
2023-02-14 · final, European Data Protection Board (EDPB)
- Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
2021-06-18 · final, European Data Protection Board (EDPB)
Enforcement and fines
- 100 million euro fine for MLU B.V. (Yango) for transfers to Russia
2026-04-01 · status not established, Autoriteit Persoonsgegevens