GDPR Article 45: Adequacy Decisions for International Data Transfers

Advanced Analysis — A comprehensive guide to the EU's primary mechanism for lawful cross-border data flows

Legal Structure of Article 45

Article 45 is composed of several distinct provisions, each governing a different aspect of the adequacy framework.

1

Article 45(1) — Transfer Without Further Authorisation

The Commission may determine that a third country, territory, specified sector, or international organisation ensures an adequate level of protection. Transfers may then occur without further authorisation — no SCCs, BCRs, transfer impact assessments, or derogations are required.

2

Article 45(2) — Evaluation Criteria

  • Rule of law and respect for human rights
  • Relevant data protection and security legislation
  • Criminal law provisions and public authority access powers
  • Independent supervisory authorities
  • International commitments and effective judicial redress
3

Articles 45(3–5) — Adoption, Monitoring & Repeal

  • Decisions adopted through implementing acts with EDPB opinions
  • EU Member States participate via comitology process
  • Commission continuously monitors developments
  • Commission may suspend, repeal, or amend where protection is no longer adequate
4

Article 45(9) — Continuity of Prior Decisions

Earlier adequacy decisions under Directive 95/46/EC remain valid unless modified, ensuring legal continuity for organisations that relied upon pre-GDPR adequacy frameworks.

The "Essentially Equivalent" Standard

The Court of Justice of the European Union (CJEU) has repeatedly emphasised that adequacy does not require identical legal systems. The central test is whether protection is "essentially equivalent" to that within the EU.

Enforceable Rights

Individuals must enjoy enforceable rights in the destination jurisdiction, not merely aspirational protections.

Effective Remedies

Effective judicial or administrative remedies must exist and be practically accessible to data subjects.

Proportionate Surveillance

Government surveillance powers must be necessary and proportionate — not permitting bulk or indiscriminate collection.

Independent Oversight

Independent supervisory authorities must be present and empowered to enforce data protection obligations.

The landmark Schrems I and Schrems II decisions invalidated Safe Harbor and Privacy Shield respectively, because U.S. surveillance and redress mechanisms were deemed insufficient at those times — establishing the essential equivalence doctrine as the definitive legal standard.

Current Adequate Countries and Organisations

As of 2026, the European Commission recognises the following jurisdictions and organisations as adequate under Article 45. Practitioners must note that adequacy is not necessarily country-wide.

🌍 Europe & Islands

Andorra · Faroe Islands · Guernsey · Isle of Man · Jersey · Switzerland · United Kingdom

🌎 Americas

Argentina · Canada (commercial organisations only) · Uruguay · United States (DPF-certified organisations only)

🌏 Asia-Pacific & Middle East

Israel · Japan · New Zealand · Republic of Korea

🏛️ International Organisations

European Patent Organisation

⚠️ Practitioner Observation

Adequacy is not necessarily country-wide.

  • Canada — adequacy only for commercial organisations subject to PIPEDA
  • United States — adequacy only for organisations certified under the EU-U.S. Data Privacy Framework (DPF)

Always verify the precise scope of any adequacy decision before relying upon it.

Article 45 in Practice — Worked Examples

The following scenarios illustrate how Article 45 applies — and does not apply — across common commercial situations.

Example 1 — Adequacy Applicable

An EU manufacturer transfers employee data to a Japanese HR service provider. Japan benefits from an adequacy decision. No SCCs required. Transfer may proceed under Article 45.

Example 2 — Adequacy Not Applicable

An EU company transfers customer data to a Brazilian cloud provider. Brazil does not yet have a final adequacy decision. SCCs or another transfer mechanism are required.

⚖️ Example 3 — Partial Adequacy (U.S.)

An EU controller transfers data to a U.S. vendor. If DPF-certified → Article 45 applies. If not DPF-certified → SCCs and transfer impact assessment remain necessary.

🔄 Example 4 — Onward Transfers

A Japanese recipient subsequently transfers data to India. The original exporter must ensure onward transfer restrictions, contractual controls, and accountability. Adequacy does not automatically extend through subsequent transfers.

GDPR Articles Intersecting with Article 45

Advanced practitioners must teach and apply Article 45 within the broader GDPR framework. The following provisions are directly relevant.

Chapter V — Transfer Framework

  • Art. 44 – General principle for transfers
  • Art. 45 – Adequacy decisions
  • Art. 46 – Appropriate safeguards
  • Art. 47 – Binding Corporate Rules
  • Art. 48 – Foreign judgments
  • Art. 49 – Derogations
  • Art. 50 – International cooperation

Accountability Framework

  • Art. 5 – Processing principles
  • Art. 24 – Controller accountability
  • Art. 25 – Privacy by design
  • Art. 28 – Processor obligations
  • Art. 30 – Records of processing
  • Art. 32–36 – Security, breach & DPIAs

Governance Framework

  • Arts. 13–14 – Transparency
  • Arts. 15–22 – Data subject rights
  • Art. 37 – Data Protection Officer
  • Art. 40 – Codes of conduct
  • Art. 42 – Certification

Enforcement Framework

  • Art. 58 – Supervisory powers
  • Art. 77 – Complaints
  • Art. 79 – Judicial remedies
  • Art. 82 – Compensation
  • Art. 83 – Administrative fines

Twenty Cross-Cutting Technical and Organisational Controls

Advanced practitioners should implement the following controls regardless of whether adequacy exists. These form the backbone of a mature international transfer governance programme.

Transfer Inventory Control

Maintain a complete register of all international transfers.

Data Flow Mapping

Document origin, destination, processing purpose, and onward transfers.

Jurisdiction Classification Control

Classify destinations as adequate, SCC-based, BCR-based, or derogation-based.

Adequacy Monitoring Control

Continuously monitor Commission decisions for changes or revocations.

Vendor Due Diligence Control

Assess recipient legal and operational practices before transfer.

DPF Certification Validation

Validate U.S. DPF participation before transfer to U.S. organisations.

Annual Transfer Review

Reassess all international transfers on an annual basis.

Data Minimisation Enforcement

Restrict transferred datasets to necessary elements only.

Purpose Limitation Enforcement

Prevent secondary uses of transferred personal data.

Encryption at Rest & in Transit

Strong cryptographic protection and TLS transport security for all transferred data.

🔑 Key Management Governance

Segregated key management architecture to prevent unauthorised access.

👤 Access Control Enforcement

Role-based access control limiting data access to authorised personnel.

📋 Audit Logging

Immutable transfer audit records for accountability and investigation.

🔗 Onward Transfer Governance

Controls governing downstream recipients and subsequent transfers.

🚨 Incident Response Integration

Transfer-specific breach procedures integrated into the wider incident response plan.

🏛️ Transfer Governance Board

Formal executive oversight of all international transfer decisions and risks.

Detailed Assessment: The U.S. Data Protection Framework

Historical Background

The United States has been the most legally contentious transfer destination under GDPR. The principal challenge has always been balancing commercial privacy protections and national security surveillance authorities against GDPR's fundamental rights framework.

1

Safe Harbor

First framework enabling EU-U.S. transfers. Invalidated by the CJEU in Schrems I due to inadequate surveillance safeguards and lack of effective redress.

2

Privacy Shield

Successor framework with enhanced commitments. Invalidated by the CJEU in Schrems II — U.S. intelligence access powers remained disproportionate.

3

EU-U.S. Data Privacy Framework

Current framework. Supported by Executive Order 14086 and the Data Protection Review Court. Adequacy decision adopted and upheld by the General Court in 2025.

Current Framework — Commercial Privacy Obligations

Participating organisations must self-certify annually, adhere to DPF Principles, publish compliant privacy notices, maintain accountability for onward transfers, provide complaint handling mechanisms, and submit to regulatory enforcement by the Federal Trade Commission and Department of Transportation. The Department of Commerce administers certification.

Surveillance Reforms & the Data Protection Review Court

Executive Order 14086 — Surveillance Reforms

A central concern in Schrems II involved intelligence collection. The U.S. responded through:

  • Executive Order 14086 establishing new intelligence oversight mechanisms
  • Enhanced necessity and proportionality standards for signals intelligence
  • Independent review mechanisms for intelligence activities
  • Binding limitations on bulk data collection

Data Protection Review Court (DPRC)

The DPRC was created to provide redress mechanisms for EU individuals whose data is processed by U.S. intelligence agencies. This was one of the decisive factors supporting the adequacy decision.

  • Independent review process
  • Investigation of complaints from EU data subjects
  • Binding remedial authority
  • Oversight of intelligence activities

Strengths and Weaknesses of the U.S. Framework

Advanced practitioners must maintain a balanced, evidence-based assessment of the EU-U.S. Data Privacy Framework's durability and legal resilience.

Legal Stability Assessment

Current Position

Adequacy Remains Valid

The Commission completed its first review and the General Court upheld the adequacy decision in 2025. Continued monitoring remains mandatory.

Future Litigation Likely

Advanced practitioners should assume that another Schrems-style challenge remains possible. The legal landscape is not static.

Maintain Contingency SCCs

Contingency SCC frameworks should be maintained for critical processing operations, even where Article 45 adequacy currently applies.

"Advanced practitioners should nevertheless assume: future litigation remains likely. Another Schrems-style challenge remains possible. Contingency SCC frameworks should be maintained for critical processing operations."

Advanced Practitioner Conclusions

Article 45 is the GDPR's preferred international transfer mechanism — but it demands active, sophisticated governance rather than passive reliance.

Adequacy is a Geopolitical Risk Assessment

Adequacy is fundamentally a geopolitical and legal-risk assessment rather than merely a privacy assessment. The central test remains "essential equivalence."

Continuous Monitoring is Mandatory

Organisations cannot treat adequacy as permanent. Adequacy decisions can be suspended or repealed. Monitoring must be embedded into governance programmes.

The U.S. Remains the Critical Jurisdiction

The United States remains the most strategically important and legally scrutinised adequacy jurisdiction. DPF certification status must be validated before every transfer.

Mature Programmes Maintain Full Controls

Mature compliance programmes should maintain transfer governance, inventory management, technical security controls, and contingency mechanisms even when relying on Article 45 adequacy decisions.

Article 45 is One Component, Not an Exemption

The most defensible governance model treats Article 45 not as an exemption from transfer governance, but as one component of a comprehensive international data transfer risk-management framework.

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.