Advanced Analysis — A comprehensive guide to the EU's primary mechanism for lawful cross-border data flows
Article 45 is composed of several distinct provisions, each governing a different aspect of the adequacy framework.
The Commission may determine that a third country, territory, specified sector, or international organisation ensures an adequate level of protection. Transfers may then occur without further authorisation — no SCCs, BCRs, transfer impact assessments, or derogations are required.
Earlier adequacy decisions under Directive 95/46/EC remain valid unless modified, ensuring legal continuity for organisations that relied upon pre-GDPR adequacy frameworks.
The Court of Justice of the European Union (CJEU) has repeatedly emphasised that adequacy does not require identical legal systems. The central test is whether protection is "essentially equivalent" to that within the EU.
Individuals must enjoy enforceable rights in the destination jurisdiction, not merely aspirational protections.
Effective judicial or administrative remedies must exist and be practically accessible to data subjects.
Government surveillance powers must be necessary and proportionate — not permitting bulk or indiscriminate collection.
Independent supervisory authorities must be present and empowered to enforce data protection obligations.
The landmark Schrems I and Schrems II decisions invalidated Safe Harbor and Privacy Shield respectively, because U.S. surveillance and redress mechanisms were deemed insufficient at those times — establishing the essential equivalence doctrine as the definitive legal standard.
As of 2026, the European Commission recognises the following jurisdictions and organisations as adequate under Article 45. Practitioners must note that adequacy is not necessarily country-wide.
Andorra · Faroe Islands · Guernsey · Isle of Man · Jersey · Switzerland · United Kingdom
Argentina · Canada (commercial organisations only) · Uruguay · United States (DPF-certified organisations only)
Israel · Japan · New Zealand · Republic of Korea
European Patent Organisation
Adequacy is not necessarily country-wide.
Always verify the precise scope of any adequacy decision before relying upon it.
The following scenarios illustrate how Article 45 applies — and does not apply — across common commercial situations.
An EU manufacturer transfers employee data to a Japanese HR service provider. Japan benefits from an adequacy decision. No SCCs required. Transfer may proceed under Article 45.
An EU company transfers customer data to a Brazilian cloud provider. Brazil does not yet have a final adequacy decision. SCCs or another transfer mechanism are required.
An EU controller transfers data to a U.S. vendor. If DPF-certified → Article 45 applies. If not DPF-certified → SCCs and transfer impact assessment remain necessary.
A Japanese recipient subsequently transfers data to India. The original exporter must ensure onward transfer restrictions, contractual controls, and accountability. Adequacy does not automatically extend through subsequent transfers.
Advanced practitioners must teach and apply Article 45 within the broader GDPR framework. The following provisions are directly relevant.
Advanced practitioners should implement the following controls regardless of whether adequacy exists. These form the backbone of a mature international transfer governance programme.
Maintain a complete register of all international transfers.
Document origin, destination, processing purpose, and onward transfers.
Classify destinations as adequate, SCC-based, BCR-based, or derogation-based.
Continuously monitor Commission decisions for changes or revocations.
Assess recipient legal and operational practices before transfer.
Validate U.S. DPF participation before transfer to U.S. organisations.
Reassess all international transfers on an annual basis.
Restrict transferred datasets to necessary elements only.
Prevent secondary uses of transferred personal data.
Strong cryptographic protection and TLS transport security for all transferred data.
Segregated key management architecture to prevent unauthorised access.
Role-based access control limiting data access to authorised personnel.
Immutable transfer audit records for accountability and investigation.
Controls governing downstream recipients and subsequent transfers.
Transfer-specific breach procedures integrated into the wider incident response plan.
Formal executive oversight of all international transfer decisions and risks.
The United States has been the most legally contentious transfer destination under GDPR. The principal challenge has always been balancing commercial privacy protections and national security surveillance authorities against GDPR's fundamental rights framework.
First framework enabling EU-U.S. transfers. Invalidated by the CJEU in Schrems I due to inadequate surveillance safeguards and lack of effective redress.
Successor framework with enhanced commitments. Invalidated by the CJEU in Schrems II — U.S. intelligence access powers remained disproportionate.
Current framework. Supported by Executive Order 14086 and the Data Protection Review Court. Adequacy decision adopted and upheld by the General Court in 2025.
Participating organisations must self-certify annually, adhere to DPF Principles, publish compliant privacy notices, maintain accountability for onward transfers, provide complaint handling mechanisms, and submit to regulatory enforcement by the Federal Trade Commission and Department of Transportation. The Department of Commerce administers certification.
A central concern in Schrems II involved intelligence collection. The U.S. responded through:
The DPRC was created to provide redress mechanisms for EU individuals whose data is processed by U.S. intelligence agencies. This was one of the decisive factors supporting the adequacy decision.
Advanced practitioners must maintain a balanced, evidence-based assessment of the EU-U.S. Data Privacy Framework's durability and legal resilience.

The Commission completed its first review and the General Court upheld the adequacy decision in 2025. Continued monitoring remains mandatory.
Advanced practitioners should assume that another Schrems-style challenge remains possible. The legal landscape is not static.
Contingency SCC frameworks should be maintained for critical processing operations, even where Article 45 adequacy currently applies.
"Advanced practitioners should nevertheless assume: future litigation remains likely. Another Schrems-style challenge remains possible. Contingency SCC frameworks should be maintained for critical processing operations."
Article 45 is the GDPR's preferred international transfer mechanism — but it demands active, sophisticated governance rather than passive reliance.
Adequacy is fundamentally a geopolitical and legal-risk assessment rather than merely a privacy assessment. The central test remains "essential equivalence."
Organisations cannot treat adequacy as permanent. Adequacy decisions can be suspended or repealed. Monitoring must be embedded into governance programmes.
The United States remains the most strategically important and legally scrutinised adequacy jurisdiction. DPF certification status must be validated before every transfer.
Mature compliance programmes should maintain transfer governance, inventory management, technical security controls, and contingency mechanisms even when relying on Article 45 adequacy decisions.
The most defensible governance model treats Article 45 not as an exemption from transfer governance, but as one component of a comprehensive international data transfer risk-management framework.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
GDPR Article 45: Adequacy Decisions for International Data Transfers