Transfers or Disclosures Not Authorised by Union Law — A comprehensive legal and technical examination
The General Data Protection Regulation (GDPR) Article 48 occupies a unique position within Chapter V of the GDPR governing international data transfers. Unlike Articles 45, 46, and 49, Article 48 is not itself a transfer mechanism or legal basis for processing.
Rather, Article 48 functions as a constitutional safeguard protecting European legal sovereignty and preventing the unilateral extraterritorial application of foreign laws against entities subject to the GDPR.
The provision addresses a recurring problem in global data governance: foreign governments, regulators, law-enforcement agencies, courts, competition authorities, securities regulators, and intelligence services frequently seek direct access to personal data held by organisations located within the European Economic Area (EEA).
Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognized or enforceable where based upon an international agreement, such as a Mutual Legal Assistance Treaty (MLAT), in force between the requesting third country and the Union or a Member State, without prejudice to other transfer grounds contained in Chapter V.
Any court, tribunal, or administrative authority order from a third country requiring transfer or disclosure of personal data
May only be recognised or enforceable where based upon an international agreement in force between the requesting country and the EU or a Member State
Other transfer grounds contained in Chapter V remain applicable and must be independently satisfied
Article 48 was designed to prevent foreign governments from bypassing EU legal safeguards. The objective is not to prohibit all disclosures — rather, to ensure that disclosures occur through legally recognised international cooperation frameworks and remain subject to GDPR protections.
Foreign courts issuing subpoenas directly to EEA-based entities without going through recognised legal channels
Broad discovery orders in foreign litigation seeking extensive categories of personal data from EU organisations
Foreign regulatory bodies demanding disclosure as part of cross-border enforcement actions
Direct demands from foreign police, prosecutors, and investigative agencies bypassing MLAT channels
Intelligence and security service requests invoking domestic national security legislation
Administrative orders from foreign tax, customs, competition, and other regulatory authorities
The requesting authority must generally rely upon a recognised international legal instrument. Even when such an agreement exists, GDPR obligations remain fully applicable and must be independently satisfied.
International Agreement — Formal treaty between the requesting country and the EU or a Member State
Mutual Legal Assistance Treaty (MLAT) — Bilateral or multilateral law-enforcement cooperation framework
Bilateral Treaty — Specific bilateral arrangements covering data exchange
Sector-Specific Mechanism — Cooperation frameworks in tax, competition, or financial regulation
Other Recognised Instrument — Any other internationally recognised legal basis for the request
All entities subject to GDPR operating within the EEA
Cloud service providers processing EU personal data
Banks, insurers, and financial services organisations
Hospitals, clinics, and health data processors
Multinational organisations processing EU personal data globally
Telecoms providers and digital technology platforms
Foreign courts and judicial bodies issuing disclosure orders
Securities regulators, competition authorities, and anti-corruption agencies
Foreign tax authorities and customs and border authorities
Foreign police, prosecutors, and law-enforcement agencies
National intelligence and security authorities
Foreign administrative bodies with regulatory disclosure powers
Article 48 applies across the full spectrum of personal data categories processed by organisations subject to GDPR. Heightened protections apply to special category and criminal conviction data.
Standard personal data alongside special category data including health, biometric, and genetic information subject to Article 9 restrictions
HR records, employment data, customer profiles, and consumer transaction information held by organisations
Banking records, transaction histories, medical records, and health-related data subject to sector-specific protections
Communications metadata, digital platform data, and behavioural and profiling data generated through online activity
The EDPB's Guidelines 02/2024 establish a structured assessment methodology that organisations must follow before responding to any foreign authority request for personal data.
Organisations must identify a lawful basis under Article 6. A foreign order alone does not automatically create a lawful basis. The assessment must be conducted independently of the foreign authority's demands.
The organisation must separately identify a Chapter V transfer mechanism. Both requirements — a valid legal basis and a valid transfer mechanism — must be satisfied simultaneously. Neither alone is sufficient.
Article 45 — Commission decision that the third country ensures an adequate level of protection
Article 46 — Standard Contractual Clauses, Binding Corporate Rules, and related safeguards
Limited derogations for specific situations including vital interests and important public interest
International agreements recognised under Article 48, including MLATs and bilateral treaties
A U.S. federal prosecutor seeks records from a German cloud provider. The request is transmitted through an existing MLAT between the United States and Germany. The German authority validates the request, and GDPR legal basis and transfer safeguards are established.
MLAT channel used
Legal obligation identified
Transfer safeguards in place
Records retained
Outcome: Disclosure potentially lawful.
The FBI directly serves an EU company with a subpoena. No MLAT channel is used. No recognised international agreement supports the request.
No MLAT or treaty used
Order lacks automatic EU recognition
Disclosure creates significant GDPR risk
Refer to legal counsel and supervisory authority
Outcome: Disclosure not lawful without further steps.
A non-EU tax authority requests customer transaction records from a French bank. A bilateral tax information exchange treaty exists between the two countries, and the treaty contains procedural safeguards.
Bilateral tax treaty potentially applicable
Chapter V mechanisms must still be independently assessed
Only the minimum necessary data may be disclosed
A foreign authority requests location information to locate a missing child. Vital interests are clearly implicated, creating an exceptional circumstance under the GDPR framework.
Vital interests of the data subject or another natural person
Derogations for important public interest or vital interests may apply
Proportionality analysis and documentation remain necessary even in emergencies
Article 48 does not operate in isolation. A comprehensive compliance assessment requires engagement with numerous intersecting GDPR provisions spanning territorial scope, processing principles, lawful basis, special categories, and accountability.
Territorial Scope — Determines whether GDPR applies; frequently relevant where foreign authorities seek data from multinational enterprises
Processing Principles — Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality
Lawful Basis — Central to all disclosures under Article 48; must be independently identified
Special Category & Criminal Data — Additional restrictions for health, biometric, genetic, and criminal conviction data
Transparency — Potential obligations to inform affected individuals of disclosures
Accountability & Privacy by Design — System architecture should anticipate foreign disclosure demands; demonstration of compliance required
Processor Obligations — Processors must notify controllers when they receive foreign authority requests for personal data
Records of Processing — Documentation obligations require logging of all foreign disclosure decisions and their legal bases
Security of Processing — Security controls must surround all disclosure processes to prevent unauthorised access
Breach Notification — Incorrect or unlawful disclosures may constitute reportable personal data breaches
DPIAs — Data Protection Impact Assessments required for high-risk cross-border transfer scenarios
General Transfer Principle — Foundation of Chapter V; all transfers must comply with this overarching requirement
Adequacy Decisions — Primary transfer mechanism where the Commission has recognised adequate protection
Appropriate Safeguards — Standard Contractual Clauses and related safeguards for transfers without adequacy decisions
Binding Corporate Rules — Relevant for multinational groups transferring data within corporate structures
Derogations — Limited exceptional transfers for specific circumstances including vital interests and public interest
Non-compliance with Article 48 exposes organisations to significant regulatory enforcement action and substantial financial penalties under the GDPR's tiered sanctions regime.
National data protection authorities hold broad investigative, corrective, and advisory powers to enforce Article 48 compliance, including the power to impose temporary or permanent bans on processing
Unlawful disclosures in breach of Article 48 may attract fines of up to €20 million or 4% of global annual turnover, whichever is higher, under the upper tier of GDPR penalties
Member States may impose national supplementary sanctions beyond the GDPR's administrative fines regime, including criminal liability in certain jurisdictions
Organisations may face directly competing obligations where GDPR prohibits disclosure whilst foreign law simultaneously requires it. Article 48 acts as a conflict-management mechanism, establishing EU law's primacy within the EEA whilst providing a structured pathway for legitimate international cooperation. Organisations must seek specialist legal advice when facing genuine conflicts.
The U.S. Clarifying Lawful Overseas Use of Data (CLOUD) Act can create significant tensions with GDPR. Organisations must evaluate whether any disclosure mechanisms satisfy both Article 48 and Chapter V requirements. Direct compliance with foreign law alone does not eliminate GDPR obligations, and organisations cannot simply defer to U.S. law when processing EU personal data.
U.S. civil discovery processes often seek broad categories of information through wide-ranging production requests. GDPR requires proportionality and necessity assessments for every disclosure. Blanket production requests are particularly problematic and must be challenged or narrowed before any disclosure can be considered lawful under the GDPR framework.
Formal board-approved policy defining response procedures and governance structure for all foreign authority requests
Mandatory legal review before any disclosure, with defined escalation thresholds and approval chains
Systematic verification of applicable MLATs, bilateral treaties, and sector-specific cooperation agreements
Structured evaluation of transfer risks including assessment of the requesting country's legal framework
Comprehensive immutable logging of all foreign requests received, assessments conducted, and decisions made
Single controlled channel for receiving and triaging all foreign authority requests to prevent ad hoc responses
Restrict disclosure authority to specifically approved and trained personnel only
Controlled review environment for requested datasets, preventing broader access during assessment
Systematic identification and labelling of regulated, sensitive, and special category datasets
Comprehensive understanding of where requested data resides across all systems and jurisdictions
Technical mechanisms to reduce disclosed data volumes to the minimum necessary for the stated purpose
Multi-stage approval processes requiring sign-off from legal, privacy, and compliance teams before any release
Encryption of personal data during storage and transmission to protect against unauthorised interception
Controlled export mechanisms ensuring data is transmitted only through approved secure channels
Tamper-resistant records of all disclosure activities providing a complete and verifiable audit trail
Automated alerts ensuring processors immediately notify controllers upon receipt of any foreign authority request
Automated verification of applicable transfer mechanisms before any cross-border disclosure is permitted
Assessment of downstream implications for data subject rights arising from each disclosure decision
Structured determination of whether supervisory authority engagement or notification is required
Periodic audits, control testing, independent assurance reviews, and lessons-learned processes following each request
Treat Article 48 as a sovereignty safeguard rather than a transfer mechanism — it is a constitutional protection for EU legal order
Never assume a foreign order is automatically enforceable — always conduct an independent structured assessment
Require independent assessment of both processing legality and transfer legality simultaneously
Maintain documented evidence of all disclosure decisions including the reasoning and legal bases relied upon
Embed Article 48 considerations into cloud governance, investigations management, e-discovery, and incident response
Conduct periodic exercises simulating foreign authority requests to test organisational readiness
Lead legal assessment of Article 48 and Chapter V requirements
Oversight of GDPR compliance and supervisory authority engagement
Technical controls and secure disclosure infrastructure
Policy governance and documentation management
International litigation and conflict-of-laws expertise
GDPR Article 48