GDPR Article 48

Transfers or Disclosures Not Authorised by Union Law — A comprehensive legal and technical examination

Introduction

The General Data Protection Regulation (GDPR) Article 48 occupies a unique position within Chapter V of the GDPR governing international data transfers. Unlike Articles 45, 46, and 49, Article 48 is not itself a transfer mechanism or legal basis for processing.

Rather, Article 48 functions as a constitutional safeguard protecting European legal sovereignty and preventing the unilateral extraterritorial application of foreign laws against entities subject to the GDPR.

The provision addresses a recurring problem in global data governance: foreign governments, regulators, law-enforcement agencies, courts, competition authorities, securities regulators, and intelligence services frequently seek direct access to personal data held by organisations located within the European Economic Area (EEA).

Key Principles

  • Foreign judicial or administrative orders do not automatically become enforceable merely because a foreign authority has issued them
  • Organisations must conduct a structured assessment before responding to such requests
  • Compliance with both general GDPR requirements and Chapter V international transfer requirements is mandatory
  • The EDPB has issued Guidelines 02/2024 reinforcing this structured approach

Text of Article 48

Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognized or enforceable where based upon an international agreement, such as a Mutual Legal Assistance Treaty (MLAT), in force between the requesting third country and the Union or a Member State, without prejudice to other transfer grounds contained in Chapter V.

Foreign Judgment or Decision

Any court, tribunal, or administrative authority order from a third country requiring transfer or disclosure of personal data

Recognition Requirement

May only be recognised or enforceable where based upon an international agreement in force between the requesting country and the EU or a Member State

Without Prejudice

Other transfer grounds contained in Chapter V remain applicable and must be independently satisfied

Legislative Purpose

Article 48 was designed to prevent foreign governments from bypassing EU legal safeguards. The objective is not to prohibit all disclosures — rather, to ensure that disclosures occur through legally recognised international cooperation frameworks and remain subject to GDPR protections.

Extraterritorial Subpoenas

Foreign courts issuing subpoenas directly to EEA-based entities without going through recognised legal channels

Discovery Orders

Broad discovery orders in foreign litigation seeking extensive categories of personal data from EU organisations

Regulatory Investigations

Foreign regulatory bodies demanding disclosure as part of cross-border enforcement actions

Law-Enforcement Requests

Direct demands from foreign police, prosecutors, and investigative agencies bypassing MLAT channels

National Security Demands

Intelligence and security service requests invoking domestic national security legislation

Administrative Disclosure Mandates

Administrative orders from foreign tax, customs, competition, and other regulatory authorities

Core Legal Principle

The requesting authority must generally rely upon a recognised international legal instrument. Even when such an agreement exists, GDPR obligations remain fully applicable and must be independently satisfied.

Recognised International Instruments

International Agreement — Formal treaty between the requesting country and the EU or a Member State

Mutual Legal Assistance Treaty (MLAT) — Bilateral or multilateral law-enforcement cooperation framework

Bilateral Treaty — Specific bilateral arrangements covering data exchange

Sector-Specific Mechanism — Cooperation frameworks in tax, competition, or financial regulation

Other Recognised Instrument — Any other internationally recognised legal basis for the request

Scope of Article 48

Entities Covered

Controllers & Processors

All entities subject to GDPR operating within the EEA

Cloud Providers

Cloud service providers processing EU personal data

Financial Institutions

Banks, insurers, and financial services organisations

Healthcare Organisations

Hospitals, clinics, and health data processors

Multinationals

Multinational organisations processing EU personal data globally

Technology Platforms

Telecoms providers and digital technology platforms

Foreign Authorities Covered

Courts & Tribunals

Foreign courts and judicial bodies issuing disclosure orders

Securities & Competition

Securities regulators, competition authorities, and anti-corruption agencies

Tax & Customs

Foreign tax authorities and customs and border authorities

Law Enforcement

Foreign police, prosecutors, and law-enforcement agencies

Intelligence Services

National intelligence and security authorities

Administrative Agencies

Foreign administrative bodies with regulatory disclosure powers

Types of Data Covered

Article 48 applies across the full spectrum of personal data categories processed by organisations subject to GDPR. Heightened protections apply to special category and criminal conviction data.

Personal & Special Category Data

Standard personal data alongside special category data including health, biometric, and genetic information subject to Article 9 restrictions

Employee & Customer Information

HR records, employment data, customer profiles, and consumer transaction information held by organisations

Financial & Health Records

Banking records, transaction histories, medical records, and health-related data subject to sector-specific protections

Communications & Digital Data

Communications metadata, digital platform data, and behavioural and profiling data generated through online activity

The EDPB's Two-Step Assessment Framework

EDPB Guidelines 02/2024

The EDPB's Guidelines 02/2024 establish a structured assessment methodology that organisations must follow before responding to any foreign authority request for personal data.

Step 1: Identify a Valid GDPR Legal Basis

Organisations must identify a lawful basis under Article 6. A foreign order alone does not automatically create a lawful basis. The assessment must be conducted independently of the foreign authority's demands.

Possible Legal Bases

  • Legal obligation under Article 6(1)(c)
  • Public task under Article 6(1)(e)
  • Legitimate interests under Article 6(1)(f) in limited circumstances
  • Vital interests under Article 6(1)(d) in exceptional circumstances only

Step 2: Identify a Valid International Transfer Mechanism

The organisation must separately identify a Chapter V transfer mechanism. Both requirements — a valid legal basis and a valid transfer mechanism — must be satisfied simultaneously. Neither alone is sufficient.

1

Adequacy Decision

Article 45 — Commission decision that the third country ensures an adequate level of protection

2

Appropriate Safeguards

Article 46 — Standard Contractual Clauses, Binding Corporate Rules, and related safeguards

3

Article 49 Derogations

Limited derogations for specific situations including vital interests and important public interest

4

Article 48 Agreement

International agreements recognised under Article 48, including MLATs and bilateral treaties

Practical Examples: Compliance Assessments

Example 1

U.S. Criminal Investigation via MLAT

A U.S. federal prosecutor seeks records from a German cloud provider. The request is transmitted through an existing MLAT between the United States and Germany. The German authority validates the request, and GDPR legal basis and transfer safeguards are established.

✓ Article 48 Satisfied

MLAT channel used

✓ Article 6 Basis

Legal obligation identified

✓ Chapter V Mechanism

Transfer safeguards in place

✓ Documentation

Records retained

Outcome: Disclosure potentially lawful.

Example 2

Direct FBI Demand to an EU Company

The FBI directly serves an EU company with a subpoena. No MLAT channel is used. No recognised international agreement supports the request.

✗ Article 48 Not Satisfied

No MLAT or treaty used

✗ No Recognition

Order lacks automatic EU recognition

âš  Substantial Risk

Disclosure creates significant GDPR risk

âš  Escalate

Refer to legal counsel and supervisory authority

Outcome: Disclosure not lawful without further steps.

Further Practical Examples

Example 3

Foreign Tax Authority Request

A non-EU tax authority requests customer transaction records from a French bank. A bilateral tax information exchange treaty exists between the two countries, and the treaty contains procedural safeguards.

Article 48 May Be Satisfied

Bilateral tax treaty potentially applicable

Transfer Safeguards Required

Chapter V mechanisms must still be independently assessed

Data Minimisation Applies

Only the minimum necessary data may be disclosed

Example 4

Emergency Child Abduction Case

A foreign authority requests location information to locate a missing child. Vital interests are clearly implicated, creating an exceptional circumstance under the GDPR framework.

Article 6(1)(d) May Apply

Vital interests of the data subject or another natural person

Article 49 Derogations

Derogations for important public interest or vital interests may apply

Documentation Required

Proportionality analysis and documentation remain necessary even in emergencies

Articles Intersecting with Article 48

Article 48 does not operate in isolation. A comprehensive compliance assessment requires engagement with numerous intersecting GDPR provisions spanning territorial scope, processing principles, lawful basis, special categories, and accountability.

1

Article 3

Territorial Scope — Determines whether GDPR applies; frequently relevant where foreign authorities seek data from multinational enterprises

2

Article 5

Processing Principles — Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality

3

Article 6

Lawful Basis — Central to all disclosures under Article 48; must be independently identified

4

Articles 9 & 10

Special Category & Criminal Data — Additional restrictions for health, biometric, genetic, and criminal conviction data

5

Articles 12–14

Transparency — Potential obligations to inform affected individuals of disclosures

6

Articles 24 & 25

Accountability & Privacy by Design — System architecture should anticipate foreign disclosure demands; demonstration of compliance required

Further Intersecting GDPR Provisions

Article 28

Processor Obligations — Processors must notify controllers when they receive foreign authority requests for personal data

Article 30

Records of Processing — Documentation obligations require logging of all foreign disclosure decisions and their legal bases

Article 32

Security of Processing — Security controls must surround all disclosure processes to prevent unauthorised access

Article 33

Breach Notification — Incorrect or unlawful disclosures may constitute reportable personal data breaches

Article 35

DPIAs — Data Protection Impact Assessments required for high-risk cross-border transfer scenarios

Article 44

General Transfer Principle — Foundation of Chapter V; all transfers must comply with this overarching requirement

Article 45

Adequacy Decisions — Primary transfer mechanism where the Commission has recognised adequate protection

Article 46

Appropriate Safeguards — Standard Contractual Clauses and related safeguards for transfers without adequacy decisions

Article 47

Binding Corporate Rules — Relevant for multinational groups transferring data within corporate structures

Article 49

Derogations — Limited exceptional transfers for specific circumstances including vital interests and public interest

Enforcement Provisions

Regulatory Powers & Penalties

Non-compliance with Article 48 exposes organisations to significant regulatory enforcement action and substantial financial penalties under the GDPR's tiered sanctions regime.

Article 58 — Supervisory Authority Powers

National data protection authorities hold broad investigative, corrective, and advisory powers to enforce Article 48 compliance, including the power to impose temporary or permanent bans on processing

Article 83 — Administrative Fines

Unlawful disclosures in breach of Article 48 may attract fines of up to €20 million or 4% of global annual turnover, whichever is higher, under the upper tier of GDPR penalties

Article 84 — Additional Penalties

Member States may impose national supplementary sanctions beyond the GDPR's administrative fines regime, including criminal liability in certain jurisdictions

Advanced Legal Challenges

1

Conflict of Laws

Organisations may face directly competing obligations where GDPR prohibits disclosure whilst foreign law simultaneously requires it. Article 48 acts as a conflict-management mechanism, establishing EU law's primacy within the EEA whilst providing a structured pathway for legitimate international cooperation. Organisations must seek specialist legal advice when facing genuine conflicts.

2

U.S. CLOUD Act Tensions

The U.S. Clarifying Lawful Overseas Use of Data (CLOUD) Act can create significant tensions with GDPR. Organisations must evaluate whether any disclosure mechanisms satisfy both Article 48 and Chapter V requirements. Direct compliance with foreign law alone does not eliminate GDPR obligations, and organisations cannot simply defer to U.S. law when processing EU personal data.

3

Discovery and Litigation Risks

U.S. civil discovery processes often seek broad categories of information through wide-ranging production requests. GDPR requires proportionality and necessity assessments for every disclosure. Blanket production requests are particularly problematic and must be challenged or narrowed before any disclosure can be considered lawful under the GDPR framework.

Twenty Cross-Cutting Technical Controls for Article 48 Compliance

Controls 1–10
01

Foreign Authority Request Governance Policy

Formal board-approved policy defining response procedures and governance structure for all foreign authority requests

02

Legal Escalation Workflow

Mandatory legal review before any disclosure, with defined escalation thresholds and approval chains

03

International Agreement Verification Process

Systematic verification of applicable MLATs, bilateral treaties, and sector-specific cooperation agreements

04

Transfer Impact Assessment Framework

Structured evaluation of transfer risks including assessment of the requesting country's legal framework

05

Article 48 Decision Registry

Comprehensive immutable logging of all foreign requests received, assessments conducted, and decisions made

06

Centralised Request Intake Portal

Single controlled channel for receiving and triaging all foreign authority requests to prevent ad hoc responses

07

Role-Based Access Controls

Restrict disclosure authority to specifically approved and trained personnel only

08

Segregated Legal Hold Environment

Controlled review environment for requested datasets, preventing broader access during assessment

09

Data Classification Programme

Systematic identification and labelling of regulated, sensitive, and special category datasets

10

Data Mapping and Lineage Controls

Comprehensive understanding of where requested data resides across all systems and jurisdictions

Twenty Cross-Cutting Technical Controls (Continued)

Controls 11–20
01

Automated Data Minimisation Controls

Technical mechanisms to reduce disclosed data volumes to the minimum necessary for the stated purpose

02

Disclosure Approval Workflow Engine

Multi-stage approval processes requiring sign-off from legal, privacy, and compliance teams before any release

03

Cryptographic Protection Controls

Encryption of personal data during storage and transmission to protect against unauthorised interception

04

Secure Export and Transfer Infrastructure

Controlled export mechanisms ensuring data is transmitted only through approved secure channels

05

Immutable Audit Logging

Tamper-resistant records of all disclosure activities providing a complete and verifiable audit trail

06

Processor Notification Controls

Automated alerts ensuring processors immediately notify controllers upon receipt of any foreign authority request

07

Cross-Border Transfer Validation Engine

Automated verification of applicable transfer mechanisms before any cross-border disclosure is permitted

08

Data Subject Rights Impact Review

Assessment of downstream implications for data subject rights arising from each disclosure decision

09

Regulatory Notification Assessment Process

Structured determination of whether supervisory authority engagement or notification is required

10

Continuous Monitoring and Assurance Programme

Periodic audits, control testing, independent assurance reviews, and lessons-learned processes following each request

Best Practices & Conclusion

Best Practices for Advanced Practitioners

Treat Article 48 as a sovereignty safeguard rather than a transfer mechanism — it is a constitutional protection for EU legal order

Never assume a foreign order is automatically enforceable — always conduct an independent structured assessment

Require independent assessment of both processing legality and transfer legality simultaneously

Maintain documented evidence of all disclosure decisions including the reasoning and legal bases relied upon

Embed Article 48 considerations into cloud governance, investigations management, e-discovery, and incident response

Conduct periodic exercises simulating foreign authority requests to test organisational readiness

Multidisciplinary Review Teams

Privacy Counsel

Lead legal assessment of Article 48 and Chapter V requirements

Data Protection Officers

Oversight of GDPR compliance and supervisory authority engagement

Security Architects

Technical controls and secure disclosure infrastructure

Compliance Teams

Policy governance and documentation management

Litigation Specialists

International litigation and conflict-of-laws expertise

Datari Home