Data Transfer Mechanism Selector
Work out which Chapter V transfer mechanism covers a specific international data transfer, which standard contractual clause module applies, and whether a transfer impact assessment is still required.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Adequacy first, because it removes the rest of the work
If the destination has an adequacy decision, no further safeguard is required and no transfer impact assessment is needed. That is the entire point of adequacy, and checking it first saves an organisation from negotiating clauses it does not need. The list is short and changes, and an adequacy decision can be partial: the EU-US Data Privacy Framework covers only organisations that have self-certified and remain on the list, so a US recipient is adequate or not depending on that recipient rather than on the country.
The module is decided by both ends, not by yours
The 2021 standard contractual clauses have four modules covering controller to controller, controller to processor, processor to processor and processor to controller. Choosing the wrong module is common and consequential, because the obligations differ substantially, and the processor-to-controller module in particular is frequently used where processor to processor was needed. The module follows from the capacity of the exporter and the importer, so both must be settled before the clauses are drafted.
Derogations are for occasional transfers, not for a business model
Article 49 permits transfers on consent, contractual necessity and several other grounds, but the EDPB reads these as exceptions for occasional and non-repetitive transfers. A recurring transfer that forms part of normal operations is not saved by collecting consent, and building a product around that reading is the most common structural error in this area. If the transfer happens every day, the derogation is almost certainly the wrong instrument.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Do I need a transfer impact assessment if I use SCCs?
Yes. Schrems II requires the exporter to verify that the law of the destination does not undermine the clauses, and to add supplementary measures if it does. Adequacy removes that requirement; the clauses do not.
Is the US adequate?
Only for recipients that have self-certified to the EU-US Data Privacy Framework and remain on the list. Adequacy attaches to the recipient rather than to the country, so the answer depends on which organisation is receiving the data.
Which SCC module do I need?
It follows from the capacity of both parties: controller to controller, controller to processor, processor to processor, or processor to controller. The processor-to-controller module is frequently used where processor to processor was needed, and the obligations differ substantially.
Can I rely on consent for regular transfers?
Generally no. The EDPB reads the Article 49 derogations as exceptions for occasional and non-repetitive transfers, so a transfer that forms part of normal daily operations is not saved by collecting consent.
Does remote access from abroad count as a transfer?
Yes. Making data accessible from a third country is a transfer even if nothing is copied, which is why support teams and administrators outside the region are in scope.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Describe the transfer and see which mechanism applies.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.