Transfer Impact Assessment Builder
Build and score a transfer impact assessment covering the transfer map, the destination law analysis, supplementary measures and the reasoned conclusion, with the elements that cannot be omitted.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
The question is about the law, not about the vendor
A transfer impact assessment asks whether the law and practice of the destination permit public authority access that would undermine the standard contractual clauses. It does not ask whether the importer is a reputable company with good security, and assessments frequently answer the second question at length while never addressing the first. A trustworthy importer subject to a law compelling disclosure without effective redress is exactly the situation Schrems II was decided about.
Encryption is the measure that actually works
The EDPB recommendations treat encryption with keys held outside the destination as one of the few supplementary measures that can be effective on its own, because it removes the importer from the position of being able to comply with an access request even under legal compulsion. Contractual and organisational measures cannot bind a public authority, which the recommendations say plainly, so an assessment resting on them alone has not found a measure that addresses the problem it identified.
An assessment without a review date expires silently
Foreign law changes, adequacy decisions are annulled, and importers are acquired by companies in different jurisdictions. An assessment dated three years ago describing a legal position that has since moved is worse than none, because it documents a conclusion the organisation is no longer entitled to rely on while giving everyone the impression the question was settled.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What is a transfer impact assessment?
An assessment of whether the law and practice of the destination permit public authority access that would undermine the standard contractual clauses, required by Schrems II before relying on those clauses.
Do I need one if the destination has adequacy?
No. Adequacy removes the requirement, which is why checking adequacy first saves the work. Clauses do not remove it.
Which supplementary measures actually work?
Encryption with keys held outside the destination is treated as capable of being effective on its own. Contractual and organisational measures cannot bind a public authority and supplement technical measures rather than replacing them.
Does remote access count as a transfer?
Yes. Making data accessible from a third country is a transfer even if nothing is copied, and it is the transfer most often left out of scope.
How often should it be reviewed?
On a set date with a named owner, and immediately on any change in the destination law, in the importer’s ownership, or in the adequacy position. An assessment with no review date silently expires.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Tick the elements of the assessment you have completed.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.