Compliance

Transfer Impact Assessment Builder

Build and score a transfer impact assessment covering the transfer map, the destination law analysis, supplementary measures and the reasoned conclusion, with the elements that cannot be omitted.

Last reviewed by the Radiatus Cloud team

Results appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

The question is about the law, not about the vendor

A transfer impact assessment asks whether the law and practice of the destination permit public authority access that would undermine the standard contractual clauses. It does not ask whether the importer is a reputable company with good security, and assessments frequently answer the second question at length while never addressing the first. A trustworthy importer subject to a law compelling disclosure without effective redress is exactly the situation Schrems II was decided about.

Encryption is the measure that actually works

The EDPB recommendations treat encryption with keys held outside the destination as one of the few supplementary measures that can be effective on its own, because it removes the importer from the position of being able to comply with an access request even under legal compulsion. Contractual and organisational measures cannot bind a public authority, which the recommendations say plainly, so an assessment resting on them alone has not found a measure that addresses the problem it identified.

An assessment without a review date expires silently

Foreign law changes, adequacy decisions are annulled, and importers are acquired by companies in different jurisdictions. An assessment dated three years ago describing a legal position that has since moved is worse than none, because it documents a conclusion the organisation is no longer entitled to rely on while giving everyone the impression the question was settled.

Related tools

Frequently Asked Questions

What is a transfer impact assessment?

An assessment of whether the law and practice of the destination permit public authority access that would undermine the standard contractual clauses, required by Schrems II before relying on those clauses.

Do I need one if the destination has adequacy?

No. Adequacy removes the requirement, which is why checking adequacy first saves the work. Clauses do not remove it.

Which supplementary measures actually work?

Encryption with keys held outside the destination is treated as capable of being effective on its own. Contractual and organisational measures cannot bind a public authority and supplement technical measures rather than replacing them.

Does remote access count as a transfer?

Yes. Making data accessible from a third country is a transfer even if nothing is copied, and it is the transfer most often left out of scope.

How often should it be reviewed?

On a set date with a named owner, and immediately on any change in the destination law, in the importer’s ownership, or in the adequacy position. An assessment with no review date silently expires.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Tick the elements of the assessment you have completed.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.