DenmarkDatatilsynet
Datatilsynet: TIA required before SCC/BCR transfers, not for adequacy ones
Datatilsynet: adequacy-country transfers need no further exporter measures, while Article 46 SCC/BCR transfers require a prior TIA, aided by the CNIL guide and EDPS checklist.
By Taxxa AI OyPublished 3 October 2026
Datatilsynet's guidance page on Tredjelandsoverførsler now draws a sharp line between the two main routes for sending personal data outside the EU/EEADatatilsynet. Where the destination is a so-called secure third country or an international organisation covered by an adequacy decision, the transfer can proceed without any further approval or additional measures on the data exporter's side.
Datatilsynet
The position is different where the transfer rests on one of the tools in Article 46 of the databeskyttelsesforordningen — for example EU-Kommissionens standardbestemmelser (SCC) or bindende virksomhedsregler (BCR). In that case the data exporter must, before the transfer takes place, carry out a so-called transfer impact assessment (TIA)Datatilsynet and assess whether a level of protection for the transferred data that in essence corresponds to the level within the Union can actually be secured in practice
Datatilsynet.
The distinction follows the structure of the Regulation's Chapter V. Every transfer to a third country must satisfy the Chapter's conditions so that the level of protection guaranteed by the Regulation is not undermined, and Article 46 permits transfers only with appropriate safeguards plus enforceable data subject rights and effective legal remedies. The Court of Justice confirmed in Schrems II that SCCs alone, being purely contractual, cannot bind a third country's public authorities: the exporter must examine, case by case and together with the recipient where relevant, both the agreed clauses and the destination country's legal system — including public-authority access to the data — add supplementary safeguards where the local position requires it, and suspend or end the transfer where adequate protection cannot be ensured.
To help exporters produce the assessment, Datatilsynet points to two aids. The French supervisory authority CNIL has prepared a practical TIA guide available in English, together with a TIA template on its website, and the European Data Protection Supervisor (EDPS) has drawn up a checklist of the elements a TIA must contain. Although the EDPS checklist is addressed to EU institutions, Datatilsynet notes it is also highly useful for data exporters subject to the Regulation.
The clarification matters for any business using a non-EEA provider to operate IT systems or handle customer service, and for authorities transferring tax, health or similar data to a third-country authority under an agreement — the examples the page itself gives. Those relying on an adequacy decision gain confirmation that no TIA exercise is expected of themDatatilsynet, while those relying on SCCs or BCRs are told the prior assessment is mandatory, not optional
Datatilsynet.
Legal basis: GDPR Chapter V, Articles 44–46 of Regulation (EU) 2016/679, as interpreted by the Court of Justice in Schrems II (C-311/18).
If you transfer personal data outside the EU/EEA under SCCs or BCRs, carry out a transfer impact assessment before the transfer, using the CNIL TIA guide and the EDPS checklist as aids.
Sources
- Tredjelandsoverførsler
- REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance)
- 62018CJ0311