CHAPTER VTRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS

Article 45Transfers on the basis of an adequacy decision

Official text

(1)A transfer of personal data to a third country or an international organisation may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.

(2)When assessing the adequacy of the level of protection, the Commission shall, in particular, take account of the following elements:

(a)the rule of law, respect for human rights and fundamental freedoms, relevant legislation, both general and sectoral, including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, as well as the implementation of such legislation, data protection rules, professional rules and security measures, including rules for the onward transfer of personal data to another third country or international organisation which are complied with in that country or international organisation, case-law, as well as effective and enforceable data subject rights and effective administrative and judicial redress for the data subjects whose personal data are being transferred;

(b)the existence and effective functioning of one or more independent supervisory authorities in the third country or to which an international organisation is subject, with responsibility for ensuring and enforcing compliance with the data protection rules, including adequate enforcement powers, for assisting and advising the data subjects in exercising their rights and for cooperation with the supervisory authorities of the Member States; and

(c)the international commitments the third country or international organisation concerned has entered into, or other obligations arising from legally binding conventions or instruments as well as from its participation in multilateral or regional systems, in particular in relation to the protection of personal data.

(3)The Commission, after assessing the adequacy of the level of protection, may decide, by means of implementing act, that a third country, a territory or one or more specified sectors within a third country, or an international organisation ensures an adequate level of protection within the meaning of paragraph 2 of this Article. The implementing act shall provide for a mechanism for a periodic review, at least every four years, which shall take into account all relevant developments in the third country or international organisation. The implementing act shall specify its territorial and sectoral application and, where applicable, identify the supervisory authority or authorities referred to in point (b) of paragraph 2 of this Article. The implementing act shall be adopted in accordance with the examination procedure referred to in Article 93 (2).

(4)The Commission shall, on an ongoing basis, monitor developments in third countries and international organisations that could affect the functioning of decisions adopted pursuant to paragraph 3 of this Article and decisions adopted on the basis of Article 25(6) of Directive 95/46/EC.

(5)The Commission shall, where available information reveals, in particular following the review referred to in paragraph 3 of this Article, that a third country, a territory or one or more specified sectors within a third country, or an international organisation no longer ensures an adequate level of protection within the meaning of paragraph 2 of this Article, to the extent necessary, repeal, amend or suspend the decision referred to in paragraph 3 of this Article by means of implementing acts without retro-active effect. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93 (2). On duly justified imperative grounds of urgency, the Commission shall adopt immediately applicable implementing acts in accordance with the procedure referred to in Article 93 (3).

(6)The Commission shall enter into consultations with the third country or international organisation with a view to remedying the situation giving rise to the decision made pursuant to paragraph 5.

(7)A decision pursuant to paragraph 5 of this Article is without prejudice to transfers of personal data to the third country, a territory or one or more specified sectors within that third country, or the international organisation in question pursuant to Articles 46 to 49.

(8)The Commission shall publish in the Official Journal of the European Union and on its website a list of the third countries, territories and specified sectors within a third country and international organisations for which it has decided that an adequate level of protection is or is no longer ensured.

(9)Decisions adopted by the Commission on the basis of Article 25(6) of Directive 95/46/EC shall remain in force until amended, replaced or repealed by a Commission Decision adopted in accordance with paragraph 3 or 5 of this Article.

Commentary

At a glance

MechanismTransfers on the basis of a Commission adequacy decision
TestEssential equivalence, assessed on laws, government access, rights, remedies and practice
ReviewPeriodic review at least every four years; may be amended, suspended or repealed
EffectNo further authorisation needed for the transfer itself

Article 45 is the first and, in practical terms, the simplest transfer mechanism in Chapter V GDPR. It deals with situations where the European Commission has already examined the data-protection framework of a third country and has concluded that the country provides anadequate level of protection.

The easiest way to understand Article 45 is this:

The EU has already assessed the destination country for you. If the Commission has found that the country provides an adequate level of protection, a controller can generally transfer personal data there without separately putting in place an Article 46 safeguard such as SCCs.

But “adequate” does not mean that the third country must have copied the GDPR word-for-word. Nor does an adequacy decision mean thatevery transfer to every entity in that country is automatically lawful. This distinction is extremely important.

Article 45 is therefore not simply about asking:

“Does Country X have a data-protection law?”

The real question is considerably broader:

Does the legal and institutional system of Country X provide protection for individuals that is essentially equivalent, in substance and effectiveness, to the protection guaranteed within the EU?

That requires looking at legislation, government access, surveillance, judicial remedies, supervisory authorities, enforcement, international commitments, onward transfers, and the practical ability of individuals to enforce their rights.

Where Article 45 fits within Chapter V

Before understanding Article 45 itself, it is useful to understand the architecture of international transfers under the GDPR.

Chapter V essentially creates different routes through which personal data can lawfully leave the EEA.

The principal mechanisms are:

  1. Article 45, Adequacy decision

  2. Article 46, Appropriate safeguards

  3. Article 49, Derogations for specific situations

Article 45 is the most straightforward.

Imagine:

EU company → personal data → Japan

If Japan has an applicable EU adequacy decision, the company does not ordinarily need to create a separate SCC arrangement merely because the data is going to Japan.

By contrast:

EU company → personal data → Country X

If Country X does not have an adequacy decision, the company may need to rely on Article 46, for example through Standard Contractual Clauses, together with the necessary assessment and supplementary measures.

Article 49 is different again. It is designed for specific and exceptional situations, rather than functioning as the ordinary replacement for adequacy or Article 46 safeguards.

So, conceptually:

Adequacy → Commission has already recognised protection

Article 46 → exporter/importer must establish appropriate safeguards

Article 49 → exceptional transfer situation applies

This makes Article 45 particularly attractive operationally.

The central idea: “adequate” does not mean “identical”

This is probably the single most important concept in Article 45.

A common mistake is to think:

“For Country X to be adequate, it must have a GDPR equivalent.”

That is not the test.

The adequacy assessment does not require the third country to reproduce the GDPR article-by-article.

The source material correctly emphasises the idea that the objective is not to mirror European legislation point by point, but to establish the essential/core requirements of European protection.

Therefore, Country X can have:

  • different legislation;

  • different institutional structures;

  • different terminology;

  • different enforcement mechanisms;

  • different regulatory architecture;

and still potentially be adequate.

Example

Suppose the GDPR provides:

  • right of access;
  • right to rectification;
  • right to erasure;
  • purpose limitation;

  • security obligations;

  • independent supervision.

Country X may use completely different statutory provisions and terminology.

That alone does not make Country X inadequate.

The Commission asks a more functional question:

Do these different mechanisms, taken as a whole, provide essentially equivalent protection?

This is why the adequacy test is often described as an “essential equivalence” standard rather than an “identical legislation” standard.

What does “essentially equivalent” actually mean?

The expression became particularly important through the CJEU's international-transfer jurisprudence, especially Schrems I andSchrems II.

“Essentially equivalent” does not mean:

“Exactly the same.”

But it also does not mean:

“Roughly similar.”

There must be a meaningful level of protection for fundamental rights.

The assessment is therefore substantive and practical.

Suppose Country X has an excellent private-sector data-protection statute.

But suppose its national-security legislation allows intelligence agencies to obtain enormous amounts of foreign individuals' data without meaningful limits or remedies.

The Commission cannot simply say:

“The private-sector data law looks good, therefore the country is adequate.”

The broader legal environment matters.

This is one of the most important lessons from Schrems II.

Adequacy is about the entire protection environment

The adequacy assessment is not confined to a country's general data-protection legislation.

Article 45(2)(a) requires consideration of a wide range of factors.

These include:

  • rule of law;

  • human rights;

  • fundamental freedoms;

  • general legislation;

  • sectoral legislation;

  • public security;

  • defence;

  • national security;

  • criminal law;

  • government access to personal data;

  • implementation of legislation;

  • data-protection rules;

  • professional rules;

  • security measures;

  • onward-transfer rules;

  • case law;

  • enforceable data-subject rights;

  • administrative remedies;

  • judicial remedies.

That is an extraordinarily broad assessment.

It means that adequacy is ultimately an ecosystem assessment.

Why national-security law matters so much

This is one of the trickiest aspects of Article 45.

Imagine Country X has a very strong GDPR-style privacy statute.

However, another statute gives the intelligence authorities broad access to data held by telecommunications providers.

Now imagine that:

  • the surveillance power is extremely broad;

  • there are limited conditions;

  • independent oversight is weak;

  • individuals cannot effectively challenge the surveillance;

  • there is no meaningful judicial remedy.

The question becomes:

Can the private-sector privacy law genuinely protect EU individuals if another part of the legal system permits extensive government access?

This is precisely why Article 45 expressly refers to:

  • public security;

  • defence;

  • national security;

  • criminal law;

  • access of public authorities to personal data.

The Commission therefore cannot assess the country's privacy law in isolation.

Practical lesson

When conducting an adequacy assessment, government access is not a side issue.

It is one of the central issues.

The four essential guarantees for government access

The material you provided refers to four essential guarantees developed in European jurisprudence and reflected in the adequacy assessment.

These are particularly useful for understanding surveillance issues.

Clear, precise and accessible rules

Government access to personal data should not be based upon vague or unlimited legal authority.

The individual should be able to understand:

  • who can access data;

  • under what circumstances;

  • for what purpose;

  • subject to what limitations;

  • using what legal authority.

Example

A law stating: “The intelligence authorities may obtain any information considered useful for national security.” would raise serious concerns if there were no further safeguards. By contrast, a framework specifying:

  • defined purposes;

  • defined categories of data;

  • defined authorities;

  • procedural requirements;

  • judicial or independent oversight;

is more capable of satisfying the requirement.

Necessity and proportionality

The existence of a legitimate government objective is not enough.

A government may legitimately pursue:

  • national security;

  • prevention of terrorism;

  • serious crime;

  • public safety.

But the means used must satisfy requirements of necessity and proportionality.

Suppose the objective is preventing a particular terrorist threat.

That does not automatically justify unrestricted access to everyone's communications.

The question becomes:

Is the interference with privacy and data-protection rights necessary and proportionate to achieving the legitimate objective?

This distinction is fundamental.

Example

Targeted surveillance of a person reasonably suspected of involvement in terrorism is conceptually different from indiscriminate collection of communications relating to millions of individuals. The adequacy analysis therefore examines not merelywhy government access occurs, but alsohow extensively it occurs.

Independent oversight

Government surveillance should not effectively operate without supervision.

There should be an independent mechanism capable of examining whether authorities are complying with the law.

That may involve:

  • courts;

  • independent commissioners;

  • supervisory bodies;

  • parliamentary mechanisms;

  • specialised oversight institutions.

The critical question is whether the oversight is genuinely independent and effective.

An organisation technically called an “independent oversight body” is not necessarily sufficient.

Its:

  • powers;

  • funding;

  • institutional independence;

  • access to information;

  • ability to investigate;

  • ability to issue binding decisions;

matter.

Effective remedies

This is another major issue.

Suppose an intelligence authority unlawfully obtains the personal data of an EU resident.

What can the individual do?

Can the individual:

  • complain?

  • obtain information?

  • challenge the processing?

  • obtain judicial review?

  • obtain compensation?

  • obtain an effective remedy?

If the answer is effectively “nothing”, this creates a serious adequacy problem.

A right that exists only on paper is not necessarily an effective and enforceable right.

This distinction between formal rights andeffective rights runs throughout Article 45.

Article 45(2)(a): Rule of law

The first broad criterion is the rule of law.

This is much wider than simply asking whether Country X has statutes.

A country could theoretically have hundreds of privacy laws but still have deficiencies in:

  • judicial independence;

  • enforcement;

  • access to justice;

  • institutional accountability;

  • respect for fundamental rights.

Therefore, the Commission examines the legal system more broadly.

Illustration

Country A has:

  • excellent privacy legislation;
  • independent courts;
  • independent regulator;
  • effective remedies.

Country B has similar written privacy legislation but:

  • courts cannot effectively review government action;

  • regulators lack independence;

  • citizens cannot meaningfully challenge unlawful processing.

Country A would generally present a much stronger adequacy case.

Data-protection rules themselves

The Commission also examines the country's substantive data-protection framework.

The source material identifies several core concepts.

These include:

Lawfulness and fairness

There must be identifiable grounds for lawful processing.

Purpose limitation

Data collected for one purpose should not simply be repurposed without appropriate justification.

Data quality and proportionality

Data processing should not be excessive in relation to the legitimate purpose.

Retention

There should be appropriate limits or controls concerning how long personal data can be retained.

Security and confidentiality

The framework should protect personal data against unauthorised access, disclosure, alteration or destruction.

Transparency

Individuals should have meaningful information concerning the processing of their data.

These principles need not necessarily appear using the exact GDPR terminology.

What matters is whether the system provides comparable protection in substance.

Data-subject rights

An adequate system must provide meaningful rights to individuals.

The source material identifies rights such as:

  • access;

  • rectification;

  • erasure;

  • objection.

But the important word is effective.

Imagine Country X says:

“Individuals have a right to access their data.”

But the procedure:

  • is practically inaccessible;

  • takes several years;

  • is subject to arbitrary refusal;

  • provides no appeal.

The existence of the right on paper does not necessarily establish adequacy.

Article 45 therefore concerns enforceable rights, not merely legislative declarations.

Administrative and judicial redress

This is closely connected but should be distinguished from substantive rights.

There are two separate questions:

Question 1:

Does the individual have a right?

Question 2:

Can the individual actually enforce that right?

For adequacy, both matter.

For example:

A person has a right to object to unlawful processing.

But if the regulator cannot investigate complaints and courts cannot grant effective remedies, the protection is incomplete.

This is why Article 45 specifically mentions:

  • administrative redress; and

  • judicial redress.

Compensation matters

Effective redress can also include compensation where appropriate.

Suppose a company unlawfully processes someone's personal data and causes damage.

An adequate framework should provide a realistic mechanism for the individual to seek relief.

This demonstrates an important principle:

Data protection is not merely about regulatory compliance; it is also about enforceable individual rights.

Article 45(2)(b): Independent supervisory authorities

The second major criterion concerns the existence and functioning of an independent supervisory authority.

This is essentially the equivalent of asking:

“Who is policing the privacy framework in Country X?”

The authority should have:

  • independence;

  • investigative powers;

  • enforcement powers;

  • advisory functions;

  • ability to assist data subjects;

  • ability to cooperate with EU supervisory authorities.

Why independence matters

Imagine Country X establishes a “Data Protection Authority”.

But:

  • the Minister can dismiss its head at will;

  • the government controls its budget;

  • it cannot investigate public authorities;

  • it cannot issue meaningful sanctions.

Technically, an authority exists.

Practically, however, it may not provide independent supervision.

That distinction is critical.

Therefore:

Existence ≠ effective functioning.

This is a recurring theme of Article 45.

Enforcement powers

A regulator should have enough power to make data-protection law meaningful.

Depending on the system, this may include powers to:

  • investigate;

  • access information;

  • conduct audits;

  • order corrective measures;

  • issue administrative penalties;

  • advise controllers and processors;

  • assist individuals.

A regulator that can only issue non-binding recommendations may not provide the same level of protection as an authority with genuine enforcement authority.

Cooperation with EU supervisory authorities

Article 45 also considers whether the third-country authority can cooperate with EU supervisory authorities.

This becomes important because international data protection is inherently cross-border.

Suppose:

French company → personal data → Country X processor

If there is a complaint involving the processor, effective cooperation between the French supervisory authority and Country X's authority can become extremely important.

Without cooperation, enforcement can become fragmented.

Article 45(2)(c): International commitments

The third category concerns international obligations.

The Commission looks at:

  • international treaties;

  • legally binding conventions;

  • multilateral systems;

  • regional systems;

  • commitments concerning personal-data protection.

The reason is straightforward.

A country's domestic law is only part of its legal environment.

Its international commitments can reinforce, or potentially complicate, its data-protection obligations.

Why international commitments matter

Imagine Country X has strong domestic privacy law but has entered into an international agreement requiring extensive information sharing with another state.

The Commission may need to examine:

  • what information can be shared;

  • for what purposes;

  • what safeguards apply;

  • whether onward transfers are controlled;

  • what rights individuals have.

Again, adequacy is an overall-system assessment.

Onward transfers, a particularly tricky issue

One of the most important and frequently overlooked parts of Article 45 is onward transfer.

Imagine:

EU company → Country A

Country A has an adequacy decision.

But then:

Country A company → Country B

What happens?

The adequacy of Country A does not automatically make the second transfer lawful.

This is because Article 45 expressly considers rules concerning onward transfers.

Example

An EU company sends customer data to a Japanese service provider. Japan has an adequacy decision. The Japanese provider then sends the data to a subcontractor in another country. The analysis must consider the legal framework governing that onward transfer.

The mere statement:

“Japan is adequate”

does not mean:

“Every subsequent destination is automatically adequate.”

This is a major operational point.

Sectoral and territorial adequacy

Another important nuance is that adequacy does not necessarily have to apply to an entire country.

Article 45 permits adequacy for:

  • an entire third country;

  • a territory;

  • one or more specified sectors.

This creates a very important compliance distinction.

Suppose the Commission finds:

Country X is adequate only for certain commercial organisations.

Then a transfer to:

  • a covered commercial organisation

may fall within the decision.

But a transfer to:

  • a government body;

  • an excluded sector;

  • an entity outside the scope of the decision;

may not.

Therefore:

Never ask merely:

“Is Country X adequate?”

Ask:

“Is this particular transfer covered by the scope of the adequacy decision?”

The US example illustrates this perfectly

The US is a particularly useful example because adequacy has historically been linked to specific frameworks and participation conditions rather than being a blanket statement that every US entity enjoys GDPR-equivalent protection.

The relevant question is therefore not simply:

“Are we transferring data to the United States?”

Instead:

“What legal mechanism covers this particular US transfer, and does the recipient fall within its scope?”

This is precisely why transfer mapping matters.

“No specific authorisation”, what does it actually mean?

Article 45 says that a transfer based on an adequacy decision does not require a specific authorisation.

This is often misunderstood.

It does not mean:

“Once adequacy exists, forget the GDPR.”

It means that the controller does not need to separately obtain a transfer authorisation merely because it is transferring personal data to that adequate destination.

The rest of the GDPR continues to apply.

For example, the controller still needs to consider:

  • lawful basis;

  • transparency;

  • purpose limitation;

  • data minimisation;

  • security;

  • accountability;

  • data-subject rights;

  • processor requirements;

  • retention.

So:

Adequacy removes the Chapter V obstacle associated with an unapproved international destination.

It does not remove ordinary GDPR compliance.

Article 44 and Article 45 must be read together

This is extremely important for understanding the structure.

Article 44 establishes the overarching principle:

International transfers must not undermine GDPR protection.

Article 45 then provides one mechanism for achieving that protection:

The Commission has assessed the destination as adequate.

Therefore, an adequacy decision does not exist in isolation from Article 44.

The overall logic is:

Article 44 → protection must not be undermined

Article 45 → Commission has determined that destination provides adequate protection

Result → transfer can occur without an Article 46 safeguard

Does adequacy mean the destination is “safe”?

Not necessarily in the everyday sense of the word.

Adequacy is a legal determination, not a guarantee that:

  • no breach will occur;

  • no cyberattack will happen;

  • no employee will misuse data;

  • no government investigation will occur;

  • every company in that country will comply.

The decision means that the legal framework and safeguards applicable to the relevant destination are considered adequate for the purposes of Chapter V.

Individual controllers still have their own obligations.

Article 45 and Schrems I

The importance of adequacy cannot be understood without the Schrems litigation.

In Schrems I, the CJEU invalidated the EU-US Safe Harbor arrangement.

One of the central concerns was whether US law provided protection essentially equivalent to EU protection.

This established a critical principle:

The Commission cannot simply declare a country adequate without the underlying legal framework genuinely providing sufficient protection.

An adequacy decision is therefore not immune from judicial scrutiny.

Schrems II, the deeper lesson

Schrems II (C-311/18) is even more important for international-transfer analysis.

The case concerned transfers of Facebook users' data from Ireland to the United States.

The CJEU examined issues including:

  • US surveillance law;

  • government access;

  • effective remedies;

  • SCCs;

  • fundamental rights.

The Court invalidated the EU-US Privacy Shield.

But importantly, it upheld the validity of SCCs in principle.

This created a crucial distinction:

A transfer mechanism may be valid in abstracto while a particular transfer may nevertheless have to be suspended because the destination country's law prevents the required protection from being achieved.

Why Schrems II matters to Article 45

Schrems II reinforces the principle that international transfers must be assessed against the actual legal environment of the destination.

The fact that a company has contractual protections is not necessarily enough where government law can override those protections.

Suppose:

EU exporter → US importer

The contract says:

“Importer shall not disclose the data except as required by law.”

Now suppose US law legally requires the importer to provide the data to an intelligence authority.

The private contract cannot simply bind the government.

This is why the assessment must consider public-authority access.

The key distinction: private law vs public law

This is one of the most important conceptual lessons.

A transfer can be governed by:

Private arrangements

such as:

  • contracts;

  • SCCs;

  • processor agreements.

But the importer remains subject to:

Public law

such as:

  • surveillance legislation;

  • national-security legislation;

  • criminal law;

  • government-access powers.

A contract cannot magically eliminate a mandatory statutory obligation.

Therefore, adequacy requires examination of both layers.

Article 45 and “essential equivalence” after Schrems II

The CJEU's reasoning essentially makes the following proposition important:

The level of protection must remain essentially equivalent to that guaranteed within the EU, considering the legal order of the destination country.

That includes:

  1. substantive rights;

  2. government-access rules;

  3. limitations on government power;

  4. oversight;

  5. remedies.

This makes adequacy much more than a comparison of privacy statutes.

Article 45(3): How an adequacy decision is created

The Commission does not simply publish a casual statement saying:

“Country X looks okay.”

There is a formal decision-making process.

The Commission assesses the country and may adopt an implementing act establishing adequacy.

The decision must identify relevant scope.

It must also include a mechanism for periodic review.

Why periodic review matters

Adequacy is not necessarily permanent.

The legal environment of a country can change.

For example:

  • a new surveillance statute may be introduced;

  • the constitutional court may change its interpretation;

  • the regulator may lose independence;

  • a new government-access mechanism may emerge;

  • international agreements may change;

  • remedies may become ineffective.

Therefore, the Commission must continue monitoring the destination.

The GDPR specifies that the review mechanism must operate at least every four years.

But importantly, this does not mean:

“The Commission only looks at the country once every four years.”

Article 45(4) establishes ongoing monitoring.

Four-year review vs continuous monitoring

This is an excellent exam trap.

Article 45(3)

Requires a mechanism for periodic review at least every four years.

Article 45(4)

Requires the Commission to monitor developments on an ongoing basis.

Therefore:

Four-year review ≠ only monitoring every four years.

The Commission can respond to significant developments before the next scheduled review.

What can trigger concern?

Information indicating that adequacy may no longer be justified can come from different sources.

For example:

  • legislative changes;

  • court judgments;

  • regulatory developments;

  • surveillance revelations;

  • enforcement failures;

  • political developments affecting institutional independence;

  • international commitments;

  • reports from relevant bodies.

The basic idea is:

Adequacy must remain connected to reality.

A country cannot continue indefinitely to rely on an adequacy decision if the underlying conditions have materially deteriorated.

Article 45(5): Repeal, amendment or suspension

If the Commission determines that adequate protection is no longer ensured, it may:

Repeal

The decision is withdrawn.

Amend

The decision is modified.

Suspend

The operation of the decision is temporarily stopped.

These are different responses.

The Commission must act to the extent necessary.

This means the response should correspond to the problem.

Why “without retroactive effect” matters

This is a subtle but important point.

Suppose Country X loses adequacy on 1 January.

The Commission's withdrawal does not automatically transform every transfer made during the previous five years into an unlawful transfer.

The decision operates prospectively.

This provides legal certainty.

However, this does not mean that all historical processing was necessarily lawful in every respect. Other GDPR obligations could still have been violated.

The key point is that the withdrawal itself does not retroactively invalidate transfers merely because adequacy subsequently ceased.

Urgency mechanism

Article 45(5) also recognises that circumstances can sometimes require immediate action.

Suppose there is a sudden and serious legal development in Country X creating an immediate threat to the protection of transferred data.

The Commission can use an urgent procedure for an immediately applicable implementing act.

This reflects the practical reality that waiting for an ordinary procedural timetable may sometimes undermine data-subject protection.

Article 45(6): Consultation with the third country

The Commission is not required simply to withdraw adequacy and walk away.

Article 45(6) provides for consultation with the third country or international organisation.

The objective is to remedy the situation.

This is important because adequacy is not designed as a punitive mechanism.

The broader objective is:

restore an adequate level of protection.

Therefore, dialogue between the EU and the third country is built into the system.

Article 45(7): Loss of adequacy does not necessarily mean “all transfers stop”

This is one of the most important operational consequences.

Suppose Country X loses its adequacy decision.

Does that mean:

“No personal data can ever be transferred to Country X”?

No.

Article 45(7) preserves the possibility of using other transfer mechanisms under Articles 46, 49, subject to their requirements.

For example:

  1. Adequacy disappears
  2. Controller examines Article 46
  3. SCCs may potentially be used
  4. But the controller must satisfy the applicable requirements

This distinction is critical.

Why the loss of adequacy is operationally significant

Although alternative mechanisms may exist, losing adequacy can create significant compliance work.

Imagine a multinational company has:

  • 100 EU entities;

  • 300 processors;

  • 20,000 data subjects;

  • hundreds of data flows into Country X.

While adequacy exists, many transfers can rely on that decision.

If adequacy disappears, the company may need to:

  • map affected transfers;

  • identify exporters and importers;

  • determine appropriate Article 46 mechanisms;

  • execute SCCs where required;

  • conduct transfer assessments;

  • assess government-access risks;

  • implement supplementary measures;

  • update privacy notices;

  • update contracts;

  • reassess vendors;

  • document decisions.

Thus, Article 45 has enormous practical significance for compliance teams.

Adequacy and vendor management

Suppose an EU company is selecting a cloud service provider.

The provider says:

“Our servers are located in Country X.”

The company should not stop its analysis at:

“Country X is adequate.”

It should ask:

  • Is the specific service provider covered?

  • Is the relevant sector covered?

  • Does the adequacy decision apply to the relevant processing?

  • Are there onward transfers?

  • Are subprocessors located elsewhere?

  • What happens to backups?

  • Where is support access performed?

  • Can remote administrators access EU personal data?

  • Does the service provider use another jurisdiction for technical support?

This is where Article 45 moves from legal theory to operational compliance.

Cloud computing example

Consider:

German company → US cloud provider

Suppose the provider is covered by the relevant adequacy framework.

At first glance, the transfer may be covered.

But now suppose:

US cloud provider → Indian support team

That is an onward transfer.

The company must consider whether that subsequent transfer is itself appropriately covered.

Similarly:

US cloud provider → Singapore backup infrastructure

Again, a further international data flow may exist.

Therefore, a vendor's statement:

“We are US-based and covered by the adequacy framework”

may be insufficient for a complete transfer analysis.

You must understand the data-flow chain.

Adequacy does not eliminate data mapping

Another common mistake is:

“If a country is adequate, I don't need transfer mapping.”

Incorrect.

Transfer mapping remains important because the organisation must know:

  • where data goes;

  • who receives it;

  • why it is transferred;

  • whether the destination falls within adequacy;

  • whether onward transfers occur.

Adequacy simplifies the legal transfer mechanism, but it does not eliminate accountability.

Adequacy and processors

Article 45 applies to transfers involving controllers and processors.

Suppose:

EU controller → processor in adequate country

The transfer can potentially rely on Article 45.

But the controller still needs to comply with Article 28 requirements where applicable.

Thus:

Adequacy ≠ processor compliance exemption.

The processor agreement remains relevant.

Adequacy does not replace Article 6

This is an important conceptual distinction.

Article 45 answers:

Can the personal data legally leave the EEA under Chapter V?

Article 6 asks:

What is the lawful basis for processing the personal data?

These are different questions.

For example:

A company may have a valid Article 45 transfer route but still have no lawful basis under Article 6 for the underlying processing.

Therefore:

Lawful processing + lawful international transfer

are separate requirements.

Adequacy does not replace transparency obligations

Suppose an EU company transfers employee data to an adequate country.

It may still need to inform employees about:

  • processing;

  • recipients;

  • purposes;

  • relevant transfer information where applicable.

The existence of adequacy does not eliminate the transparency architecture of the GDPR.

Adequacy and Article 5

Article 45 does not override Article 5.

The organisation must continue to respect principles such as:

  • lawfulness, fairness and transparency;

  • purpose limitation;

  • data minimisation;

  • accuracy;

  • storage limitation;

  • integrity and confidentiality;

  • accountability.

This is why Article 44's language, requiring compliance with the GDPR generally, is so important.

Adequacy is a destination-level determination

This is another useful conceptual formulation.

An adequacy decision primarily tells you something about the destination legal environment.

It does not say:

“This particular company is trustworthy.”

For example, a country may have an adequate framework, but an individual company could still:

  • violate privacy laws;

  • suffer a security breach;

  • misuse data;

  • breach its contractual obligations.

The controller therefore still needs vendor due diligence.

Adequacy does not guarantee cybersecurity

Adequacy includes consideration of security measures, but it is not a cyber-risk certification.

An organisation should not interpret:

“Country X is adequate”

as:

“Every organisation in Country X has adequate cybersecurity.”

Those are completely different propositions.

A company still needs appropriate technical and organisational measures under the GDPR.

Adequacy and international organisations

Article 45 is not limited to countries.

An adequacy decision can concern an international organisation.

This is important because international organisations can operate across jurisdictions and process substantial amounts of personal data.

The Commission can assess:

  • the organisation's legal framework;

  • institutional safeguards;

  • supervisory mechanisms;

  • individual rights;

  • international obligations;

  • remedies.

Why “adequacy” can apply to a territory or sector

The ability to make sectoral decisions reflects the fact that privacy protection may differ significantly within a country.

For example, a country might provide strong protections for:

  • commercial organisations;

but have a separate and less protective framework for:

  • public authorities.

A sector-specific adequacy decision allows the EU to recognise protection only where the relevant conditions are satisfied.

This is why compliance professionals should always check the scope of the decision, not merely its title.

The adequacy decision is a Commission-level determination

An individual company cannot declare:

“We have assessed Country X ourselves and believe it is adequate.”

That is not how Article 45 works.

The legal mechanism of Article 45 adequacy depends upon a Commission decision.

An organisation may conduct its own risk assessment, but that does not turn Country X into an Article 45 adequate country.

This distinction is particularly important in compliance documentation.

Can a company create its own “adequacy assessment”?

It can certainly assess the destination country for other compliance purposes.

For example, a company may perform:

  • transfer risk assessment;

  • vendor due diligence;

  • legal assessment;

  • security assessment.

But it cannot substitute its own assessment for a formal Commission adequacy decision where Article 45 is being relied upon.

That is a crucial distinction between:

Article 45 adequacy

and

Article 46 transfer safeguards.

Article 45 vs Article 46, practical distinction

Consider two situations.

Situation A

The European Commission has recognised Country X as adequate.

The organisation may rely on Article 45, assuming the transfer falls within the scope of that decision.

Situation B

Country Y has no adequacy decision.

The organisation wants to transfer data there.

It may need an Article 46 mechanism, such as SCCs.

Therefore:

Article 45 = destination has already been recognised

Article 46 = organisation uses a prescribed safeguard mechanism

This is why adequacy is often operationally easier.

But Article 45 is not necessarily “better” in every sense

Adequacy is administratively convenient because the exporter does not have to construct the transfer mechanism itself.

But organisations have less control over the mechanism because it depends on the Commission's assessment.

If adequacy changes, thousands of transfers can suddenly require reassessment.

Article 46 arrangements can therefore sometimes provide more direct contractual control, although they also carry greater compliance responsibilities.

The dynamic nature of adequacy

Adequacy should be understood as dynamic, not static.

The legal landscape can change.

For example:

Year 1:

Country X → adequate.

Year 3:

Country X introduces expansive surveillance legislation.

Year 3.5:

Commission investigates.

Year 4:

adequacy decision is amended/suspended/repealed.

The organisation's transfer compliance strategy therefore cannot simply be:

“We checked this five years ago.”

The current status of the decision matters.

Operational checklist for an organisation

When relying on Article 45, a privacy team should ask:

Step 1, Identify the destination

Where exactly is the recipient located?

Step 2, Check whether an adequacy decision exists

Is there a current Commission adequacy decision?

Step 3, Check scope

Does it apply to:

  • the country?

  • territory?

  • sector?

  • category of recipient?

Step 4, Identify the recipient

Is the specific recipient covered?

Step 5, Check onward transfers

Will the recipient disclose the data further?

Step 6, Check ordinary GDPR compliance

Does the underlying processing comply with:

  • Article 5?

  • Article 6/9?

  • transparency?

  • security?

  • data-subject rights?

Step 7, Document reliance

Record why Article 45 applies.

Step 8, Monitor developments

Especially for material vendor or regulatory changes.

This is how Article 45 becomes an actual compliance process.

A complete practical example

Imagine a French company, EuroTech, collects customer information.

The data includes:

  • names;

  • email addresses;

  • billing information;

  • account history.

EuroTech uses a service provider in a country covered by an applicable adequacy decision.

Step 1

EuroTech establishes that the provider is located within the scope of the adequacy decision.

Step 2

The transfer does not require a separate Article 46 safeguard merely because the data is going outside the EEA.

Step 3

EuroTech still needs a lawful basis for processing.

Step 4

EuroTech still needs appropriate transparency.

Step 5

EuroTech must ensure appropriate security.

Step 6

The processor arrangement must comply with Article 28 where applicable.

Step 7

EuroTech checks whether the provider uses subprocessors in other countries.

Suppose it discovers:

Provider → Subprocessor in Country Y

Now EuroTech must separately consider that onward transfer.

This example demonstrates the central principle:

Adequacy simplifies one layer of the compliance analysis; it does not eliminate the rest.

A difficult grey area: remote access

Suppose the personal data remains physically stored in Germany.

However, employees of a service provider in an adequate third country can remotely access the data.

Does physical storage in Germany automatically mean there is no international transfer?

Not necessarily.

The transfer analysis focuses on whether personal data is made available to an entity in a third country, not merely where the physical server sits.

Therefore, privacy teams must examine:

  • who can access the data;

  • from where;

  • under whose authority;

  • whether the accessing entity is a separate controller or processor.

This is why data-flow mapping should include remote access, not just server location.

Another grey area: corporate groups

Suppose:

EU parent company → subsidiary in Country X

The fact that both entities belong to the same corporate group does not automatically eliminate transfer considerations.

Separate entities can be separate controllers or processors.

Therefore, intra-group transfers may still constitute international transfers.

This is an important point for multinational organisations.

Another grey area: direct collection by a foreign entity

The source material also highlights an important distinction.

Imagine a US company directly collects information from an individual in the EU through its own website.

That situation can involve Article 3(2) GDPR because the company may be offering services to individuals in the EU or monitoring their behaviour.

But the specific Chapter V transfer regime is not necessarily triggered merely because the foreign company directly collects the data.

This distinction is subtle:

Scenario A

EU controller sends data to US processor. → Chapter V transfer analysis is engaged.

Scenario B

US company directly collects data from an EU individual. → GDPR may apply under Article 3(2), but that does not automatically mean an Article 45/46 transfer has occurred. If that US company subsequently sends the data to another third-country recipient, Chapter V may become relevant to that onward transmission. This is an excellent exam issue.

Article 45 does not make Article 3 irrelevant

The interaction between Articles 3 and Chapter V can be confusing.

Article 3 determines whether the GDPR applies to a processing activity.

Chapter V determines whether a relevant international transfer is subject to transfer-specific requirements.

Therefore:

GDPR territorial scope ≠ international transfer mechanism.

A company can be subject to GDPR under Article 3 without every processing operation necessarily constituting a Chapter V transfer.

Adequacy and public authorities

Another difficult point is whether adequacy covers government recipients.

The answer depends on the scope and substance of the relevant adequacy decision.

You cannot automatically assume that:

“Country X is adequate for commercial transfers”

means:

“Country X's intelligence services are covered.”

The adequacy decision must be examined carefully.

This is particularly important where personal data may enter government-controlled environments.

Why case law is part of the adequacy assessment

Article 45(2)(a) expressly considers case law.

This is important because legislation alone may not tell the whole story.

Suppose Country X has excellent privacy legislation.

But its highest court repeatedly interprets the law in a manner that permits disproportionate government surveillance.

The Commission must take those judicial developments into account.

Thus:

==Law on paper + law as interpreted and enforced = actual legal environment.==

Enforcement in practice

The adequacy assessment is concerned with whether protection works in practice.

This means asking:

  • Are complaints investigated?

  • Are unlawful processors sanctioned?

  • Do regulators have sufficient resources?

  • Do courts grant meaningful relief?

  • Do individuals actually exercise their rights?

  • Are government agencies subject to meaningful constraints?

This is why a sophisticated adequacy analysis goes beyond legislation.

“Effective” is the recurring keyword

Notice how frequently Article 45 uses concepts such as:

  • effective functioning;

  • effective rights;

  • effective redress;

  • effective supervision.

This is deliberate.

A theoretical legal entitlement is insufficient.

The GDPR's philosophy is essentially:

Rights must work in reality.

That is one of the most important principles to remember for the CIPP/E.

Adequacy and fundamental rights

The adequacy framework is ultimately connected to the EU Charter.

The relevant rights include, among others:

  • privacy;

  • protection of personal data;

  • effective judicial protection.

Therefore, adequacy is not simply a commercial trade facilitation mechanism.

It is also a fundamental-rights protection mechanism.

This explains why government surveillance can be decisive in adequacy assessments.

Why adequacy promotes international trade

There is also a commercial dimension.

Modern businesses routinely need to move data internationally.

If every transfer required individual regulatory approval, international commerce would become extremely difficult.

Adequacy creates a form of legal certainty:

The EU has already assessed the destination's legal environment.

This allows ordinary commercial transfers to take place more efficiently.

Thus, Article 45 tries to balance two objectives:

Free flow of data

and

Protection of individuals.

The “three-tier” structure, with an important qualification

The source describes Chapter V as having a structure involving:

  1. adequacy;

  2. appropriate safeguards;

  3. derogations.

That is useful conceptually.

However, do not interpret this as meaning:

“If there is no adequacy, simply use Article 49.”

Article 49 is not intended to become the routine substitute for Article 45.

Its derogations are specific and subject to their own conditions.

For exam purposes, remember:

Adequacy is the preferred straightforward route where available; Article 46 provides safeguards where adequacy is unavailable; Article 49 addresses specific exceptional situations.

A very important misconception: adequacy is not based only on GDPR-style legislation

Suppose Country X does not have a comprehensive GDPR equivalent.

That does not automatically mean it cannot be adequate.

The assessment is holistic.

The Commission may consider:

  • legislation;

  • sectoral rules;

  • judicial decisions;

  • regulator;

  • remedies;

  • government access;

  • international commitments;

  • practical enforcement.

Therefore, the correct exam answer is not:

“The third country must have legislation identical to the GDPR.”

The correct concept is:

The third country must provide a level of protection essentially equivalent to that guaranteed within the EU, assessed holistically and in practice.

Article 45 and accountability

Even where Article 45 is available, an organisation should be able to explain:

“Why are we permitted to make this transfer?”

The answer should be:

“Because the transfer falls within the scope of an applicable Commission adequacy decision.”

Not merely:

“The vendor told us the country is safe.”

That is weak accountability.

A mature privacy programme should maintain:

  • transfer inventories;

  • vendor records;

  • adequacy decision references;

  • scope assessments;

  • subprocessor information;

  • review dates.

What happens when adequacy is withdrawn?

Consider:

Monday: Country X is adequate.

Tuesday: Commission suspends adequacy.

The privacy team cannot simply continue relying on Article 45.

It needs to determine whether another lawful transfer mechanism can be used.

For example:

Article 46 SCCs

may potentially become relevant.

But the organisation cannot assume that signing SCCs automatically resolves the problem.

The Schrems II logic means the destination's legal environment still matters.

The deeper Schrems II lesson for operational compliance

Suppose adequacy disappears and an organisation switches to SCCs.

The organisation might say:

“We have signed the SCCs, therefore the transfer is lawful.”

That is too simplistic.

The organisation may need to assess:

  • government access;

  • surveillance powers;

  • enforceability;

  • effective remedies;

  • supplementary measures;

  • practical ability of the importer to comply with the SCCs.

Therefore:

Transfer mechanism ≠ automatic legality.

The mechanism must actually be capable of protecting the data.

What makes Article 45 different from SCCs?

Consider the burden allocation.

Article 45

The Commission has already undertaken the systemic assessment.

Article 46

The exporter and importer must establish appropriate safeguards and ensure that the required level of protection can be maintained.

Therefore, Article 45 shifts much of the country-level assessment to the Commission.

That is the primary reason adequacy is operationally attractive.

What should a CIPP/E candidate remember?

For examination purposes, Article 45 can be reduced to a conceptual chain:

  1. ADEQUACY Commission decision
  2. Third country / territory / specified sector / international organisation
  3. Essentially equivalent protection
  4. No specific transfer authorisation
  5. Ongoing monitoring
  6. Periodic review at least every four years

If protection deteriorates:

repeal / amend / suspend

Potentially:

Articles 46, 49 remain available, subject to their conditions

That is the skeleton.

The detailed analysis sits underneath it.

The biggest Article 45 traps

Trap 1

“Adequate” means identical to GDPR.

Wrong.

It means essentially equivalent, not identical.

Trap 2

Adequacy means the company has no GDPR obligations.

Wrong.

Ordinary GDPR obligations continue.

Trap 3

Adequacy applies automatically to every entity in the country.

Wrong.

The scope of the decision must be examined.

Trap 4

Adequacy means onward transfers are automatically permitted.

Wrong.

Onward transfers require their own analysis.

Trap 5

Four-year review means the Commission only monitors every four years.

Wrong.

There is ongoing monitoring plus periodic review.

Trap 6

If adequacy is withdrawn, all transfers immediately become impossible.

Wrong.

Articles 46, 49 may provide alternative routes.

Trap 7

SCCs always solve government-access problems.

Wrong.

Schrems II makes the actual legal environment relevant.

Trap 8

A data-protection authority merely needs to exist.

Wrong.

It must be independent and effective.

Trap 9

Having rights on paper is sufficient.

Wrong.

Rights must be effective and enforceable.

Trap 10

A country having a privacy statute automatically makes it adequate.

Wrong.

Adequacy is a holistic assessment.

The Article 45 mental model

A very effective way of remembering the entire provision is to think of Article 45 as answering five questions.

Question 1, Who decides?

European Commission.

Not the individual controller.

Question 2, What is being assessed?

The overall level of protection in:

  • a country;

  • territory;

  • specified sector;

  • international organisation.

Question 3, What is being examined?

At minimum:

Law + rights + government access + regulator + remedies + international commitments + onward transfers.

Question 4, What happens if adequacy exists?

The transfer can occur without a specific transfer authorisation and without needing to rely on Article 46 merely because it is an international transfer.

Question 5, What happens if adequacy fails?

The Commission can:

repeal / amend / suspend

and the organisation may need to move to another Chapter V mechanism.

The most important conceptual distinction: country risk vs transfer mechanism

This is perhaps the most sophisticated way of understanding Article 45.

There are two different levels of analysis.

Level 1, Systemic country assessment

Is the destination's legal system adequate?

That is principally what Article 45 addresses.

Level 2, Individual transfer compliance

Is this particular processing activity lawful and appropriately secured?

That involves the rest of the GDPR and, where relevant, other Chapter V mechanisms.

Therefore:

Article 45 solves the destination-level transfer question; it does not solve every question concerning the processing activity.

Final synthesis

Article 45 is essentially the GDPR's institutional shortcut for international transfers.

Instead of requiring every individual controller to independently recreate a complete assessment of a foreign legal system, the European Commission conducts that assessment at the systemic level.

It asks whether the third country provides protection that is essentially equivalent to EU protection.

That assessment is deliberately broad.

It does not stop with:

“Does Country X have a privacy law?”

It asks:

  • Does the rule of law function?

  • Are fundamental rights respected?

  • Are data-protection rules meaningful?

  • Are government-access powers sufficiently constrained?

  • Are surveillance measures necessary and proportionate?

  • Is there independent oversight?

  • Are supervisory authorities genuinely independent?

  • Do individuals have enforceable rights?

  • Can they obtain administrative and judicial remedies?

  • Are there meaningful rules on onward transfers?

  • Does the country comply with relevant international obligations?

  • Does the framework work in practice?

If the answer is sufficiently positive, the Commission can issue an adequacy decision.

The practical benefit is significant:

The exporter does not need a separate Article 46 safeguard merely because the data is being transferred to that adequate destination.

But that convenience has to be understood correctly.

Adequacy does not mean:

  • the recipient is automatically trustworthy;

  • every organisation in the country is compliant;

  • every sector is necessarily covered;

  • onward transfers are automatically permitted;

  • ordinary GDPR obligations disappear;

  • security obligations disappear;

  • lawful-basis requirements disappear;

  • data-subject rights disappear.

It simply means that the destination-level Chapter V protection requirement has been addressed through a Commission adequacy decision, provided that the particular transfer falls within its scope.

And because the legal environment of a country can change, adequacy is not frozen forever. The Commission must monitor developments continuously, provide for periodic review at least every four years, and can suspend, amend or repeal an adequacy decision when the necessary level of protection is no longer maintained.

The most important lesson from Schrems I and Schrems II is that the phrase “essentially equivalent” has real legal substance. International data-transfer mechanisms cannot be treated as formal paperwork exercises if the legal system of the destination country allows disproportionate government access, lacks independent oversight, or fails to provide effective remedies.

So, if you have to explain Article 45 in one sentence for a CIPP/E exam or an interview, the strongest formulation is:

Article 45 permits international transfers without a separate transfer authorisation where the European Commission has determined that the destination provides a level of protection essentially equivalent to that guaranteed in the EU, assessed holistically by reference to the country's laws, fundamental rights, government access, supervisory authorities, individual rights, remedies, international commitments and practical effectiveness.

And if you have to remember its operational logic, remember:

Commission assessment → adequacy decision → covered destination → transfer without Article 46 safeguard → ongoing monitoring → possible withdrawal → alternative Chapter V mechanism if necessary.

That is the core of Article 45.