At a glance
| Mechanism | Transfers subject to appropriate safeguards |
| Tools | SCCs, BCRs, codes of conduct, certification, legally binding instruments, ad hoc clauses |
| Duty | Transfer impact assessment and supplementary measures where third country law defeats the safeguards |
| Limit | Contracts cannot bind foreign public authorities |
Article 46 is one of the most practically important provisions in Chapter V of the GDPR. If Article 45 asks, “Has the European Commission already determined that this country provides adequate protection?”, Article 46 answers the next question:
“If there is no adequacy decision, how can the organisation still lawfully transfer personal data outside the EEA while preserving GDPR-level protection?”
The answer is: through appropriate safeguards, enforceable rights for data subjects, and effective legal remedies.
This is why Article 46 is particularly important for organisations using cloud providers, multinational groups, outsourcing arrangements, HR platforms, SaaS applications, customer-support providers, analytics providers, vendors and other service providers located outside the EEA.
A crucial point, however, is that Article 46 should not be understood as simply saying:
“Sign an SCC and the transfer is legal.”
That understanding is incomplete, particularly after Schrems II. The legal mechanism is more sophisticated. The organisation must consider the transfer instrument, the law and practice of the destination country, possible government access, the ability of the importer to comply with its contractual obligations, supplementary measures where necessary, and the availability of effective rights and remedies.
The best way to understand Article 46 is therefore to break it into its underlying architecture.