CHAPTER VTRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS

Article 48Transfers or disclosures not authorised by Union law

Official text

Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.

Commentary

At a glance

SubjectJudgments and decisions of third country authorities requiring transfer or disclosure
RuleRecognised or enforceable only through mutual legal assistance or another international agreement
Not a mechanismArt. 48 does not itself authorise a transfer; a Chapter V basis is still required
DistinctionArt. 48 is not the same as the Art. 49 derogations

Article 48 is a relatively short provision, but it is conceptually important because it sits at the intersection of GDPR international-transfer rules, foreign governmental demands, sovereignty, conflict of laws, and international judicial cooperation.

The central idea is simple:

A foreign government cannot simply point to its own domestic law or obtain a foreign court/administrative order and thereby automatically compel an EU-based organisation to hand over GDPR-protected personal data.

The foreign request must be assessed through the GDPR framework. In particular, a third-country judgment or administrative decision does not automatically become enforceable in the EU merely because it exists.

The EDPB's Article 48 guidance is particularly important here. The EDPB adopted Guidelines 02/2024 on 5 June 2025 in their final version; the earlier December 2024 document was the consultation version. (European Data Protection Board)

What problem is Article 48 actually trying to solve?

Imagine this situation:

Company A, established in France, operates an online platform. It holds personal data of millions of EU users.

A US authority issues an order requiring Company A to disclose:

  • names,

  • email addresses,

  • IP addresses,

  • transaction records,

  • location data, or

  • communications.

The US authority says:

"Our domestic law gives us the power to demand this information."

The question is:

Is the French company automatically required to comply because the US authority has issued a legally valid order under US law?

No.

This is precisely the problem Article 48 addresses.

The GDPR recognises that third countries may have their own laws and legal processes. But the GDPR does not accept the proposition that a foreign government can unilaterally extend its authority into the EU data-protection sphere.

The EDPB describes the objective of Article 48 as clarifying that judgments or decisions of third-country authorities cannot automatically and directly be recognised or enforced in an EU Member State. (European Data Protection Board)

Article 48 is fundamentally about sovereignty

The deeper principle behind Article 48 is legal sovereignty.

Suppose India passes a law saying:

"Every company anywhere in the world that possesses information relating to Indian citizens must disclose it to an Indian authority whenever requested."

That law may have an intended extraterritorial effect, but it does not automatically mean that a French company holding data in France must hand over that data.

Why?

Because the French legal system determines whether and how a foreign judgment or administrative decision can be recognised and enforced in France.

Article 48 therefore acts as a barrier against automatic recognition of foreign governmental demands.

It essentially says:

A third-country authority cannot bypass EU legal mechanisms simply by issuing its own order.

This is particularly significant in the modern cloud economy because personal data may be stored by multinational companies whose infrastructure, employees and corporate entities are spread across several jurisdictions.

The most important distinction: "foreign order" ≠ "GDPR transfer mechanism"

This is probably the single most important point to remember for Article 48.

A foreign authority may issue a perfectly valid order under its own domestic law.

But that does not automatically provide a lawful basis for transferring the data under the GDPR.

There are effectively two separate questions:

Question 1, Is the foreign order legally valid?

For example:

Does US law permit the US authority to demand the information?

Question 2, Can the EU-based organisation lawfully disclose the information under the GDPR?

These are different questions.

A company might have a legal obligation under the foreign country's law and still have to determine whether disclosure is permissible under GDPR requirements.

That is why the EDPB emphasises that responding to a third-country authority's request constitutes a transfer under Chapter V where the GDPR applies, and the organisation must comply with both the GDPR's general requirements and Chapter V. (European Data Protection Board)

Article 48 does NOT itself authorise the transfer

This is another extremely important examination and practical point.

Article 48 is not itself a transfer mechanism.

It establishes the circumstances in which a foreign judgment or administrative decision can be recognised or enforced in the EU.

It does not say:

"If a foreign court orders disclosure, Article 48 permits the transfer."

Instead, the organisation must still identify an appropriate legal framework for the transfer.

Think of it as:

Foreign order → Article 48 analysis → GDPR Article 6 analysis + Chapter V transfer analysis

rather than:

Foreign order → Article 48 → automatic disclosure

The EDPB expressly states that Article 48 itself is not a transfer ground. (European Data Protection Board)

The "two-step" structure

The easiest way to understand Article 48 operationally is to divide the analysis into two levels.

Step 1, Can the foreign decision be recognised/enforced?

You ask:

Is the foreign judgment or administrative decision based on an applicable international agreement between the requesting country and the EU or relevant Member State?

If no, the foreign decision cannot simply be recognised or enforced in the EU by virtue of that decision alone.

If yes, proceed to the next question.

Step 2, Is the actual disclosure lawful under GDPR?

Even if there is an applicable international agreement, the organisation must still determine:

  1. What is the Article 6 legal basis?

  2. Is the disclosure a Chapter V transfer?

  3. What Chapter V transfer mechanism applies?

  4. Are Article 44 requirements satisfied?

  5. Are other GDPR principles satisfied?

  6. Are there special-category data considerations?

  7. Is the disclosure proportionate and limited to what is necessary?

The EDPB's guidance makes this distinction particularly clear: an international agreement may provide both an Article 6 legal basis and an Article 46(2)(a) transfer mechanism, but if it does not, other legal bases or transfer mechanisms may need to be considered. (European Data Protection Board)

What exactly counts as the relevant foreign decision?

Article 48 concerns decisions originating from:

  • a court;

  • a tribunal; or

  • an administrative authority

of a third country.

The important point is that the request must have a governmental/judicial character.

Example 1, Court order

A US court orders an EU-based company to produce customer records. This is squarely within the type of situation Article 48 addresses.

Example 2, Administrative authority

A Canadian financial regulator orders an EU-based bank to disclose transaction information. Again, Article 48 may be engaged.

Example 3, Foreign police request

A foreign police officer sends an informal email: "Please send us the user's account details." This is different. The question becomes whether there is actually abinding decision/order from an authority falling within Article 48.

An informal request should not automatically be treated as equivalent to a judicial or administrative decision.

Article 48 is not limited to criminal investigations

This is a particularly important nuance.

One might initially assume Article 48 is mainly about:

police + criminal investigations + subpoenas.

That is too narrow.

The EDPB explains that Article 48 is not restricted by the purpose for which the data is requested. Requests can arise in contexts including:

  • law enforcement;

  • national security;

  • financial regulation;

  • pharmaceutical regulation;

  • other administrative functions. (European Data Protection Board)

Example

Suppose an EU pharmaceutical company possesses clinical-trial information. A foreign pharmaceutical regulator demands access to personal data contained in those records. This is not a criminal investigation. Nevertheless, Article 48 may still be relevant because the request originates from a third-country administrative authority.

Why "administrative authority" matters

The word administrative considerably expands the practical importance of Article 48.

It is not limited to courts.

Consider:

Scenario A, Foreign tax authority

A US tax authority orders an EU company to disclose employee information. Potential Article 48 issue.

Scenario B, Foreign financial regulator

A regulator demands customer transaction records. Potential Article 48 issue.

Scenario C, Foreign health regulator

A regulator demands identifiable clinical information. Potential Article 48 issue.

Scenario D, Foreign competition authority

A competition authority requires personal information contained in corporate records. Potential Article 48 issue. Therefore, a company's Article 48 procedure cannot sit exclusively within its litigation/legal department. It may need to involve:

  • privacy;
  • compliance;

  • regulatory;

  • litigation;

  • information security;

  • government-relations teams.

What does "transfer or disclose" mean?

The provision deliberately uses both concepts.

Transfer

Think of:

EU company → foreign authority

where personal data is transmitted to the third country.

Disclosure

The concept can be broader and focuses on making personal data available to the requesting authority.

For example:

A German company has a database in Germany.

A US authority demands access to specific customer records.

The relevant question is not merely:

"Are the servers physically moved to America?"

The concern is that personal data is being made available to a third-country authority.

Therefore, physical movement of servers is not the determining concept.

The data-protection analysis concerns the disclosure/access to the personal data.

The importance of "based on an international agreement"

This is the heart of Article 48.

A foreign judgment or administrative decision may be recognised or enforced where it is based on an applicable international agreement.

The classic example is a:

Mutual Legal Assistance Treaty, MLAT

Suppose:

  1. US authorities need evidence held by a French company.

  2. The US and France have an applicable mutual legal assistance framework.

  3. The US authority uses the mechanism established under that framework.

  4. The request reaches the appropriate French authority through the treaty mechanism.

This is fundamentally different from:

US authority → directly sends order to French company → "you must comply because US law says so."

The international agreement creates the bridge between the legal systems.

Why MLATs are important

An MLAT is essentially a state-to-state legal cooperation mechanism.

Instead of allowing Country A's authorities to exercise their powers directly against entities located in Country B, the treaty creates a formal mechanism through which Country B can participate.

This protects:

  • sovereignty;

  • procedural fairness;

  • jurisdictional boundaries;

  • individual rights;

  • data protection.

It also provides a structured mechanism for challenging or limiting requests.

International agreement does not necessarily mean "any treaty"

This is a subtle point.

The mere existence of some international agreement between two countries does not automatically solve the GDPR problem.

The agreement must be relevant to the request and capable of providing the necessary legal framework.

For example:

France and Country X have a general friendship treaty.

That does not mean Country X's regulator can automatically obtain personal data from a French company.

The relevant agreement needs to provide an appropriate mechanism concerning the requested cooperation/data disclosure.

The EDPB guidance specifically contemplates an international agreement that can give the request the necessary legal effect and may provide both a legal basis and a Chapter V transfer mechanism. (European Data Protection Board)

Article 48 and Article 6 GDPR must be separated

Another common mistake is to think:

"The foreign court ordered it, therefore Article 6(1)(c) applies."

Not necessarily.

Article 6 concerns the lawfulness of processing.

Chapter V concerns the international transfer.

Therefore, you should analyse them separately.

Example

A French company receives a valid request through an applicable international agreement. The company may ask:Article 6 question: Do I have a lawful basis for processing/disclosing this information?

Then:

Chapter V question:

Do I have a lawful transfer mechanism for sending/making the information available to the third country?

Both need to be addressed.

The EDPB specifically notes that an international agreement can potentially provide a legal basis under Article 6(1)(c) or 6(1)(e), as well as an appropriate safeguard under Article 46(2)(a). (European Data Protection Board)

The relationship with Article 46(2)(a)

This is one of the trickier aspects.

Article 46(2)(a) recognises:

legally binding and enforceable instruments between public authorities or bodies

as an appropriate safeguard for international transfers.

An international agreement contemplated under Article 48 may therefore potentially also operate as an Article 46(2)(a) mechanism.

Example

Suppose:

  • EU Member State A;
  • Country B have a legally binding agreement dealing with cross-border government cooperation and personal-data safeguards.

That agreement might potentially provide:

  1. the legal framework for cooperation;

  2. the legal obligation necessary for the disclosure;

  3. appropriate safeguards for the transfer.

This is why Articles 46 and 48 need to be read together.

But Article 48 does not magically convert an international agreement into a lawful transfer

This is where practitioners must be careful.

Imagine:

There is an international agreement.

But the agreement does not provide sufficient safeguards for personal data.

You cannot simply say:

"International agreement exists, therefore transfer is lawful."

You still have to examine the Chapter V requirements.

The EDPB's guidance explains that where an international agreement does not provide appropriate safeguards, other transfer grounds may need to be considered, including potentially Article 49 derogations. (European Data Protection Board)

Article 49 becomes relevant in difficult cases

This creates an important fallback analysis.

Suppose:

  • foreign authority makes a request;

  • no applicable international agreement exists;

  • the organisation nevertheless faces a genuine situation requiring disclosure.

Article 48 does not itself authorise disclosure.

The organisation may need to examine whether another Chapter V mechanism applies, potentially including an Article 49 derogation where its strict conditions are satisfied.

But this is not a general escape route.

Article 49 derogations are interpreted narrowly and should not be treated as a routine substitute for a proper international transfer mechanism.

So:

No MLAT ≠ automatic disclosure.

And also:

No MLAT ≠ automatic impossibility in every conceivable situation.

The organisation must examine whether another lawful Chapter V mechanism exists.

Article 48 and "extraterritorial laws"

This is one of the most significant real-world issues.

Third countries increasingly enact laws that claim jurisdiction over companies outside their territory.

For example:

"Any company doing business with customers in Country X must provide information to Country X authorities."

The GDPR does not simply accept that assertion of jurisdiction.

Recital 115 specifically recognises the problem of third-country laws that purport to directly regulate entities under Member State jurisdiction and notes that such extraterritorial application may conflict with international law and the protection guaranteed by the GDPR.

Therefore:

foreign domestic law ≠ automatic EU legal obligation.

Example

cloud provider This is probably the most practical illustration. Imagine:

  • Company X is established in Germany.
  • It uses a cloud provider belonging to a US corporate group.
  • Personal data of EU customers is stored in Germany.
  • A US authority issues a demand to the US parent company for that data. The US parent may say: "We are legally required under US law to provide it." That does not end the analysis. The organisation needs to determine:
  1. Is the entity receiving the request subject to the GDPR?
  2. Is the requested information personal data?
  3. Does disclosure constitute a transfer under Chapter V?
  4. Is there an applicable international agreement?
  5. Does that agreement provide an appropriate legal framework?
  6. Is there an Article 6 legal basis?
  7. Is there an Article 46 mechanism?
  8. Are Article 44 requirements satisfied?
  9. Are there other applicable restrictions? This is precisely why Article 48 becomes important in cloud and multinational group arrangements.

Article 48 and multinational companies

Article 48 becomes especially complicated where the company has:

  • EU subsidiaries;

  • US parent companies;

  • Asian service providers;

  • global IT infrastructure;

  • centralised databases.

The corporate group cannot simply assume:

"Our parent is subject to foreign law, therefore the EU subsidiary must disclose the data."

Corporate structure does not override GDPR.

The EU entity must independently assess its obligations.

A crucial distinction: recognition/enforcement versus voluntary compliance

This is a particularly subtle aspect of Article 48.

The provision speaks about whether a foreign judgment or administrative decision may be recognised or enforced in the EU.

That does not necessarily mean that every foreign request automatically becomes legally irrelevant merely because Article 48 prevents direct enforcement.

There can be situations where an organisation voluntarily considers disclosure under another lawful GDPR mechanism.

That is why the final words:

"without prejudice to other grounds for transfer pursuant to this Chapter"

matter enormously.

Article 48 prevents the foreign decision itself from automatically becoming an EU enforcement instrument.

But it does not necessarily prevent a lawful transfer where another Chapter V mechanism independently permits the transfer.

The EDPB specifically treats Article 48 as interacting with other Chapter V grounds rather than functioning as an absolute prohibition on every disclosure in the absence of a treaty. (European Data Protection Board)

The "without prejudice" clause

This is probably the most easily overlooked phrase in Article 48.

It essentially means:

Article 48 does not destroy the possibility of using another lawful Chapter V transfer mechanism.

Example

A foreign authority asks for information. There is no international agreement. Article 48 means: The foreign decision itself cannot simply be recognised/enforced in the EU.

But the organisation may still need to ask:

Is there another valid Chapter V mechanism?

Potentially, depending on the circumstances:

  • Article 46 safeguards;

  • Article 49 derogation.

The important point is that the foreign order itself is not the transfer mechanism.

Does Article 48 apply only where the foreign order is legally enforceable?

This is a tricky point.

The EDPB's guidance takes a broad approach to the relevant requests and does not make the Article 48 analysis depend simply on whether refusal to comply would produce adverse consequences.

Therefore, a company should not assume:

"They cannot punish me if I don't comply, so Article 48 is irrelevant."

The more important question is:

What is the nature of the foreign decision/request, and how does the GDPR regulate the resulting disclosure?

This is important operationally because organisations should not build their privacy process around assumptions about whether the foreign authority will actually enforce the order.

What about arbitration?

The distinction between public authority decisions andprivate dispute-resolution mechanisms is important.

Article 48 specifically addresses judgments or decisions from:

  • courts;

  • tribunals;

  • administrative authorities.

A private arbitral institution is not automatically equivalent to a third-country governmental authority for Article 48 purposes.

Therefore, if an arbitral tribunal orders production of documents containing personal data, the legal analysis may involve:

  • GDPR Article 6;

  • Article 44;

  • other Chapter V mechanisms;

  • applicable procedural law;

but one should not automatically characterise the arbitral order as an Article 48 governmental decision.

This distinction is particularly important in international commercial arbitration.

Pre-trial requests and Article 48

Another nuance is that not every request occurring during litigation necessarily constitutes the type of judgment or administrative decision contemplated by Article 48.

For example:

A lawyer representing a foreign party sends an evidence request to an EU company.

That is not automatically equivalent to:

A foreign court issues a binding judicial order requiring disclosure.

So organisations need to distinguish between:

informal/private evidence requests

and

binding governmental/judicial decisions.

But even where Article 48 itself is not engaged, GDPR obligations do not disappear.

The disclosure may still constitute processing and potentially an international transfer.

Article 48 does not depend on the subject matter of the request

This is another important operational point.

The provision does not say:

only criminal data requests.

Nor does it say:

only national-security requests.

Nor:

only law-enforcement requests.

It can potentially cover requests involving:

  • banking;

  • tax;

  • securities;

  • healthcare;

  • pharmaceuticals;

  • employment;

  • consumer protection;

  • law enforcement;

  • national security.

The EDPB specifically highlights the breadth of contexts in which third-country authorities may issue requests. (European Data Protection Board)

Example

financial regulator Suppose a German bank has personal data relating to customers. A Singaporean financial regulator issues an administrative decision demanding: "Provide all transaction records relating to customer X." The bank cannot simply conclude: "This is a regulator, so we must comply." Instead:Step 1 Identify the legal nature of the decision. Step 2 Determine whether an applicable international agreement exists. Step 3 Determine whether that agreement provides a lawful cooperation mechanism. Step 4 Identify the Article 6 basis. Step 5 Identify the Chapter V mechanism. Step 6 Assess the scope of data requested. Step 7 Provide only what is lawfully necessary, if disclosure is permitted.

Example

law enforcement Imagine an EU social-media company receives a foreign criminal investigation order requesting:

  • username;
  • IP address;
  • private messages;
  • location history;
  • payment details. These categories have very different privacy implications. Even if the underlying request is lawful, the organisation should not treat: "Provide all information" as automatically meaning that every category can be disclosed. Data minimisation, purpose limitation and other GDPR principles remain relevant. This is one reason Article 48 should never be treated as a mere treaty-checking exercise.

Article 48 and proportionality

A foreign authority might request:

"All customer information for the last ten years."

Even if an international cooperation framework exists, that does not automatically mean the organisation can simply dump its entire database.

The GDPR framework continues to impose substantive obligations.

The organisation should examine:

  • necessity;

  • relevance;

  • scope;

  • categories of data;

  • retention;

  • purpose;

  • security;

  • special-category information;

  • rights of data subjects.

The practical question becomes:

What exactly must be disclosed, to whom, for what purpose, and under what legal authority?

Special-category data creates additional complexity

Suppose a foreign authority requests information revealing:

  • health status;

  • biometric information;

  • political opinions;

  • religious beliefs;

  • sexual orientation;

  • genetic information.

The organisation cannot stop its analysis at Article 48.

It must also consider the GDPR rules governing special categories of personal data.

Therefore:

Article 48 is only one component of the legal analysis.

Article 48 and processors

The provision applies to controllers and processors.

This matters enormously in practice.

Suppose:

EU Company A = controller Cloud Provider B = processor

A foreign government sends the demand to Cloud Provider B.

The processor cannot necessarily say:

"We have received a government order, so we can disclose the data."

The processor must consider:

  • its contractual obligations;

  • GDPR requirements;

  • Chapter V;

  • Article 28 obligations;

  • instructions from the controller;

  • applicable legal requirements.

This is why international-transfer clauses and government-access provisions are increasingly important in processor contracts.

Operational significance for contracts

Article 48 has direct contractual implications.

Organisations should consider contractual provisions dealing with:

Government access requests

For example:

The processor will notify the controller of a government request unless legally prohibited.

Challenge obligations

Where legally permissible:

The processor will challenge unlawful or disproportionate requests.

Minimisation

The processor should disclose only what is legally required and appropriate.

Transparency

The controller should know about government access requests where legally possible.

Legal review

The contract may require the processor to obtain legal advice before disclosure.

These contractual protections do not replace the GDPR, but they help operationalise compliance.

Article 48 and the Schrems II philosophy

Although Article 48 itself is not the Schrems II provision, it fits into the broader philosophy of maintaining EU-level protection when personal data leaves the EU legal environment.

The broader Chapter V principle is:

The level of protection guaranteed by EU law should not simply disappear when the data moves outside the EU.

Article 48 applies that thinking to governmental demands.

The concern is essentially:

A foreign government should not be able to obtain EU personal data simply because its own domestic law says it has jurisdiction.

Article 48 is therefore different from Article 46

A useful distinction:

Article 46Article 48
Provides appropriate safeguards for transfersAddresses foreign judgments/administrative decisions
Focuses on transfer mechanismsFocuses on recognition/enforcement of foreign decisions
Examples include SCCs, BCRsExample: foreign court order
Primarily a transfer frameworkPrimarily a sovereignty/recognition framework
Can directly support transfer where requirements are metDoes not itself authorise transfer

This distinction is extremely important.

Article 48 is also different from Article 49

Article 48

asks:

Can the foreign governmental decision be recognised/enforced?

Article 49

asks:

Is there a specific derogation permitting the transfer despite the absence of an adequacy decision or Article 46 safeguard?

Therefore:

Article 48 ≠ Article 49.

But the two can become relevant in the same factual situation.

The practical decision tree

A privacy team receiving a foreign governmental demand can use something like this:

STEP 1, Identify the requester

Is it:

  • court?

  • tribunal?

  • administrative authority?

  • police?

  • regulator?

  • private party?

  • lawyer?

  • arbitrator?

STEP 2, Identify the legal instrument

Is it:

  • judgment?

  • binding administrative decision?

  • subpoena?

  • warrant?

  • informal request?

  • statutory demand?

  • voluntary request?

STEP 3, Determine whether GDPR applies

Ask:

Is the relevant processing within the material and territorial scope of GDPR?

STEP 4, Determine whether personal data is involved

If yes, identify:

  • categories;

  • subjects;

  • volume;

  • sensitivity.

STEP 5, Determine whether disclosure is a Chapter V transfer

If data is being made available to a third-country recipient, Chapter V needs to be considered.

STEP 6, Check Article 48

Ask:

Is the foreign decision based on an applicable international agreement?

STEP 7, Identify Article 6 basis

Ask:

What makes the disclosure lawful as processing?

STEP 8, Identify Chapter V mechanism

Potentially:

  • adequacy;

  • Article 46 mechanism;

  • Article 49 derogation, where applicable.

STEP 9, Check substantive GDPR requirements

Especially:

  • purpose limitation;

  • data minimisation;

  • security;

  • transparency;

  • special-category rules;

  • accountability.

STEP 10, Decide how to respond

Possible outcomes include:

  • comply;

  • partially comply;

  • seek clarification;

  • challenge the order;

  • route the request through an MLAT mechanism;

  • refuse disclosure;

  • seek advice from the competent authority/counsel.

The biggest misconception: "The foreign law requires disclosure"

This is perhaps the most important practical lesson.

Suppose US law says:

Company X must disclose data.

The company cannot simply write:

"US law requires disclosure, therefore GDPR allows disclosure."

That reasoning is incomplete.

The correct reasoning is:

US law may create an obligation under US law, but the company must independently determine whether disclosure is lawful under EU law, including Article 48 and Chapter V.

This is the central conflict-of-laws issue.

Another misconception: "Article 48 prohibits all foreign requests"

That is also incorrect.

Article 48 does not mean:

"No foreign authority can ever obtain EU personal data."

International judicial cooperation is perfectly possible.

The GDPR recognises this.

The issue is how the request is legally channelled and what safeguards apply.

Therefore:

Article 48 is not anti-cooperation.

It is essentially:

pro-lawful cooperation.

Another misconception: "An MLAT automatically makes disclosure lawful"

Again, not necessarily.

An MLAT can establish the necessary international legal framework, but the organisation must still examine:

  • Article 6;

  • Chapter V;

  • safeguards;

  • scope;

  • necessity;

  • other GDPR obligations.

The EDPB's guidance specifically explains that an international agreement may provide both an Article 6 legal basis and an Article 46(2)(a) transfer ground, but those elements must actually be present. (European Data Protection Board)

The relationship with Article 44

Article 44 is the general gateway provision for international transfers.

The easiest conceptual model is:

Article 44 = overarching principle

Article 45 = adequacy

Article 46 = appropriate safeguards

Article 47 = BCRs

Article 48 = foreign governmental/judicial demands

Article 49 = derogations

Article 48 therefore cannot be read in isolation.

The EDPB expressly says Article 48 must be read together with Article 44 and the other Chapter V provisions. (European Data Protection Board)

The sovereignty problem in one illustration

Consider:

EU: "You cannot transfer this data unless GDPR conditions are satisfied."

Country X: "Our law says you must give us this data."

Company: "Which law governs my conduct?"

Article 48 does not itself resolve every conflict-of-laws question, but it establishes a critical principle:

Country X's governmental decision does not automatically become enforceable in the EU merely because Country X issued it.

There must be an appropriate legal bridge, such as an applicable international agreement, or another independent GDPR-compliant basis for the transfer.

What should companies actually build?

For multinational organisations, Article 48 should translate into a government access request procedure.

A mature procedure should contain:

Centralised intake

All foreign governmental requests should be routed to:

  • legal;

  • privacy;

  • compliance;

  • security, where necessary.

Authentication

Verify:

  • identity of authority;

  • authenticity of order;

  • jurisdiction;

  • scope.

Determine whether it is:

  • court order;

  • administrative decision;

  • informal request;

  • private request.

International agreement assessment

Identify:

  • MLAT;

  • treaty;

  • convention;

  • bilateral agreement;

  • applicable EU framework.

GDPR assessment

Perform:

  • Article 6 analysis;

  • Chapter V analysis;

  • proportionality/minimisation analysis.

Challenge assessment

Determine whether the request can legally be:

  • challenged;

  • narrowed;

  • routed through the appropriate authority.

Documentation

Record:

  • request;

  • legal assessment;

  • decision;

  • data disclosed;

  • recipients;

  • safeguards.

This is an important part of accountability.

Article 48 and data-transfer impact assessments

Where foreign-government access is a realistic possibility, organisations should also consider it during their broader international-transfer risk assessments.

For example, if an organisation stores EU customer data with a provider exposed to a foreign government's compulsory-access regime, the organisation should understand:

  • which entity could receive the demand;

  • what type of data could be demanded;

  • what legal powers exist;

  • whether the demand can be challenged;

  • whether the data can be encrypted;

  • who controls the encryption keys;

  • whether disclosure can occur without EU entity involvement.

Article 48 therefore has implications far beyond responding to an actual subpoena.

Encryption and Article 48

Encryption can be relevant, but it should not be misunderstood.

Suppose a cloud provider stores encrypted EU data but does not possess the decryption keys.

A foreign authority demands the data.

The provider may technically be unable to provide intelligible personal data.

That can materially affect the risk and practical ability to comply.

But encryption is not itself a substitute for the Chapter V analysis.

It is a technical safeguard, not a magic exemption from GDPR.

Data localisation is not the same as GDPR compliance

Another common mistake is:

"The database is physically in Europe, so Article 48 does not matter."

Not necessarily.

If an EU-based organisation discloses data to a third-country authority, the physical location of the server is not the only relevant factor.

The issue is the availability/disclosure of the personal data to the third-country recipient.

Therefore:

EU server ≠ immunity from Article 48 issues.

The key grey area: "other grounds for transfer"

The final phrase of Article 48 is particularly important because it prevents an overly rigid interpretation.

Suppose there is:

  • no applicable international agreement;

  • but another valid Chapter V mechanism is potentially available.

Article 48 does not necessarily mean:

"The data can never leave the EU."

Rather:

"The foreign judgment/decision itself does not automatically authorise or become enforceable merely because it exists."

The transfer must instead stand on its own GDPR-compliant legal footing.

This distinction between:

authority to enforce the foreign order

and

GDPR permission to transfer

is the conceptual key to the entire provision.

A difficult hypothetical

Facts

An Indian regulator issues an order requiring an EU-based company to disclose personal data of Indian customers.

The company is established in Germany.

There is no applicable international agreement covering the particular disclosure.

Analysis

The company should not reason:

"The Indian regulator issued an order, therefore we must disclose."

Instead:

First

Determine whether Article 48 is engaged.

Second

Ask whether the foreign decision is based on an applicable international agreement.

If not, the foreign decision cannot simply be recognised/enforced in Germany through Article 48.

Third

Ask independently:

Is there another GDPR legal basis for processing?

Fourth

Ask:

Is there another Chapter V transfer mechanism?

Potentially an Article 49 derogation may need consideration, depending on the precise circumstances and conditions.

Fifth

Apply all other GDPR requirements.

The outcome therefore depends on the complete legal analysis rather than the mere existence of the foreign order.

What Article 48 ultimately protects

Article 48 protects several things simultaneously.

Foreign authorities cannot automatically exercise their legal powers inside the EU.

Data-subject rights

A person's GDPR rights cannot simply disappear because a foreign authority wants the data.

Controlled international transfers

Personal data must move internationally through recognised GDPR mechanisms.

The provision does not prohibit cooperation; it encourages cooperation through appropriate legal frameworks.

Accountability of organisations

Companies must assess the legal basis and transfer mechanism rather than mechanically obeying foreign demands.

Article 48 in one sentence

If you had to reduce the whole provision to one sentence:

A foreign court or administrative authority cannot automatically compel an EU-based controller or processor to disclose GDPR-protected personal data merely because its domestic law authorises the demand; recognition/enforcement requires an applicable international legal framework, while the actual disclosure must independently satisfy the GDPR's Article 6 and Chapter V requirements.

Article 48, exam-oriented conceptual map

For CIPP/E purposes, remember this sequence:

  1. Foreign governmental demand
  2. Court / tribunal / administrative authority?
  3. Judgment/decision requiring disclosure?

Article 48 potentially engaged

  1. Is it based on an applicable international agreement?YES: examine what the agreement actually provides →NO: foreign order does not automatically become enforceable in EU
  2. Separate Article 6 lawfulness analysis - Separate Chapter V transfer analysis

Article 44 + relevant transfer mechanism

  1. Other GDPR requirements
  2. Comply / narrow / challenge / refuse, depending on the legal analysis

The five traps you should remember

Trap 1

Article 48 is not a transfer mechanism.

Trap 2

A foreign court order is not automatically enforceable in the EU.

Trap 3

A foreign domestic law does not automatically override GDPR.

Trap 4

An international agreement does not automatically eliminate the need for Article 6 and Chapter V analysis.

Trap 5

Article 48 does not mean that every foreign request must be refused.

The correct approach is much more nuanced:

Foreign authority → international legal framework → GDPR legal basis → Chapter V mechanism → substantive GDPR compliance.

That is the architecture of Article 48.

Current-source note: the EDPB's original Guidelines 02/2024 on Article 48 were issued for consultation in December 2024, but the EDPB subsequently published thefinal version on 5 June 2025. For exam or professional work, the final version should be preferred over the consultation draft. (European Data Protection Board) EDPB, Final Guidelines 02/2024 on Article 48 GDPR