CHAPTER VTRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS

Article 49Derogations for specific situations

Official text

(1)In the absence of an adequacy decision pursuant to Article 45 (3), or of appropriate safeguards pursuant to Article 46, including binding corporate rules, a transfer or a set of transfers of personal data to a third country or an international organisation shall take place only on one of the following conditions:

(a)the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for the data subject due to the absence of an adequacy decision and appropriate safeguards;

(b)the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject’s request;

(c)the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another natural or legal person;

(d)the transfer is necessary for important reasons of public interest;

(e)the transfer is necessary for the establishment, exercise or defence of legal claims;

(f)the transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent;

(g)the transfer is made from a register which according to Union or Member State law is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest, but only to the extent that the conditions laid down by Union or Member State law for consultation are fulfilled in the particular case.

Where a transfer could not be based on a provision in Article 45 or 46, including the provisions on binding corporate rules, and none of the derogations for a specific situation referred to in the first subparagraph of this paragraph is applicable, a transfer to a third country or an international organisation may take place only if the transfer is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject, and the controller has assessed all the circumstances surrounding the data transfer and has on the basis of that assessment provided suitable safeguards with regard to the protection of personal data. The controller shall inform the supervisory authority of the transfer. The controller shall, in addition to providing the information referred to in Articles 13 and 14, inform the data subject of the transfer and on the compelling legitimate interests pursued.

(2)A transfer pursuant to point (g) of the first subparagraph of paragraph 1 shall not involve the entirety of the personal data or entire categories of the personal data contained in the register. Where the register is intended for consultation by persons having a legitimate interest, the transfer shall be made only at the request of those persons or if they are to be the recipients.

(3)Points (a),

(b)and (c) of the first subparagraph of paragraph 1 and the second subparagraph thereof shall not apply to activities carried out by public authorities in the exercise of their public powers.

(4)The public interest referred to in point (d) of the first subparagraph of paragraph 1 shall be recognised in Union law or in the law of the Member State to which the controller is subject.

(5)In the absence of an adequacy decision, Union or Member State law may, for important reasons of public interest, expressly set limits to the transfer of specific categories of personal data to a third country or an international organisation. Member States shall notify such provisions to the Commission.

(6)The controller or processor shall document the assessment as well as the suitable safeguards referred to in the second subparagraph of paragraph 1 of this Article in the records referred to in Article 30.

Commentary

At a glance

MechanismDerogations for specific situations, the exceptional route
GroundsExplicit consent, contract, important public interest, legal claims, vital interests, public registers, compelling legitimate interests
CharacterOccasional, non repetitive and limited in scope
OrderConsider Art. 45 and Art. 46 first

Article 49 is the derogation provision for international transfers. It deals with situations where a transfer of personal data to a third country or international organisation cannot rely on the normal transfer mechanisms under Articles 45 or 46.

The most important point to understand at the outset is that Article 49 is an exception, not an alternative general mechanism for routine international transfers. The EDPB's approach is essentially hierarchical: adequacy under Article 45 comes first; appropriate safeguards under Article 46 come next; and only where those mechanisms are unavailable should Article 49 derogations be considered.

This is important because Article 49 can otherwise look deceptively broad. Almost every international transfer could potentially be described as being connected with a contract, litigation, public interest, consent, or a legitimate interest. The GDPR does not intend that. The derogations are to be interpreted restrictively, and the controller must be able to demonstrate why the particular derogation genuinely applies.

The place of Article 49 within Chapter V

To understand Article 49 properly, it has to be read together with Articles 44, 45, 46 and 48.

The structure is essentially:

Article 44 → general rule

Every transfer outside the EEA must satisfy the Chapter V requirements and must not undermine the level of protection guaranteed by the GDPR.

Article 45 → adequacy

If the European Commission has determined that a third country provides an adequate level of protection, transfers can generally take place on that basis.

Article 46 → appropriate safeguards

If there is no adequacy decision, a controller may generally rely on mechanisms such as SCCs, BCRs, approved certification mechanisms or approved codes of conduct, subject to their respective requirements.

Article 49 → derogations

If neither Article 45 nor Article 46 provides a transfer mechanism, certain narrowly defined exceptional situations may permit the transfer.

So, conceptually:

Article 49 is the third layer, not the first choice.

For example, suppose a German company routinely sends its European employees' HR data to its US parent company every month.

It should not normally say:

"There is no adequacy decision, but the transfer is necessary for our business, so we will rely on Article 49."

The first question should be whether an Article 46 mechanism, such as SCCs or BCRs, is available.

If the transfer is regular and structural, Article 49 is particularly difficult to justify.

This is one of the most important operational implications of Article 49.

Article 49 is a closed list of derogations

The Article 49(1)(a), (g) situations constitute a limited set of derogations.

The controller cannot simply invent another reason because it believes the transfer is commercially sensible.

For example:

"The recipient is a reputable company."

Not enough.

"The recipient has excellent cybersecurity."

Not enough.

"The transfer is commercially important."

Not enough.

"The transfer would be administratively convenient."

Not enough.

The controller has to fit the transfer into one of the recognised Article 49 situations.

There is, however, a residual mechanism based on compelling legitimate interests in the second subparagraph of Article 49(1). That provision is deliberately surrounded by additional conditions and is intended for genuinely residual cases.

Therefore, Article 49 should be understood as:

specific derogations + strict conditions + necessity + restrictive interpretation.

One of the easiest mistakes in Article 49 analysis is confusing:

  1. the legal basis for processing, and

  2. the transfer mechanism.

They are different questions.

Suppose an Indian company processes data relating to an EU individual and needs to send some information to another country.

The organisation must ask:

Question 1, Is the processing itself lawful?

This involves the normal GDPR rules, including Article 6 and, where applicable, Article 9.

Question 2, Is the international transfer lawful?

This involves Chapter V.

Article 49 answers the second question.

Therefore, relying on Article 49 does not automatically make the underlying processing lawful.

For example, consent under Article 49(1)(a) is a transfer derogation. It does not eliminate the need to examine whether the processing itself has an appropriate legal basis and complies with the other GDPR requirements.

This distinction becomes particularly important in compliance documentation.

A transfer assessment should not simply say:

"Legal basis: Article 49."

That is conceptually incomplete.

The organisation should separately identify the applicable legal basis for processing and the Chapter V transfer mechanism/derogation.

Article 49(1)(a): Explicit consent

The first derogation is based on explicit consent from the data subject.

But this is not ordinary consent.

Article 49 imposes an additional informational requirement: the person must be informed of the possible risks of the transfer arising from the absence of an adequacy decision and appropriate safeguards.

This makes Article 49 consent materially more demanding than simply obtaining a generic privacy-policy consent.

Example

Imagine an EU-based patient wants to use a medical consultation service operated by a provider in a third country. The provider wants to transfer medical information to that country. Suppose there is no adequacy decision and no appropriate safeguard mechanism available for the particular transfer. The organisation might consider Article 49(1)(a).

It would need to obtain explicit consent specifically covering the proposed transfer, and the individual must understand the relevant risks resulting from the absence of the usual safeguards.

Simply putting this sentence into a long privacy policy:

"By using our services, you consent to international data transfers."

may not be sufficient.

The person needs meaningful information about the transfer and the particular consequences/risk environment.

There are two separate ideas here:

Consent must be explicit

The controller needs an affirmative expression of consent. Silence, inactivity or merely continuing to use a service is problematic.

Consent must be informed about the transfer risk

The person must understand that the destination country does not benefit from an adequacy decision or the relevant Article 46 safeguards.

This is important because Article 49 consent is effectively being used in circumstances where the normal structural protection mechanism is absent.

The person therefore needs to understand what they are agreeing to.

The practical weakness of consent under Article 49

Consent may appear attractive because it is relatively easy to obtain.

But that can be misleading.

If an organisation has thousands of recurring transfers to a third country, asking individuals repeatedly to consent does not transform a structural transfer arrangement into an Article 49-compliant exceptional transfer.

For example:

A European SaaS provider transfers every customer's data to its non-adequate third-country cloud infrastructure every day.

The company cannot realistically say:

"All customers consented, therefore Article 49 solves our transfer problem."

The regular and systemic nature of the transfer raises serious concerns about whether Article 49 is being used as an exception to replace a proper Article 46 mechanism.

This is why the EDPB has emphasised the exceptional nature of Article 49 derogations.

Article 49(1)(b): Necessary for a contract with the data subject

The second derogation concerns transfers that are necessary for the performance of a contract with the data subject, or for pre-contractual measures taken at the individual's request.

Three concepts matter:

  1. there must be a contract or relevant pre-contractual activity;

  2. the transfer must actually be necessary;

  3. the pre-contractual activity must have been taken at the data subject's request.

The word necessary does substantial work here.

What does "necessary" mean?

Necessity does not mean:

"The transfer is useful."

It means something closer to:

Without the transfer, the particular contractual activity could not properly be performed.

Consider a European customer booking a hotel located in Japan.

The hotel may need to send reservation information to its Japanese operations team to perform the booking.

There is a strong connection between the transfer and the contract.

By contrast, suppose the hotel sends all European customer data to a third-country marketing company because it finds that arrangement commercially convenient.

That is not necessarily required to perform the customer's hotel contract.

The distinction is:

Contractually necessary → potentially Article 49(b)

Commercially useful → generally insufficient

Necessity versus convenience

This distinction is extremely important in practice.

Imagine:

A French company sells products to customers in Europe. It uses an Indian analytics provider to analyse customer behaviour.

The company argues:

"The analytics are necessary for our business and therefore necessary for the customer's contract."

That does not automatically work.

The question is whether the particular international transfer is necessary to perform the particular contract with the data subject.

If the organisation could perform the contractual obligation without transferring the data to India, the necessity argument becomes much weaker.

Article 49 is not intended to allow organisations to convert every business activity connected with a contract into a contractual transfer derogation.

Pre-contractual measures

The provision also covers certain pre-contractual measures.

But there is an additional requirement:

They must be taken at the data subject's request.

For example:

A person in France asks a US financial institution for a specific quotation for a financial product. The institution needs certain information from the individual to prepare the requested quotation.

There may be a stronger argument that the transfer is connected with a pre-contractual measure requested by the individual.

But imagine the institution independently transfers the person's information to its overseas affiliate for general market research before the individual has requested anything.

That is very different.

The individual's request must have a genuine connection with the pre-contractual activity.

Occasional versus regular transfers under Article 49(b)

This is one of the most important nuances.

Article 49 derogations are generally understood as exceptional. Recital 111 reinforces the idea that contractual derogations concern transfers that are occasional and necessary.

Suppose a European company has a business relationship with a US service provider and transfers customer data to the US every week for three years.

Calling every weekly transfer "necessary for the performance of the contract" is unlikely to reflect the intended exceptional character of Article 49.

The better approach for a structural relationship is generally to establish an appropriate Article 46 safeguard where possible.

An occasional transfer arising from a specific contractual situation is much easier to reconcile with Article 49.

Article 49(1)(c): Contract concluded in the interest of the data subject

This provision is subtly different from Article 49(1)(b).

Under Article 49(b):

Data subject ↔ controller

The transfer is necessary for the contract between them.

Under Article 49(c):

Controller ↔ another person/entity

The contract is concluded in the interest of the data subject.

For example, imagine an EU resident purchases an insurance product from an EU insurer. The insurer has a contract with a medical provider located in a third country, and transferring specific information is necessary to perform that contract for the individual's benefit.

The contractual relationship involving the transfer is not necessarily directly between the data subject and the recipient.

The crucial point is that the contract must genuinely be in the interest of the data subject.

Again, necessity matters.

Article 49(b) versus 49(c)

A simple way to understand the distinction:

Article 49(b)

"I am transferring your data because I need to perform our contract with you."

Article 49(c)

"I am transferring your data because I need to perform a contract with another party that was concluded for your benefit."

The two provisions should not be casually merged.

Example

international travel Consider an EU resident booking an international tour. The EU travel company may have a contract with a local hotel, airline, transport operator or medical assistance provider in the destination country. Some transfers may be necessary to arrange the services for the traveller. Article 49(c) could potentially become relevant where the contractual relationship with the foreign provider is genuinely concluded in the traveller's interest. But the company cannot automatically use Article 49(c) for every transfer to every overseas supplier. The specific transfer must satisfy the necessity requirement and fit the particular contractual arrangement.

Article 49(1)(d): Important reasons of public interest

This is one of the most misunderstood derogations.

The phrase "important reasons of public interest" cannot simply mean:

"This transfer is beneficial to society."

Article 49(4) is crucial: the relevant public interest must be recognised in Union law or the law of the Member State to which the controller is subject.

Therefore, the public interest needs a legal foundation.

Recital 112 gives examples such as:

  • international exchange between competition authorities;

  • tax authorities;

  • customs authorities;

  • financial supervisory authorities;

  • social-security authorities;

  • public-health cooperation;

  • certain public-health emergencies;

  • anti-doping activities.

The provision therefore recognises that international cooperation can sometimes require data transfers even where adequacy or Article 46 safeguards are unavailable.

Public interest is not the same as "government request"

A common mistake is:

"A government authority requested the data, therefore Article 49(d) applies."

Not necessarily.

The mere fact that the recipient is a public authority does not itself establish an important public interest under Article 49(d).

The relevant public interest must be recognised in applicable EU or Member State law.

For example:

A foreign regulator requests information from a European private company.

The company cannot automatically invoke Article 49(d) merely because the foreign regulator claims that the information is needed for regulatory purposes.

The organisation must examine the legal basis for the public interest and the requirements of Chapter V.

Why Recital 112 matters

Recital 112 demonstrates that Article 49(d) is intended to accommodate legitimate international cooperation.

Consider financial regulation.

Suppose an EU financial institution is involved in a regulatory investigation involving a foreign jurisdiction.

International cooperation between financial regulators may serve a recognised public interest.

The GDPR does not intend to make legitimate international regulatory cooperation impossible.

But that does not mean that every foreign regulatory request automatically qualifies.

The public interest must be sufficiently grounded in the relevant EU or Member State legal framework.

Article 49(1)(e): Legal claims

This is one of the most practically significant derogations.

It covers transfers necessary for:

  • establishment of legal claims;

  • exercise of legal claims;

  • defence of legal claims.

The concept is broader than only litigation already pending before a court.

It can potentially encompass judicial, administrative and certain other legally grounded proceedings.

The key word again is:

necessary

And there needs to be a meaningful connection between the transfer and the particular legal claim.

Example

defending litigation abroad Suppose a German company is sued in a US court. The company has relevant documents containing personal data in Germany. The US proceedings require the company to produce particular information. The company may examine Article 49(1)(e). But the correct analysis is not simply: "There is a lawsuit, therefore Article 49 applies." Instead:

  1. Is there a specific legal proceeding?
  2. What information is required?
  3. Is transferring this particular information necessary for establishing, exercising or defending the claim?
  4. Can the objective be achieved without transferring the personal data?
  5. Is only the necessary information being disclosed? The last question is particularly important under the GDPR's minimisation principle.

Article 49(e) and pre-trial discovery

Cross-border litigation creates difficult issues because some jurisdictions have broad discovery mechanisms.

Suppose a US litigant requests:

"All emails of every employee who worked on this project for the last five years."

The existence of litigation does not automatically justify transferring the entire dataset.

The European organisation still has to examine necessity and proportionality.

A narrower disclosure might be required.

For example:

  • relevant employees only;

  • relevant period only;

  • relevant documents only;

  • relevant personal data only.

This is where Article 5 GDPR principles continue to operate alongside Chapter V.

Article 49 does not create a GDPR-free zone for litigation.

Article 48 and Article 49(e): an important relationship

This is a particularly tricky area.

Suppose a US court orders an EU company to disclose personal data.

Article 48 says that a third-country judgment or administrative decision should not simply be recognised or enforced in the EU unless it is based on an applicable international agreement, such as a mutual legal assistance treaty.

But Article 48 also preserves other transfer grounds under Chapter V.

This means Article 48 and Article 49 should be analysed together.

A foreign court order does not automatically become a GDPR-authorised transfer mechanism.

The organisation must determine whether there is an applicable international agreement and, separately, whether a Chapter V transfer ground exists.

Article 49(e) may potentially be relevant where the transfer is genuinely necessary for the establishment, exercise or defence of a legal claim.

But the mere existence of a foreign court order should not be treated as automatically satisfying Article 49.

This is another important boundary.

Suppose a company says:

"We might be sued in the United States someday, so we will regularly copy all European customer data to our US server."

That is very different from transferring specific data because an actual legal proceeding requires it.

Article 49(e) is designed around specific legal necessity, not speculative future litigation.

The more remote the claim, the weaker the derogation.

Article 49(1)(f): Vital interests

This derogation concerns situations where the transfer is necessary to protect the vital interests of the data subject or another person and the data subject is physically or legally incapable of giving consent.

The classic example is an emergency.

Imagine an EU tourist suffers a serious accident abroad.

The person is unconscious.

Doctors need relevant medical information from a European hospital.

There may be no time to establish an Article 46 mechanism.

If the necessary conditions are satisfied, the vital-interest derogation may permit the transfer.

The incapacity requirement is important

The derogation is not simply:

"The person's life is important."

There is an additional requirement concerning the person's inability to give consent.

Suppose a person is fully conscious and capable of giving consent.

The organisation should not simply invoke Article 49(f) because the matter concerns health or safety.

The consent-based derogation may need to be considered instead, assuming its requirements can be satisfied.

The source commentary identifies different forms of incapacity.

Examples could includePhysical incapacity A person is unconscious following an accident. Mental incapacity The person is temporarily or otherwise unable to make the relevant decision.

Legal incapacity

The person lacks legal capacity to provide consent in the relevant circumstances.

The important point is that the organisation should be able to justify the claimed incapacity rather than merely asserting that the situation was urgent.

The concept of "vital interests"

"Vital interests" should be understood as interests of fundamental importance, particularly involving serious threats to life or physical integrity.

It should not be expanded into:

"Anything that is beneficial to the individual."

For example:

Sending someone's medical information overseas because it would make administrative processing easier is not the same as sending necessary information to emergency medical personnel when the person is unconscious.

The latter is much closer to the core purpose of Article 49(f).

Article 49(1)(g): Public registers

The public-register derogation is another highly technical provision.

It applies where personal data are transferred from a register that is intended by Union or Member State law to provide information to the public.

Examples

might include certain legally established registers that are designed to provide information to the public or to persons demonstrating a legitimate interest. But the fact that a database is available online doesnot automatically mean that every international extraction of its contents is permitted. There are significant limitations.

Public access does not mean unlimited international access

Suppose a Member State creates a public register containing information about companies.

A person in India accesses one entry legitimately.

That does not necessarily mean a third party can scrape the entire database and transfer it outside the EU.

The register derogation must be applied within the conditions established by the relevant law.

The GDPR deliberately prevents the public-register exception from becoming a loophole for mass international data extraction.

Legitimate-interest registers

Some registers are not open to everyone.

They may only be accessible to people who can demonstrate a legitimate interest.

In that situation, the transfer should be linked to that legitimate-interest access framework.

For example, if the law allows a particular category of person to consult a register for a defined purpose, the fact that someone outside the EU wants the information does not automatically override those conditions.

The transfer has to remain within the legal framework governing access to the register.

Article 49(2): no transfer of the entire register

This is an important limitation.

Even when the public-register derogation applies, it does not permit transferring the entirety of the personal data or entire categories of personal data contained in the register.

This reflects a basic proportionality principle.

Imagine a public register contains 500,000 records.

A company cannot necessarily say:

"The register is public, so we can export the whole database to a third country."

Article 49 is much narrower.

A specific request for a particular record is fundamentally different from bulk extraction of the database.

Why the register restriction exists

Public availability does not eliminate privacy rights.

A piece of information may be publicly accessible in Europe for a specific legal purpose while still being subject to restrictions on:

  • reuse;

  • aggregation;

  • mass extraction;

  • international transfer;

  • secondary purposes.

This distinction is increasingly important in the context of:

  • data scraping;

  • OSINT;

  • bulk datasets;

  • commercial databases;

  • AI training;

  • data aggregation.

A "publicly available" dataset is not automatically a dataset that can be freely exported internationally.

The residual derogation: compelling legitimate interests

The final mechanism in Article 49(1) is particularly important because it operates as a residual safety valve.

It can be considered only where:

  1. Article 45 does not provide a transfer mechanism;

  2. Article 46 does not provide a transfer mechanism;

  3. none of the specific Article 49(1)(a), (g) derogations applies.

Even then, several cumulative conditions must be satisfied.

This is therefore not:

"We have a legitimate interest, so Article 49 applies."

It is considerably narrower.

Why "legitimate interest" is not enough

The GDPR uses the stronger expression:

compelling legitimate interests

This is deliberately stricter.

The controller must identify an interest that is sufficiently important to justify the exceptional transfer.

A routine commercial objective is not automatically "compelling".

For example:

"We want to reduce IT costs."

That would ordinarily be a weak basis for invoking this residual derogation.

By contrast, an unusually important corporate or societal interest that cannot reasonably be protected through another transfer mechanism might warrant closer examination.

Even then, the other requirements remain.

First requirement: non-repetitive transfer

The transfer must be not repetitive.

This is critical.

Suppose an organisation transfers customer data to a US recipient every Monday.

That is clearly repetitive.

It would be difficult to reconcile such a systematic transfer arrangement with a derogation intended for exceptional circumstances.

The residual mechanism therefore cannot normally become a substitute for establishing SCCs, BCRs or another structural transfer mechanism.

Second requirement: limited number of data subjects

The transfer must concern only a limited number of data subjects.

This is another safeguard against using the derogation as a general business mechanism.

For example:

A transfer involving information concerning five individuals in connection with an exceptional corporate dispute is qualitatively different from transferring information concerning ten million customers.

The GDPR does not prescribe a universal numerical threshold in Article 49.

Therefore, "limited number" must be assessed contextually.

This is an area where organisations should document why the number is limited in the circumstances rather than relying on an arbitrary numerical formula.

Third requirement: compelling legitimate interests

The controller must identify its legitimate interest and demonstrate why it is compelling.

There is then a balancing exercise.

The controller's interest must not be overridden by:

  • the interests of the data subject; or

  • their rights and freedoms.

The more sensitive the data and the greater the potential harm, the harder it becomes to justify the transfer.

Fourth requirement: assessment of all circumstances

The controller must assess all the circumstances surrounding the transfer.

This is deliberately broad.

The assessment may need to consider factors such as:

  • nature of the personal data;

  • sensitivity;

  • number of individuals;

  • purpose;

  • duration;

  • destination country;

  • recipient;

  • onward transfers;

  • possibility of government access;

  • security measures;

  • consequences of disclosure;

  • alternatives to the transfer;

  • expectations of the data subjects.

This is not merely a box-ticking exercise.

The controller should be able to demonstrate the reasoning that led to the conclusion that the transfer was justified.

Fifth requirement: suitable safeguards

Even where the residual derogation is available, the controller must provide suitable safeguards.

This is significant because Article 49 is not intended to mean:

"No safeguards are required."

Instead, where an exceptional transfer takes place, the controller should take measures appropriate to reduce the risks.

Depending on the circumstances, this might involve measures such as:

  • encryption;

  • pseudonymisation;

  • data minimisation;

  • restricted access;

  • strict retention periods;

  • limited recipient access;

  • contractual confidentiality;

  • technical access controls.

The exact safeguard must be appropriate to the particular risk.

Notification to the supervisory authority

The controller must also inform the supervisory authority about the transfer when relying on the residual compelling-legitimate-interest derogation.

This creates an important governance obligation.

The organisation cannot simply make the transfer internally and leave no regulatory trail.

It should maintain documentation explaining:

  • why Articles 45 and 46 were unavailable;

  • why Articles 49(a), (g) did not apply;

  • what compelling legitimate interest existed;

  • how the balancing exercise was conducted;

  • why the transfer was non-repetitive;

  • why the number of data subjects was limited;

  • what safeguards were implemented.

Information to the data subject

The data subject must also receive information about:

  1. the transfer; and

  2. the compelling legitimate interests pursued by the controller.

This is additional to the normal transparency obligations under Articles 13 and 14.

The purpose is obvious: because the transfer is occurring outside the ordinary transfer mechanisms, the individual should not be left unaware of the exceptional basis being relied upon.

Article 49(3): public authorities exercising public powers

Article 49 contains an important restriction concerning public authorities.

The contractual derogations in Article 49(1)(a), (b), (c), and the residual compelling-legitimate-interest derogation do not apply to activities carried out by public authorities in the exercise of their public powers.

This prevents a public authority from using private-law concepts to circumvent the rules applicable to governmental activity.

For example, a tax authority cannot simply say:

"The data subject has consented, so we can transfer the information."

Where the authority is exercising its public powers, the GDPR specifically prevents reliance on these derogations in the circumstances covered by Article 49(3).

The appropriate legal framework has to be identified instead.

Article 49(4): public interest must be recognised in law

This paragraph is essential for understanding Article 49(d).

The relevant public interest must be recognised in:

  • Union law; or

  • the law of the Member State to which the controller is subject.

Therefore, the organisation cannot create its own public-interest justification.

For example:

"We think international cooperation is in the public interest."

That is not enough.

There must be an appropriate legal recognition of that public interest.

This provides an important limitation on governmental and regulatory transfers.

Article 49(5): Member States may restrict transfers

The GDPR also allows Union or Member State law to expressly limit transfers of certain categories of personal data to third countries for important public-interest reasons.

This is a recognition that certain categories of information may require additional protection because of their significance.

The restriction must be legally grounded rather than simply imposed through informal organisational policy.

Article 49(6): documentation

The final provision is particularly important from a compliance perspective.

Where the controller relies on the residual compelling-legitimate-interest derogation, it must document:

  • its assessment; and

  • the suitable safeguards.

The documentation becomes part of the Article 30 records.

This means that Article 49 compliance is not simply about making the right decision.

The controller must also be able to demonstrate how and why it reached that decision.

This connects Article 49 with the broader accountability principle.

The concept of "necessity" runs throughout Article 49

One of the most important analytical themes is necessity.

A transfer may be:

  • useful;

  • efficient;

  • commercially desirable;

  • cheaper;

  • faster;

  • administratively convenient;

without being legally necessary.

For Article 49, necessity generally requires a much closer relationship between the transfer and the specific objective being pursued.

Consider three scenarios.

Scenario A, necessary

A person is unconscious after an accident and their medical records must be sent to foreign emergency doctors. Strong necessity argument.

Scenario B, useful

A company wants to send European customer information to an overseas analytics provider because the analytics platform is cheaper. Weak Article 49 necessity argument.

Scenario C, structurally required

A multinational routinely sends European employee data to its overseas headquarters every month. The transfer may genuinely be operationally necessary for the company's structure, but its repetitive and structural nature makes Article 46 mechanisms much more relevant. This distinction is fundamental.

Occasional versus repetitive transfers

The repeated appearance of the concept of occasional/non-repetitive transfer is intentional.

Article 49 is designed for exceptional circumstances.

Imagine two companies:

Company A

Transfers data once because a particular lawsuit requires specific documents.

Company B

Transfers employee data to the same third-country affiliate every month as part of ordinary HR administration.

Company A looks much more like the type of exceptional situation contemplated by Article 49.

Company B looks like a structural international transfer arrangement requiring an Article 46 mechanism.

What happens if the organisation could use SCCs?

This is an important operational question.

Suppose an organisation says:

"We have no adequacy decision, but we could sign SCCs."

It would generally be inappropriate to bypass Article 46 and choose Article 49 merely because Article 49 appears easier.

The architecture of Chapter V expects controllers to use the normal transfer mechanisms where available.

Article 49 is therefore not intended as a convenient shortcut around SCC implementation.

Article 49 and Schrems II

The principles established in Schrems II are important to the broader Chapter V framework.

The CJEU emphasised that international transfers must maintain a level of protection essentially equivalent to that guaranteed within the EU legal order.

Article 49 differs from Article 46 because it is an exceptional derogation rather than a structural safeguard mechanism.

This makes it particularly important not to treat Article 49 as a general replacement for transfer safeguards.

The underlying Article 44 principle remains relevant: the protection guaranteed by the GDPR should not simply be undermined by moving the data outside the EU.

Article 49 and Article 48: foreign government demands

This is one of the most difficult practical situations.

Imagine:

A US authority demands data from a French company.

The company needs to determine:

Step 1: Is the company subject to the GDPR?

Step 2: Is the demand a judgment or decision covered by Article 48?

Step 3: Is there an applicable international agreement or MLAT?

Step 4: What is the underlying legal basis for the processing/disclosure?

Step 5: What Chapter V transfer mechanism applies?

Article 48 prevents a foreign authority from simply treating its own domestic legal order as automatically capable of compelling disclosure from an EU organisation.

The existence of a foreign legal demand therefore does not end the GDPR analysis.

Article 49 and public authorities: another distinction

A foreign government request may sometimes involve:

  • law enforcement;

  • tax;

  • customs;

  • financial regulation;

  • public health;

  • national security;

  • other public functions.

The purpose of the request does not itself decide which Article 49 derogation applies.

The organisation must identify the actual legal circumstances.

For example, a foreign tax authority's request may potentially engage public-interest considerations, but the organisation still needs to determine whether the relevant public interest is recognised under EU or Member State law and whether the other Chapter V requirements are satisfied.

The "public interest" cannot simply be imported from foreign law

This is an important nuance.

Suppose a third-country law says:

"Disclosure of this information serves an important public interest."

That does not automatically satisfy Article 49(1)(d).

Article 49(4) looks to the public interest recognised in Union law or the relevant Member State law.

The foreign country's assertion of public interest is therefore not, by itself, sufficient.

Article 49 and sensitive data

Article 49 does not remove the protection applicable to special categories of personal data under Article 9.

Suppose a transfer involves:

  • health data;

  • biometric data;

  • genetic data;

  • political opinions;

  • religious beliefs;

  • trade-union membership;

  • sexual-orientation information.

The controller must separately consider the applicable Article 9 condition.

A valid Article 49 derogation does not automatically create an Article 9 exception.

This is an important distinction for practical transfer assessments.

Article 49 does not eliminate data minimisation

Suppose a court proceeding requires five documents.

The organisation has 5,000 documents available.

The existence of a legal claim does not automatically justify transferring all 5,000.

The controller should identify the information actually necessary for the legal purpose.

Similarly, under the public-register derogation, the GDPR expressly limits bulk transfer.

This demonstrates a broader principle:

A derogation from Chapter V is not a derogation from the rest of the GDPR.

Article 49 and pseudonymisation

Suppose an exceptional transfer genuinely qualifies under Article 49.

The controller should still consider whether personal data can be protected through measures such as pseudonymisation or encryption.

For example:

Instead of transferring:

Name + address + medical history + national ID + full records

the organisation might be able to transfer:

Pseudonymous identifier + only the medical information necessary for the emergency.

The effectiveness of the safeguard depends on the specific circumstances.

The grey area of "limited number"

Article 49 does not establish a universal numerical threshold for what constitutes a "limited number of data subjects" under the residual derogation.

That creates an important practical grey area.

One hundred individuals may be "limited" in one context but substantial in another.

The organisation should therefore avoid simplistic rules such as:

"Anything below 100 is automatically permitted."

A contextual assessment is more defensible.

Relevant considerations could include:

  • sensitivity of the information;

  • scale of the organisation;

  • nature of the transfer;

  • purpose;

  • consequences for individuals;

  • whether the transfer is truly exceptional.

The grey area of "compelling"

Similarly, Article 49 does not provide a mathematical test for "compelling legitimate interests."

The controller must explain why the interest is sufficiently strong to justify the exceptional transfer.

This requires more than simply identifying a legitimate business interest.

For example:

"The transfer will save €50,000."

That identifies a commercial interest.

It does not automatically establish that the interest is compelling.

The stronger question is:

Why is this interest sufficiently important that the controller cannot reasonably achieve its objective through a lawful Article 45 or Article 46 mechanism or another Article 49 derogation?

The grey area of "occasional"

Similarly, there is no simple universal number.

A transfer occurring once may clearly be occasional.

A transfer occurring every month is clearly repetitive.

The difficult cases lie between those extremes.

The organisation should look at the actual pattern and purpose.

If the transfer is built into an ordinary recurring business process, that is a strong indication that the organisation should seek a structural transfer mechanism rather than repeatedly invoke Article 49.

Article 49 and cloud computing

Consider an EU company using a third-country cloud provider.

If European personal data are routinely stored or accessed on the provider's infrastructure outside the EEA, the organisation generally needs a proper Chapter V transfer mechanism.

It would be problematic to argue:

"Our customers consented to the transfer once, so Article 49 covers all future cloud processing."

The systematic nature of cloud processing is fundamentally different from the exceptional transfers Article 49 is intended to address.

This is a particularly important operational implication for:

  • SaaS;

  • cloud hosting;

  • HR platforms;

  • CRM platforms;

  • analytics;

  • customer-support systems.

Article 49 and multinational groups

The same logic applies to multinational companies.

Suppose a European subsidiary routinely sends employee data to its parent company in a third country.

Even if the transfer is necessary for group HR administration, the routine nature of the transfer makes Article 46 mechanisms, particularly BCRs or SCCs, much more relevant.

Article 49 should not become the default transfer mechanism for intra-group data flows.

Article 49 and mergers/acquisitions

A one-off transfer during an M&A transaction may raise Article 49 questions.

For example, a European target company may need to transfer a limited set of employee or customer information to a third-country buyer during a specific transaction.

The organisation would need to analyse:

  • whether Article 45 applies;

  • whether Article 46 safeguards can be implemented;

  • whether a legal-claims derogation or another Article 49 ground genuinely applies;

  • whether the transfer is necessary;

  • whether the data set can be minimised.

The fact that the transaction is commercially important does not automatically establish a derogation.

Article 49 and investigations

Consider an internal investigation involving employees across several countries.

The company may need to transfer specific information to overseas counsel.

Article 49(e) may become relevant if the transfer is genuinely necessary for establishing, exercising or defending a specific legal claim.

But simply saying:

"This is an internal investigation"

is insufficient.

The organisation must establish the connection with the relevant legal claim and the necessity of the transfer.

Article 49 and arbitration

The source commentary notes that the legal-claims derogation can extend beyond conventional court proceedings to certain administrative, arbitration and related proceedings.

The important point is not merely the label of the proceeding.

The organisation should ask whether there is a genuine legal claim and whether the transfer is necessary for its establishment, exercise or defence.

Again, proportionality and minimisation remain relevant.

Article 49 and regulatory investigations

A regulator's request requires careful classification.

Suppose a European company receives a request from a foreign competition authority.

Possible issues include:

  • Article 48;

  • international cooperation arrangements;

  • Article 49(d);

  • Article 49(e);

  • applicable EU/Member State law;

  • other Chapter V mechanisms.

The organisation should not simply pick Article 49(d) because the foreign authority is governmental.

The legal basis and transfer mechanism need to be separately established.

Article 49 and research

Recital 113 specifically recognises scientific, historical and statistical research in discussing the residual derogation.

This does not mean that every international research transfer automatically qualifies.

The organisation must still examine:

  • whether another Chapter V mechanism exists;

  • whether the transfer is genuinely exceptional;

  • whether the number of data subjects is limited;

  • the nature of the legitimate interest;

  • safeguards;

  • the expectations and rights of data subjects.

Research may strengthen the contextual analysis of legitimate interests, but it does not eliminate the statutory conditions.

Article 49 is not a "business necessity" exception

This is perhaps the most important practical lesson.

Organisations frequently use the word "necessary" in a commercial sense:

"We need this data to run our business."

The GDPR uses necessity much more carefully.

The question is not:

"Do we want this transfer?"

The question is:

"Is this particular transfer genuinely necessary to achieve the specific objective identified by the relevant Article 49 derogation?"

That change in framing dramatically improves transfer analysis.

Operational decision-making under Article 49

In practice, a privacy team considering an exceptional transfer should work through the hierarchy.

First:

Is there an adequacy decision?

If yes, Article 45 may apply.

If no:

Can an Article 46 mechanism be used?

If yes, use the appropriate safeguard.

If no:

Does a specific Article 49 derogation apply?

Consider:

  • explicit informed consent;

  • contract;

  • contract in the data subject's interest;

  • important public interest;

  • legal claims;

  • vital interests;

  • public register.

If none applies:

Does the residual compelling-legitimate-interest derogation genuinely apply?

If not, the transfer should not proceed on the basis of Article 49.

Why the residual derogation is especially demanding

The residual derogation requires the controller to demonstrate several facts simultaneously.

For example:

"This is a one-off transfer involving 12 individuals. No adequacy decision exists. No Article 46 safeguard is available in the circumstances. No Article 49(a), (g) derogation applies. The controller has a compelling legitimate interest. The data subjects' rights do not override that interest. The transfer is genuinely necessary. The risks have been assessed. Suitable safeguards have been implemented. The supervisory authority has been informed. The affected individuals have been informed."

That is a considerably higher threshold than merely saying:

"We have a legitimate interest."

Article 49 and accountability

The documentation requirement is important because Article 49 creates an accountability problem.

An organisation might make an exceptional transfer today and later face questions from:

  • the supervisory authority;

  • the data subject;

  • auditors;

  • internal compliance;

  • litigation counsel.

The organisation therefore needs to reconstruct its reasoning.

A strong record should explain the facts and reasoning rather than merely cite:

"Article 49(1)(e)."

For example:

"The transfer concerns documents X, Y and Z, requested in proceedings X. The documents are necessary because they contain evidence relevant to claim Y. No broader dataset is being transferred. The transfer is one-off. The recipient is external counsel. Access is restricted and the documents are encrypted."

That is much more meaningful compliance evidence.

Article 49 does not make the recipient trustworthy

Another common misunderstanding is:

"The recipient is a reputable international organisation, therefore Article 49 is satisfied."

Recipient reputation is not itself a derogation.

The legal basis must come from Article 49 or another Chapter V provision.

The recipient's reputation may be relevant to risk assessment and safeguards, but it does not create a transfer mechanism.

Article 49 does not permanently solve the transfer

Suppose an organisation makes one lawful transfer under Article 49(e).

That does not mean future transfers of similar data can automatically rely on Article 49(e).

Each transfer must continue to fit the relevant derogation.

If the same transfer becomes recurring, that may indicate that the organisation should establish an Article 46 mechanism.

This is an important compliance signal:

Repeated reliance on an exceptional derogation may indicate that the underlying transfer architecture needs to change.

Article 49 and data subject expectations

Data subject expectations are particularly relevant where the residual legitimate-interest derogation is used.

Suppose an EU employee reasonably expects their HR data to remain within a European HR system.

A sudden transfer of sensitive employee information to a third country could create a stronger privacy impact.

The controller therefore needs to consider:

  • what the person reasonably expected;

  • what information is involved;

  • why the transfer is necessary;

  • what safeguards exist;

  • what consequences could result.

This is particularly important where sensitive or intrusive processing is involved.

The relationship between Article 49 and transparency

Transparency does not disappear because a derogation is used.

For the residual derogation, Article 49 expressly requires additional information to be given to the data subject.

The person should be informed about the transfer and the compelling legitimate interests relied upon.

This reinforces a broader principle:

Exceptional international transfers should not become invisible processing operations.

Article 49 and onward transfers

An organisation should also think beyond the immediate recipient.

Suppose:

EU controller → US processor → Singapore sub-processor

The first transfer is not necessarily the end of the analysis.

The organisation should consider whether the data will subsequently move to another country.

This is particularly important because an Article 49 derogation should not become a vehicle for uncontrolled onward transfers.

The purpose and scope of the transfer must remain within the relevant legal and factual conditions.

Article 49 and encryption

Encryption can be an important supplementary protective measure.

For example, where an exceptional transfer is necessary, the controller might ensure that the recipient cannot access the data except for the narrowly defined purpose.

But encryption does not automatically make an unlawful transfer lawful.

The sequence remains:

legal basis → Chapter V mechanism/derogation → necessity → safeguards.

Technical safeguards complement the legal analysis; they do not replace it.

Article 49 and data minimisation

Data minimisation is particularly powerful in Article 49 situations.

Suppose litigation requires information relating to three employees.

Sending:

all employee records of the entire company

would be difficult to justify.

Sending:

the three relevant employees' specific documents

is much easier to analyse.

The same reasoning applies to emergency transfers, public-register access and regulatory requests.

The deeper policy objective of Article 49

Article 49 reflects a balancing exercise.

The GDPR recognises that absolute prohibition of every transfer to a non-adequate country would be impractical.

Real-world situations arise:

  • people travel;

  • emergencies happen;

  • litigation occurs;

  • regulators cooperate;

  • contracts cross borders;

  • public registers exist;

  • international public interests arise.

Article 49 therefore provides carefully defined escape routes.

But the escape routes are deliberately narrow because otherwise organisations could avoid the more robust safeguards in Article 46.

The fundamental distinction: structural versus exceptional transfers

This is the single best way to understand Article 49.

Structural transfer

"Our European customer database is routinely stored in the United States."

This is a continuing architecture.

Think Article 45/46.

Exceptional transfer

"A particular European customer's data must be sent once to a foreign hospital because the customer is unconscious."

This is a specific event.

Think Article 49(f).

Another exceptional transfer

"Specific documents must be sent to foreign counsel for a particular legal proceeding."

Potentially Article 49(e).

Another exceptional transfer

"A person expressly requests a service requiring a particular transfer and gives informed explicit consent after being warned of the relevant transfer risks."

Potentially Article 49(a).

This structural-versus-exceptional distinction makes many difficult Article 49 problems much easier to analyse.

This is one of the areas where organisations need to be particularly cautious.

A simplistic interpretation would be:

"If we obtain explicit consent, we can transfer."

But Article 49 is not intended to provide a general mechanism for systematic transfers.

If a company has a structural transfer arrangement, the organisation should first consider whether an Article 46 mechanism should be implemented.

Consent should therefore not become a convenient replacement for SCCs or BCRs merely because it is easier operationally.

The most important grey area: "Can a contract justify every transfer?"

No.

The contractual derogations require necessity.

For example:

"Our contract with the customer says that their data may be transferred to our overseas affiliate."

That contractual clause does not by itself establish Article 49(b).

The question is whether the transfer is actually necessary for the performance of the contract.

A contractual clause cannot manufacture necessity.

The most important grey area: "Does a court order automatically authorise transfer?"

No.

Article 48 is critical.

A third-country court order does not automatically override Chapter V.

The organisation needs to analyse the international agreement position and then identify the applicable transfer mechanism or derogation.

Article 49(e) may be relevant in some circumstances, but the court order itself should not be treated as a magic authorisation.

The most important grey area: "Does public interest mean government request?"

No.

A government request and a public interest under Article 49(d) are not synonymous.

The public interest must be recognised in applicable EU or Member State law.

The organisation must therefore identify the actual legal foundation for the public-interest transfer.

The most important grey area: "Can a public database be copied abroad?"

Not merely because it is public.

Article 49(2) prevents the derogation from being used to transfer the entirety of the data or entire categories of data contained in a register.

The conditions governing access to the register also matter.

Public accessibility is therefore not equivalent to unrestricted international portability.

The most important grey area: "Can legitimate interest solve everything?"

No.

The residual provision is deliberately exceptional.

It requires:

  • no Article 45 mechanism;

  • no Article 46 mechanism;

  • no applicable Article 49(a), (g);

  • non-repetitive transfer;

  • limited number of data subjects;

  • compelling legitimate interest;

  • balancing;

  • assessment of all circumstances;

  • suitable safeguards;

  • supervisory-authority notification;

  • data-subject information;

  • documentation.

It is therefore one of the most demanding routes in Article 49.

A worked example: European company and US litigation

Consider this scenario:

A French company becomes involved in litigation in the United States. The US lawyers request documents relating to six employees.

There is no adequacy decision applicable to the transfer.

Step 1, Article 45

No adequacy decision.

Step 2, Article 46

Could SCCs or another appropriate safeguard reasonably be used?

If this is a specific litigation disclosure, the company may need to examine whether a derogation is more directly applicable.

Step 3, Article 49(e)

There is an identified legal claim.

The requested documents are directly relevant.

The transfer is limited to six employees.

The transfer is necessary for the defence of the claim.

Only relevant documents are disclosed.

This is much closer to the intended operation of Article 49(e).

But if the company instead transferred the entire HR database to US counsel merely because "there is litigation", the analysis would be much weaker.

Worked example

emergency medical situation An EU resident is unconscious following an accident in India. The European hospital possesses critical medical information. Indian doctors urgently need the information. There is no opportunity to establish SCCs or another structural transfer mechanism. The individual cannot give consent. The transfer is necessary to protect their vital interests. This is a classic situation in which Article 49(f) is conceptually designed to operate. The organisation should nevertheless transfer only the information necessary for the emergency.

Worked example

recurring HR transfer A French subsidiary sends all employee data to its US parent every month. The parent performs centralised HR administration. The company wants to rely on Article 49(b), saying: "The transfers are necessary to perform the employment relationship." The recurring nature of the transfers is a major problem. This is precisely the sort of structural transfer for which an Article 46 mechanism should generally be considered. The contractual connection alone does not convert a systematic transfer into an exceptional Article 49 transfer.

Worked example

public register A company wants to download an entire European public register containing millions of personal records and host the database on servers in a third country. It argues: "The register is public." Article 49(2) creates a major obstacle to this approach. The derogation does not permit transferring the entirety of the personal data or entire categories of personal data contained in the register. The organisation must instead examine the specific legal framework and the permitted scope of consultation.

Worked example

residual legitimate interest Suppose a company needs to make a one-time transfer concerning 8 individuals to a third country. There is:

  • no adequacy decision;
  • no suitable Article 46 mechanism available for the particular circumstances;
  • no consent;
  • no relevant contract derogation;
  • no legal claim;
  • no vital-interest situation;
  • no public-interest derogation;
  • no public-register derogation. The company identifies an unusually important legitimate interest and determines that the transfer is compelling. It assesses the risks, limits the information, encrypts the data, restricts access and informs the relevant supervisory authority and data subjects. This is the type of scenario in which the residual provision becomes relevant. But the organisation must be able to defend every element of the analysis.

What Article 49 ultimately requires from a privacy professional

A privacy professional should resist the temptation to ask:

"Which Article 49 exception can we use?"

The better question is:

"Why is this exceptional transfer necessary, and why cannot the normal Chapter V mechanisms be used?"

That question forces the organisation to examine the architecture of Chapter V properly.

The analysis should move from:

Transfer

Destination

Article 45?

Article 46?

Article 49(a), (g)?

Residual compelling legitimate interest?

Necessity

Minimisation

Risk

Safeguards

Transparency

Documentation

This is much closer to the regulatory logic of Article 49.

Overall interpretation of Article 49

Article 49 is best understood as a controlled exception mechanism for exceptional international transfers.

Its purpose is not to make international transfers generally easier. Its purpose is to prevent the GDPR from producing unreasonable results in situations where an international transfer genuinely needs to happen but the normal mechanisms are unavailable.

The provision therefore balances two competing objectives.

On one side:

International data flows sometimes need to happen.

A person may need emergency treatment. A company may need to defend litigation. Regulators may need to cooperate. A contract may genuinely require a particular one-off transfer.

On the other side:

A derogation should not become a loophole.

If Article 49 were interpreted broadly, organisations could avoid implementing SCCs, BCRs and other Article 46 safeguards simply by describing their business activities as contractual, legitimate or commercially necessary.

The restrictive approach prevents that.

The most important conceptual distinction is therefore:

Article 45 and Article 46 are the normal architecture for international transfers; Article 49 is the exceptional escape route.

And within Article 49 itself, the strongest analyses are those that demonstrate specificity, necessity, limited scope, exceptional circumstances and accountability.

The fact that a transfer is desirable is not enough.

The fact that a transfer is commercially important is not enough.

The fact that a contract exists is not enough.

The fact that a foreign authority asks for the data is not enough.

The fact that the data are publicly accessible is not enough.

The fact that the controller has a legitimate interest is not enough.

The organisation must identify a legally recognised derogation, satisfy its specific conditions, continue complying with the rest of the GDPR, and be able to demonstrate why the exceptional transfer was justified.

That is the central logic running through the entire Article 49 framework.