Cross-border data transfer is the movement of personal or regulated data across national jurisdictions, governed by data-protection laws that restrict where and how such data may be processed. Compliance mechanisms include adequacy decisions, standard contractual clauses, binding corporate rules, and localisation requirements. It is a central concern of privacy regimes such as GDPR and various Asia-Pacific frameworks.

Content

  • Lawful transfer typically rests on adequacy findings, contractual safeguards, or explicit consent, with some regimes adding data-localisation mandates. Diverging regional rules force multinationals to map data flows precisely and adopt layered safeguards, since a single non-compliant transfer can trigger significant regulatory penalties.