What is an international data transfer?
An international data transfer is any movement of personal data from one country to another, including remote access from abroad. GDPR restricts transfers out of the EU unless a legal mechanism covers them. Common mechanisms are Standard Contractual Clauses (SCCs), adequacy decisions, and the EU-US Data Privacy Framework.
What the buyer is really asking
If personal data leaves the EU, UK, or another restricted region, buyers need the legal mechanism that covers it. Name the mechanism (Standard Contractual Clauses, the EU-US Data Privacy Framework, or an adequacy decision) and list the countries data goes to, including through subprocessors.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you handle international transfers of personal data?”
- “Do you rely on Standard Contractual Clauses?”
- “Is personal data transferred outside the EEA?”
- “Are you certified under the EU-US Data Privacy Framework?”
Evidence to have ready
- The transfer mechanism named in your DPA
- Your subprocessor list with each processing location
- A transfer impact assessment, if you have done one
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.