
Standard contractual clauses: data sent outside Europe
At a glance
EU-06MediumGDPR Arts. 44 to 49; Art. 13(1)(f); fines under Art. 83(5)(b) and (c)
Peeky looks for visitor data leaving for servers outside Europe and whether the privacy policy says how that data is protected.
Last checked against the source:
The rule
Chapter V of the GDPR begins with a general principle. Under Article 44, any transfer of personal data to a third country “shall take place only if” the conditions laid down in the chapter “are complied with by the controller and processor”, including for onward transfers, and the chapter’s provisions apply “to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.”
The chapter then gives the sender a ladder. The first rung is an adequacy decision under Article 45, after which a transfer “shall not require any specific authorisation.” Without one, Article 46 applies.
Under Article 46(1), in the absence of an adequacy decision a controller or processor may transfer data to a third country “only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.” Article 46(2) lists the safeguards, among them binding corporate rules and “standard data protection clauses adopted by the Commission.” The Commission’s current clauses are in Implementing Decision (EU) 2021/914, which treats them as appropriate safeguards under Article 46(1) and (2)(c).
Article 49 sets out narrow derogations, such as explicit consent after being told the risks. They apply only “in the absence of” an adequacy decision or appropriate safeguards.
Two sources shape how this is read. In Schrems II (C-311/18, 16 July 2020) the Court of Justice invalidated the EU-US Privacy Shield and upheld standard contractual clauses, with the exporter responsible for checking that they work in the destination country. The EDPB’s Recommendations 01/2020 turn that into six steps, from knowing your transfers to re-evaluating at intervals. The EDPB also notes in a footnote that remote access from a third country to data held in the EEA is a transfer.
The United States is the destination most websites meet. On 10 July 2023 the Commission adopted an adequacy decision for the EU-US Data Privacy Framework. The EDPB’s information note says it covers organisations “included in the ‘Data Privacy Framework List’” kept by the US Department of Commerce, so a transfer to a listed organisation needs no Article 46 tool and no supplementary measures, while a transfer to an unlisted one does. On 3 September 2025 the General Court dismissed an action to annul the decision (T-553/23, Latombe v Commission), finding that the United States ensured an adequate level of protection on the date the decision was adopted. The press release notes that an appeal on points of law is possible.
The part a website shows is the disclosure. Article 13(1)(f) requires the controller to provide, “where applicable, that the controller intends to transfer personal data to a recipient in a third country or international organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available.”
Both layers sit in the upper fine tier. Article 83(5)(c) covers “the transfers of personal data to a recipient in a third country” under Articles 44 to 49, and 83(5)(b) covers data subjects’ rights under Articles 12 to 22, which includes Article 13. The ceiling is EUR 20 million or, for an undertaking, 4% of total worldwide annual turnover, whichever is higher.
What PeekWell checks and how
EU-06 puts two observations side by side: where the page sends visitor data, and what the privacy policy says about it. It does not decide whether a transfer is covered. It writes down whether the policy names a mechanism.
The scan opens a public page in a clean browser and records every network request. It resolves the domains and addresses to a hosting location and flags requests that look like they carry visitor data to places outside the EU and outside the countries with adequacy decisions. The policy fetcher then reads your privacy policy, and a language model checks whether the transfer section names a mechanism: an adequacy decision, the Data Privacy Framework, standard contractual clauses or binding corporate rules. The report states the pairing, for example “data sent to a US endpoint; policy names no transfer mechanism”. The decision that the two did not match is made by code from that evidence. The model reads and explains, and never decides that a finding exists.
The method matches EU-04, which finds recipients the policy does not name. EU-06 adds where the recipient sits and the safeguard sentence. EU-08 covers the other Article 13 items.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. An address that resolves to a server in one country does not say who the legal recipient is, and content delivery networks answer from nearby servers. Whether a vendor sits on the Data Privacy Framework List, and what a signed contract says, are things the browser cannot see. Collection that happens on a server or inside an app is outside a browser visit. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
The first reason is the size of the record. In the Meta Ireland decision the DPC found that transfers continued after Schrems II on the 2021 clauses plus supplementary measures, and that this did not address the risks the Court of Justice had named. The fine was EUR 1.2 billion, reflecting a binding decision of the EDPB, and the order required future transfers to be suspended. In the Uber decision the issue was simpler: for over two years drivers’ data, including identity documents and location data, went to the US headquarters with no transfer tool in use. The TikTok decision reached remote access from China.
The second reason is the paperwork. The TikTok decision found the 2021 privacy policy did not name China and did not explain that the processing included remote access by staff there. The disclosure was a finding in its own right, separate from the transfers.
The third is that the duty sits with the sender, not the vendor. In the Caffeina Media decision the company said it had no ability to negotiate with Google, to see what data went where or to check Google’s technical measures. The Garante took that imbalance into account in assessing the company’s conduct, and still cited Articles 44, 46 and 13(1)(f). That decision predates the current EU-US framework, so it shows how authorities reason about a vendor the sender cannot inspect, not how a Data Privacy Framework listing would be treated today.
Smaller companies and larger companies
The rule has no size threshold. What differs is how the gap comes about.
In a small company the transfer usually arrives with a tool. A marketer adds analytics, a chat widget, a video embed and an email service. Each vendor has its own answer to whether it is listed, on clauses, or neither. The privacy policy came from a generator before the tools were added, and nobody holds the list of vendors. In Italy a single analytics tool on a magazine site led to a complaint and a formal warning.
In a larger company the problem is scale and change. Data moves between group entities, support teams and cloud regions, sometimes by remote access rather than copying, which still counts, as the EDPB footnote and the TikTok decision show. Contracts on the older clauses had to be replaced: Decision 2021/914 let them stand only until 27 December 2022, and only while processing stayed unchanged.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Meta Platforms Ireland Limited
The DPC found that Meta Ireland infringed Article 46(1) GDPR by continuing to transfer EU and EEA user data to the United States after the Schrems II judgment. The transfers rested on the 2021 standard contractual clauses plus supplementary measures, which the DPC found did not address the risks to users' rights that the Court of Justice had identified. It ordered future transfers suspended and the processing brought into line.
Read the Data Protection Commission (Ireland) publication about Meta Platforms Ireland LimitedUber
The Dutch authority found that Uber moved European drivers' data to its US headquarters for over two years without using a transfer tool, after it stopped relying on standard contractual clauses in August 2021. The data included account details, taxi licences, location data, photos, payment details and identity documents. Uber said it intended to object to the fine.
Read the Autoriteit Persoonsgegevens (Netherlands) publication about UberTikTok Technology Limited
The DPC found that TikTok's transfers of EEA user data to China, by remote access from staff there, infringed Article 46(1) because it had not verified that the standard contractual clauses and supplementary measures gave essentially equivalent protection. It also found that the October 2021 privacy policy did not name China as a destination, an Article 13(1)(f) failing. The decision orders the transfers brought into compliance or suspended.
Read the Data Protection Commission (Ireland) publication about TikTok Technology Limited
Smaller companies
Caffeina Media S.r.l.
After a complaint, the Garante found that the company's magazine website sent visitors' cookie identifiers, IP addresses, device data and activity to Google LLC in the United States through the free version of Google Analytics. The company had used standard contractual clauses with Google's own supplementary measures but said it could not verify them. The Garante cited Articles 5, 13(1)(f), 24, 44 and 46, warned the company and required it to report its corrective steps within 90 days.
Read the Garante per la protezione dei dati personali (Italy) publication about Caffeina Media S.r.l.
How to fix it
The EDPB says that knowing your transfers is “an essential first step to fulfil your obligations under the principle of accountability.” The steps below follow that order, then close with the policy wording and a re-scan.
- List what leaves. Open your site in a private window with the browser’s network tab open and write down every third-party domain that receives requests. Add tools that do not show up there, such as your email platform and support desk. Mark which receive personal data, including IP addresses and cookie identifiers.
- Find where each recipient sits. Ask each vendor, or read its data processing terms, for the countries where it and its sub-processors handle the data. Include remote access by staff or group companies elsewhere, because the EDPB treats that as a transfer.
- Name the tool for each. For a US vendor, check the Data Privacy Framework List and keep a dated copy of the entry. For any vendor that is not covered by an adequacy decision, make sure a signed set of the Commission’s 2021 standard contractual clauses is in place, or binding corporate rules inside a group. Contracts that still use the older clauses should be replaced.
- Assess where clauses are the tool. The EDPB’s step three asks you to look at the destination’s law and practice for your specific transfer and, if needed, add supplementary measures. Keep a short written note of what you decided. If you cannot do this, a vendor hosting inside the EU is an option.
- Write the sentence in your privacy policy. For each destination, name the country, say whether it rests on an adequacy decision or on safeguards, and say how a visitor can get a copy of those safeguards, as Article 13(1)(f) asks. Update it when a tool is added or removed.
- Re-scan. Run a scan again after the change. EU-06 should show the policy naming a mechanism for each destination the page reached.
Whether a particular transfer is covered is a question for your legal adviser, and Peeky reports only what it sees.
Questions
Do I need standard contractual clauses to use a US service?
Only if the US company is not covered by an adequacy decision. If it is on the Data Privacy Framework List, the EDPB says the transfer can rest on that decision without a further transfer tool. If it is not, Article 46 expects safeguards such as the Commission's standard contractual clauses.
Check the list for each vendor, because the answer is per company, not per country.
What is the EU-US Data Privacy Framework?
It is the Commission's adequacy decision of 10 July 2023 for US organisations that appear on the Data Privacy Framework List. A transfer to a listed organisation needs no Article 46 tool and no supplementary measures. The General Court dismissed a challenge to it on 3 September 2025, and that judgment can be appealed on points of law.
What did Schrems II change for websites?
It made the sender responsible for checking that a transfer tool works in practice. On 16 July 2020 the Court of Justice invalidated the Privacy Shield and upheld standard contractual clauses, on the footing that the exporter checks the destination's law and adds measures where needed. The EDPB's recommendations turn that into a step-by-step process.
What does Article 46 of the GDPR require?
Article 46(1) lets a controller transfer data outside the EU, when there is no adequacy decision, only if it has provided appropriate safeguards and data subjects have enforceable rights and effective remedies. Paragraph 2 lists the safeguards, including standard data protection clauses and binding corporate rules. The safeguard has to work in practice, not only exist on paper.
Does my privacy policy have to name the transfer mechanism?
Yes, where you transfer data to a third country. Article 13(1)(f) asks for the fact of the transfer and either the adequacy decision or a reference to the safeguards and how to get a copy. The DPC found a privacy policy short of this when it did not name China as a destination.
Filed with
The rule
GDPR (Regulation (EU) 2016/679), Arts. 13(1)(f), 44 to 49 and 83(5)
Read the rule (GDPR (Regulation (EU) 2016/679), Arts. 13(1)(f), 44 to 49 and 83(5))Sources
- Regulation (EU) 2016/679 (GDPR), Official Journal L 119, 4 May 2016, Arts. 13, 44 to 46, 49 and 83
- Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses
- EDPB, Recommendations 01/2020 on measures that supplement transfer tools, version 2.0, adopted 18 June 2021
- EDPB, Information note on data transfers under the GDPR to the United States after the adequacy decision of 10 July 2023
- Court of Justice, press release No 91/20 on Case C-311/18 (Schrems II), 16 July 2020
- General Court, press release No 106/25 on Case T-553/23 (Latombe v Commission), 3 September 2025
- DPC (Ireland), conclusion of inquiry into Meta Ireland, 22 May 2023 (decision of 12 May 2023)
- Autoriteit Persoonsgegevens (Netherlands), fine of 290 million euro on Uber, 26 August 2024
- DPC (Ireland), TikTok fined 530 million euro, 2 May 2025
- Garante (Italy), provvedimento of 9 June 2022, docweb 9782890 (Caffeina Media S.r.l.)
- European Commission, EU-US data transfers (Data Privacy Framework, adopted 10 July 2023)
Last checked against the source:
For information only. Not legal advice.


