Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 44 General principle for transfers


Summary What does Article 44 of the GDPR regulation say?

This is a short but foundational article that acts as the gateway to the entire chapter governing transfers of personal data to third countries or international organisations.

It establishes the overarching rule: no such transfer can take place unless the conditions set out in this chapter are met by both the controller and the processor.

Crucially, it extends this requirement to onward transfers — meaning that if data is passed from a third country or international organisation to yet another third country or international organisation, the same rules apply.

The article's closing principle makes clear that the protections guaranteed by the Regulation must not be undermined at any point in the transfer chain.

Important points:

  • Ensure that any transfer of personal data to a third country or international organisation complies with the conditions laid down in this chapter — this obligation falls on both controllers and processors.
  • The rules extend to onward transfers, covering situations where data moves from one third country or international organisation to another.
  • The overarching purpose of this chapter is to ensure that the level of protection afforded to individuals by the Regulation is not weakened through the act of transfer.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod