Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 44 General principle for transfers
Summary What does Article 44 of the GDPR regulation say?
This is a short but foundational article that acts as the gateway to the entire chapter governing transfers of personal data to third countries or international organisations.
It establishes the overarching rule: no such transfer can take place unless the conditions set out in this chapter are met by both the controller and the processor.
Crucially, it extends this requirement to onward transfers — meaning that if data is passed from a third country or international organisation to yet another third country or international organisation, the same rules apply.
The article's closing principle makes clear that the protections guaranteed by the Regulation must not be undermined at any point in the transfer chain.
Important points:
- Ensure that any transfer of personal data to a third country or international organisation complies with the conditions laid down in this chapter — this obligation falls on both controllers and processors.
- The rules extend to onward transfers, covering situations where data moves from one third country or international organisation to another.
- The overarching purpose of this chapter is to ensure that the level of protection afforded to individuals by the Regulation is not weakened through the act of transfer.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.
Relevant recitals
Recital 101 Safeguards for international transfers
Flows of personal data to and from countries outside the Union and international organisations are necessary for the expansion of international trade and international cooperation. The increase in such flows has raised new challenges and concerns with regard to the protection of personal data. However, when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by this Regulation should not be undermined, including in cases of onward transfers of personal data from the third country or international organisation to controllers, processors in the same or another third country or international organisation. In any event, transfers to third countries and international organisations may only be carried out in full compliance with this Regulation. A transfer could take place only if, subject to the other provisions of this Regulation, the conditions laid down in the provisions of this Regulation relating to the transfer of personal data to third countries or international organisations are complied with by the controller or processor.
Recital 114 Enforceable rights absent adequacy decision
In any case, where the Commission has taken no decision on the adequate level of data protection in a third country, the controller or processor should make use of solutions that provide data subjects with enforceable and effective rights as regards the processing of their data in the Union once those data have been transferred so that that they will continue to benefit from fundamental rights and safeguards.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
recipient
Definition
international organisation
Definition
third party
Definition
personal data