Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 48 Transfers or disclosures not authorised by Union law


Summary What does Article 48 of the GDPR regulation say?

This article acts as a safeguard within the broader chapter on international data transfers.

It addresses a specific scenario: where a foreign court, tribunal, or administrative authority issues an order requiring a controller or processor to hand over personal data.

The article makes clear that such foreign orders cannot simply be acted upon — they are only recognised or enforceable if grounded in a formal international agreement, such as a mutual legal assistance treaty, between the requesting third country and either the Union or a Member State.

Important points:

  • Controllers and processors must not comply with foreign judicial or administrative orders to transfer personal data unless those orders are backed by a valid international agreement with the EU or a Member State.
  • The requirement for an international agreement applies to any form of recognition or enforceability of such foreign orders, without exception.
  • Other lawful grounds for international data transfers established elsewhere in this chapter remain unaffected by this article.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod