Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 48 Transfers or disclosures not authorised by Union law
Summary What does Article 48 of the GDPR regulation say?
This article acts as a safeguard within the broader chapter on international data transfers.
It addresses a specific scenario: where a foreign court, tribunal, or administrative authority issues an order requiring a controller or processor to hand over personal data.
The article makes clear that such foreign orders cannot simply be acted upon — they are only recognised or enforceable if grounded in a formal international agreement, such as a mutual legal assistance treaty, between the requesting third country and either the Union or a Member State.
Important points:
- Controllers and processors must not comply with foreign judicial or administrative orders to transfer personal data unless those orders are backed by a valid international agreement with the EU or a Member State.
- The requirement for an international agreement applies to any form of recognition or enforceability of such foreign orders, without exception.
- Other lawful grounds for international data transfers established elsewhere in this chapter remain unaffected by this article.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Any judgment of a court or tribunal and any decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to this Chapter.
Relevant recitals
Recital 115 Risks from extraterritorial third-country law
Some third countries adopt laws, regulations and other legal acts which purport to directly regulate the processing activities of natural and legal persons under the jurisdiction of the Member States. This may include judgments of courts or tribunals or decisions of administrative authorities in third countries requiring a controller or processor to transfer or disclose personal data, and which are not based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State. The extraterritorial application of those laws, regulations and other legal acts may be in breach of international law and may impede the attainment of the protection of natural persons ensured in the Union by this Regulation. Transfers should only be allowed where the conditions of this Regulation for a transfer to third countries are met. This may be the case, inter alia, where disclosure is necessary for an important ground of public interest recognised in Union or Member State law to which the controller is subject.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
personal data