Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 48 Transferts ou divulgations non autorisés par le droit de l'Union


Summary What does Article 48 of the GDPR regulation say?

This article acts as a safeguard within the broader chapter on international data transfers.

It addresses a specific scenario: where a foreign court, tribunal, or administrative authority issues an order requiring a controller or processor to hand over personal data.

The article makes clear that such foreign orders cannot simply be acted upon — they are only recognised or enforceable if grounded in a formal international agreement, such as a mutual legal assistance treaty, between the requesting third country and either the Union or a Member State.

Important points:

  • Controllers and processors must not comply with foreign judicial or administrative orders to transfer personal data unless those orders are backed by a valid international agreement with the EU or a Member State.
  • The requirement for an international agreement applies to any form of recognition or enforceability of such foreign orders, without exception.
  • Other lawful grounds for international data transfers established elsewhere in this chapter remain unaffected by this article.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

Toute décision d'une juridiction ou d'une autorité administrative d'un pays tiers exigeant d'un responsable du traitement ou d'un sous-traitant qu'il transfère ou divulgue des données à caractère personnel ne peut être reconnue ou rendue exécutoire de quelque manière que ce soit qu'à la condition qu'elle soit fondée sur un accord international, tel qu'un traité d'entraide judiciaire, en vigueur entre le pays tiers demandeur et l'Union ou un État membre, sans préjudice d'autres motifs de transfert en vertu du présent chapitre.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod