Cross-border transfer rules decide where your stack can physically live. Four mechanisms cover most of the world, and a shortlist of localization regimes overrides all of them.
The four mechanisms
Adequacy
A government-to-government finding that the destination protects data well enough for free flows. The EU's list is the one that matters most; the UK, Japan, Korea, Brazil and others run their own versions. The full EU list is on the adequacy page.
Standard contractual clauses
Regulator-approved contract terms bolted onto vendor agreements. The EU's 2021 modules are the global default, but Brazil (2024 regulation, adaptation deadline passed August 2025), Turkey (with a five-business-day filing duty), China (with a government filing) and the UK (IDTA and Addendum) each require their own paper. One vendor contract can need four different clause sets.
Binding corporate rules and certifications
Group-wide internal rules approved by regulators, plus certification schemes like the APEC CBPR. Heavy to obtain, durable once held.
The EU-US Data Privacy Framework
The 2023 adequacy arrangement for certified US companies, which restored a lawful default route for the transatlantic stack after Schrems II killed Privacy Shield. It has survived its annual reviews, and the EU's General Court upheld it in 2025. An appeal to the Court of Justice keeps a Schrems III ruling on the table, the standing tail risk every transfer assessment should mention. Switzerland runs a parallel Swiss-US framework, in force since September 2024.
Localization: where data must stay put
These regimes do not ask how well the destination protects data; they require it to remain on local soil, at least in primary form.
| Jurisdiction | Rule |
|---|---|
| Russia | Citizens’ data must be stored in Russia; transfers need prior notification to Roskomnadzor. |
| China | Transfers run through CAC security assessment, standard contract filing or certification; 2024 easing exempted low-volume and contract-necessary transfers. |
| Kazakhstan | Citizens’ personal data stored on in-country servers. |
| Uzbekistan | Processing of citizens’ data on servers physically in Uzbekistan since 2021. |
| Kyrgyzstan | Localization added by the 2021 amendments. |
| Rwanda | Storage in Rwanda by default unless the NCSA authorizes transfer. |
| Zambia | Sensitive personal data must be processed and stored in Zambia. |
| Vietnam | Transfer impact assessment dossiers filed with the Ministry of Public Security; Data Law adds controls for core and important data. |
| India (sectoral) | RBI payments-data localization persists under the DPDP regime. |
| Indonesia (sectoral) | Public-sector and regulated-industry localization survives the PDP Law. |
What a transfer program looks like
Map the flows (CRM, analytics, adtech, support tooling), classify each destination (adequate, DPF-certified, SCC-required, localized), execute the right paper, and record a short transfer impact assessment where the destination has surveillance-law exposure. The companies fined over transfers (Meta EUR 1.2B, TikTok EUR 530M, Uber EUR 290M, and Trip.com in China in 2026) were moving data on mechanisms that no longer held or had never been completed.