DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Reference · Infrastructure

Cross-border transfers, explained

Four mechanisms move data lawfully across borders. A dozen regimes require it to stay home. This page maps both.

Updated September 28, 2026 · digitalprivacyregs.com

Cross-border transfer rules decide where your stack can physically live. Four mechanisms cover most of the world, and a shortlist of localization regimes overrides all of them.

The four mechanisms

Adequacy

A government-to-government finding that the destination protects data well enough for free flows. The EU's list is the one that matters most; the UK, Japan, Korea, Brazil and others run their own versions. The full EU list is on the adequacy page.

Standard contractual clauses

Regulator-approved contract terms bolted onto vendor agreements. The EU's 2021 modules are the global default, but Brazil (2024 regulation, adaptation deadline passed August 2025), Turkey (with a five-business-day filing duty), China (with a government filing) and the UK (IDTA and Addendum) each require their own paper. One vendor contract can need four different clause sets.

Binding corporate rules and certifications

Group-wide internal rules approved by regulators, plus certification schemes like the APEC CBPR. Heavy to obtain, durable once held.

The EU-US Data Privacy Framework

The 2023 adequacy arrangement for certified US companies, which restored a lawful default route for the transatlantic stack after Schrems II killed Privacy Shield. It has survived its annual reviews, and the EU's General Court upheld it in 2025. An appeal to the Court of Justice keeps a Schrems III ruling on the table, the standing tail risk every transfer assessment should mention. Switzerland runs a parallel Swiss-US framework, in force since September 2024.

Localization: where data must stay put

These regimes do not ask how well the destination protects data; they require it to remain on local soil, at least in primary form.

JurisdictionRule
RussiaCitizens’ data must be stored in Russia; transfers need prior notification to Roskomnadzor.
ChinaTransfers run through CAC security assessment, standard contract filing or certification; 2024 easing exempted low-volume and contract-necessary transfers.
KazakhstanCitizens’ personal data stored on in-country servers.
UzbekistanProcessing of citizens’ data on servers physically in Uzbekistan since 2021.
KyrgyzstanLocalization added by the 2021 amendments.
RwandaStorage in Rwanda by default unless the NCSA authorizes transfer.
ZambiaSensitive personal data must be processed and stored in Zambia.
VietnamTransfer impact assessment dossiers filed with the Ministry of Public Security; Data Law adds controls for core and important data.
India (sectoral)RBI payments-data localization persists under the DPDP regime.
Indonesia (sectoral)Public-sector and regulated-industry localization survives the PDP Law.

What a transfer program looks like

Map the flows (CRM, analytics, adtech, support tooling), classify each destination (adequate, DPF-certified, SCC-required, localized), execute the right paper, and record a short transfer impact assessment where the destination has surveillance-law exposure. The companies fined over transfers (Meta EUR 1.2B, TikTok EUR 530M, Uber EUR 290M, and Trip.com in China in 2026) were moving data on mechanisms that no longer held or had never been completed.

Cite this page: "Cross-Border Data Transfers: Mechanisms and Localization." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/transfers.html. Accessed [date].