Skip to content
RGPD

Article 46

Transfers subject to appropriate safeguards

1.   In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.

2.   The appropriate safeguards referred to in paragraph 1 may be provided for, without requiring any specific authorisation from a supervisory authority, by:

(a)

a legally binding and enforceable instrument between public authorities or bodies;

(b)

binding corporate rules in accordance with Article 47;

(c)

standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2);

(d)

standard data protection clauses adopted by a supervisory authority and approved by the Commission pursuant to the examination procedure referred to in Article 93(2);

(e)

an approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights; or

(f)

an approved certification mechanism pursuant to Article 42 together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects' rights.

3.   Subject to the authorisation from the competent supervisory authority, the appropriate safeguards referred to in paragraph 1 may also be provided for, in particular, by:

(a)

contractual clauses between the controller or processor and the controller, processor or the recipient of the personal data in the third country or international organisation; or

(b)

provisions to be inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data subject rights.

4.   The supervisory authority shall apply the consistency mechanism referred to in Article 63 in the cases referred to in paragraph 3 of this Article.

5.   Authorisations by a Member State or supervisory authority on the basis of Article 26(2) of Directive 95/46/EC shall remain valid until amended, replaced or repealed, if necessary, by that supervisory authority. Decisions adopted by the Commission on the basis of Article 26(4) of Directive 95/46/EC shall remain in force until amended, replaced or repealed, if necessary, by a Commission Decision adopted in accordance with paragraph 2 of this Article.

Common Questions

Frequently Asked Questions

When do I need appropriate safeguards under Article 46?

Article 46 applies when there is no adequacy decision under Article 45(3) for the destination. In that case a controller or processor may transfer personal data to a third country or an international organisation only if it has provided appropriate safeguards.

There is a second condition: enforceable data subject rights and effective legal remedies must be available for the people whose data is transferred.

Which safeguards can I use without specific authorisation from a supervisory authority?

Article 46(2) lists six instruments that work without any specific authorisation from a supervisory authority:

  • a legally binding and enforceable instrument between public authorities or bodies
  • binding corporate rules in accordance with Article 47
  • standard data protection clauses adopted by the Commission
  • standard data protection clauses adopted by a supervisory authority and approved by the Commission
  • an approved code of conduct under Article 40, together with binding and enforceable commitments of the controller or processor in the third country
  • an approved certification mechanism under Article 42, also combined with binding and enforceable commitments

For the code of conduct and the certification mechanism, those commitments include applying the safeguards as regards data subjects' rights.

Which transfer tools require prior authorisation from the supervisory authority?

Under Article 46(3), two options need authorisation from the competent supervisory authority: contractual clauses between the controller or processor and the controller, processor or recipient of the personal data in the third country or international organisation, and provisions inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data subject rights.

In those cases the supervisory authority applies the consistency mechanism referred to in Article 63.

Do authorisations granted under Directive 95/46/EC remain valid?
Yes. Authorisations by a Member State or supervisory authority on the basis of Article 26(2) of Directive 95/46/EC remain valid until amended, replaced or repealed, if necessary, by that supervisory authority. Likewise, decisions adopted by the Commission on the basis of Article 26(4) of that Directive remain in force until amended, replaced or repealed, if necessary, by a Commission Decision adopted in accordance with Article 46(2).