Articles 44–49 GDPR · General Court Case T-553/23 (3 Sept 2025)

International Data Transfers Under GDPR: Adequacy, SCCs and the EU-US Data Privacy Framework After the Latombe Ruling

Grounded in Regulation (EU) 2016/679, Commission Implementing Decision (EU) 2023/1795 and General Court Case T-553/23 · Stand: 07/2026 · Last reviewed 2026-07-26

Sending personal data outside the EEA is only lawful under GDPR if it rests on one of three Chapter V mechanisms: an adequacy decision (Article 45), appropriate safeguards such as Standard Contractual Clauses (Article 46), or a narrow Article 49 derogation. One of the most commercially significant of these corridors — EU to US — currently runs on the EU-US Data Privacy Framework adequacy decision, but that decision has already survived one annulment challenge (General Court, 3 September 2025) and is now on appeal to the Court of Justice, following the same pattern that struck down its two predecessors, Safe Harbor and Privacy Shield.

Key facts at a glance

Legal basis
Articles 44–49, Regulation (EU) 2016/679
Three mechanisms
Adequacy decision · appropriate safeguards (SCCs/BCRs) · Art. 49 derogations
EU-US mechanism
Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795 (10 July 2023)
Latest ruling
General Court Case T-553/23, Latombe v Commission — dismissed, 3 Sept 2025
Currently pending
CJEU appeal, Case C-703/25 P (brought 31 Oct 2025)
Prior precedent
Safe Harbor (Schrems I, 2015) and Privacy Shield (Schrems II, 2020) were both annulled

On this page

  1. What are the three lawful transfer mechanisms?
  2. Which countries have an adequacy decision?
  3. Is the EU-US Data Privacy Framework still valid?
  4. Do you still need SCCs if a vendor is DPF-certified?
  5. What is a Transfer Impact Assessment?
  6. When can you use the Article 49 derogations?
  7. FAQ

What are the three lawful ways to transfer personal data outside the EEA?

An adequacy decision, appropriate safeguards, or a narrow derogation — and in that order of preference, because each removes progressively less risk from the exporter. Article 45 lets the Commission declare that a third country’s laws already ensure "an adequate level of protection," in which case a transfer needs no further authorisation. Without that, Article 46 allows a transfer if the controller or processor has "provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available" — in practice, almost always Standard Contractual Clauses (Commission-approved model clauses) or Binding Corporate Rules for intra-group transfers. Only if neither route is available do the narrow Article 49 derogations apply, and even then only for non-repetitive, limited transfers.

Which countries currently have an EU adequacy decision?

A defined, periodically-reviewed list that currently includes Andorra, Argentina, Brazil, Canada (commercial organisations only), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay and the United States (only via the Data Privacy Framework, and only for self-certified organisations). The newest addition is Brazil, where the Commission adopted its adequacy decision on 26 January 2026, alongside Brazil’s own mirrored recognition of the EU under its data protection law (LGPD) — a mutual adequacy finding, rather than a one-way EU decision alone. Before any decision, Article 45(2) requires the Commission to assess the rule of law, human rights protections, data protection legislation and independent supervisory authorities in the destination country, and Article 45(3) then requires that assessment to be repeated in a periodic review at least every four years. The list is not static: the Commission can amend, suspend or repeal a decision if a country’s level of protection changes — which is exactly the risk now sitting over the Data Privacy Framework while the Latombe appeal is pending.

Is the EU-US Data Privacy Framework still valid? The Latombe ruling

Yes, for now — the General Court dismissed a challenge to the Data Privacy Framework’s adequacy decision in its entirety on 3 September 2025, but the applicant has appealed to the Court of Justice, so the question is not finally closed. In Case T-553/23, French politician Philippe Latombe sought annulment of Commission Implementing Decision (EU) 2023/1795, arguing that the US Data Protection Review Court (DPRC) created by Executive Order 14086 lacked genuine independence and that US intelligence agencies could still collect data in bulk without prior judicial authorisation, among several pleas raised. On these two central points, the General Court held that "essential equivalence" does not require the third country’s institutional arrangements to be identical to the EU’s, only that they be effective in practice, and it found the DPRC’s appointment rules, for-cause dismissal protections and binding decision-making authority sufficient to meet Article 47 Charter standards — even though the DPRC was created by executive order rather than legislation. On bulk collection, it accepted that ex post judicial review by the DPRC satisfies the Schrems II requirement, without needing prior authorisation before each collection. The Court dismissed the action in its entirety and ordered Latombe to bear the costs. He appealed to the Court of Justice on 31 October 2025 (Case C-703/25 P), which was still pending when this guide was last reviewed.

That pending appeal matters for exam purposes because it is not the first time this exact pattern has played out. The CJEU annulled the original EU-US Safe Harbor framework in Schrems I (2015) and its successor Privacy Shield in Schrems II (2020) — both times after a Commission adequacy decision had already been in force for years. The Data Privacy Framework was built specifically to answer the Schrems II findings, and the General Court’s 2025 judgment in Latombe is the first ruling to test whether it succeeded — but it is only a first instance ruling in this specific case, now under appeal. Whether the Court of Justice reaches the same conclusion once it decides Case C-703/25 P remains genuinely open.

See how this is tested in practice

International transfer mechanisms are a heavily tested GDPR topic. Practise recognising Article 45, 46 and 49 scenarios in realistic multiple-choice questions.

Start free Try 30 questions free — no time limit, no credit card.

Do you still need SCCs if your US vendor is Data Privacy Framework-certified?

Not legally — the adequacy decision alone is sufficient for a transfer to a self-certified organisation — but it only covers organisations that have actively self-certified, and it is not automatically permanent. A US company must apply to the US Department of Commerce, commit to the Framework’s Principles, and appear on the official Data Privacy Framework List; a vendor that has not done so still needs Standard Contractual Clauses or another Article 46 safeguard, regardless of how the company markets itself. Because the Latombe appeal leaves a real, if uncertain, possibility that the adequacy decision could later be annulled — as happened to both of its predecessors — some organisations keep SCCs in place as a fallback even where DPF certification would be enough on its own; one legal-services FAQ summarising this exact question for in-house counsel puts it plainly: "due to the possibility that DPF could potentially be invalidated… some companies are taking a ‘belt and suspenders’ approach, and are choosing to self-certify under DPF and to continue to rely on SCCs."

What is a Transfer Impact Assessment, and when do you need one?

A documented, case-by-case assessment of whether the destination country’s law and practice undermines the protections in your Standard Contractual Clauses — required whenever you rely on SCCs (or BCRs) rather than an adequacy decision. The requirement comes directly from the CJEU’s Schrems II ruling: contractual clauses alone cannot override a third country’s public authority access powers, so the exporter must check first. The EDPB’s Recommendations 01/2020 set out a six-step methodology — map the transfer, identify the safeguard used, assess whether local law or practice impinges on its effectiveness, identify supplementary measures if needed, take the necessary formal steps, and re-evaluate at appropriate intervals. A transfer relying on an adequacy decision does not need this assessment, because the Commission has already made that determination for the whole country.

When can you use the Article 49 derogations instead?

Only as a fallback for occasional, limited transfers where neither an adequacy decision nor appropriate safeguards are available — not as a routine, repeated transfer mechanism. Article 49(1) lists specific grounds, including explicit informed consent to the transfer, necessity for performing a contract with the data subject, necessity for important reasons of public interest, and necessity to establish, exercise or defend legal claims. Where none of these grounds apply and no other safeguard is available, a narrower residual derogation permits a transfer only if it is not repetitive, concerns a limited number of data subjects, is necessary for compelling legitimate interests that are not overridden by the data subject’s own rights, and the controller has assessed the circumstances and put suitable safeguards around it. Two further steps are separately mandatory, not optional extras: the controller must inform the supervisory authority of the transfer, and must independently inform the data subject of the transfer and of the compelling legitimate interests pursued. EDPB guidance treats Article 49 as an exception to be used sparingly, not a substitute for setting up SCCs when transfers are regular.

MechanismWhen it appliesExtra work required
Adequacy decision (Art. 45)Destination country/sector on the Commission’s list (e.g. DPF-certified US org)None — treated like an intra-EEA transfer
SCCs / BCRs (Art. 46)No adequacy decision, but a contractual or intra-group safeguard is in placeTransfer Impact Assessment, possible supplementary measures
Art. 49 derogationNo adequacy decision or safeguard available; transfer is occasional and limitedCase-by-case justification; DPA and data subject must both be informed; not for repeated transfers

Preparing for a DPO / GDPR certification exam?

GDPR Exam Trainer turns material like this into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.

Create your free account No in-person course required · Cancel anytime.

Frequently asked questions

Is it still legal to send personal data to a US company under GDPR?

Yes, if the transfer relies on one of the three Chapter V mechanisms: the EU-US Data Privacy Framework adequacy decision (only for US organisations that have self-certified), Standard Contractual Clauses or Binding Corporate Rules with a Transfer Impact Assessment, or one of the narrow Article 49 derogations. Sending data to a US company that has done none of these is not automatically lawful.

Does every US company automatically qualify for the Data Privacy Framework?

No. Only US organisations that have actively self-certified with the US Department of Commerce and appear on the official Data Privacy Framework List are covered by the adequacy decision. A US vendor that has not self-certified needs a separate lawful transfer mechanism, such as Standard Contractual Clauses.

What happened in the Latombe case?

French politician Philippe Latombe asked the EU General Court to annul the Commission’s 2023 adequacy decision for the Data Privacy Framework, arguing US surveillance safeguards were insufficient. On 3 September 2025 the Court dismissed the action in its entirety (Case T-553/23) and upheld the decision. Latombe appealed to the Court of Justice on 31 October 2025 (Case C-703/25 P), which had not yet ruled as of this guide’s last review.

Has an EU-US data transfer framework ever been struck down before?

Yes, twice. The CJEU annulled the original Safe Harbor framework in Schrems I (2015) and its successor Privacy Shield in Schrems II (2020), both times over concerns about US government surveillance access and the lack of an effective remedy for EU individuals. The Data Privacy Framework was designed to address those specific findings, and the General Court’s 2025 Latombe judgment is the first ruling to test whether it succeeded — but the appeal to the CJEU means the question is not yet finally settled.

Do I need a Transfer Impact Assessment if I use Standard Contractual Clauses?

Yes. Since the CJEU’s Schrems II ruling, using SCCs is not enough on its own — the exporter must also assess, case by case, whether the law and practice of the destination country undermines the SCCs’ protections, and add supplementary technical, contractual or organisational measures if it does. The EDPB’s Recommendations 01/2020 set out the six-step methodology for this assessment.

Primary sources

This guide summarises the GDPR, Commission Implementing Decision (EU) 2023/1795 and General Court Case T-553/23 for study and general information. It is not legal advice; article numbers, case facts and the appeal status are simplified for clarity and may change once the Court of Justice rules on Case C-703/25 P. For a binding interpretation, consult the official text on EUR-Lex, the EDPB, your competent supervisory authority, or a qualified data protection lawyer.