- The main players
- When the GDPR reaches an Australian business
- The general rule: protection travels with the data
- Route one: an adequacy decision
- The Schrems II complication
- Derogations: the residual route
- Where the regime bites for Australian businesses
- When to bring in a lawyer
- Where most of the exposure sits
The European Union's General Data Protection Regulation, or the GDPR, has applied since 25 May 2018 and governs how personal data about people in the EU is collected, used and moved. For an Australian business, the regulation usually enters the picture in one of two ways: the business sells goods or services to customers in the EU, or an EU counterparty sends it customer data to host or process. In either case, the GDPR's rules on international transfers decide whether that data may lawfully leave the EU at all.
This article walks through how those transfer rules actually operate: when the GDPR reaches an Australian business, the general restriction on transfers outside the EU, the two main lawful routes for moving data (adequacy decisions and appropriate safeguards), the fallout of the 2020 Schrems II ruling, and the residual options. If your business already holds EU customer data, or is about to start, this is the regime that determines whether you are lawfully entitled to keep it.
The main players
Before the mechanics, it helps to know who does what. A transfer of personal data out of the EU typically involves:
- EU controller: the business established in the EU, or otherwise subject to the GDPR, that decides how and why personal data is processed and wants to send it outside the EU.
- Data importer: the overseas recipient, which might be an Australian company, a cloud provider such as Amazon Web Services, or a parent or subsidiary in another country.
- EU data subjects: the individuals whose personal data is being transferred. They hold enforceable rights under the GDPR, including access, correction, erasure (the "right to be forgotten") and data portability.
- Supervisory authorities: the independent data protection authorities in each EU member state that investigate complaints, audit and impose fines.
- European Commission and European Data Protection Board: the Commission adopts adequacy decisions and approves standard contractual clauses; the EDPB issues opinions and guidance that shape how the rules are applied.
The tension in the system is straightforward. The GDPR wants the protection it gives to EU residents to keep applying to their data wherever it goes. The business wants to move data cheaply and freely. The transfer regime is the compromise: data may leave the EU, but only through a route that keeps the protection attached.
When the GDPR reaches an Australian business
The GDPR applies directly to businesses established in the EU. But it also reaches well beyond the EU's borders. Under Article 3 of the GDPR, the regulation applies to a controller or processor not established in the EU where its processing relates to:
- offering goods or services to individuals in the EU, whether or not payment is required; or
- monitoring the behaviour of individuals in the EU, where that behaviour takes place in the EU.
The Office of the Australian Information Commissioner (OAIC) puts it plainly: Australian businesses of any size may need to comply if they have an establishment in the EU, if they offer goods and services in the EU, or if they monitor the behaviour of individuals in the EU. A website that targets EU customers by offering ordering in a European language or pricing in euros can be enough. So can tracking EU visitors and profiling them for advertising.
Note the difference from Australian privacy law here. The Privacy Act 1988 (Cth) mostly applies to organisations with an annual turnover above $3 million, but the GDPR has no size threshold. A two-person Australian startup selling an app to EU users is squarely within scope. Non-EU controllers and processors covered by the GDPR must generally also appoint a representative established in an EU member state under Article 27, who acts as the point of contact for regulators and individuals.
The general rule: protection travels with the data
The GDPR treats a transfer to a country outside the EU and the European Economic Area as a risk to be managed, not an everyday event. Article 44 of the GDPR states the general principle: any transfer of personal data to a third country may take place only if the conditions in Chapter V of the regulation are complied with, so that the level of protection the GDPR guarantees is not undermined.
The word "transfer" is wider than you might think. It covers sending data to an overseas contractor, uploading it to a cloud server located overseas, letting an overseas parent company access a shared database, and even remote access by support staff in another country. If EU personal data becomes accessible from outside the EU, a transfer has occurred and Chapter V must be satisfied.
Chapter V offers two main routes for a lawful transfer: an adequacy decision under Article 45, or appropriate safeguards under Article 46. A residual set of derogations under Article 49 covers specific situations. There is no general "the recipient is a reputable company" route. The mechanism must be in place before the data moves.
Route one: an adequacy decision
An adequacy decision is the cleanest route. Under Article 45, the European Commission can determine that a country outside the EU provides an adequate level of data protection. The decision follows a Commission proposal, an opinion from the European Data Protection Board and approval from representatives of the EU member states. Once in place, personal data can flow to that country just as it flows between EU member states, with no further safeguard required.
The Commission has so far recognised Andorra, Argentina, Brazil, Canada (for commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States (for organisations participating in the EU-US Data Privacy Framework) and Uruguay, along with the European Patent Organisation, as providing adequate protection.
Australia is not on the list. That matters for every Australian business in this space: an EU business cannot rely on Australia's privacy laws to justify a transfer here, and an Australian business holding EU customer data will almost certainly have received it under one of the safeguard mechanisms below rather than an adequacy decision.
Route two: appropriate safeguards
Where there is no adequacy decision, Article 46 of the GDPR allows a transfer if the parties have put in place "appropriate safeguards", on the condition that enforceable data subject rights and effective legal remedies remain available to the individuals. The practical options are standard contractual clauses, binding corporate rules, and, less commonly, approved codes of conduct or certification mechanisms.
Standard contractual clauses
Standard contractual clauses, or SCCs, are pre-approved model contract terms issued by the European Commission. When an EU business and an overseas recipient sign a contract incorporating them, the transfer can proceed without seeking individual approval from a supervisory authority. SCCs are by far the most common mechanism, and the one an Australian business will most often be asked to sign as the data importer.
The current set was adopted on 4 June 2021 by Commission Implementing Decision (EU) 2021/914. These modernised clauses replaced the three earlier sets issued under the EU's 1995 Data Protection Directive. New contracts had to use the 2021 clauses from 27 September 2021, and contracts based on the old clauses had to be migrated by 27 December 2022. If your business signed SCCs before 2021 and has not updated them, they are likely no longer a valid transfer mechanism.
The 2021 clauses come in four modules so the parties can select the right one for their relationship: controller to controller, controller to processor, processor to processor, and processor to controller. Whichever module applies, the clauses oblige the data importer to:
- apply security measures appropriate to the data;
- help the exporter respond to EU individuals exercising their rights, such as access or erasure;
- cooperate with EU supervisory authorities;
- tell the exporter if it cannot comply because of a conflict with local law; and
- delete or return the data when the contract ends.
The clauses also include the specific annexes the parties must complete, which describe the data being transferred, the categories of data subjects, the security measures, and the sub-processors the importer is allowed to use.
Binding corporate rules
For multinational groups, binding corporate rules (BCRs) are an alternative. These are a set of internal data protection rules covering every entity in a corporate group, approved by a lead supervisory authority, that bind each entity wherever it operates. BCRs suit large groups that move data constantly between subsidiaries. For most Australian small and medium businesses, SCCs will be the relevant mechanism.
The Schrems II complication
If SCCs are the workhorse of international transfers, the 2020 ruling in Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (Case C-311/18, decided 16 July 2020) is the reason they can no longer be signed on autopilot.
The Court of Justice of the European Union invalidated the EU-US Privacy Shield, the framework that had let US companies receive EU data by self-certifying, because US surveillance law did not provide essentially equivalent protection. The Court upheld the standard contractual clauses, but with a catch: before relying on SCCs, the exporter must verify, case by case, whether the laws of the destination country let the importer actually honour the clauses, and must add supplementary measures if they do not. In practice this means a transfer impact assessment: a documented review of the destination country's law, the data involved, and the additional protections needed.
The Privacy Shield's replacement, the EU-US Data Privacy Framework, received an adequacy decision on 10 July 2023, so transfers to US companies that have self-certified under the framework can now proceed on that basis. But the history is instructive: the framework replaced an arrangement that the EU's highest court struck down, and the new one has already been challenged. A transfer mechanism that looks safe today can be invalidated tomorrow, which is why the assessment discipline matters.
Derogations: the residual route
Article 49 provides derogations that allow transfers in specific situations without an adequacy decision or appropriate safeguards. They include transfers made with the data subject's explicit informed consent after being told of the risks, transfers necessary for performing a contract with the data subject, transfers needed for legal claims, and transfers to protect someone's vital interests.
These derogations are narrow. The European Data Protection Board treats them as exceptions rather than a general workaround, and a derogation such as "occasional transfers" cannot be used to justify a routine, large-scale transfer programme. If an Australian business regularly receives EU customer data, the transfer should be built on SCCs, not on consent boxes or contract-performance arguments.
Where the regime bites for Australian businesses
Several practical situations bring this home:
- Cloud hosting: An EU business that puts customer data in an Australian cloud, or an Australian business that hosts EU customers' data on servers outside the EU, needs a transfer mechanism for each hop. AWS, Azure and similar providers offer SCC-based arrangements precisely because of this.
- Sub-processors: If your Australian business is the data importer and you in turn use a sub-processor, the SCCs require the exporter's authorisation and a chain of obligations flowing down to the sub-processor.
- Intra-group transfers: An Australian subsidiary receiving EU customer data from its European parent cannot rely on being "part of the same company". Without BCRs or SCCs, the transfer is unlawful.
- Dual compliance: The GDPR and the Privacy Act operate side by side. Australian Privacy Principle 8 requires an APP entity to take reasonable steps to ensure an overseas recipient does not breach the Australian Privacy Principles before disclosing personal information, subject to exceptions such as a reasonable belief that the recipient is subject to substantially similar laws, or informed consent. Section 16C of the Privacy Act 1988 (Cth) goes further: an overseas recipient's acts are treated as the APP entity's own acts, so the Australian business stays accountable. A compliant transfer must satisfy both regimes.
- Enforcement: A supervisory authority in the EU can investigate a transfer chain, and fines under Article 83 reach up to €20 million or 4% of a company's global annual turnover, whichever is higher. Even where the regulator's attention falls on the EU exporter, the Australian importer can face contractual claims under the SCCs if its conduct put the exporter in breach.
When to bring in a lawyer
The transfer rules reward getting in early. A privacy lawyer can help with the points where businesses most often trip:
- assessing whether the GDPR applies to your business at all under Article 3;
- mapping your data flows so every transfer of EU personal data is identified;
- completing transfer impact assessments and documenting supplementary measures where the destination country's laws fall short;
- negotiating and completing the SCC annexes, including the sub-processor list and security measures;
- structuring binding corporate rules if your group moves data internally; and
- building a compliance program that satisfies the GDPR and the Privacy Act together, including how to handle data subject requests and supervisory authority inquiries.
Much of this work is documentation and analysis that is far cheaper to do properly before a regulator or a contract dispute focuses attention on it.
Where most of the exposure sits
The single fact that should shape your approach is this: because Australia has no adequacy decision, every piece of EU personal data an Australian business holds arrived under a safeguard mechanism, most likely SCCs, and every transfer you make of that data must satisfy the same Chapter V conditions. That makes the transfer paperwork the point of maximum exposure, not a back-office formality.
After Schrems II, SCCs are only as good as the assessment behind them. The business that signs them without documenting whether the recipient can honour them has signed a mechanism that may not hold up. Review your transfer chain now, while the data volumes are manageable, rather than after a complaint or an inquiry. A focused review with a lawyer is a modest cost measured against a fine of up to €20 million or 4% of global turnover, and a free initial consultation is a sensible first step to finding out where your business actually stands.