A six-person architecture practice, a brochure website, a contact form. Behind the front page sit three US tools: the newsletter goes out through an email service, quotes are filed in a shared cloud drive, and a chat bubble in the bottom corner handles visitor questions. Every time a prospect leaves a name and an email address, that data leaves the European Union. The owner has been told that "transfers to the United States are no longer allowed". That is not what the regulation says. The GDPR does not prohibit transfers: it sets conditions for them, and it offers three routes to make them lawful. This article walks through the three routes and ends with a five-step method for a small business.
Disclaimer: this article is provided for information only and does not constitute legal advice. The texts cited are those in force at the time of writing; for a specific situation, consult a qualified legal professional.
Before reading on, put these three questions to each of your providers. The answers decide which route applies.
Chapter V of the GDPR, titled "Transfers of personal data to third countries or international organisations", opens with a general principle. Article 44 GDPR states that a transfer "shall take place only if [...] the conditions laid down in this Chapter are complied with by the controller and processor", including for onward transfers from the third country. The regulation does not define the word "transfer". The European Data Protection Board filled that gap in its Guidelines 05/2021 (version 2.0, adopted on 14 February 2023) with three cumulative criteria:
The same guidelines add that remote access from a third country, even if it only means displaying data on a screen for support or administration, and storage in a cloud located outside the EEA, are also considered a transfer when the three criteria are met. For the architecture practice, all three tools are caught: the email service stores the addresses in the United States, the cloud drive does too, and the chat tool gives a support team outside the EU access to the conversations.
One reassuring point: the country where a company is incorporated is not the test. What matters is where the data can be reached for that particular processing. A US provider that offers EU hosting with no access from outside may not be transferring at all. Ask the provider in writing and keep the answer.
Article 45(1) GDPR allows a transfer "where the Commission has decided that the third country, a territory or one or more specified sectors within that third country [...] ensures an adequate level of protection". Such a transfer "shall not require any specific authorisation". It is the simplest route: nothing to sign, nothing to assess yourself.
For the United States, that decision exists: Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the EU-US Data Privacy Framework (DPF). Its Article 1 is precise: the United States ensures an adequate level of protection for personal data transferred "to organisations in the United States that are included in the 'Data Privacy Framework List'", maintained and published by the US Department of Commerce. Three practical consequences follow:
The decision was challenged before the General Court of the European Union. In its judgment of 3 September 2025 in case T-553/23, the General Court (Tenth Chamber, Extended Composition) dismissed the action. At the time of writing, Decision 2023/1795 is therefore in force. Article 45(3) GDPR also provides that every adequacy decision includes a mechanism for periodic review, at least every four years: the position can change, which is one more reason to date your checks.
When the provider is not on the DPF list, or sits in another country with no adequacy decision, the next stop is Article 46 GDPR. Paragraph 1 allows the transfer if the controller or processor "has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available". Paragraph 2(c) lists, among those safeguards, "standard data protection clauses adopted by the Commission".
Those clauses are the ones in Commission Implementing Decision (EU) 2021/914 of 4 June 2021. They come in four modules depending on the roles of the parties; for a small business handing data to an online tool, module two (controller to processor) is the usual one. In practice the clauses are not negotiated: the provider builds them into its data processing addendum (the "DPA"), and the customer accepts them by signing or ticking a box. The work on the customer's side is to find that addendum, confirm that it refers to Decision 2021/914, and file a copy.
The clauses do not work alone. In its judgment of 16 July 2020 in case C-311/18, the Court of Justice (Grand Chamber) held that the assessment of the level of protection "must, in particular, take into consideration" both the contractual clauses agreed with the recipient and, as regards access by the public authorities of the third country, "the relevant aspects of the legal system of that third country". This is the origin of what is now called a transfer impact assessment. The EDPB set out the method in its Recommendations 01/2020 (version 2.0, 18 June 2021). For a small business, a reasonable version of that assessment fits on one page per provider: which country, which data, which transfer tool, which technical measures the provider applies (encryption, EU hosting), and a date.
Article 49 GDPR opens with a condition: it applies only "in the absence of an adequacy decision [...] or of appropriate safeguards". It then lists specific situations, among them the explicit consent of the person, informed of the risks, and a transfer "necessary for the performance of a contract between the data subject and the controller". The French supervisory authority, on its page on transfers outside the EU, describes these exceptions as usable only in particular situations.
For a small business the conclusion is short: Article 49 is not a route for a tool used every day. A newsletter sent monthly to the whole list is not a particular situation. A derogation can cover an isolated case; it does not replace the DPF list or the standard clauses.
Once the route is chosen, three articles of the regulation ask for a visible trace of it.
The table below takes the three tools of the architecture practice and the most common situations. It does not replace a provider-by-provider check.
| Situation | Transfer? | Preferred route | Where to record it |
|---|---|---|---|
| US email service, provider on the DPF list | Yes | Adequacy decision, Article 45 GDPR and Decision 2023/1795 | Privacy policy, record, dated screenshot of the list entry |
| US cloud storage, provider not on the DPF list | Yes | Standard clauses, Article 46 GDPR and Decision 2021/914, in the DPA | Privacy policy, record, copy of the DPA, one-page assessment |
| Support chat hosted in the EU, support team outside the EU | Yes, through remote access | DPF list if the provider is on it, otherwise standard clauses (Article 46 GDPR) | Privacy policy, record, copy of the DPA |
| US hosting provider with an EU region enabled and access limited to the EU, confirmed in writing | No, if the three criteria are not met | None; keep the provider's written confirmation | Record (hosting location), Article 28 GDPR contract |
The free Sitetals check reviews your home page and reports, among other things, whether a legal notice page or a privacy policy page is missing or unreachable, and which third-party services your site loads. It is a starting point for the review described above, not a replacement for it.
Also worth reading:
Sources: Regulation (EU) 2016/679, Articles 13, 28, 30, 44, 45, 46 and 49 · Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 · Commission Implementing Decision (EU) 2021/914 of 4 June 2021 · CJEU, judgment of 16 July 2020, case C-311/18 · General Court, judgment of 3 September 2025, case T-553/23 · EDPB Guidelines 05/2021, version 2.0 · EDPB Recommendations 01/2020, version 2.0 · CNIL, "Transférer des données hors de l'UE" · Sitetals methodology.
Sitetals editorial team