Cross-Border Data Transfers
Also called: International Data Transfers · Data Localisation
Cross-border data transfer provisions govern whether personal data may leave the country or region where it was collected, and what safeguards apply if it does. Many data-protection regimes restrict such transfers unless specific legal mechanisms are in place.
In more detail
This is one of the most common places where a SaaS contract quietly creates a compliance problem. Cloud infrastructure spans regions by default, so data frequently moves across borders without the customer having consciously agreed to it.
Compliance mechanisms differ by regime — standard contractual clauses, adequacy findings, explicit consent, or local storage requirements are all used. Some sectors and jurisdictions additionally impose outright data-localisation rules for certain categories of data.
The practical contract questions are simple to ask and often not answered: where will the data physically be stored, which sub-processors are in which countries, and can the customer require a specific region?
Transfer rules are among the fastest-moving areas of data-protection law, and mechanisms considered valid at signature can be challenged later. Contracts should anticipate the mechanism changing rather than hardcoding one.
What our lawyers check
- Where data is stored and processed, and whether the contract commits to it
- Which transfer mechanism is relied on, and whether it is currently valid
- Whether the customer can require region-specific hosting
- Sector-specific localisation requirements that may override the contract
Contracts where this clause matters
Related terms
This definition is general information about commercial contracting practice, not legal advice. How a clause operates depends on the specific wording of your agreement and the law that governs it. For advice on your contract, have it reviewed by a lawyer.
All glossary terms