Personal data transfers outside the EEA: cost and likely outcome depend on whether a recognised transfer mechanism, usually a standard contractual arrangement backed by a documented transfer impact assessment, is in place before data leaves. Cost tracks the number of processors and contracts touched; the outcome holds up when mapping is done properly and fails when it is not.
Who this concerns
The question comes up in three recurring situations. A Swedish company onboards a cloud vendor, a payroll provider or a customer support platform whose servers, or whose sub-processors, sit outside the EEA. A group with a parent or sister company abroad routes HR data, customer records or analytics through that entity as a matter of course, without anyone having mapped what leaves and where it lands. Or a buyer's counsel, during due diligence on an acquisition, asks a straightforward question that the target cannot answer with a document: where does the data actually go, and on what basis.
None of these situations is exotic. They are the default state of most mid-sized businesses that use foreign SaaS tools, outsource part of their operations, or belong to a group with a holding structure abroad. What changes the calculation is not whether a transfer exists, since it almost always does, but whether anyone has looked at it directly and put a mechanism and a record behind it.
The commercial context matters as much as the legal one. A company preparing for a funding round, a sale, or a regulatory audit is judged on documentation it can produce on request, not on the transfer having been theoretically compliant all along. If nobody can point to a signed clause, a completed assessment, and a list of what was actually assessed, the position is weak regardless of what the underlying facts would have supported.
What the law says
The starting position is restrictive: personal data may not move outside the EEA unless a recognised basis for the transfer exists. That basis usually takes one of a small number of forms: a formal finding that the destination country offers an adequate level of protection, a contractual mechanism between the exporter and the importer that reproduces the relevant safeguards, an internal group-wide framework covering intra-group transfers, or a narrow derogation that applies to a specific, limited transfer rather than to ongoing data flows.
None of these bases is self-executing. A contractual mechanism has to actually be signed, cover the right parties, and be backed by an assessment of whether the destination country's laws or practices could undermine the safeguards on paper. Where that assessment identifies a real risk, supplementary measures, technical or organisational, are expected to close the gap rather than being noted and left unaddressed.
Enforcement in Sweden runs through the national supervisory authority, which can order a transfer to stop, require remediation, or impose a sanction calculated as a proportion of turnover. Under Swedish law as it currently stands, the authority's practice in this area treats an undocumented transfer and a transfer that was assessed but poorly documented very differently: the first is a compliance gap, the second is a defensible position even if imperfect. That distinction is where most of the practical cost and risk actually sits, and it is the reason a paper trail matters more than a theoretically correct legal analysis that nobody can point to.
How it works in practice
Mapping where personal data actually goes
The starting point is not the contract with the primary vendor. It is the full chain: the vendor's own hosting arrangement, its sub-processors, any support function based outside the EEA, and any group entity that receives a copy of the data for reporting or analytics. A mapping exercise that stops at the first layer routinely misses the transfer that actually creates the exposure.
Choosing a transfer mechanism
Once the destination is known, the mechanism follows from it. A country covered by a current adequacy finding needs no further contractual layer for that specific transfer. Everywhere else, the default is a contractual arrangement between exporter and importer, occasionally supplemented by an internal group framework where the volume of intra-group transfers justifies building one. A narrow derogation, such as a one-off transfer necessary for a specific transaction, is not a substitute for a mechanism covering an ongoing data flow and should not be used as one.
Running a transfer impact assessment
The assessment looks at the destination country's legal environment as it actually operates, not as it is described in a vendor's marketing material: whether public authorities there have powers of access to the data, whether those powers are subject to independent oversight, and whether the importer has any practical ability to resist or notify. The output is a documented judgement, not a checklist tick, and it needs to be specific to the data and the destination, not a generic template copied across every vendor.
Supplementary technical and organisational measures
Where the assessment finds a real gap, something has to close it: encryption that leaves the importer without practical access to the plaintext, pseudonymisation before transfer, contractual commitments to challenge disclosure requests, or a decision to keep the most sensitive categories of data out of the transfer altogether. Measures adopted for form rather than effect do not survive scrutiny.
Updating processor and intra-group agreements
The commercial contract and the data protection terms need to say the same thing about who the data goes to and under what mechanism. A vendor agreement that lists a mechanism the parties never actually signed, or that was signed for an earlier version of the vendor's sub-processor list, is a liability disguised as compliance.
Vendor and sub-processor due diligence
A vendor's own assurance that it "is compliant" is not evidence of anything specific to the customer's data. What matters is the vendor's actual sub-processor list, its own transfer mechanisms with those sub-processors, and whether it will provide the documentation an assessment requires rather than a marketing statement about its posture.
Documentation that has to exist before the transfer, not after
The record of the mapping, the mechanism chosen, the assessment carried out and any supplementary measures adopted needs to exist at the time the transfer starts. Reconstructing it after a regulator or a counterparty asks is materially weaker, and in practice often impossible to do convincingly.
What to check
- The current, actual sub-processor list of every vendor that touches the data, not the list from the onboarding date.
- Which specific transfers rely on an adequacy finding and whether that finding is still current.
- Whether the contractual transfer mechanism in the vendor agreement matches the mechanism actually described in the data protection terms.
- Whether a transfer impact assessment exists for each distinct destination, not one generic assessment covering every vendor.
- Whether supplementary measures identified as necessary were actually implemented, not merely proposed.
- Whether intra-group transfers are covered by the same discipline applied to third-party vendors, rather than assumed to be safe because the recipient is related.
Can a European patent opt-out decision be reversed once filed?
No. A decision to opt a European patent out of the unified court's jurisdiction becomes fixed once filed and the relevant window has closed; the choice of forum applies for the remaining life of the patent. The opt-out decisions for European patents sets out which deadlines cannot be recovered and what happens when the filing window is missed.
How does resigning from the board affect which court has authority?
Timing determines the forum. Resigning before or after a particular corporate event can shift whether a dispute over the resignation falls to the ordinary courts or to a specialised forum, and a back-dated resignation letter does not change that outcome after the fact. The mechanics are set out in resigning from a board seat.
What is a servitut?
A servitut is a right attached to a piece of real property for the benefit of a neighbouring property, rather than a personal right held by whoever currently owns the land. It survives a change of ownership and is recorded against the burdened title. See the term servitut for how it differs from a purely personal right of use.
The numbers
There is no fixed price for putting a transfer on a proper footing, and any figure quoted without reference to the specific vendor landscape should be treated with suspicion. Cost tracks three variables in practice: how many distinct destinations and sub-processors are actually in play, how many existing contracts need to be reopened and amended rather than drafted fresh, and whether a genuine assessment has to be carried out for each destination or whether some can rely on an existing finding.
Timing works the same way. There is no statutory countdown that starts on a fixed date; the practical timeline depends on how many counterparties have to sign an amended agreement, how responsive those counterparties are, and how much of the underlying mapping already exists versus has to be built from scratch. A company with three vendors and a clean contract set moves faster than one with forty vendors and no current list of sub-processors, regardless of what either company would prefer the timeline to be.
The exposure side of the calculation is similarly variable. A sanction is calculated against turnover rather than against a fixed amount, which means the practical stakes scale with the size of the business rather than with the size of the transfer. A small, well-documented transfer by a large company carries different exposure to an undocumented transfer of the same data by the same company, even though the underlying data flow is identical.
Where it usually goes wrong
An adequacy finding covering the primary vendor's jurisdiction is treated as covering every sub-processor the vendor uses, without anyone checking where those sub-processors actually sit. The finding covers the country it names; it does not automatically extend to a support function the vendor has quietly moved elsewhere.
A transfer impact assessment done once, at onboarding, is treated as permanent. Vendors change hosting arrangements, add sub-processors, and shift support functions between jurisdictions, and an assessment written for the original setup does not describe the current one.
Encryption in transit is treated as a complete answer to a destination-country access risk, when the risk being assessed is often access to data at rest, where the importer holds the keys, or access compelled through the importer directly rather than through interception of the transmission.
Intra-group transfers are assumed to be low risk because the recipient is related, and are consequently left out of the mapping exercise entirely. A group relationship changes who is accountable to whom internally; it does not change what the receiving jurisdiction's authorities can compel the recipient entity to disclose.
A transfer that was properly assessed at the outset is left unreviewed after a merger, a change of hosting provider, or a change in the destination country's own legal environment, on the assumption that the original clearance still holds. It does not hold automatically; it holds until something material changes, and something material changes more often than the paperwork gets revisited.
What to do next
A mapping exercise and a documented mechanism close most of the gap described above, and a company with the internal resource to run both can do so without external input for straightforward vendor relationships. The compliance, sanctions and cyber practice covers this and adjacent exposure areas where the underlying question is not the data flow itself but a related control, such as classifying goods or software under export control and dual-use rules, where the analysis follows a similar logic of mapping, classification and documentation.
Where the vendor landscape is large, where the group structure spans several jurisdictions, or where a transaction or an audit puts a deadline on producing the documentation, the point of self-directed work runs out quickly. That is the point to have someone look at the actual contract set and sub-processor chain rather than the general position. Book an assessment to have the current transfer landscape reviewed before it is tested by a counterparty, a regulator, or a buyer's due diligence team.