Personal data transfers outside the EEA: what to do in the first ten days starts with mapping the flow, not with drafting clauses: which system sends what data, to which recipient, in which country, and whether a lawful transfer mechanism already covers it. Under Swedish law as it currently stands, an unmapped or uncovered transfer should be paused, not documented after the fact.
Who this concerns
This applies to any organisation established in Sweden, or trading into Sweden, that sends personal data to a recipient outside the EEA: a parent company in the United States, a support team in India, a cloud vendor whose backup region sits in Singapore, or a due diligence file shared with an acquirer's lawyers abroad. The trigger is rarely a fine. More often it is a supplier onboarding form that asks where the data actually goes, a customer's procurement questionnaire, or an internal audit that traces a data flow nobody had mapped before.
This is a common situation in group structures with a non-EEA parent, and equally common where a vendor's subprocessor is added later without anyone revisiting the original assessment. This work sits inside Lodline's compliance, sanctions and cyber practice, alongside sanctions screening and internal reporting channels, because the same three questions, where the data goes, on what basis, and who signed off, recur across all three.
What changes once the recipient sits outside the EEA is the burden of proof. Inside the EEA, the exporter can rely on the fact that the recipient is bound by the same regulation. Outside it, the exporter has to demonstrate, on paper, that the level of protection travels with the data. If the receiving entity is a group parent, a subsidiary, or a processor engaged by either, the group relationship does not remove that burden; it only changes who drafts the paperwork.
What the law says
Under Swedish law as it currently stands, a transfer of personal data to a country outside the EEA is permitted only where one of three conditions is met: the destination country benefits from a decision recognising it as offering an adequate level of protection, the exporter has put an appropriate safeguard in place, such as standard contractual clauses or binding corporate rules, or the transfer falls within one of the narrow derogations reserved for occasional, non-systematic situations.
None of the three conditions is self-certifying. An adequacy finding can be reviewed and withdrawn for a given country without notice to individual exporters. A safeguard such as standard contractual clauses does not, on its own, guarantee protection: current supervisory practice requires the exporter to assess whether the destination country's own laws, surveillance powers in particular, undermine the practical effect of the clauses, and to add supplementary technical or organisational measures where they do. A derogation covering an occasional transfer does not extend to a transfer that repeats on a schedule; using it that way is one of the more common ways the position collapses later.
The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) applies this framework directly. There is no separate Swedish transfer regime layered on top of it, which means the analysis does not change depending on whether the exporter is a Swedish parent or a Swedish subsidiary of a foreign group.
How it works in practice
The first ten days matter because they set the record that everything afterwards is judged against. What gets written down now, in what order, is harder to challenge later than anything drafted retroactively once a question has been asked from outside.
Day 1: freeze the flow, not the investigation
If the transfer that surfaced has no mechanism behind it, or the mechanism cannot be located, the flow itself is paused first, before anyone starts drafting a fix. Pausing is not the same as announcing a breach; it is an operational instruction to the system owner. Continuing to send data while a gap is being assessed is the single decision that is hardest to defend afterwards.
Day 2-3: map every transfer, not just the one that surfaced
The transfer that triggered the review is almost never the only one. The same audit, once opened, usually finds two or three more: a backup routine, an analytics tool, a support ticketing system with servers outside the EEA. Each one needs its own line: sender, recipient, country, category of data, volume, and whether a mechanism already covers it.
Day 4-5: check what actually covers each flow, not what was assumed to
A signed set of standard contractual clauses from several years ago does not automatically cover a transfer that started later, on different terms, to a different recipient entity within the same group. Group intercompany agreements are the most common false comfort here: the fact that a data processing agreement exists between two group entities says nothing about which transfer mechanism sits underneath it.
Day 6-7: assess the destination country's own legal environment
For any flow relying on contractual clauses rather than an adequacy finding, the exporter needs a short, documented view of whether the destination country's laws on government access to data could undermine what the clauses promise. This does not need to be exhaustive by day seven; it needs to exist, and it needs to identify where supplementary measures, encryption in transit, access controls, data minimisation, would close the gap if one is found.
Day 8: decide on suspension, supplementary measures, or documented acceptance
Three outcomes are available for each flow mapped so far: keep it running as is because the mechanism is sound, keep it running with additional technical measures added, or suspend it until the mechanism is fixed. What is not available is leaving it undecided while work continues elsewhere. An undecided flow is the one that gets asked about first if a regulator or a customer raises the topic independently.
Day 9: brief whoever will field the next question
Sales, procurement response teams, and whoever manages customer due diligence questionnaires need to know, in one sentence per flow, what the current position is. A supplier due diligence answer that contradicts the internal record created in the first eight days is a self-inflicted problem, and one of the easier ones to avoid.
Day 10: close the record
The output of the first ten days is not a fix for every flow; it is a dated inventory showing what was found, what was done about each item, and what remains open with an owner and a next step. That inventory is the document that gets produced if anyone asks later why the position looked the way it did on a given date.
What to check in that inventory, flow by flow:
- Which system or team initiates the transfer, and does that team know it is happening
- The legal basis claimed for the transfer, named specifically rather than as "GDPR-compliant"
- Whether the mechanism relied on was drafted for this recipient, or inherited from an older arrangement
- Whether the transfer is occasional or systematic, if a derogation is the basis claimed
- Whether the receiving entity's own security posture has been checked, not just its paperwork
- Whether the same data also flows onward from that recipient to a fourth party
Does copying data to a group parent company outside the EEA count as a transfer?
Yes. The transfer regime does not distinguish between third parties and group entities; a Swedish subsidiary sending HR or customer data to a non-EEA parent is transferring it in exactly the same legal sense as sending it to an unrelated vendor, and needs the same mechanism behind it.
Can standard contractual clauses alone justify a transfer to any country?
Not on their own. Current supervisory practice treats the clauses as a starting point that has to be paired with an assessment of the destination country's laws, and with supplementary measures where that assessment finds a gap. Signing the clauses without doing that assessment leaves the position half-built.
What happens if the ten-day window is missed?
Nothing procedural happens automatically; there is no statutory clock that expires on day eleven. What is lost is the ability to show that the organisation acted promptly once the issue was known, which matters if the same flow later becomes the subject of a complaint, an audit, or a regulatory inquiry.
The numbers
There is no single figure that applies to every case. The exposure attached to an unmapped or uncovered transfer depends on a small number of variables rather than a fixed scale. The category of data involved changes the picture substantially: ordinary contact or billing data outside the EEA carries a different weight than health records, biometric identifiers, or data about children. The number of individuals affected by a given flow matters more than the number of flows found, because a single high-volume feed outweighs several small, low-risk ones.
Whether the transfer was ongoing at the time it surfaced, rather than historic and already stopped, also changes what the first ten days need to produce. An ongoing flow needs a same-week decision on continuation, while a historic one needs a record explaining why it stopped and whether anyone downstream still holds a copy.
If the same investigation uncovers a personal data breach alongside the transfer issue, for instance a misconfigured storage bucket rather than a deliberately chosen but unlawful transfer, a separate and much shorter notification clock starts running, measured in hours rather than weeks, and it runs independently of the ten-day process described here. The cost of the exercise itself is driven less by the number of pages produced and more by how many systems the mapping has to touch, and whether the organisation already has an inventory to start from or is building one from scratch.
Where it usually goes wrong
The most common failure is treating the intra-group transfer as internal and therefore exempt. It is not exempt, and the fact that both entities share a parent, a compliance policy, or an IT department does not change the legal character of the transfer between them.
The second is relying on a mechanism's existence rather than its currency. Standard contractual clauses signed for one recipient, one purpose, and one data set are frequently pointed to as covering a different recipient, a different purpose, or an expanded data set added later without anyone revisiting the paperwork.
The third is using an occasional-transfer derogation for something that has quietly become systematic. A one-off transfer to support a specific negotiation is a different case from the same category of data flowing to the same recipient every month; the second needs a standing mechanism, not a repeated derogation.
The fourth is stopping the analysis at the exporter's own contract and never looking at the recipient's onward transfers. A recipient outside the EEA that itself uses a subprocessor in a third country extends the chain, and the exporter's mechanism needs to account for that extension, not just the first hop.
Finally, the position stops working entirely where the destination country's status changes mid-relationship, an adequacy finding withdrawn, or a new surveillance law enacted after the mechanism was put in place. A transfer mechanism assessed once at signature and never revisited is, by year two or three, frequently assessed against a legal environment that no longer matches the one it was built for.
What to do next
The work described above establishes where a transfer stands on a given date; it does not, on its own, produce a defensible mechanism where none exists, and it does not show whether the same kind of gap exists in the channel that would have surfaced the issue earlier. That second question is closely tied to how internal reporting and investigation processes are structured, covered separately in the internal reporting and investigation process material.
Where the first ten days produce an inventory with open items rather than closed ones, the next step is an assessment against the actual documents and the actual data flow, not against a template mechanism. Book an assessment call to have that inventory reviewed before it becomes the record a regulator or a customer asks to see.