Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Personal data across borders — EU

Every requirement in the theme as a row, with the provision, the deadline and the supervisor in this jurisdiction.

The question this page answers

We move personal data between the EU, the United States and China, which legal basis, which assessment and which notification applies in each jurisdiction?

Requirement rows

  • Legal basis for the transfer

    Dataskyddsförordningen

    art. 44 till 46

    A transfer to a third country requires an adequacy decision or appropriate safeguards, in practice the Commission's standard contractual clauses.

    Deadline:
    Before the transfer begins
    Penalty:
    Up to EUR 20 million or four percent of global turnover
    Supervision:
    Integritetsskyddsmyndigheten och EDPB
    Open the row in the register

    Read 2026-08-22

  • Assessment before processing begins

    Dataskyddsförordningen

    art. 35

    A data protection impact assessment is required where processing is likely to result in high risk, and must be done before processing starts.

    Deadline:
    Before the transfer begins
    Penalty:
    Up to EUR 10 million or two percent of global turnover
    Supervision:
    Integritetsskyddsmyndigheten
    Open the row in the register

    Read 2026-08-22

  • Notice and consent

    Dataskyddsförordningen

    art. 6, 13 och 14

    Processing requires a legal basis, and the notice is given when the data is collected. Consent is one basis among several, not the default.

    Deadline:
    Ongoing, for as long as the processing continues
    Penalty:
    Up to EUR 20 million or four percent of global turnover
    Supervision:
    Integritetsskyddsmyndigheten
    Open the row in the register

    Read 2026-08-22

  • Individual rights

    Dataskyddsförordningen

    art. 15 till 22

    Access, rectification, erasure, restriction, portability and objection, with an answer without undue delay.

    Deadline:
    One month, extendable by two months where complex
    Penalty:
    Up to EUR 20 million or four percent of global turnover
    Supervision:
    Integritetsskyddsmyndigheten
    Open the row in the register

    Read 2026-08-22

  • Personal data breach

    Dataskyddsförordningen

    art. 33 och 34

    The supervisory authority is notified where there is a risk to the individual, and the individual where the risk is high.

    Deadline:
    72 hours from becoming aware of the breach
    Penalty:
    Up to EUR 10 million or two percent of global turnover
    Supervision:
    Integritetsskyddsmyndigheten
    Open the row in the register

    Read 2026-08-22

  • Supervision and penalty

    Dataskyddsförordningen

    art. 83

    The supervisory authority of the main establishment decides, with cooperation and dispute resolution in the European Data Protection Board.

    Deadline:
    No deadline stated
    Penalty:
    Up to EUR 20 million or four percent of global turnover
    Supervision:
    Integritetsskyddsmyndigheten och EDPB
    Open the row in the register

    Read 2026-08-22

Connections

Sources and review

Register version crossover-v1.0.0 · Read 2026-08-22

This page restates written law with the provision and the official source. It is not legal advice in an individual matter.

Next step

Three ways to put the register to work in your own practice.

Start with your task