Personal data across borders — EU
Every requirement in the theme as a row, with the provision, the deadline and the supervisor in this jurisdiction.
The question this page answers
We move personal data between the EU, the United States and China, which legal basis, which assessment and which notification applies in each jurisdiction?
Requirement rows
- Legal basis for the transfer
Dataskyddsförordningen
art. 44 till 46
A transfer to a third country requires an adequacy decision or appropriate safeguards, in practice the Commission's standard contractual clauses.
- Deadline:
- Before the transfer begins
- Penalty:
- Up to EUR 20 million or four percent of global turnover
- Supervision:
- Integritetsskyddsmyndigheten och EDPB
Read 2026-08-22
- Assessment before processing begins
Dataskyddsförordningen
art. 35
A data protection impact assessment is required where processing is likely to result in high risk, and must be done before processing starts.
- Deadline:
- Before the transfer begins
- Penalty:
- Up to EUR 10 million or two percent of global turnover
- Supervision:
- Integritetsskyddsmyndigheten
Read 2026-08-22
- Notice and consent
Dataskyddsförordningen
art. 6, 13 och 14
Processing requires a legal basis, and the notice is given when the data is collected. Consent is one basis among several, not the default.
- Deadline:
- Ongoing, for as long as the processing continues
- Penalty:
- Up to EUR 20 million or four percent of global turnover
- Supervision:
- Integritetsskyddsmyndigheten
Read 2026-08-22
- Individual rights
Dataskyddsförordningen
art. 15 till 22
Access, rectification, erasure, restriction, portability and objection, with an answer without undue delay.
- Deadline:
- One month, extendable by two months where complex
- Penalty:
- Up to EUR 20 million or four percent of global turnover
- Supervision:
- Integritetsskyddsmyndigheten
Read 2026-08-22
- Personal data breach
Dataskyddsförordningen
art. 33 och 34
The supervisory authority is notified where there is a risk to the individual, and the individual where the risk is high.
- Deadline:
- 72 hours from becoming aware of the breach
- Penalty:
- Up to EUR 10 million or two percent of global turnover
- Supervision:
- Integritetsskyddsmyndigheten
Read 2026-08-22
- Supervision and penalty
Dataskyddsförordningen
art. 83
The supervisory authority of the main establishment decides, with cooperation and dispute resolution in the European Data Protection Board.
- Deadline:
- No deadline stated
- Penalty:
- Up to EUR 20 million or four percent of global turnover
- Supervision:
- Integritetsskyddsmyndigheten och EDPB
Read 2026-08-22
Connections
Sources and review
Register version crossover-v1.0.0 · Read 2026-08-22
This page restates written law with the provision and the official source. It is not legal advice in an individual matter.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.