Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that a cross-border arrangement…
Cyber Security

What are the signs that a cross-border arrangement is not a transfer under the GDPR?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Cyber Security

A common sign is that the data moves directly from the individual to the foreign controller, rather than through an EU exporter. Another is remote access by an employee who remains part of the same controller, because the disclosure stays within one organisation. In both cases, the second transfer criterion is not met, so Chapter V does not apply.

How to tell when Chapter V is not engaged

The key question is whether the scenario contains a transfer from an EU exporter to a separate recipient outside the EU/EEA, or whether the data subject is disclosing directly to a foreign controller. If the arrangement is simply remote access within one controller, or another structure without a distinct export step, the cross-border element alone does not make it a transfer under GDPR.

A practical way to test the boundary is to trace who is actually disclosing the data, who is receiving it, and whether the receiving party is a separate controller or processor in the transfer chain. The same fact pattern can look cross-border operationally while still falling outside Chapter V because the legal transfer criteria are not satisfied.

For the underlying rule set, the general GDPR text remains the primary reference, especially the provisions that distinguish ordinary processing from transfer-specific obligations: EU General Data Protection Regulation (GDPR).

Common fact patterns that do not amount to a transfer

Direct collection from the individual is the clearest example. If a person in the EU sends data directly to a controller abroad, the operation may be international in reach, but it is not the classic Chapter V transfer scenario because there is no EU exporter handing data off to a foreign recipient.

Remote access is the other common pattern. An employee or contractor may view or process data from outside the EEA while still acting for the same controller, so the disclosure remains inside one organisation. In that case, the location of the user does not, by itself, turn the access into a transfer. The legal analysis turns on organisational structure and disclosure path, not geography alone.

That boundary is why records, notices, and internal maps should describe the processing chain, not just the network path. A cross-border session can be operationally real while still being legally ordinary access rather than a transfer event.

For related governance and control expectations around data handling, classification, and access management, CIS Controls v8 and the NIST Privacy Framework are useful complements.

Practitioner checks for boundary cases

When the pattern is unclear, focus first on the legal roles and the direction of disclosure. If the foreign party is not receiving data from an EU exporter, or if the access is merely remote administration by personnel acting within the same controller, the transfer analysis may stop there. If, however, data is being sent to a separate foreign entity for its own purposes or to a processor in a true transfer chain, Chapter V analysis resumes.

What to verify: confirm who decides the purposes and means, whether the data is disclosed or merely accessed, and whether the foreign party is a separate controller, processor, or just a remote user within the same controller. That distinction should be visible in contracts, internal processing maps, and privacy notices.

Common mistake: treating every offshore login or every overseas recipient as a transfer. That shortcut overstates Chapter V in some cases and can obscure the real compliance question, which is whether a transfer relationship exists at all.

Practitioner takeaway: classify the arrangement by disclosure path and legal relationship first, then apply Chapter V only if there is a real exporter-to-recipient transfer structure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Risk and Threat OversightCross-border transfer analysis affects privacy and security governance decisions.
Recommendation — Define who owns transfer-risk decisions and keep the legal assessment tied to the actual data-flow model.
CIS Controls v814.1 — Security Awareness and Skills TrainingTeams handling international data flows need clear process knowledge to avoid misclassifying transfers.
Recommendation — Train privacy and operations teams to distinguish direct disclosure, remote access, and true third-party transfer.
NIST SP 800-63IAL — Identity Assurance LevelRemote access cases depend on knowing who is acting within the controller, which relies on strong identity proofing.
Recommendation — Use strong identity proofing so remote users can be correctly attributed to the same controller where relevant.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org