In EU privacy law, a country outside the European Union that has not been confirmed as providing an adequate level of personal data protection. Transfers to a third country require a lawful mechanism and a documented assessment that protection remains equivalent in practice.
What a third country means in EU privacy law
A third country is any jurisdiction outside the EU that has not been recognised as providing an adequate level of personal data protection. That status changes how transfers are assessed, documented, and justified under EU privacy rules.
The key point is that “third country” is a legal transfer concept, not a synonym for “unsafe” or “unregulated.” A transfer can still be lawful, but only if the controller or processor relies on a valid transfer mechanism and can show that the protection expected under EU law remains effective in practice.
This is why the term is tied to cross-border transfer governance, not geography alone. The same country may be a third country for one transfer purpose and still support lawful processing if the transfer safeguards, local law analysis, and organisational controls are strong enough.
Why adequacy matters for transfer decisions
EU transfer rules treat adequacy as a shortcut only when the destination has already been assessed as providing essentially equivalent protection. When adequacy is absent, the organisation must look at the legal basis, the recipient context, and any supplementary measures needed to reduce transfer risk.
That makes the third-country concept central to transfer architecture. It determines whether an organisation can rely on an adequacy decision or must instead evaluate a different mechanism, such as standard contractual clauses, binding corporate rules, or another lawful route that fits the transfer scenario.
In practice, this is also where many transfer failures begin: a valid paper mechanism may exist, but the practical environment in the destination country can still undermine protections if local access rules, government powers, or weak recipient controls are not properly addressed. The NIST Privacy Framework is useful here because it frames data transfer as part of broader privacy risk management, not just a legal checkbox.
For broader governance context, DORA’s emphasis on third-party and operational resilience shows why destination risk, service dependency, and provider oversight often matter alongside the privacy analysis itself.
How to assess whether a transfer remains lawful
Lawful transfer assessment is usually a layered exercise. First, confirm whether the destination is covered by an adequacy decision. If not, identify the transfer mechanism and then test whether supplementary safeguards are necessary to keep protection equivalent in practice.
The substantive questions are whether the recipient can honour the transfer commitments, whether onward access is controlled, whether disclosure limits are enforceable, and whether the organisation can actually verify those conditions over time. That is why assessments should cover both the legal text and the operational reality of the transfer path.
For practitioners, the most important discipline is evidencing the reasoning, not merely naming the mechanism. If the organisation cannot show why the destination, recipient, and safeguards together preserve protection, the transfer position is weak even if a contract exists. The SOC 2 Trust Services Criteria (AICPA) can be a helpful external reference point when assessing confidentiality, vendor controls, and third-party assurance in the transfer chain.
Where the transfer relies on cloud or outsourced processing, the State of Non-Human Identity Security is relevant because third-party access often depends on machine credentials, tokens, and service identities that must be governed tightly to avoid uncontrolled disclosure.
Risk and Threat Considerations
Third-country transfers create risk when legal protection, recipient controls, and operational access do not line up. The main exposure is that personal data may be accessible in ways that undermine EU expectations, especially when onward disclosure, public authority access, or weak recipient governance is not fully understood.
Failure mechanism: The transfer appears lawful on paper, but the destination environment or recipient practice makes the promised safeguards ineffective, so personal data can be accessed, disclosed, or retained beyond what the EU transfer assessment assumed.
Impact: The result can be unlawful transfer exposure, regulatory enforcement, contractual breach, loss of trust, and a need to suspend or redesign the transfer path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST IR 8596 set the technical controls, while DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Third-country transfers require documented privacy and transfer risk decisions. |
| GV.SC-05 — Third-Party and Supply Chain Risk Management | Cross-border transfers often depend on vendors and processors in other jurisdictions. | |
| PR.DS-02 — Data-in-Transit Protection | Transfer lawfulness depends on protecting personal data while it moves across borders. | |
| Recommendation — Document transfer risk decisions and review them when destination conditions change. Assess third-party transfer controls and verify contractual safeguards before enabling data movement. Protect cross-border data flows with approved encryption and transport safeguards. | ||
| DORA | Article 28 — ICT Third-Party Risk Management | DORA materially addresses third-party dependencies and oversight relevant to cross-border processing. |
| Recommendation — Contractually govern third-party ICT dependencies and review transfer risk continuously. | ||
| NIST IR 8596 | GV-1 — AI Governance | Privacy transfer assessments increasingly intersect with data governance and privacy risk management. |
| Recommendation — Align privacy transfer controls with enterprise data governance and risk ownership. | ||
Practitioner Guidance
Governance implication: Treat “third country” as a transfer control trigger, not a descriptive label. The organisation should know which transfers depend on adequacy, which rely on alternative mechanisms, and which require repeat review because the destination risk or vendor posture can change.
What to watch for: Gaps usually appear when transfer inventories are incomplete, recipient access is poorly understood, or legal assessments are not updated after changes in processing, subcontracting, or destination law.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org