Almost every SME uses US services — office suite, cloud, newsletter, AI. Whenever personal data leaves the EU in the process, the GDPR demands an additional basis for the transfer. It sounds like big-firm lawyering, but for the common services it is checkable in three steps — once you know what to look for.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Within the EU and EEA the same level of protection applies everywhere — data may flow freely. Outside (“third countries”) that is not automatic: authorities might access data, or data subject rights might run empty. That is why Art. 44 ff. GDPR demand a separate basis for every transfer to a third country — in addition to the DPA, which governs the processing relationship itself.
| Step | Question | Where to find it |
|---|---|---|
| 1 | Does data leave the EU/EEA at all? Several US providers offer EU data regions — then there is often no transfer in the first place. | Provider privacy notes, the “data region” setting |
| 2 | Is the provider certified under the EU-US Data Privacy Framework? Then an adequacy decision carries the transfer. | The public DPF list of the US Department of Commerce; the big providers (Microsoft, Google, OpenAI and others) are listed |
| 3 | If not: are Standard Contractual Clauses (SCCs) in place? Almost every serious provider builds them into its Data Processing Agreement. | The provider's DPA, usually as an annex |
The result of the three steps belongs in writing per tool — the “third country: yes/no/unchecked” column in the tool inventory exists for exactly that. “Unchecked” is an honest interim entry, not a permanent state.
The EU-US adequacy decision has a history: both predecessors (Safe Harbor, Privacy Shield) were struck down by the Court of Justice, and the Data Privacy Framework faces challenges too. For today it is a workable basis — but one more reason to note per tool what each transfer rests on: if a basis falls, you instantly know which tools are affected instead of starting from zero.
First, the fallacy “DPA in place = everything settled”: the DPA governs the processing relationship, not the border crossing — both need checking. Second, the free account: personal tiers of many US services offer neither a DPA nor reliable transfer commitments; both belong to the business tier. The rule “company data only in approved tools” thus solves the third-country problem along the way.
In the KlarComply subscription (from €49/month) your tool inventory carries the third-country entry per tool — together with personal-data and DPA status the foundation for records, questionnaires and audits. The free 2-minute check shows where you stand.
As a rule, yes — with the business tier including a DPA and a transfer basis: many large US providers are certified under the EU-US Data Privacy Framework, others build Standard Contractual Clauses into their Data Processing Agreement. It must be checked and documented per tool.
No. The data processing agreement (Art. 28) governs processing on instructions; the third-country transfer additionally needs a basis under Art. 44 ff. — an adequacy decision (such as the Data Privacy Framework) or Standard Contractual Clauses.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free