KlarComply
HomeKnowledge › US tools & transfers

US tools at work: the third-country transfer, checked sensibly in three steps

Almost every SME uses US services — office suite, cloud, newsletter, AI. Whenever personal data leaves the EU in the process, the GDPR demands an additional basis for the transfer. It sounds like big-firm lawyering, but for the common services it is checkable in three steps — once you know what to look for.

By , Founder of KlarComply · Reviewed on

Infographic: US tools: the third-country check in three steps — Office, cloud, newsletter, AI — what SMEs actually need to verify.
The key points of this article as a graphic — feel free to share or download it.

Why the rule exists

Within the EU and EEA the same level of protection applies everywhere — data may flow freely. Outside (“third countries”) that is not automatic: authorities might access data, or data subject rights might run empty. That is why Art. 44 ff. GDPR demand a separate basis for every transfer to a third country — in addition to the DPA, which governs the processing relationship itself.

The three steps for practice

StepQuestionWhere to find it
1Does data leave the EU/EEA at all? Several US providers offer EU data regions — then there is often no transfer in the first place.Provider privacy notes, the “data region” setting
2Is the provider certified under the EU-US Data Privacy Framework? Then an adequacy decision carries the transfer.The public DPF list of the US Department of Commerce; the big providers (Microsoft, Google, OpenAI and others) are listed
3If not: are Standard Contractual Clauses (SCCs) in place? Almost every serious provider builds them into its Data Processing Agreement.The provider's DPA, usually as an annex

The result of the three steps belongs in writing per tool — the “third country: yes/no/unchecked” column in the tool inventory exists for exactly that. “Unchecked” is an honest interim entry, not a permanent state.

An honest note on stability

The EU-US adequacy decision has a history: both predecessors (Safe Harbor, Privacy Shield) were struck down by the Court of Justice, and the Data Privacy Framework faces challenges too. For today it is a workable basis — but one more reason to note per tool what each transfer rests on: if a basis falls, you instantly know which tools are affected instead of starting from zero.

The two everyday mistakes

First, the fallacy “DPA in place = everything settled”: the DPA governs the processing relationship, not the border crossing — both need checking. Second, the free account: personal tiers of many US services offer neither a DPA nor reliable transfer commitments; both belong to the business tier. The rule “company data only in approved tools” thus solves the third-country problem along the way.

Where to start

In the KlarComply subscription (from €49/month) your tool inventory carries the third-country entry per tool — together with personal-data and DPA status the foundation for records, questionnaires and audits. The free 2-minute check shows where you stand.

Frequently asked questions

Can I use US tools like Microsoft 365 or OpenAI in a GDPR-compliant way?

As a rule, yes — with the business tier including a DPA and a transfer basis: many large US providers are certified under the EU-US Data Privacy Framework, others build Standard Contractual Clauses into their Data Processing Agreement. It must be checked and documented per tool.

Is the DPA enough for using a US service?

No. The data processing agreement (Art. 28) governs processing on instructions; the third-country transfer additionally needs a basis under Art. 44 ff. — an adequacy decision (such as the Data Privacy Framework) or Standard Contractual Clauses.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training →
Sources:
Article 44 GDPR — general principle for transfers
Article 46 GDPR — appropriate safeguards (incl. SCCs)
European Commission — EU-US Data Privacy Framework adequacy decision
Reviewed on 1 September 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.