Papalocal
Loading…
Papalocal Your local communities & everything app — businesses, deals, library, and more.

GDPR Adequacy Decisions: Which Countries Can Freely Receive EU Data

How the EU determines which countries have strong enough privacy laws to receive personal data without extra safeguards.

By Garret Merkley · Explainer · Jun 16, 2026
Branched from How GDPR's Standard Contractual Clauses Work and Why They're Under Legal Scrutiny
Quick take
  • An adequacy decision means the EU officially recognizes a country's privacy laws as equivalent to GDPR, allowing direct data transfers without contracts.
  • The EU conducts a thorough legal assessment covering data protection law, enforcement, and individual rights before granting adequacy status.
  • Only about 12 countries currently hold adequacy decisions; most others require Standard Contractual Clauses or other legal mechanisms to receive EU data.

An adequacy decision is the EU's official stamp of approval that a country's data protection laws are strong enough to protect EU citizens' personal data to the same standard as GDPR. When a country receives an adequacy decision, organizations can transfer personal data there freely, without needing contracts, clauses, or extra legal paperwork. It's the simplest and most direct path for international data flows.

How the EU Assesses a Country for Adequacy

The European Commission, not individual EU member states, decides whether a country qualifies for adequacy. The process is rigorous and can take years. The Commission examines the country's data protection laws on paper, then investigates whether those laws are actually enforced in practice. They look at whether individuals have real rights—can they access their data, correct errors, lodge complaints? They also check whether the country's government or courts can override those protections for national security or law enforcement, and if so, whether those overrides are proportionate and transparent.

The assessment covers the entire legal framework, not just a single statute. That means the Commission reviews constitutional law, sectoral regulations, case law, and the independence of the country's data protection authority. They also consult with the European Data Protection Board, which includes representatives from all EU member states' privacy regulators, before making a final decision.

Countries That Currently Hold Adequacy Decisions

As of 2024, only about a dozen countries or territories have received adequacy decisions. These include Canada, Japan, South Korea, New Zealand, Israel, the UK (post-Brexit), and several others. The list is deliberately short because the bar is high—a country must demonstrate legal and institutional safeguards that genuinely match GDPR's standard. Notably, the United States does not have a blanket adequacy decision, which is why most US-based companies rely on Standard Contractual Clauses or other mechanisms instead.

Country/RegionStatusKey Notes
CanadaAdequacy (2001, reaffirmed 2023)Strong federal and provincial privacy laws; independent oversight.
JapanAdequacy (2019)Comprehensive data protection framework with enforcement authority.
South KoreaAdequacy (2020)Robust privacy laws and institutional safeguards.
New ZealandAdequacy (2013)Privacy Act with independent commissioner.
United KingdomAdequacy (2021)Post-Brexit; maintains GDPR-equivalent protections.
IsraelAdequacy (2017)Privacy Protection Law with dedicated authority.
United StatesNo blanket decisionSector-specific (Privacy Shield terminated 2020); uses SCCs instead.
AustraliaUnder reviewOngoing assessment of privacy framework.

Why Adequacy Decisions Matter in Practice

For organizations, an adequacy decision simplifies compliance dramatically. You can transfer payroll data, customer records, or employee information to an adequately protected country without negotiating Standard Contractual Clauses, conducting transfer impact assessments, or implementing supplementary technical measures. This saves time and legal costs, and it removes uncertainty about whether the transfer is lawful.

For individuals, adequacy decisions provide reassurance that their data will be protected by laws that meet a genuine standard of equivalence. The EU is not simply trusting another government; it has verified that legal mechanisms and enforcement exist. However, adequacy decisions can be withdrawn if a country's laws weaken or enforcement lapses, so they are not permanent.

The Adequacy Decision Process and Timeline

A country typically initiates the process by requesting an assessment from the European Commission. The Commission then opens a formal investigation, which involves collecting documentation, consulting with the country's authorities, and seeking advice from the European Data Protection Board. This phase can last 1–3 years or longer. Once the Commission publishes a draft adequacy decision, it goes to the European Parliament and Council for review. If approved, the decision is formally adopted and published in the Official Journal. The decision can include conditions or be limited in scope—for example, adequacy might apply only to certain sectors or with periodic review requirements.

Adequacy Decisions Can Change
  • The EU can suspend or withdraw an adequacy decision if a country's laws weaken, enforcement falters, or significant privacy breaches occur.
  • For example, adequacy decisions for countries in the Schrems II case (Austria, France) came under scrutiny due to government surveillance practices.
  • Organizations should monitor changes to adequacy status and have backup mechanisms (like SCCs) in place.

Adequacy vs. Other Transfer Mechanisms

When a country does not have an adequacy decision, organizations must use alternative mechanisms. Standard Contractual Clauses (SCCs) are the most common: they are pre-approved contract terms that commit both parties to GDPR-level protections. However, SCCs require a transfer impact assessment to confirm that the destination country's laws don't undermine the clauses. Binding Corporate Rules (BCRs) are another option for multinational companies, allowing internal policies to govern transfers between group entities. Derogations—narrow exceptions for specific situations like individual consent or contract performance—are also available but limited in scope.

Practical Checklist for Data Transfers
  • Check whether the destination country has an adequacy decision (European Commission website maintains the current list).
  • If yes: transfer is lawful under Article 45 GDPR; no additional safeguards required.
  • If no: use Standard Contractual Clauses and conduct a transfer impact assessment (Article 46 GDPR).
  • Document your legal basis for the transfer and keep records of the assessment.
  • Review periodically, especially if the country's laws or political situation changes.
Can a company transfer data to a non-adequate country if the data subject consents?
Consent can be a legal basis under Article 49 GDPR, but it must be freely given, specific, and informed. The individual must understand the risks and have a genuine choice to refuse. Relying solely on consent for routine business transfers is risky and not recommended; adequacy or SCCs are more robust.
How long does an adequacy decision take to obtain?
The formal assessment process typically takes 1–3 years, sometimes longer. Canada's reassessment took about 18 months; Japan's took roughly 2 years. The timeline depends on the complexity of the country's legal framework and the responsiveness of its authorities.
What happens if a country loses its adequacy decision?
Organizations must immediately switch to an alternative mechanism, usually Standard Contractual Clauses. Any transfers already made under the adequacy decision remain lawful, but new transfers require a different legal basis. Companies should have contingency plans in place.
Are adequacy decisions the same across all EU member states?
Yes. An adequacy decision is made by the European Commission and applies uniformly across the entire EU. Individual member states cannot grant their own adequacy decisions or override the Commission's assessment.
Why doesn't the US have an adequacy decision?
The US does not have comprehensive federal data protection legislation equivalent to GDPR. US privacy laws are sectoral (healthcare, finance, credit) and fragmented across state and federal levels. Additionally, US government surveillance authorities and the lack of explicit restrictions on accessing EU data for national security reasons have been barriers. The Privacy Shield agreement was struck down by the EU Court of Justice in 2020, and no replacement adequacy decision has been granted.

Sources