GDPR Adequacy Decisions: Which Countries Can Freely Receive EU Data
How the EU determines which countries have strong enough privacy laws to receive personal data without extra safeguards.
- An adequacy decision means the EU officially recognizes a country's privacy laws as equivalent to GDPR, allowing direct data transfers without contracts.
- The EU conducts a thorough legal assessment covering data protection law, enforcement, and individual rights before granting adequacy status.
- Only about 12 countries currently hold adequacy decisions; most others require Standard Contractual Clauses or other legal mechanisms to receive EU data.
An adequacy decision is the EU's official stamp of approval that a country's data protection laws are strong enough to protect EU citizens' personal data to the same standard as GDPR. When a country receives an adequacy decision, organizations can transfer personal data there freely, without needing contracts, clauses, or extra legal paperwork. It's the simplest and most direct path for international data flows.
How the EU Assesses a Country for Adequacy
The European Commission, not individual EU member states, decides whether a country qualifies for adequacy. The process is rigorous and can take years. The Commission examines the country's data protection laws on paper, then investigates whether those laws are actually enforced in practice. They look at whether individuals have real rights—can they access their data, correct errors, lodge complaints? They also check whether the country's government or courts can override those protections for national security or law enforcement, and if so, whether those overrides are proportionate and transparent.
The assessment covers the entire legal framework, not just a single statute. That means the Commission reviews constitutional law, sectoral regulations, case law, and the independence of the country's data protection authority. They also consult with the European Data Protection Board, which includes representatives from all EU member states' privacy regulators, before making a final decision.
Countries That Currently Hold Adequacy Decisions
As of 2024, only about a dozen countries or territories have received adequacy decisions. These include Canada, Japan, South Korea, New Zealand, Israel, the UK (post-Brexit), and several others. The list is deliberately short because the bar is high—a country must demonstrate legal and institutional safeguards that genuinely match GDPR's standard. Notably, the United States does not have a blanket adequacy decision, which is why most US-based companies rely on Standard Contractual Clauses or other mechanisms instead.
| Country/Region | Status | Key Notes |
|---|---|---|
| Canada | Adequacy (2001, reaffirmed 2023) | Strong federal and provincial privacy laws; independent oversight. |
| Japan | Adequacy (2019) | Comprehensive data protection framework with enforcement authority. |
| South Korea | Adequacy (2020) | Robust privacy laws and institutional safeguards. |
| New Zealand | Adequacy (2013) | Privacy Act with independent commissioner. |
| United Kingdom | Adequacy (2021) | Post-Brexit; maintains GDPR-equivalent protections. |
| Israel | Adequacy (2017) | Privacy Protection Law with dedicated authority. |
| United States | No blanket decision | Sector-specific (Privacy Shield terminated 2020); uses SCCs instead. |
| Australia | Under review | Ongoing assessment of privacy framework. |
Why Adequacy Decisions Matter in Practice
For organizations, an adequacy decision simplifies compliance dramatically. You can transfer payroll data, customer records, or employee information to an adequately protected country without negotiating Standard Contractual Clauses, conducting transfer impact assessments, or implementing supplementary technical measures. This saves time and legal costs, and it removes uncertainty about whether the transfer is lawful.
For individuals, adequacy decisions provide reassurance that their data will be protected by laws that meet a genuine standard of equivalence. The EU is not simply trusting another government; it has verified that legal mechanisms and enforcement exist. However, adequacy decisions can be withdrawn if a country's laws weaken or enforcement lapses, so they are not permanent.
The Adequacy Decision Process and Timeline
A country typically initiates the process by requesting an assessment from the European Commission. The Commission then opens a formal investigation, which involves collecting documentation, consulting with the country's authorities, and seeking advice from the European Data Protection Board. This phase can last 1–3 years or longer. Once the Commission publishes a draft adequacy decision, it goes to the European Parliament and Council for review. If approved, the decision is formally adopted and published in the Official Journal. The decision can include conditions or be limited in scope—for example, adequacy might apply only to certain sectors or with periodic review requirements.
- The EU can suspend or withdraw an adequacy decision if a country's laws weaken, enforcement falters, or significant privacy breaches occur.
- For example, adequacy decisions for countries in the Schrems II case (Austria, France) came under scrutiny due to government surveillance practices.
- Organizations should monitor changes to adequacy status and have backup mechanisms (like SCCs) in place.
Adequacy vs. Other Transfer Mechanisms
When a country does not have an adequacy decision, organizations must use alternative mechanisms. Standard Contractual Clauses (SCCs) are the most common: they are pre-approved contract terms that commit both parties to GDPR-level protections. However, SCCs require a transfer impact assessment to confirm that the destination country's laws don't undermine the clauses. Binding Corporate Rules (BCRs) are another option for multinational companies, allowing internal policies to govern transfers between group entities. Derogations—narrow exceptions for specific situations like individual consent or contract performance—are also available but limited in scope.
- Check whether the destination country has an adequacy decision (European Commission website maintains the current list).
- If yes: transfer is lawful under Article 45 GDPR; no additional safeguards required.
- If no: use Standard Contractual Clauses and conduct a transfer impact assessment (Article 46 GDPR).
- Document your legal basis for the transfer and keep records of the assessment.
- Review periodically, especially if the country's laws or political situation changes.
Sources
- European Commission, 'Transfers of personal data to third countries' (official list of adequacy decisions and assessment criteria)
- GDPR Article 45 (Transfers on the basis of an adequacy decision)
- European Data Protection Board, Guidelines on data transfers (2021)
- Schrems II case (C-311/18) — landmark ruling on transfer mechanisms and surveillance
