Cross-Border Data Flows Are Still the Most Underestimated Compliance Risk

Ask the general counsel of a GDPR-subject organization whether their cross-border data transfers are compliant. The answer is yes. Ask them which systems send personal data to which jurisdictions, through which transfer mechanisms, with what transfer impact assessments covering which data categories

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

. The specificity of the answer will tell you more about the actual compliance position than the initial yes. Cross-border data transfer compliance is the area of GDPR enforcement where the gap between documented compliance and operational compliance is most consistently significant — and where the regulatory enforcement trajectory is most clearly toward higher requirements and larger penalties.

Why It Remains Underestimated

Cross-border data transfer compliance is underestimated because the documentation of compliance is relatively straightforward — update the SCCs, reference them in the DPA, document the transfer mechanism in the Article 30 records — while the operational reality of compliance is significantly more complex. The SCC is a document. Ensuring that the SCC actually covers the transfers occurring, that the transfer impact assessment accurately reflects the protections available in the recipient country, and that new transfers created after the SCC was executed are covered by a valid mechanism requires ongoing operational governance that the documentation does not automatically produce.

The gap between the documented position and the operational position is the enforcement gap. Regulators examining cross-border transfer compliance are increasingly conducting technical investigations — examining actual data flows, comparing them against disclosed transfer mechanisms, and assessing whether the organizations' transfer impact assessments reflect genuine analysis rather than template-based assertions. The documentation that was adequate for early GDPR enforcement is not adequate for the enforcement approach that has developed since Schrems II.

The SCC in the file confirms that the organization has a transfer mechanism documentation. It does not confirm that the transfers occurring are covered by the mechanism, that the TIA reflects genuine analysis, or that new transfers created since the SCC was executed have been assessed. Documentation compliance and operational compliance are different positions.

The Specific Gaps That Enforcement Is Finding

Transfer Mechanisms That Do Not Cover All Transfers

Organizations that have SCCs in place for their primary vendor relationships may have undocumented transfers to analytics platforms, marketing tools, and SaaS applications whose data flows were not identified when the SCC framework was established. Each new SaaS integration that sends EU personal data to a non-EU server creates a new transfer that requires a mechanism. Mechanisms that were established for identified transfers at a point in time do not extend automatically to transfers created after that point.

Transfer Impact Assessments That Are Templates Rather Than Analysis

Transfer impact assessments are required to reflect genuine analysis of the specific data categories transferred, the specific recipient country's legal framework, and the specific supplementary measures in place. TIAs that use template language — assertions that the recipient country's legal framework is 'broadly equivalent' to EU protections, descriptions of supplementary measures that are identical across all transfers regardless of the specific circumstances — do not meet the standard that EDPB guidance and enforcement decisions have established.

The EU-US Data Privacy Framework Dependencies

The EU-US Data Privacy Framework provides an adequacy-based transfer mechanism for transfers to certified US organizations. Relying on the DPF requires verifying that the specific US recipient is currently certified — certification must be renewed annually. Organizations that verified DPF certification at vendor onboarding but do not monitor ongoing certification status may be relying on lapsed certifications without knowing it.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

The Enforcement Trajectory

The EDPB's coordinated enforcement action on data transfers from 2023 and 2024 demonstrated a more technical and thorough approach to transfer compliance assessment than early GDPR enforcement. Regulators are examining actual data flows, testing TIA quality, and assessing whether SCC restrictions are actually implemented operationally rather than only documented contractually. The enforcement trend is toward more scrutiny, more technical depth, and larger penalties.

The Irish DPC's decisions involving major US tech companies have set expectations for the granularity of transfer impact assessment that is required — expectations that apply to all organizations subject to GDPR, not only to the large platforms whose cases have received the most attention. The Meta decisions have established that legitimate interests cannot support behavioral advertising data transfers and that SCCs require genuine TIA analysis, not template assertions.

Organizations that have maintained a documentation-only approach to cross-border transfer compliance — updating the SCC versions, referencing them in DPAs, documenting transfer mechanisms in Article 30 records — without building the operational governance that ensures actual transfers are covered and TIAs reflect genuine analysis are exposed to an enforcement environment that is assessing operational compliance, not documentation compliance.

Audit the actual transfers against the documented mechanisms. Test the TIA quality against the standard enforcement has established. The documentation-only position is no longer adequate.

Map what is actually flowing across borders. Compare it to what is documented. Assess the TIA quality against current enforcement standards. The gap between those three pictures is the compliance exposure.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.