[codicts-css-switcher id=”346″]

Global Law Experts Logo
cross-border data transfers italy

How to Transfer Personal Data Outside the EU From Italy (2026): Sccs, Transfer Impact Assessments & the Garante's Expectations

By Global Law Experts
– posted 2 hours ago

Cross-border data transfers italy compliance has become one of the sharpest operational challenges facing Italian controllers and processors in 2026, as intensified Garante scrutiny and updated European Data Protection Board (EDPB) guidance raise the bar for documentation and technical safeguards. This practitioner guide sets out a structured, step-by-step process for lawfully moving personal data from Italy to non-EU countries, covering adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs) and Article 49 derogations. It is written for DPOs, in-house counsel, compliance officers and IT/security managers who need concrete procedures rather than market commentary.

Every legal claim is anchored to primary sources, the GDPR text, the CJEU’s Schrems II judgment, EDPB recommendations and Garante guidance, so your compliance file will withstand inspection.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Susanna Greggio at GTA Studio Legale, a member of the Global Law Experts network.

Quick answer and key legal sources

To transfer personal data lawfully outside the EU from Italy you must: (1) map the transfer; (2) check whether the destination country benefits from an adequacy decision; (3) if not, select a valid transfer tool (SCCs, BCRs or an Article 49 derogation); (4) run a Transfer Impact Assessment (TIA); (5) implement and document supplementary technical measures; and (6) keep records available for the Garante. The core legal framework is found in Articles 44–50 of the GDPR, interpreted by the CJEU in Schrems II (C-311/18) and operationalised by EDPB recommendations and Garante guidance.

Overview: the legal framework for cross-border data transfers Italy

The rules governing cross-border data transfers italy apply on top of, not instead of, the ordinary GDPR obligations. In Italy the GDPR is directly applicable and is supplemented by Decreto Legislativo 196/2003 (the Codice in materia di protezione dei dati personali) as amended by Decreto Legislativo 101/2018, which adapted the national data protection framework to Regulation (EU) 2016/679. Together these instruments confirm that any transmission of personal data to a “third country” (a non-EEA jurisdiction) or to an international organisation triggers the specific transfer regime set out in Chapter V of the GDPR.

There are four principal legal routes for transferring data lawfully: reliance on a European Commission adequacy decision; the use of appropriate safeguards such as SCCs or BCRs; reliance on one of the narrow Article 49 derogations; and, in limited cases, other approved mechanisms such as approved codes of conduct or certification. The Italian supervisory authority, the Garante per la Protezione dei Dati Personali, enforces these rules, inspects documentation and expects controllers to be able to demonstrate, on request, that the chosen mechanism was correctly selected and supported by a documented risk assessment.

Key legal sources to consult

  • GDPR Articles 44–50. The general principle (Art. 44), adequacy (Art. 45), appropriate safeguards including SCCs and BCRs (Arts. 46–47) and derogations (Art. 49).
  • CJEU Schrems II (C-311/18). The judgment that invalidated the EU–US Privacy Shield and confirmed that exporters relying on SCCs must assess whether the law of the destination country provides essentially equivalent protection.
  • EDPB recommendations on international transfers. Practical guidance on the six-step methodology for TIAs and supplementary measures (notably Recommendations 01/2020).
  • Garante guidance on international transfers. Italy-specific expectations on documentation, records and inspection readiness.

Eligibility, when the rules apply and which legal basis to use

Before selecting a mechanism, you must correctly identify whether a “transfer” is taking place at all. Under Chapter V, a transfer occurs whenever personal data is made available to a recipient in a third country. This is broader than a simple export of files: it captures remote access by staff located abroad, use of cloud infrastructure hosted outside the EEA, and onward disclosure by a processor to a sub-processor established in a third country. If an engineer in a non-EU country can view or administer a database held in Italy, that access is generally a transfer under the EDPB’s interpretation.

When transfers are covered, controller, processor and sub-processor scenarios

The transfer regime applies across every configuration in the data supply chain:

  • Controller to controller. For example, an Italian parent company sharing HR data with an affiliate in a non-adequate country for group-wide talent management.
  • Controller to processor. For example, engaging a cloud CRM provider whose servers or support teams sit outside the EEA for marketing operations.
  • Processor to sub-processor. For example, an Italian-based processor that outsources analytics or helpdesk functions to a sub-processor in a third country.

Certain data types demand enhanced scrutiny within the cross-border data transfers italy analysis. Special category data (health, biometric, religious or trade-union data under Article 9), large-scale datasets, and data relating to vulnerable individuals materially increase the risk profile and the depth of the TIA the Garante will expect.

Legal bases for transfer and their practical thresholds

  • Adequacy decision (Art. 45). Where the Commission has decided the destination country ensures an adequate level of protection, no additional authorisation is needed. Always verify the recipient falls within the precise scope of the decision.
  • Appropriate safeguards, SCCs (Art. 46). The default tool for most commercial transfers to non-adequate countries. Post-Schrems II, SCCs must be accompanied by a TIA and, where required, supplementary measures.
  • Binding Corporate Rules (Art. 47). Suitable for large multinational groups transferring data internally; requires supervisory authority approval and has a long lead time.
  • Article 49 derogations. Explicit consent, contractual necessity, or important reasons of public interest, reserved for occasional, non-repetitive transfers and scrutinised closely by the Garante.

Step-by-step: how to perform a compliant transfer

This is the operational core of cross-border data transfers italy compliance. Follow the eight steps below in sequence, documenting the output of each stage so that your file tells a coherent story to any inspector. Assign a named owner to every step.

  1. Step 1, Map the transfer and data flows

    Who: IT (data mapping) with the DPO. Output: a data-flow map and a record entry. Identify every recipient, the purposes of the transfer, the categories of data, the destination countries and the technical route (including cloud regions and remote-access points). This map is the foundation of the entire assessment; an incomplete map is a common reason a TIA later fails.

  2. Step 2, Check the adequacy decision

    Who: DPO/Legal. Output: an adequacy log. Consult the European Commission’s list of adequacy decisions. If the destination country (or the specific framework covering the recipient) is adequate, document the reliance and proceed. If it is not, move to Step 3.

  3. Step 3, Select the transfer mechanism

    Who: Legal and Procurement. Output: signed SCCs, a BCR application, or a documented derogation justification. For most vendor relationships this means the 2021 Commission SCCs (adopted by Implementing Decision (EU) 2021/914). Choose the correct module (controller-to-controller, controller-to-processor, processor-to-processor or processor-to-controller) based on the parties’ roles established in Step 1.

  4. Step 4, Run a Transfer Impact Assessment (TIA)

    Who: DPO, Data Owner, IT/Security and Legal. Output: a TIA report. Following the EDPB’s six-step methodology, assess: the specifics of the transfer; the transfer tool relied upon; the law and practice of the destination country (particularly public-authority access to data); the supplementary measures needed; any procedural steps to adopt those measures; and a schedule for re-evaluation. Score country legal risk, evaluate whether the SCC guarantees are effective in practice, and record the reasoning. Where risk cannot be mitigated, the transfer must not proceed.

  5. Step 5, Implement technical and organisational supplementary measures

    Who: IT/Security. Output: documented technical evidence. Typical measures include strong encryption with keys held in the EEA, pseudonymisation, strict access controls and identity management, and detailed logging. The measures must be capable of addressing the specific risks identified in the TIA, a generic “we use encryption” statement is insufficient. Record configurations and produce evidence that can be shown to the Garante.

  6. Step 6, Execute the contract (SCCs)

    Who: Legal/Procurement. Output: signed SCCs with complete annexes. Insert the correct parties, select the applicable module, and complete the annexes describing the data, the technical measures and the sub-processors. Address liability, audit rights, sub-processor authorisation and the docking clause for multi-party arrangements. Do not accept a vendor’s pre-filled template without checking that its annexes match your Step 1 map and Step 5 measures.

  7. Step 7, Record keeping and TIA/DPIA filing

    Who: DPO. Output: updated records of processing. Add the transfer to your Article 30 records, attach the transfer justification and the TIA outcome, and, where the transfer forms part of high-risk processing, cross-reference the relevant Data Protection Impact Assessment (DPIA).

  8. Step 8, Ongoing monitoring and re-assessment triggers

    Who: DPO/IT. Output: a monitoring schedule and review log. Set a periodic review (at least annual) and define material-change triggers: a change in the destination country’s surveillance laws, a new sub-processor, a security incident, or a change in the volume or nature of the data. Maintain a cross-border breach response procedure so that any incident affecting transferred data can be handled and notified promptly.

To keep this process auditable, use the ownership and duration table below when planning a transfer project such as onboarding a cloud vendor with non-EU sub-processors. The durations shown are indicative planning estimates only.

Step Who (owner) Typical duration (indicative)
1. Map transfers & data flows IT (data mapping) + DPO 1–2 weeks
2. Check adequacy decision DPO / Legal 1–3 days
3. Select transfer mechanism (SCCs/BCRs/derogation) Legal + Procurement 1–3 weeks
4. Run Transfer Impact Assessment (TIA) DPO + IT + Legal 1–3 weeks
5. Implement supplementary measures IT/Security 1–4 weeks (depends on measures)
6. Negotiate & sign contracts / SCCs Legal + Counterparty 2–6 weeks
7. Record keeping & register updates DPO 1–3 days
8. Ongoing monitoring / re-assessment DPO/IT (periodic) Quarterly/annual or on material change

Comparison of transfer mechanisms

The right tool depends on the destination country, the frequency of the transfer and the corporate structure. The table below compares the four main mechanisms and summarises the Garante’s practical stance.

Mechanism When to use Speed to implement Documentation required Garante view / notes
Adequacy decision Countries on the EU adequacy list Fast, immediate Adequacy log + record entry Preferred; document the reliance and its scope
SCCs (2021) Non-adequate countries, select the correct module for the parties’ roles Moderate, negotiation time Signed SCCs + TIA + supplementary measures Requires a TIA post-Schrems II
BCRs Intra-group multinational transfers Long, authorisation needed BCR approval + internal rules + DPAs Robust but long lead time
Article 49 derogations Very limited, occasional transfers Quick but risky Documented justification & alternatives Use only exceptionally; heavily scrutinised

Required documents for cross-border data transfers Italy

The Garante assesses compliance largely through documentation. A well-organised compliance repository, retained for the life of the transfer plus a defensible period afterwards, is your best protection during an inspection. Store documents in a secure, access-controlled repository and keep a version history so that reviewers can trace decisions over time.

Document Purpose Who prepares / stores
Data transfer map / flowchart Shows what is transferred, to whom and where IT / DPO (compliance repository)
Adequacy decision log Evidence where the recipient country is adequate DPO / Legal
Executed SCCs or BCR approval Legal basis for the transfer Legal / Procurement (signed copies)
Transfer Impact Assessment (TIA) report Risk analysis with supplementary measures DPO (with IT & Legal input)
DPIA (where applicable) Required where the transfer is part of high-risk processing DPO
Data processing agreements / sub-processor list Processor obligations & sub-processors Legal / Procurement
Record of derogations & justification (Art. 49) For exceptional transfers Legal / DPO
Evidence of technical measures Encryption configs, access logs, IAM records IT / Security
Incident response & cross-border breach logs Notification paths and records Security / Legal / DPO
Internal approvals & meeting minutes Board/DPO approvals for high-risk transfers DPO / Legal
Training records Demonstrates organisational measures HR / DPO

Timeline & deadlines, operational milestones

A typical cloud-vendor onboarding involving non-EU sub-processors runs from initial data mapping to contractual go-live in roughly eight to twelve weeks, with the negotiation of SCCs (two to six weeks) usually being the critical path. These are internal project estimates rather than statutory deadlines. Plan against these operational checkpoints:

  • Within 1–2 weeks of project kick-off: complete the data-flow map (Step 1) and the adequacy check (Step 2).
  • Before any transfer begins: complete the initial TIA (Step 4) so that data does not move before the assessment is finished.
  • Before go-live: execute the SCCs and confirm supplementary measures are live and evidenced (Steps 5 and 6).
  • Annually, or on material change: re-run the TIA and refresh records (Step 8).

Note that a separate statutory deadline applies to personal data breaches: under Article 33 GDPR, notifiable breaches must be reported to the Garante without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Treat contractual signature as a hard gate: personal data should not flow to a non-adequate country before the legal mechanism and technical measures are both in place and documented.

Costs / fees, budgetary guidance

Costs vary widely between an Italian SME onboarding a single vendor and an enterprise managing a global data estate, and the figures below are broad illustrative planning ranges rather than fixed prices. The largest variable is usually the maturity of existing technical controls. Budget for legal drafting, the TIA effort, technical implementation and vendor assurance work, and track internal FTE hours, which are frequently the hidden cost of a transfer programme.

Cost item Illustrative range (SME) Illustrative range (Enterprise) Notes
Legal review & SCC drafting €1,000–3,000 €3,000–15,000 Depends on counterparty complexity
Transfer Impact Assessment (TIA) €1,000–4,000 €5,000–20,000 Internal DPO time vs external consultant
Technical controls (encryption, logging, IAM) €2,000–10,000 €10,000–200,000+ Depends on baseline maturity
Vendor audits / security assessments €1,500–6,000 €5,000–50,000 Penetration test, SOC 2 review
Contract negotiation resource cost Internal hours / external fees Internal + external counsel fees Track FTE hours
Record management & compliance tools €500–3,000/year €5,000–50,000/year DPO / record-keeping platforms

Negotiation tips: use the standard SCC annexes rather than bespoke drafting where possible, limit audit scope to what the risk justifies, and reuse a single well-built TIA template across similar vendors to control the per-transfer cost.

What changes in 2026, EDPB & Garante updates to watch

The direction of travel in 2026 is towards deeper, better-evidenced assessments. EDPB guidance continues to emphasise that SCCs are a starting point, not a finish line: the effectiveness of the transfer tool must be tested against the real law and practice of the destination country, and supplementary measures must be genuinely capable of addressing identified risks. For Italian organisations, the practical effect is that a superficial TIA, one that asserts low risk without analysing public-authority access, is increasingly unlikely to satisfy either the EDPB methodology or the Garante on inspection.

On the enforcement side, the Garante has continued to prioritise transfers in its supervisory activity, focusing on whether controllers can produce a complete transfer map, an executed and correctly annexed SCC, a documented TIA and evidence of the technical measures they claim to have implemented. Auditability, the ability to show your working, dated and version-controlled, is now as important as the substantive decision itself. Industry observers expect the depth of TIA documentation and the quality of supplementary-measure evidence to remain the areas most likely to attract regulatory challenge.

Organisations relying on transfers to the United States should also confirm whether their US recipient is certified under the EU–US Data Privacy Framework, in respect of which the Commission adopted an adequacy decision in July 2023; the framework is subject to ongoing review and legal challenge, so its status should be verified before relied upon.

Enforcement takeaways for Italian controllers and processors

  • Documentation gaps draw scrutiny. Missing or undated TIAs and unsigned SCC annexes are frequent findings.
  • Technical claims must be evidenced. Asserting encryption without configuration proof is treated as a weakness.
  • Sub-processor chains matter. Onward transfers to a further party in a third country must be mapped and covered.
  • Re-assessment is expected. A one-off TIA with no review schedule signals an immature programme.

Common pitfalls & how to avoid them

Most cross-border data transfers italy failures are procedural rather than doctrinal. The recurring mistakes are predictable and avoidable:

  • Accepting a vendor’s SCC template as final. Verify that the annexes reflect your actual data flows and technical measures before signing.
  • Skipping a documented TIA on “low risk” grounds. The assessment should exist and be written down even where the conclusion is that risk is low.
  • Failing to record adequacy or derogations properly. An unlogged reliance on adequacy is, for inspection purposes, hard to substantiate.
  • Not implementing or documenting supplementary measures. Technical controls that exist but are not evidenced provide little defensive value.
  • Neglecting periodic re-assessment. A change in the destination country’s law can undermine your original conclusion.

Quick mitigation checklist for audits and investigations

  • Confirm every active transfer appears on the Article 30 record with a linked mechanism.
  • Retrieve the signed SCCs with completed annexes for each non-adequate transfer.
  • Produce the dated TIA and its re-assessment log.
  • Show technical evidence (encryption, IAM, logs) matching the TIA’s stated measures.
  • Demonstrate a defined trigger-based review process.

Conclusion & next steps

Getting cross-border data transfers italy compliance right in 2026 is a matter of disciplined process and defensible documentation. Take five immediate actions: map every transfer and its data flows; check the current EU adequacy list; run and record a TIA for each non-adequate destination; implement and evidence supplementary technical measures; and execute correctly annexed SCCs before any data moves. Review the whole file at least annually and whenever a material change occurs. For tailored advice, to review your SCC annexes, or to build a TIA methodology suited to your organisation, consult the Data Protection lawyers, Italy through Global Law Experts.

Sources

  1. Regulation (EU) 2016/679, GDPR (Official text)
  2. Court of Justice of the European Union, C-311/18 (Schrems II) judgment
  3. European Data Protection Board (EDPB), Recommendations 01/2020 on measures that supplement transfer tools
  4. European Commission, Adequacy decisions
  5. European Commission, Standard Contractual Clauses (2021)
  6. Garante per la Protezione dei Dati Personali
  7. Decreto Legislativo 101/2018, Gazzetta Ufficiale

FAQs

How do I legally transfer personal data from Italy to a non-EU country?
Rely on a Commission adequacy decision where one exists; otherwise use SCCs or BCRs supported by a TIA and supplementary measures, or an Article 49 derogation for exceptional, occasional transfers. Document the chosen mechanism and run a TIA where required (GDPR Arts. 44–50; EDPB recommendations; Garante guidance).
Run a TIA whenever you rely on Article 46 safeguards such as SCCs or BCRs to transfer to a country without an adequacy decision. The assessment should be more thorough where the data is sensitive, where the transfer is large-scale, or where specific legal or technical risks are identified. The Garante expects a documented risk analysis to be available (EDPB guidance; Garante).
SCCs are a valid transfer tool but are not sufficient on their own. Following Schrems II you must assess the destination country and, where necessary, supplement the SCCs with technical, organisational and contractual measures to address access by third-country public authorities (CJEU C-311/18; EDPB recommendations).
A clear transfer map, executed transfer agreements, a TIA report, evidence of technical measures and records of periodic reviews, all kept readily available for inspection (Garante guidance).
No. SOC reports are useful evidence of security controls and should feed into your TIA, but they do not replace a valid legal transfer mechanism such as SCCs when transferring to a non-adequate country (EDPB guidance).
Re-assess through the TIA, implement additional measures, or suspend the transfer if the risk cannot be mitigated. Document the re-assessment and the decision taken (EDPB recommendations; Garante).
barbados welcome stamp
By Jonathon Richards

posted 46 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Transfer Personal Data Outside the EU From Italy (2026): Sccs, Transfer Impact Assessments & the Garante's Expectations

Send welcome message

Custom Message