FillTrust

How to answer

How do you handle international transfers of personal data?

Where the servers are is only half of it. Who can reach the data, from which country, is the other half.

A model answerConfirmed in your documents

Our Data Processing Agreement incorporates the European Commission's 2021 Standard Contractual Clauses for transfers outside the EEA, and our sub-processor list states the region each processor operates in. Customers may elect [EU-only] hosting, in which case customer content remains in the EU.

Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.

Answered from
Your Data Processing Agreement, its Standard Contractual Clauses annex, and your sub-processor list.
Evidence to attach
The DPA itself, and occasionally the transfer impact assessment if the buyer is a European enterprise. A buyer relying on Data Privacy Framework adequacy may ask you to evidence a sub-processor's certification.
Where it is asked
CAIQ v4.0 · DSP-10SIG LiteBespoke vendor questionnaires

For any European buyer this is one of the questions that decides whether procurement proceeds, and it is answered from contracts rather than from architecture.

Start with the mechanism. For transfers out of the EEA the standard answer is the European Commission's 2021 Standard Contractual Clauses, incorporated into your DPA. If your DPA has them annexed, say so and name the module. If it references the old 2010 clauses or Privacy Shield, that is a paperwork problem worth fixing before the next questionnaire, because it is visible and it dates everything around it.

Know where the Data Privacy Framework fits. Since the European Commission's 2023 adequacy decision, a transfer to a US company that is certified under the EU-US Data Privacy Framework needs no separate transfer mechanism, because the destination is treated as adequate. That is worth checking for each of your US sub-processors, and worth stating when it is true. Two cautions belong with it. Adequacy covers only certified entities, so it is a per-vendor fact rather than a per-country one, and you should confirm the certification rather than assume it. And the framework is under appeal at the Court of Justice, having survived a first challenge in the General Court in September 2025, which is the reason most companies keep Standard Contractual Clauses in place alongside it rather than instead of it. Both of its predecessors were struck down by that court. Answering that you rely on the clauses, and that several sub-processors are additionally certified, is the position that survives whichever way the appeal goes.

Then the map. Which regions your infrastructure runs in, and which regions your sub-processors run in. This is where most answers quietly break: the application may be hosted in Frankfurt while the error tracker, the support desk and the model provider are all in the United States, and each of those can receive personal data in the ordinary course of work.

Access is a transfer. A support engineer in another country viewing a record is a transfer even if the disk never moves. If your team is distributed, say so and say what governs it, which is the same clauses plus your access controls. Reviewers respect an answer that raises this before they do.

Say whether EU-only is available. If a customer can elect EU hosting, that is often the sentence that closes the topic, and it belongs in the answer rather than in a later email.

Transfer impact assessments. European enterprises sometimes ask for one. If you have not done one, saying that the clauses are in place and that you will support the customer's own assessment is a normal position for a company of this size.

This grades as confirmed when your DPA is current, which is the point: the answer is a contract, not a claim, and the work is making sure the contract says what you are about to tell somebody it says.

How this one goes wrong

Specific to this question, not general advice.

  • Saying data never leaves the EU when a support tool, an error tracker or an AI provider is hosted elsewhere. Personal data in a stack trace is still personal data.
  • Citing Privacy Shield. It was invalidated in 2020, and its successor is the EU-US Data Privacy Framework, which is a different scheme with a different certification. Naming the dead one dates your paperwork immediately.
  • Treating this as a hosting question. Where the servers are is one part; who can access the data from where is the other, and remote support staff count.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.