PONOPT FIELD NOTES · Privacy и governance

Cross-Border Data Transfers for an International Property Portfolio

How to compliantly transfer tenant and property data across borders under GDPR: adequacy, SCCs, impact assessments, and a routing map.

A property group operating in several countries must treat every export of personal data — tenant records, occupier CCTV, employee files, payment data, CRM or cloud logs — as a regulated cross-border transfer. First check whether the destination benefits from an adequacy decision; if not, adopt the 2021 standard contractual clauses and complete a documented transfer impact assessment, adding supplementary measures where the destination country's law falls short. Only then, in narrow cases, rely on the limited Article 49 derogations such as explicit consent.

Key takeaways

  • A cross-border transfer occurs whenever tenant, occupier, employee or visitor data is exported to a processor or group company outside the EEA — even if you only subscribe to a US-hosted CRM, payroll, cloud or CCTV platform.
  • Adequacy decisions under Article 45 remove all Chapter V obstacles for the listed countries and territories, so always consult the current list before assuming contracts are needed.
  • Where no adequacy decision applies, the 2021 SCCs are the default tool, but they must be paired with a documented transfer impact assessment and, where necessary, supplementary measures.
  • Every transfer needs both a lawful basis under Article 6 and a Chapter V route; consent or other Article 49 derogations are exceptional and should not become routine for property operations.
  • For multi-entity groups, binding corporate rules are the durable, cost-effective mechanism for recurring intra-group flows across many jurisdictions.
  • Because data protection schedules and adequacy findings change, transfers must be re-evaluated periodically and recorded in your register of processing.

What actually crosses the border in a property portfolio

Real-estate operators often assume they are outside the data-transfer debate because they do not run a tech business. In practice a large share of the value chain is hosted overseas: tenant relationship management, lease and payment systems, occupancy analytics, CCTV platforms at car parks and entrances, visitor management, and payroll for staff in several countries. Where a supplier or a group company outside the EEA receives or accesses identifiable data, a transfer regulated by Chapter V of the GDPR has taken place.

The personal data in scope is broad. Tenant and occupier identity and lease terms, rent and payment collection records, car-park security footage and property occupancy data, information about visitors and contractors, and employee HR files are all examples that can be processed overseas. Because the categories are heterogeneous, a single legal shortcut rarely works — the compliance design has to follow each data flow separately.

  • Tenant and occupier records: identity, lease, rent history and correspondence.
  • Surveillance and occupancy data captured by cameras at car parks, lobbies and communal areas.
  • Visitor and contractor logs from access-control and management platforms.
  • Employee and payroll records processed by a central or cloud HR provider.
  • Analytics and smart-building logs linked to identified individuals.

First stop: adequacy decisions remove the barrier

Article 45 of the GDPR lets the European Commission decide that a third country or territory offers an adequate level of protection. The effect is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that country without any further safeguard. The Commission's current list includes Andorra, Argentina, Brazil, Canada (commercial organisations), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the UK, Uruguay, the European Patent Organisation, and US commercial organisations participating in the EU-US Data Privacy Framework.

Adequacy is not permanent: decisions are reviewed periodically and can be amended or withdrawn, and most cover only commercial transfers, not law-enforcement exchanges. So the list must be checked at design time and revisited on a schedule. If a property group sends data to a subsidiary in an adequacy country, that leg needs no further transfer mechanism — a meaningful simplification when most of your portfolio sits in adequacy jurisdictions.

When adequacy is missing: SCCs and the transfer impact assessment

Since 4 June 2021 the European Commission's modernised standard contractual clauses are the default tool for transfers between EU/EEA controllers or processors and parties outside the EEA. The 2021 SCCs cover the main routing shapes (controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller) and must be signed before the transfer starts.

Following the Schrems II ruling, signing the clauses is only part of the job. The European Data Protection Board's recommendations on supplementary measures set out a six-step analysis: know your transfers and map them; identify the transfer tool; assess whether the recipient country's law and practice undermine the tool; adopt supplementary measures where needed (for example end-to-end encryption, pseudonymisation or strong organisational controls); take any procedural steps; and re-evaluate periodically. That documented analysis is often called a transfer impact assessment, and regulators expect it to be genuinely country- and flow-specific, not a template with a tick-box.

  • Map every flow: data category, exporting entity, recipient, country and system.
  • Choose the SCC module that matches your controller/processor relationship.
  • Assess the destination country's law and government-access practice.
  • Add supplementary measures if the assessment shows gaps in protection.
  • Document the assessment and set a regular re-evaluation cycle.

Structured options for groups: BCRs and the Data Privacy Framework

A property group with entities in many countries often finds individual SCCs unmanageable. Binding corporate rules let an entire group adopt one set of internally binding data-protection rules, approved by a lead supervisory authority, so intra-group transfers no longer need per-flow contracts. BCRs are more expensive to set up but become efficient once the portfolio spans many jurisdictions with recurring flows.

For US destinations, the EU-US Data Privacy Framework gives a dedicated adequacy route: personal data can flow freely from the EU to US organisations that have self-certified and appear on the Department of Commerce's list. The safeguards behind the framework also make it easier to use other tools, such as SCCs, with US recipients. Because certification lapses, always verify that the specific US processor is an active DPF participant before relying on it.

Article 49 derogations are a narrow last resort

Where neither adequacy nor an Article 46 tool is available, the GDPR offers limited derogations. The most discussed is the data subject's explicit, informed consent to the proposed transfer, given after they are told of the risks. Others cover contract performance at the subject's request, important reasons of public interest, legal claims, protection of vital interests, and a constrained legitimate-interests route for non-repetitive transfers.

Derogations are meant to be exceptional and are interpreted restrictively. Basing routine tenant onboarding, rent collection or CCTV processing on consent is fragile, because consent can be withdrawn and the balance of power between landlord and tenant is questionable. For recurring property operations you should build the Article 46 infrastructure (SCCs or BCRs) rather than design your business around derogations.

Governance: records, contracts and re-evaluation

Transfer compliance becomes auditable when it is documented. Keep a register of processing that records, for each flow, the recipient, the third country, the transfer mechanism, the completion of a transfer impact assessment and any supplementary measures. Data-protection impact assessments should cover CCTV and large-scale tenant or employee processing before high-risk projects go live.

Processor contracts must align with Article 28 and, where a sub-processor sits outside the EEA, flow the relevant Chapter V obligations downstream. Given that schedules change — new adequacy decisions, renewed SCCs, or shifts in a country's practice — transfer arrangements should be reviewed on a fixed cycle and after any material change in suppliers, systems or portfolio geography.

Cross-border transfer routing compliance map

A reusable decision matrix that turns your portfolio's messy data flows into one auditable map. Fill it in per data flow (not per company) so every transfer has a named recipient, a legal route and an owner, and survives a regulator's inspection.

  1. Name the flow: data category (tenant, occupier, visitor, employee, CCTV) and the exporting country and entity.
  2. Identify the recipient: group company, processor, sub-processor or cloud service, and its country.
  3. Run an adequacy check first — if the country is on the current Commission list, record it and stop.
  4. If there is no adequacy decision, choose the transfer tool: 2021 SCCs, BCRs, or DPF for a certified US recipient.
  5. Complete a documented transfer impact assessment for that specific country and flow.
  6. Decide on supplementary measures (encryption, pseudonymisation, access controls) where the assessment shows risk.
  7. Confirm the lawful basis under Article 6 separately — consent for the transfer does not replace a processing basis.
  8. Only if no Article 45 or 46 route works, document a narrow Article 49 derogation and justify why it is not routine.
  9. Record the outcome in the register of processing and assign a flow owner across the portfolio.
  10. Set a re-evaluation date and a trigger list (new countries, new suppliers, changed adequacy findings, new SCC versions).

Questions people ask

Does using a US-hosted property-management or CCTV platform from an EU office count as a cross-border transfer if the data is processed for EU sites?

Yes. Whenever a processor or a group company outside the EEA receives or can access personal data that is identifiable — tenant names, payment history, occupancy or CCTV footage — a transfer under Chapter V of the GDPR has occurred, regardless of where the physical property sits. If the US provider is certified under the Data Privacy Framework, that adequacy route may apply; otherwise you need SCCs plus a transfer impact assessment.

Can one global privacy policy and one SCC template cover all the countries where our portfolio operates?

No. A single policy can define your standards, but each transfer route depends on the destination. Adequacy countries need no extra mechanism; others need SCCs, BCRs or the DPF; some flows may fall back on Article 49. Your transfer impact assessment must assess each destination country's law and practice separately, so a template SCC is never enough on its own without the documented per-country analysis.

Do we still need a transfer impact assessment if we have signed the 2021 standard contractual clauses?

Yes. Signing the SCCs alone does not make a transfer compliant. Following Schrems II, the exporter must assess whether the law and practice of the destination country undermine the protection the clauses are meant to provide, and adopt supplementary measures if they do. That documented assessment is expected by supervisory authorities and should be specific to the country, the recipient and the data involved.

When can we rely on explicit consent to transfer tenant data instead of setting up SCCs?

Explicit consent under Article 49 is an exceptional, last-resort derogation when no adequacy decision or Article 46 tool is available, and it must be freely given and informed of the risks. Because of the power imbalance between landlord and tenant and the ease of withdrawing consent, it is fragile for recurring property operations. Consent does not replace the need for a lawful basis under Article 6 either.

What is the practical difference between standard contractual clauses and binding corporate rules for a property group?

SCCs are signed per relationship and cover transfers to a named third-party recipient; they work well for a handful of suppliers. Binding corporate rules are a single set of approved, internally binding rules covering all intra-group transfers across every jurisdiction in which the group operates. BCRs cost more to establish and need supervisory-authority approval, but they scale better for a portfolio spanning many countries.

How often should a property company review its international transfer arrangements?

Review on a fixed schedule, typically at least annually, and immediately after any material change: adding or removing a country, switching a supplier or cloud provider, introducing a new CCTV or tenant system, a changed adequacy decision, or updated SCCs. Adequacy findings and framework certifications are periodically reviewed or can lapse, so 'set and forget' is the main compliance risk.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. Adequacy decisions — how the EU determines if a non-EU country has an adequate level of data protectionEuropean Commission
  2. Standard Contractual Clauses (SCC) for data transfers between EU and non-EU countriesEuropean Commission
  3. EU-US data transfers under the Data Privacy FrameworkEuropean Commission
  4. Sending real estate data to the US and other non-EEA countries is now a major challengeMishcon de Reya
  5. Data Transfers: the EDPB finalises Recommendations on supplemental transfer toolsMacRoberts
  6. Закон о персональных данных от 27.07.2006 № 152-ФЗ «О персональных данных»ГАРАНТ
  7. Трансграничная передача персональных данных: правила по 152-ФЗКибероснова (152ФЗ)