Knowledge for companies

Transfer Impact Assessment: a template for the actual assessment.

A Transfer Impact Assessment (TIA) assesses whether a third-country transfer relying on an Article 46 GDPR instrument actually provides the required protection. The assessment considers data flows, relevant law and practice, and effective safeguards. The editable T-NEX template connects those findings with sources, unresolved questions and the reasoned decision.

T-NEX GmbHFirst version: Updated: Editorial policy
In daily work

How to use the solution.

Sources checked on 10 September 2026. This guide is for businesses outsourcing development or support that need a traceable assessment of data access. A TIA records the assessment of a particular transfer; it is not a general supplier certification.

Overview

When a TIA is required

Where a third-country transfer relies on an Article 46 GDPR instrument, such as standard contractual clauses, assess the required protection before the transfer. The exporter is responsible for the assessment with the importer’s assistance. Clause 14 specifies this task for SCC Modules 2 and 3, frequently relevant to outsourced development.

First establish whether a transfer exists and which basis applies. An applicable adequacy decision or a valid Article 49 derogation changes the assessment route; its conditions still need checking. A TIA also differs from an Article 35 data protection impact assessment, which concerns processing likely to create high risks. A project may need both assessments.

Overview

Download and complete the TIA working template

The T-NEX template is an editable Markdown file with questions, tables and open assessment fields. Save a project copy and record the actual parties, countries, systems and evidence for each data flow. Fields start empty; no positive country or project assessment is preset.

Open the file in a text editor and replace the entries in square brackets. Give sources and evidence identifiers so that the reasoning traces back to the version assessed. Keep unknown facts unresolved; explain why a question is not applicable.

For additional regulatory methodology, CNIL publishes a final guide and an adaptable ODS template. Its publication page is dated 9 July 2025; the guide itself is the January 2025 final version. CNIL’s method is optional and contains no completed country assessments.

  • Map data flows and actual access through to further recipients.
  • Establish legal entities, data-protection roles and the Article 3 position.
  • Identify the transfer basis, SCC modules and relevant annexes.
  • Assess third-country law and practice with sources and unresolved questions.
  • Evidence supplementary measures, including key control and plaintext access.
  • Record the decision, escalation, possible suspension and review triggers.
Overview

Describe processing through to the final recipient

Start with the actual data flow. A contracting party, a cloud account and an access location are different facts. Record the legal entities, their roles, storage locations and actual access, including further recipients. The aim is to reconcile the transfer description with the contractual annexes and technical permissions.

The following information helps establish the facts for a development project. Each statement should have evidence describing the actual state.

Facts and suitable evidence for a development project
AreaFact to establishRelevant evidence
Contracts and rolesWho is the controller, processor and any sub-processor?Contracts and role allocation for each processing activity
Production systemWhich entity can read or change which personal data?Approved permission model and verified access
Test environmentWhich data is copied, and what makes it synthetic, anonymous or pseudonymised?Documented data origin and assessment of identifiability
Support and collaborationWhat personal information appears in tickets, logs, screenshots or collaboration services?Data inventory and actual service configuration
Countries and further recipientsWhere is access made from, and which other entities receive data?Confirmed access countries and complete recipient chain
End of processing and changesWhen do access and retention end, and how are changes detected?Deletion/return rules, access removal and change procedure
Overview

Assess remote access through the entities involved

A separate supplier in a third country may be an importer through remote access even when the data remains on an EEA server. However, the EDPB's criteria require a separate recipient. Its example of an employee of the same organisation accessing data during a business trip therefore does not itself constitute a Chapter V transfer.

Assess the legal relationship alongside actual permissions: an employee, an independent supplier and a different group company are distinct situations. A person’s location alone does not establish customer-data access. Even outside a transfer, processing in a third country can present risks requiring particular safeguards.

Overview

Separate Article 3, the transfer basis and the SCC module

An importer can be directly subject to the GDPR under Article 3 for a processing activity and still receive a third-country transfer. Article 1 of the 2021/914 SCCs instead scopes those clauses to importers whose relevant processing is not already subject to the GDPR. Record this scope question explicitly before selecting a module.

Module 2 addresses controller-to-processor transfers; Module 3 addresses processor-to-processor transfers. Both incorporate Article 28 requirements. The separate 2021/915 clauses are not themselves a third-country transfer instrument. For Module 4, assess the particular condition governing Clause 14; the working template includes it.

Overview

Connect law and practice to the particular transfer

The country assessment must address rules and practices relevant to the importer and data concerned. These include public-authority access powers, limits on those powers and available remedies. A general country profile or a data protection statute considered without access rules does not answer these questions.

Record the source, its legal status and its relevance to the facts. The importer's account of previous practice may contribute to the assessment; a general statement that it has never received a request cannot carry the conclusion by itself. Conflicting information and unresolved questions need to remain visible in the assessment.

Overview

Select supplementary measures by their effect

A measure must address the identified problem. Encryption in transit protects a different operation from a design in which the importer cannot decrypt the information. Where a supplier needs plaintext and problematic public-authority access rules apply to the transfer, the EDPB identifies no effective technical supplementary measure for its described Use Cases 6 and 7 at the state of the art assessed in the recommendations.

Pseudonymisation is not automatic approval either. Its protective effect depends, among other things, on who holds additional information and whether the people concerned can be identified again using available means. Removing names alone is insufficient. A short retention period limits storage but does not remove access that has already been enabled.

Overview

A development example shows where assumptions stop

Suppose a business engages a legally separate supplier outside the EEA. Development initially receives only newly generated test records without personal data. Later, someone proposes adding a production screenshot containing a customer's name to a support ticket.

The original statement about test data is no longer sufficient for that support activity. The screenshot data, entities with access, ticketing service and further recipients need assessment. The assessment needs to cover this additional support activity before the screenshot is made accessible.

A practical approach is to decide in advance how faults will be reproduced without personal production data and who assesses an exception. Evidence then comes from the implemented working process and its controls, rather than a sentence in the TIA alone.

Overview

The decision must reflect safeguards actually in operation

The conclusion must explain whether the chosen instrument and implemented measures provide the required protection for the described circumstances. A planned measure must not be treated as already implemented. If the required protection cannot be achieved, the transfer must not begin or must be suspended.

Keep a traceable record of the version assessed, factual basis, remaining actions, responsible participants and decision. The technical implementation, contractual terms and legal assessment must refer to the same state. External assistance does not remove the participating entities' respective obligations.

Decision and next action
FindingRequired action
Facts or evidence material to the decision are missing.Assign and resolve open issues; do not count planned measures as implemented protection.
The instrument and measures actually implemented ensure the required protection.Record the assessed scope, supporting evidence and reasoned decision.
The required protection cannot be ensured for the transfer considered.Do not start or suspend the transfer; change architecture, recipient or workflow and reassess.
Overview

Maintain the assessment

A TIA needs to be updated when relevant circumstances change. A new recipient, another access location, a different data category or a change in applicable law may require reassessment. Appropriate review intervals should also be set; an annual review is not a general statutory substitute for responding to specific changes.

Connect review to the actual change process. Anyone introducing another support service or additional permission needs to know when the people responsible for data protection and contracts must be involved. This keeps the transfer description connected to development operations.

FAQ

Frequently asked questions

Can I edit the T-NEX TIA template directly?

Yes. After downloading the Markdown file, edit it in a text editor. Replace placeholders, add data flows and link your evidence. The template contains no preset approval or country assessment; the conclusion comes from the completed assessment.

Does a TIA replace standard contractual clauses?

No. It assesses the effectiveness of the transfer instrument in the particular circumstances. A TIA does not replace the required legal basis or appropriate instrument.

Can I use the CNIL template unchanged?

You can use it as a working structure. Project-specific facts, legal sources, measures and conclusions still need to be established and reviewed. The CNIL template does not contain a completed country assessment.

Is a TIA the same as a DPIA?

No. A TIA concerns protection in a third-country transfer. A DPIA under Article 35 GDPR concerns processing likely to create high risks. A project may need both.

Can one country assessment cover every project?

A shared assessment can support transfers only where its facts and legal assumptions actually cover them. Different recipients, access countries or data flows must not silently be treated as covered by the same conclusion.

Who is responsible for the TIA?

The exporter is responsible for the assessment with the importer’s assistance. Specialist, legal and technical contributors provide the required assessments and evidence. The project needs a clear decision-maker for the described transfer and an escalation route for changes or insufficient protection.

Related options

You may also be interested in these.

Which task would you like to solve next?

Bring a concrete task. Together, we will define what the application needs to do.

Discuss data access in a development project