Chapter V of the Regulation is the part a software company meets on the day it signs up for a hosting region, a support desk or an analytics tool run from outside the European Economic Area. Article 44 sets the principle: any transfer of personal data to a third country or an international organisation takes place only if the conditions of the Chapter are complied with by the controller and the processor, including for onward transfers, and all its provisions are applied so that the level of protection the Regulation guarantees is not undermined. This article reads the Chapter against the catalogue StandardOS keeps of the Regulation and against the Commission's own list of adequacy decisions, with the free page that picks the mechanism from the destination and the two roles.
First question: is it a transfer at all
A recipient in one of the 27 member states, or in Iceland, Liechtenstein or Norway, is not in a third country: the Regulation applies there directly, by the Treaties and by the EEA Agreement, and Chapter V is not engaged. The record of processing still names the recipient (Article 30(1)(d)), but no mechanism is needed. Everything outside those 30 states is a third country, whether or not the recipient is a well-known company, whether or not the data are encrypted in transit, and whether or not the recipient calls itself GDPR-compliant. The question is answered by the country of the establishment that processes the data, not by the flag on the importer's website.
Second question: is there an adequacy decision
Article 45(1) lets a transfer to a country the Commission has decided ensures an adequate level of protection take place without any specific authorisation. The Commission's page on adequacy for non-EU countries, read on 12 September 2026, says it has so far recognised 17: Andorra, Argentina, Brazil, Canada, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, the United States, Uruguay and the European Patent Organisation. Eleven of them were adopted under Directive 95/46/EC and reviewed by the Commission's report of 15 January 2024; the rest under Article 45, with the newest acts the page lists being Brazil's decision of 26 January 2026, the renewal of the United Kingdom's decision on 19 December 2025, the European Patent Organisation's decision of 15 July 2025 and the first review of the Republic of Korea's decision on 23 July 2026. Two decisions have a scope a software company must check: Canada's covers commercial organisations, and the United States' covers only commercial organisations participating in the EU-US Data Privacy Framework, so a US importer is adequate if it is certified and a third-country importer like any other if it is not. The page keeps that list as data, with the date it was read, and the transfers tool asks the scope question where a decision has one.
Third question: which safeguard, and which module
Without a decision, Article 46(1) requires appropriate safeguards that give the people concerned enforceable rights and effective remedies, and Article 46(2) lists six that need no specific authorisation: a legally binding instrument between public authorities, binding corporate rules, standard data protection clauses adopted by the Commission, clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct, and an approved certification. For a software company the answer is the third: the standard contractual clauses of Commission Implementing Decision (EU) 2021/914 of 4 June 2021, whose Annex has four modules by the roles of the parties. Module One is controller to controller, the company sending its own customer data to a partner that decides what to do with them; Module Two is controller to processor, the company sending its own data to a CRM, a payroll or an email provider; Module Three is processor to processor, the company sending its customers' data to its hosting, support or AI sub-processor; Module Four is processor to controller, the rare case of a processor returning data to a non-EU controller. Signing the module is not the whole safeguard: Clause 14 requires the parties to have assessed, before the transfer, whether the laws and practices of the importer's country prevent it from complying with the clauses, which is the assessment the Court of Justice required in Schrems II, and Clause 15 sets the importer's duties when a public authority asks for the data. The assessment is documented and kept for the supervisory authority. Binding corporate rules under Article 47 are for a group of undertakings and take an authority's approval; a code or a certification helps only where one exists for the importer.
Fourth question: is this a specific situation
Article 49(1) allows a transfer without adequacy or safeguards on one of seven conditions: explicit consent after being informed of the risks, the performance of a contract with the data subject, a contract in the data subject's interest, important reasons of public interest, legal claims, vital interests, or a public register. Its second subparagraph adds the transfer necessary for compelling legitimate interests, which must not be repetitive, concern only a limited number of data subjects, be assessed and documented, and be notified to the supervisory authority. None of that describes a product in use: a hosting provider processes every customer's data every day, and a consent that would have to be obtained from each of the company's customers' end users is not a mechanism. The derogations are for the single occasion, the one file sent once, and a company that rests its architecture on them has no mechanism.
What to do with it
Take the record of processing and its recipients column, and give every recipient outside the EEA a country and a mechanism: the adequacy decision that carries it, with the scope checked for a US or Canadian importer, or the SCC module signed with its annexes and the Clause 14 assessment dated. Ask a US importer for its Data Privacy Framework certification and check it on the Department of Commerce's list; ask a UK or Japanese importer for nothing more than the contract; ask an Indian, Australian or Singaporean importer for the signed clauses and its own sub-processor list, since onward transfers stay under Chapter V. Put the mechanism into the processor terms a customer sends, because Article 28(4) puts a sub-processor under the same obligations as the processor, and into the record, because Article 30(1)(e) asks for the transfers and their safeguards. The transfers page does the determination from the destination and the two roles and writes it; the duties determination says whether transfers are among the company's duties at all.