03 · What You Need to Know
International Transfer Rules Add Another Layer to Research Data Governance
First determine whether personal data are involved
International personal-data transfer rules generally concern personal information, not every research file that crosses a national border.
If a dataset is genuinely anonymous under the applicable legal standard, personal-data transfer restrictions may no longer apply to that dataset. Pseudonymized data are different: where information can still be attributed to individuals using additional information, it generally remains personal data under GDPR-style frameworks.
This makes anonymization and pseudonymization important transfer-design tools. Where the overseas collaborator does not need identities, reducing identifiability before transfer can lower risk and may change the legal analysis.
A transfer can occur without physically sending a file
Researchers sometimes imagine an international transfer as an attachment traveling from Manila to London or a hard drive being carried through an airport.
Current UK ICO guidance makes clear that a restricted transfer can include making personal information accessible to a separate organization outside the UK, including through remote access to systems. The file itself need not be downloaded abroad for access to matter.
Other jurisdictions may define transfers differently, so researchers should apply the relevant framework rather than universalizing the UK test. The broader practical lesson remains useful: map who can access the data and from where, not merely where the primary server sits.
Data residency and international transfer are related but not identical
Data residency generally concerns where data are physically stored or hosted. International-transfer rules may instead focus on disclosure or accessibility to an overseas recipient.
A dataset stored entirely on a server in one country might still be remotely accessible to a collaborator, support team, processor, or subprocessor elsewhere. Conversely, a global cloud architecture may involve storage or processing locations that researchers do not see in the ordinary user interface.
This is why cloud-service arrangements should be reviewed for processing locations, subprocessors, support access, and transfer mechanisms where personal data are involved.
Ordinary data-sharing requirements still apply
Cross-border status does not replace the normal questions about data sharing. You still need a legitimate purpose, an appropriate basis for processing and disclosure, suitable participant information where required, defined recipient roles, minimization, security, retention, and appropriate agreements.
International-transfer requirements sit on top of those ordinary obligations.
In other words, a transfer mechanism cannot rescue a disclosure that should never have happened. Before examining international safeguards, establish whether the receiving institution should receive the research data at all.
The GDPR has specific rules for transfers outside its protected framework
Chapter V of the EU GDPR governs transfers of personal data to third countries or international organizations. Depending on the circumstances, a transfer may rely on an adequacy decision, appropriate safeguards, or one of the limited derogations provided by the Regulation.
Appropriate safeguards can include mechanisms specified by the GDPR, such as standard contractual clauses in relevant circumstances. The appropriate route depends on the parties, destination, processing, and current regulatory framework.
Researchers should not choose a transfer mechanism by copying wording from another project. International transfer compliance is normally an institutional legal or data-protection function because the analysis can depend on contracts, destination-country law, recipient role, onward transfers, and technical safeguards.
The UK now applies its own international-transfer framework
UK GDPR international-transfer rules are related to but legally distinct from the EU framework. Updated ICO guidance published in January 2026 uses a three-step test to determine whether an organization is making a restricted transfer.
The ICO states that a restricted transfer must be covered by UK adequacy regulations, appropriate safeguards, or an applicable exception. It also emphasizes that the organization initiating the restricted transfer is responsible for complying with the transfer rules.
This distinction matters in multinational projects. "GDPR compliant" is not a sufficiently precise description when EU GDPR, UK GDPR, and other national laws may impose related but different requirements.
Research status does not automatically exempt international transfers
Data protection frameworks can contain special provisions for scientific, historical, statistical, or public-interest research. Those provisions should not be read as a general permission to export personal data anywhere.
ICO guidance states that UK research provisions require appropriate safeguards and notes that complex research projects involving organizations in different countries may be subject to a range of additional regulatory requirements.
Research exemptions and international-transfer rules therefore need to be considered separately.
The Philippines uses an accountability-based cross-border approach
Section 21 of the Philippine Data Privacy Act states that a personal information controller remains responsible for personal information under its control or custody, including information transferred to a third party for processing, whether domestically or internationally. It also requires contractual or other reasonable means to provide a comparable level of protection while information is processed by a third party.
This should not be rewritten into the EU GDPR's adequacy architecture. The Philippine framework has its own statutory basis and regulatory guidance.
In May 2024, the National Privacy Commission issued Advisory No. 2024-01 containing model contractual clauses for cross-border transfers of personal data. These clauses provide a Philippine contractual mechanism designed to support transfers consistent with the Data Privacy Act and related requirements.
Researchers and institutions should determine whether and how those clauses or other appropriate contractual arrangements apply to their particular transfer rather than inserting them mechanically into every international collaboration.
The destination country matters because protection may change after transfer
International-transfer rules exist partly because data may move beyond the practical or legal protections available in the originating jurisdiction.
Depending on the applicable framework, institutions may need to consider the destination country's legal environment, government-access rules, enforceability of contractual protections, recipient safeguards, and whether supplementary technical or organizational measures are needed.
This assessment is generally more sophisticated than asking whether the destination country has "a privacy law." The relevant question is whether the proposed transfer satisfies the particular originating framework's requirements.
Encryption and pseudonymization can be important supplementary safeguards
Technical safeguards can reduce the risks of international transfers. Data may be pseudonymized before leaving the originating institution, unnecessary variables removed, files encrypted during transfer and storage, access limited to named researchers, and reidentification keys retained separately.
Under UK research provisions, appropriate safeguards explicitly include measures respecting data minimization, and ICO guidance advises researchers to use anonymous information where possible and consider pseudonymization where anonymization is not possible.
These controls do not automatically satisfy every international-transfer requirement, but they can form an important part of the overall protection.
Onward transfers need attention
Your immediate collaborator may be in Country B, but what happens after the data arrive?
The recipient might use a cloud provider whose servers are in Country C, outsource analysis to a company in Country D, or give another consortium partner access from Country E. These onward transfers can create additional legal and contractual issues.
International transfer arrangements should therefore address whether onward disclosure is permitted, to whom, under what conditions, and with what safeguards. A map containing only the first sender and first recipient may miss much of the actual processing chain.
Cloud subprocessors can make the geography surprisingly complicated
A university may contract with one cloud company, which uses several subprocessors for hosting, support, backup, security monitoring, or other services. Those organizations may operate in multiple jurisdictions.
This does not necessarily make the service unsuitable. It does mean that institutional due diligence should examine the relevant processing chain rather than assuming the country printed on the provider's invoice is where all processing occurs.
Participant consent is not automatically an international-transfer mechanism
Researchers should be particularly careful about assuming that a sentence in the participant consent form authorizing "international sharing" resolves every transfer requirement.
Under GDPR-style frameworks, explicit consent can appear among derogations for certain transfers, but derogations have specific conditions and are not interchangeable with ordinary research participation consent. Current UK guidance treats exceptions as a distinct route with defined requirements.
This reflects the broader distinction between consent to participate and consent or other authority for personal-data processing.
Transfers should be documented before access is enabled
International projects can involve several institutions, cloud platforms, processors, repositories, and research teams. Documentation should make the actual data flow intelligible.
A useful record may identify the exporter or sending organization, recipient, countries involved, categories of personal data, participant groups, purposes, legal roles, transfer mechanism, technical safeguards, onward-transfer rules, retention, deletion, and incident responsibilities.
The point is not paperwork for its own sake. If the project cannot explain where participant data can go and why, it will struggle to demonstrate that those movements are controlled.
Check the Current Rules
International-transfer frameworks change. Adequacy decisions, model clauses, regulatory guidance, and national laws can be updated. Verify the current requirements with the relevant regulator and your institution before relying on a transfer mechanism from an older protocol or agreement.