Manuel B. Garcia

Manuel B. Garcia serves as the Senior Director for Educational Technology and Digital Learning at FEU Institute of Technology, Manila, Philippines. Read More

Contact Info

1607, FEU Tech Building,
P. Paredes St, Sampaloc,
Manila, Philippines
mbgarcia@feutech.edu.ph

Follow Me

What Should You Consider Before Transferring Research Data Across Countries?

International research data transfers can trigger requirements beyond ordinary institutional data sharing. Researchers should consider not only where files are sent, but who abroad can access them, which laws apply, and what transfer safeguards are required.

318
International Research Data Transfers Guide 318 of 398
01 · The Question

When Does an International Research Collaboration Become a Cross-Border Data Transfer?

Your collaborator is in another country. You do not email them a dataset and no USB drive crosses a border. Instead, you give them login access to a secure research platform hosted by your institution.

Have you transferred the data internationally?

Potentially. Cross-border transfer rules can apply not only when files physically move between countries but also when personal data are made accessible to a separate organization abroad. The exact definition and requirements depend on the data protection framework governing the processing.

02 · The Short Answer

Check the Legal Transfer Rules Before Giving Overseas Access

In Brief

Before transferring personal research data across countries, determine whether the proposed sending or overseas access constitutes an international transfer under the applicable law, identify the sender and recipient roles, establish the lawful research processing, and satisfy any additional transfer mechanism or safeguard required for the destination.

Different jurisdictions use different cross-border frameworks. Do not assume that GDPR adequacy decisions, UK transfer mechanisms, or Philippine contractual safeguards are interchangeable. The transfer must be assessed under the law or laws that actually apply to the research.

03 · What You Need to Know

International Transfer Rules Add Another Layer to Research Data Governance

First determine whether personal data are involved

International personal-data transfer rules generally concern personal information, not every research file that crosses a national border.

If a dataset is genuinely anonymous under the applicable legal standard, personal-data transfer restrictions may no longer apply to that dataset. Pseudonymized data are different: where information can still be attributed to individuals using additional information, it generally remains personal data under GDPR-style frameworks.

This makes anonymization and pseudonymization important transfer-design tools. Where the overseas collaborator does not need identities, reducing identifiability before transfer can lower risk and may change the legal analysis.

A transfer can occur without physically sending a file

Researchers sometimes imagine an international transfer as an attachment traveling from Manila to London or a hard drive being carried through an airport.

Current UK ICO guidance makes clear that a restricted transfer can include making personal information accessible to a separate organization outside the UK, including through remote access to systems. The file itself need not be downloaded abroad for access to matter.

Other jurisdictions may define transfers differently, so researchers should apply the relevant framework rather than universalizing the UK test. The broader practical lesson remains useful: map who can access the data and from where, not merely where the primary server sits.

Data residency and international transfer are related but not identical

Data residency generally concerns where data are physically stored or hosted. International-transfer rules may instead focus on disclosure or accessibility to an overseas recipient.

A dataset stored entirely on a server in one country might still be remotely accessible to a collaborator, support team, processor, or subprocessor elsewhere. Conversely, a global cloud architecture may involve storage or processing locations that researchers do not see in the ordinary user interface.

This is why cloud-service arrangements should be reviewed for processing locations, subprocessors, support access, and transfer mechanisms where personal data are involved.

Ordinary data-sharing requirements still apply

Cross-border status does not replace the normal questions about data sharing. You still need a legitimate purpose, an appropriate basis for processing and disclosure, suitable participant information where required, defined recipient roles, minimization, security, retention, and appropriate agreements.

International-transfer requirements sit on top of those ordinary obligations.

In other words, a transfer mechanism cannot rescue a disclosure that should never have happened. Before examining international safeguards, establish whether the receiving institution should receive the research data at all.

The GDPR has specific rules for transfers outside its protected framework

Chapter V of the EU GDPR governs transfers of personal data to third countries or international organizations. Depending on the circumstances, a transfer may rely on an adequacy decision, appropriate safeguards, or one of the limited derogations provided by the Regulation.

Appropriate safeguards can include mechanisms specified by the GDPR, such as standard contractual clauses in relevant circumstances. The appropriate route depends on the parties, destination, processing, and current regulatory framework.

Researchers should not choose a transfer mechanism by copying wording from another project. International transfer compliance is normally an institutional legal or data-protection function because the analysis can depend on contracts, destination-country law, recipient role, onward transfers, and technical safeguards.

The UK now applies its own international-transfer framework

UK GDPR international-transfer rules are related to but legally distinct from the EU framework. Updated ICO guidance published in January 2026 uses a three-step test to determine whether an organization is making a restricted transfer.

The ICO states that a restricted transfer must be covered by UK adequacy regulations, appropriate safeguards, or an applicable exception. It also emphasizes that the organization initiating the restricted transfer is responsible for complying with the transfer rules.

This distinction matters in multinational projects. "GDPR compliant" is not a sufficiently precise description when EU GDPR, UK GDPR, and other national laws may impose related but different requirements.

Research status does not automatically exempt international transfers

Data protection frameworks can contain special provisions for scientific, historical, statistical, or public-interest research. Those provisions should not be read as a general permission to export personal data anywhere.

ICO guidance states that UK research provisions require appropriate safeguards and notes that complex research projects involving organizations in different countries may be subject to a range of additional regulatory requirements.

Research exemptions and international-transfer rules therefore need to be considered separately.

The Philippines uses an accountability-based cross-border approach

Section 21 of the Philippine Data Privacy Act states that a personal information controller remains responsible for personal information under its control or custody, including information transferred to a third party for processing, whether domestically or internationally. It also requires contractual or other reasonable means to provide a comparable level of protection while information is processed by a third party.

This should not be rewritten into the EU GDPR's adequacy architecture. The Philippine framework has its own statutory basis and regulatory guidance.

In May 2024, the National Privacy Commission issued Advisory No. 2024-01 containing model contractual clauses for cross-border transfers of personal data. These clauses provide a Philippine contractual mechanism designed to support transfers consistent with the Data Privacy Act and related requirements.

Researchers and institutions should determine whether and how those clauses or other appropriate contractual arrangements apply to their particular transfer rather than inserting them mechanically into every international collaboration.

The destination country matters because protection may change after transfer

International-transfer rules exist partly because data may move beyond the practical or legal protections available in the originating jurisdiction.

Depending on the applicable framework, institutions may need to consider the destination country's legal environment, government-access rules, enforceability of contractual protections, recipient safeguards, and whether supplementary technical or organizational measures are needed.

This assessment is generally more sophisticated than asking whether the destination country has "a privacy law." The relevant question is whether the proposed transfer satisfies the particular originating framework's requirements.

Encryption and pseudonymization can be important supplementary safeguards

Technical safeguards can reduce the risks of international transfers. Data may be pseudonymized before leaving the originating institution, unnecessary variables removed, files encrypted during transfer and storage, access limited to named researchers, and reidentification keys retained separately.

Under UK research provisions, appropriate safeguards explicitly include measures respecting data minimization, and ICO guidance advises researchers to use anonymous information where possible and consider pseudonymization where anonymization is not possible.

These controls do not automatically satisfy every international-transfer requirement, but they can form an important part of the overall protection.

Onward transfers need attention

Your immediate collaborator may be in Country B, but what happens after the data arrive?

The recipient might use a cloud provider whose servers are in Country C, outsource analysis to a company in Country D, or give another consortium partner access from Country E. These onward transfers can create additional legal and contractual issues.

International transfer arrangements should therefore address whether onward disclosure is permitted, to whom, under what conditions, and with what safeguards. A map containing only the first sender and first recipient may miss much of the actual processing chain.

Cloud subprocessors can make the geography surprisingly complicated

A university may contract with one cloud company, which uses several subprocessors for hosting, support, backup, security monitoring, or other services. Those organizations may operate in multiple jurisdictions.

This does not necessarily make the service unsuitable. It does mean that institutional due diligence should examine the relevant processing chain rather than assuming the country printed on the provider's invoice is where all processing occurs.

Participant consent is not automatically an international-transfer mechanism

Researchers should be particularly careful about assuming that a sentence in the participant consent form authorizing "international sharing" resolves every transfer requirement.

Under GDPR-style frameworks, explicit consent can appear among derogations for certain transfers, but derogations have specific conditions and are not interchangeable with ordinary research participation consent. Current UK guidance treats exceptions as a distinct route with defined requirements.

This reflects the broader distinction between consent to participate and consent or other authority for personal-data processing.

Transfers should be documented before access is enabled

International projects can involve several institutions, cloud platforms, processors, repositories, and research teams. Documentation should make the actual data flow intelligible.

A useful record may identify the exporter or sending organization, recipient, countries involved, categories of personal data, participant groups, purposes, legal roles, transfer mechanism, technical safeguards, onward-transfer rules, retention, deletion, and incident responsibilities.

The point is not paperwork for its own sake. If the project cannot explain where participant data can go and why, it will struggle to demonstrate that those movements are controlled.

Check the Current Rules

International-transfer frameworks change. Adequacy decisions, model clauses, regulatory guidance, and national laws can be updated. Verify the current requirements with the relevant regulator and your institution before relying on a transfer mechanism from an older protocol or agreement.

04 · A Practical Example

An International Collaborator Accesses Data Without Downloading Them

Hypothetical Example

A cross-country health research collaboration

University A holds pseudonymized participant data in its secure research environment. University B, located in another country, will perform a specialized analysis. Researchers at University B will log into University A's system remotely; downloading the dataset is disabled.

Map the access University A recognizes that keeping the server domestically does not end the analysis. Overseas researchers will be able to access personal data from another jurisdiction.
Determine the legal roles The institutions establish their controller, joint-controller, processor, or other relevant relationship under the applicable framework.
Assess transfer rules University A determines whether remote access constitutes a regulated international transfer under the law governing its processing and identifies the appropriate transfer mechanism where required.
Reduce exposure Direct identifiers remain unavailable to University B. Only variables necessary for the agreed analysis are accessible, and the reidentification key remains separately controlled.
Control access Named researchers receive individual accounts with appropriate authentication, logging, permissions, and restrictions on downloading or onward sharing.
Document the lifecycle The arrangement specifies permitted purposes, duration of access, incident reporting, onward transfers, termination, and any required deletion or retention after the collaboration ends.

No file was emailed internationally, yet an international-transfer analysis was still necessary because overseas access formed part of the processing arrangement.

05 · What Researchers Often Get Wrong

Common Misconceptions About International Research Data Transfers

Misconception

If the Server Never Leaves the Country, Is There No International Transfer?

Not necessarily. Under current UK guidance, making personal information remotely accessible to a separate overseas organization can constitute a restricted transfer. Other jurisdictions may apply different tests, so map access as well as storage location.

Misconception

If Both Countries Have Privacy Laws, Is the Transfer Automatically Permitted?

No. The originating legal framework may impose specific transfer conditions regardless of whether the destination has its own privacy statute. Determine the actual transfer mechanism or safeguards required.

Misconception

Does Ethics Approval Automatically Cover Cross-Border Transfer?

No. Ethics review may consider international sharing, but legal transfer mechanisms, contracts, institutional approvals, security, and data-protection requirements may still need separate attention.

Misconception

If Participants Consented to International Sharing, Is Nothing Else Required?

Not necessarily. Research participation consent and international-transfer requirements are distinct. Where a data protection framework recognizes consent as a transfer exception, that exception has its own legal conditions.

Misconception

Are Standard Contractual Clauses the Same Everywhere?

No. The EU, UK, Philippines, and other jurisdictions have their own legal frameworks and contractual mechanisms. A clause designed for one framework should not be assumed to satisfy another.

Misconception

If Data Are Pseudonymized, Do International Transfer Rules Disappear?

Usually not under GDPR-style frameworks because pseudonymized data remain personal data where reidentification is possible. Pseudonymization can reduce risk and support safeguards without necessarily removing the transfer from data protection law.

06 · What This Means for You

Map Countries, Organizations, Access, and Law Before the Data Move

For international research, draw the data flow before configuring the technical access. Include storage locations, researchers, collaborating institutions, service providers, subprocessors, and anyone who can remotely access personal data.

A simple decision framework

If the recipient can work with genuinely anonymous information
Consider anonymizing before transfer, while verifying that the anonymization is robust under the applicable standard.
If personal data must be transferred or made accessible abroad
Identify the governing data protection framework and determine whether specific international-transfer rules apply.
If a transfer mechanism or contractual safeguard is required
Use the mechanism applicable to that jurisdiction and arrangement rather than borrowing one from another legal system.
If a cloud provider or subprocessor operates in additional countries
Include those processing and access locations in the transfer analysis where relevant.
If the overseas recipient wants to share the data onward
Assess and document the onward transfer before access is extended to another organization or country.

International transfer analysis is one of the areas where institutional support is particularly valuable. Consult the appropriate data protection officer, privacy office, legal office, research governance unit, or equivalent before relying on contractual clauses or transfer exceptions.

07 · A Quick Checklist

Before Transferring Research Data Across Countries

Verify:
Whether the information is personal data or can be transferred in genuinely anonymous form.
Which organizations and countries can receive, store, process, support, or remotely access the data.
Which data protection law or laws govern the proposed processing and transfer.
The sender's and recipient's controller, processor, joint-controller, or equivalent roles have been established.
The underlying disclosure and research processing are lawful and consistent with ethics, participant information, contracts, and institutional requirements.
Any required adequacy basis, contractual safeguard, transfer mechanism, authorization, or exception has been identified under the applicable jurisdiction.
Only the minimum necessary personal data will be transferred or made accessible.
Appropriate encryption, pseudonymization, authentication, access controls, logging, and other safeguards are in place.
Onward transfers, subprocessors, retention, deletion, and incident responsibilities are addressed.
The current transfer requirements have been verified rather than copied from an older agreement or protocol.
08 · Frequently Asked Questions

Common Questions About International Research Data Transfers

Is remote access from another country an international data transfer?

It can be. Current UK ICO guidance, for example, treats making personal information accessible to a separate organization abroad as a transfer for purposes of its restricted-transfer analysis. Other jurisdictions may define transfers differently, so apply the governing law.

Can I send pseudonymized research data overseas?

Potentially, but pseudonymized information generally remains personal data under GDPR-style frameworks. You should still assess the applicable transfer rules, recipient authorization, safeguards, and institutional requirements.

Does the GDPR prohibit sending research data outside Europe?

No. The GDPR permits international transfers through the mechanisms provided in Chapter V, including adequacy decisions, appropriate safeguards, and specified derogations where their conditions are met. The correct mechanism depends on the transfer.

Does the Philippine Data Privacy Act prohibit international transfers?

No blanket prohibition appears in Section 21. Instead, the PIC remains accountable for personal information transferred to third parties domestically or internationally and must use contractual or other reasonable means to provide a comparable level of protection. The NPC has also issued model contractual clauses for cross-border transfers.

Can participant consent authorize an international transfer?

That depends on the applicable legal framework and the type of consent involved. Do not assume that ordinary consent to participate in research automatically functions as the required international-transfer mechanism.

Does using a cloud service mean the data have been transferred internationally?

Possibly. It depends on where the provider and relevant subprocessors process or access the data and on how the applicable law defines international transfers. Review the specific cloud architecture and contractual arrangement rather than assuming the provider operates only in the region selected in the user interface.

Do we need a separate agreement for every country?

Not necessarily. The required documentation depends on the legal framework, parties, transfer mechanism, and project structure. A multinational arrangement may cover several transfers, but each relevant data flow still needs to fall within the appropriate legal and contractual safeguards.

09 · The Bottom Line

International Transfer Is About Access and Protection, Not Just Geography

The Bottom Line

Before transferring personal research data across countries, map who abroad can access the information, determine which transfer rules apply, and establish the required legal mechanism, contractual protections, and technical safeguards before access begins.

Do not reduce the analysis to where the server is located or whether participants signed a consent form. International research can involve several legal systems and processing locations, so the safest starting point is a complete data-flow map followed by jurisdiction-specific review.

10 · Sources and Further Reading

Authoritative Sources on International Research Data Transfers

Do you like this personality?
11 · Cite this Guide

How to Cite This Guide

This guide is intended to be read, shared, and used in research, teaching, and academic work. If you draw on its ideas, explanations, or other content, please acknowledge the source by citing the guide. Doing so gives appropriate credit and helps your readers locate the original resource.

Has the Field Guide helped your research?

If a guide helped clarify a question, inform a research decision, or move your work forward, I would love to hear about your experience. Your story may also help other researchers discover the Field Guide.

Share Your Experience
Takes only a few minutes