CCTV Privacy Law Mapper
Finding 7 of 18

Footage stored outside the site's region: who can access it there?

A storage country outside the region does not settle the question; who can access or use the footage there does. From an EU or EEA site, a transfer outside the EEA needs a Chapter V mechanism (GDPR Arts. 44 to 46: an adequacy decision, standard clauses or another safeguard); from a UK site, UK GDPR Art. 44A (transfer regulations under Art. 45A, or safeguards under Art. 46); from an Australian site, APP 8 asks for reasonable steps before a disclosure overseas, and storage with a provider where you keep effective control and the provider cannot access or use the footage may not be a disclosure (OAIC guidance, named, not quoted).

When it is raised
Raised when the storage country is outside the EEA for an EU or EEA site, outside the UK for a UK site, or outside Australia for an Australian site. Storage in a cloud with no storage country is a question naming the column.
The question
Who can access or use the footage where it is stored, and which transfer mechanism covers it: an adequacy decision or regulations, standard clauses, or another safeguard?
For
your privacy lead
The column that settles it
storage country
On the row
a numbered delta and the words "stored abroad" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

GDPR (the EU General Data Protection Regulation)

GDPR Art. 44General principle for transfers

General principle for transfers. Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.

What a reviewer asks to see: A transfer register listing every transfer with the destination country, the recipient, the data categories and the Chapter V mechanism relied on; The onward transfer position for each recipient, showing what the recipient may do with the data and under which mechanism; Evidence that remote access from a third country was assessed as a transfer alongside physical movement of data; The reasoning that the level of protection is not undermined by the arrangement as a whole, not only by the chosen instrument
Where camera lists usually fall short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all; The transfer register recording the contracting entity's location rather than the locations the data can actually be accessed from; Onward transfers by the recipient left uncovered, so the chain breaks one step beyond the direct relationship; A mechanism recorded per vendor rather than per transfer, so several distinct transfers share one unexamined justification
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 45Transfers on the basis of an adequacy decision

Transfers on the basis of an adequacy decision. Personal data may be transferred to a third country, a territory, one or more specified sectors within a third country, or an international organisation where the Commission has decided that it ensures an adequate level of protection, and such a transfer requires no specific authorisation. Adequacy decisions carry a defined territorial and sectoral scope, provide for periodic review at least every four years, and may be repealed, amended or suspended by the Commission. Relying on adequacy therefore requires confirming that the specific recipient and data fall inside the scope of a decision that is in force at the time of the transfer, and monitoring for amendment, suspension or repeal of that decision.

What a reviewer asks to see: Per transfer, the adequacy decision relied on identified by instrument, with confirmation the recipient and the data fall inside its territorial and sectoral scope; A monitoring process for changes to adequacy decisions, with a named owner and evidence it has actually been run; The fallback plan for each adequacy based transfer should the decision be suspended or repealed, tested against the Article 46 and 49 options; Where a decision covers only certified or listed recipients, evidence the recipient's current status was verified
Where camera lists usually fall short: Adequacy assumed for a whole country where the decision covers only a sector or only listed recipients, with the recipient's listing never verified; No monitoring for suspension or invalidation, so a transfer continues on a decision that has since been struck down; Adequacy relied on for the direct transfer with no consideration of onward transfers out of the adequate country; The decision recorded at contract signature and never rechecked at the periodic review point
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026
GDPR Art. 46Transfers subject to appropriate safeguards

Transfers subject to appropriate safeguards. In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.

What a reviewer asks to see: The executed instrument for each transfer, with the modules, annexes and schedules of technical and organisational measures actually completed rather than left blank; The transfer risk assessment examining the destination's law and practice, in particular public authority access, and the conclusion on whether the safeguards are effective there; The supplementary measures adopted where that assessment found the instrument alone insufficient, and evidence they are in place; Supervisory authority authorisation where ad hoc contractual clauses or administrative arrangements are relied on; Evidence that data subjects can in practice exercise the rights the instrument confers, such as an operable third party beneficiary route
Where camera lists usually fall short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined; No assessment of destination law and practice, so the clauses are relied on in a jurisdiction whose law makes them unenforceable; Supplementary measures identified in the assessment and never implemented, leaving open the gap the assessment found; The instrument signed with the contracting entity while group companies that actually access the data are never brought inside it
Source: GDPR (the EU General Data Protection Regulation), read 29 Sep 2026

UK GDPR

UK GDPR Art. 44AGeneral principles for transfers

Article 44A General principles for transfers. A controller or processor may transfer personal data to a third country or international organisation only if the transfer complies with the rest of the Regulation and is approved by transfer regulations under Article 45A in force at the time, is made subject to appropriate safeguards under Article 46, or relies on an Article 49 derogation; safeguards or derogations cannot be used where regulations under Article 49A restrict the transfer. This replaced Article 44 on 5 February 2026.

What a reviewer asks to see: Transfer inventory mapping each flow to its Article 44A route; Checks against any Article 49A restrictions
Where camera lists usually fall short: Transfers with no documented route; Onward transfers by processors not assessed
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 45ATransfers under transfer regulations

Article 45A Transfers approved by regulations (with Articles 45B and 45C). The Secretary of State may approve transfers to a country, a sector or area within it, an international organisation or specified transfers by regulations, only where the data protection test is met: the protection for data subjects there, taken as a whole, is not materially lower than under the UK GDPR, Part 2 and Parts 5 to 7 of the 2018 Act, considering the rule of law and human rights, an enforcing authority, redress, onward transfer rules, international obligations and the country's constitution, traditions and culture. The Secretary of State must monitor developments, amend or revoke regulations when the test is no longer met, and publish lists of approved and formerly approved destinations. Adequacy regulations and retained adequacy decisions in force before 5 February 2026 are treated as made under Article 45A (Schedule 9 transitional provision). A controller relying on this route must check the destination and the transfer are covered by regulations in force at the time of transfer.

What a reviewer asks to see: Transfer records naming the regulations relied on and the scope they cover; Periodic check of the Secretary of State's published list
Where camera lists usually fall short: Relying on a partial approval (for example a certification-based bridge) for recipients outside its scope; Destination removed from the list but transfers continue
Source: UK GDPR, read 29 Sep 2026
UK GDPR Art. 46Transfers subject to appropriate safeguards

Article 46 Transfers subject to appropriate safeguards. A transfer is subject to appropriate safeguards only where safeguards are provided and the controller or processor, acting reasonably and proportionately, considers the data protection test met: after transfer the protection for the data subject, taken as a whole and considering the nature and volume of data, would not be materially lower than under the UK regime. Safeguards not needing the Commissioner's authorisation are a binding instrument between public bodies, binding corporate rules, standard data protection clauses specified by the Secretary of State in regulations or issued by the Commissioner under section 119A of the 2018 Act (such as the international data transfer agreement and addendum), and approved codes or certification with binding commitments; contractual clauses and administrative arrangements need the Commissioner's authorisation. Regulations under Article 47A may add further safeguards.

What a reviewer asks to see: Executed IDTA or UK addendum or other Article 46 instrument per transfer; Transfer risk assessment recording the data protection test and its reasoning; Authorisations from the Commissioner where needed
Where camera lists usually fall short: Contract signed with no documented assessment of the data protection test; EU clauses used without the UK addendum; Assessments not revisited when the destination's law changes
Source: UK GDPR, read 29 Sep 2026

Australian Privacy Principles (APPs)

APP APP 8Cross-border disclosure of personal information

APP 8 - Cross-border disclosure of personal information. Before disclosing personal information overseas, take reasonable steps to ensure the overseas recipient does not breach the APPs.

What a reviewer asks to see: Overseas disclosure assessment; Contractual safeguards with overseas recipients; Records of cross-border disclosures (APP 8.4)
Where camera lists usually fall short: Overseas disclosure without safeguards; No assessment of recipient
Source: Australian Privacy Principles (APPs), read 29 Sep 2026

Named, not quoted

See the specimen list run Map your own list