Footage stored outside the site's region: who can access it there?
A storage country outside the region does not settle the question; who can access or use the footage there does. From an EU or EEA site, a transfer outside the EEA needs a Chapter V mechanism (GDPR Arts. 44 to 46: an adequacy decision, standard clauses or another safeguard); from a UK site, UK GDPR Art. 44A (transfer regulations under Art. 45A, or safeguards under Art. 46); from an Australian site, APP 8 asks for reasonable steps before a disclosure overseas, and storage with a provider where you keep effective control and the provider cannot access or use the footage may not be a disclosure (OAIC guidance, named, not quoted).
- When it is raised
- Raised when the storage country is outside the EEA for an EU or EEA site, outside the UK for a UK site, or outside Australia for an Australian site. Storage in a cloud with no storage country is a question naming the column.
- The question
- Who can access or use the footage where it is stored, and which transfer mechanism covers it: an adequacy decision or regulations, standard clauses, or another safeguard?
- For
- your privacy lead
- The column that settles it
- storage country
- On the row
- a numbered delta and the words "stored abroad" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
GDPR (the EU General Data Protection Regulation)
GDPR Art. 44General principle for transfersGeneral principle for transfers. Transfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.
GDPR Art. 45Transfers on the basis of an adequacy decisionTransfers on the basis of an adequacy decision. Personal data may be transferred to a third country, a territory, one or more specified sectors within a third country, or an international organisation where the Commission has decided that it ensures an adequate level of protection, and such a transfer requires no specific authorisation. Adequacy decisions carry a defined territorial and sectoral scope, provide for periodic review at least every four years, and may be repealed, amended or suspended by the Commission. Relying on adequacy therefore requires confirming that the specific recipient and data fall inside the scope of a decision that is in force at the time of the transfer, and monitoring for amendment, suspension or repeal of that decision.
GDPR Art. 46Transfers subject to appropriate safeguardsTransfers subject to appropriate safeguards. In the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.
UK GDPR
UK GDPR Art. 44AGeneral principles for transfersArticle 44A General principles for transfers. A controller or processor may transfer personal data to a third country or international organisation only if the transfer complies with the rest of the Regulation and is approved by transfer regulations under Article 45A in force at the time, is made subject to appropriate safeguards under Article 46, or relies on an Article 49 derogation; safeguards or derogations cannot be used where regulations under Article 49A restrict the transfer. This replaced Article 44 on 5 February 2026.
UK GDPR Art. 45ATransfers under transfer regulationsArticle 45A Transfers approved by regulations (with Articles 45B and 45C). The Secretary of State may approve transfers to a country, a sector or area within it, an international organisation or specified transfers by regulations, only where the data protection test is met: the protection for data subjects there, taken as a whole, is not materially lower than under the UK GDPR, Part 2 and Parts 5 to 7 of the 2018 Act, considering the rule of law and human rights, an enforcing authority, redress, onward transfer rules, international obligations and the country's constitution, traditions and culture. The Secretary of State must monitor developments, amend or revoke regulations when the test is no longer met, and publish lists of approved and formerly approved destinations. Adequacy regulations and retained adequacy decisions in force before 5 February 2026 are treated as made under Article 45A (Schedule 9 transitional provision). A controller relying on this route must check the destination and the transfer are covered by regulations in force at the time of transfer.
UK GDPR Art. 46Transfers subject to appropriate safeguardsArticle 46 Transfers subject to appropriate safeguards. A transfer is subject to appropriate safeguards only where safeguards are provided and the controller or processor, acting reasonably and proportionately, considers the data protection test met: after transfer the protection for the data subject, taken as a whole and considering the nature and volume of data, would not be materially lower than under the UK regime. Safeguards not needing the Commissioner's authorisation are a binding instrument between public bodies, binding corporate rules, standard data protection clauses specified by the Secretary of State in regulations or issued by the Commissioner under section 119A of the 2018 Act (such as the international data transfer agreement and addendum), and approved codes or certification with binding commitments; contractual clauses and administrative arrangements need the Commissioner's authorisation. Regulations under Article 47A may add further safeguards.
Australian Privacy Principles (APPs)
APP APP 8Cross-border disclosure of personal informationAPP 8 - Cross-border disclosure of personal information. Before disclosing personal information overseas, take reasonable steps to ensure the overseas recipient does not breach the APPs.
Named, not quoted
- OAIC APP guidelines, chapter 8: when storing personal information with an overseas provider may not be a disclosure: the entity keeps effective control and the provider cannot access or use it (Australia; named, not quoted)