consentglass · GDPR scanner for websites

HomeGuides › Topic

Data transfers to the USA under the GDPR

Many common services (Google, Meta, Microsoft, Cloudflare) process data in the USA. Every such transfer needs a basis under Chapter V of the GDPR.

Is this a risk?

Since the adequacy decision on the EU-US Data Privacy Framework (July 2023), transfers to US companies certified under it are permitted. If the recipient is not certified, standard contractual clauses plus an assessment of the legal situation in the recipient country (transfer impact assessment) are required. If both are missing, the transfer is unlawful.

What you can do

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.