Transfer impact assessment (TIA)
A transfer impact assessment (TIA), also called a transfer risk assessment, is the documented analysis a data exporter must perform, together with the importer, before relying on appropriate safeguards under Art. 46 GDPR such as standard contractual clauses or binding corporate rules to transfer personal data to a third country. The requirement flows from the Court of Justice's Schrems II judgment (C-311/18, 16 July 2020), which held that contractual safeguards work only if the law and practice of the destination country do not prevent the importer from complying with them, and is codified in Clause 14 of the 2021 SCCs and in the EDPB Recommendations 01/2020.
The EDPB's six-step roadmap structures the exercise: map the transfers (including onward transfers and sub-processors); identify the transfer tool relied on; assess whether the tool is effective in light of the destination's legislation and practices, particularly public authority access for surveillance or law enforcement, and the availability of redress, taking into account the specific circumstances of the transfer (nature of data, sector, recipients, format); adopt supplementary measures where needed (encryption with keys in the EEA, pseudonymisation, split processing, contractual and organisational measures); take procedural steps such as amending contracts; and re-evaluate at appropriate intervals. Sources include the destination country's legislation, official reports, case law, importer transparency reports and, since the 2021 SCCs, the importer's documented experience of government access requests.
For a sponsor or CRO, TIAs are required for every non-adequate destination in the trial data flow, most commonly the United States (for importers not certified under the Data Privacy Framework), India, China, and other countries hosting sites, laboratories or technology vendors. Because health data is involved, the assessment should be specific rather than templated, but it can be streamlined by grouping transfers by importer and destination. The UK equivalent is the transfer risk assessment under ICO guidance, and Switzerland requires a similar analysis. TIAs form part of the DPIA file and are requested in inspections and due diligence.
