Guide and template

Transfer impact assessment (TIA) template for universities

If a university sends personal data outside the EEA under standard contractual clauses, it has to document whether the law of the destination country lets the importer keep its promises. This guide explains when that transfer impact assessment is needed and when it is not, walks through the six steps in the EDPB's Recommendations 01/2020, works through two realistic university examples, and includes a free Word template.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. What a TIA is and where the duty comes from
  2. When you need one, and when you do not
  3. The six EDPB steps in practice
  4. Worked example 1: a US AI tool under SCCs
  5. Worked example 2: a processor in India
  6. Supplementary measures: what works and what does not
  7. Documentation and review
  8. Common mistakes
  9. The template
  10. Sources
  11. About this page

1. What a TIA is and where the duty comes from

Chapter V of the GDPR allows a transfer to a third country only if one of its conditions is met, and Article 44 says all of Chapter V must be applied so that the level of protection the GDPR guarantees "is not undermined". Without an adequacy decision, Article 46(1) allows a transfer only with appropriate safeguards and on condition that "enforceable data subject rights and effective legal remedies for data subjects are available" [1].

In Schrems II (Case C-311/18, 16 July 2020) the Court of Justice held that it is, above all, for the controller or processor relying on standard clauses to verify, case by case and where appropriate with the recipient, whether the law of the destination country ensures adequate protection, adding safeguards where needed. If that is not possible, the exporter must suspend or end the transfer (paragraphs 134 and 135) [2].

The 2021 SCCs turned that into a contractual duty. Under Clause 14 the parties warrant that they have no reason to believe the laws and practices of the destination prevent the importer from complying, taking due account of the specific circumstances of the transfer, the relevant laws and practices, and any supplementary safeguards. Clause 14(d) adds that the parties "agree to document the assessment" and make it available to the supervisory authority on request [3]. That documented assessment is what people call a TIA. The GDPR itself does not use the term.

2. When you need one, and when you do not

Work through four questions in order. Our free transfer mechanism tool runs the same logic for a single data flow.

QuestionIf yesIf no
1. Is there a transfer? The EDPB uses three cumulative criteria: the exporter is subject to the GDPR for the processing, it discloses or makes data available to another controller or processor, and that importer is in a third country [4]. Remote access from a third country, for example in support situations, counts [5].Go to question 2.Chapter V does not apply. No TIA. Other GDPR duties remain.
2. Is the destination covered by an adequacy decision? On 7 October 2026 the Commission's list includes, among others, Japan, the Republic of Korea, Switzerland, the United Kingdom, Brazil and the United States for organisations in the Data Privacy Framework [6].No TIA. The EDPB says no further steps are needed beyond monitoring that the decision remains valid [5].Go to question 3.
3. For a US importer: is that exact legal entity on the DPF List with an active EU-U.S. certification covering the data (HR or non-HR)? See our DPF guide.No TIA. The EDPB says transfers under the adequacy decision need no supplementary measures [7].Go to question 4.
4. Do you rely on an Article 46 tool, such as SCCs or binding corporate rules?TIA needed.Only an Article 49 derogation is left. See the note below.

Article 49 derogations are exceptions. The EDPB says they cannot become "the rule" in practice [5], and Article 49(3) says explicit consent, the two contract grounds and the compelling legitimate interests ground do not apply to activities carried out by public authorities in the exercise of their public powers [1]. For a recurring vendor service at a public university, a derogation is rarely a realistic route.

Clause 14 applies to Modules 1, 2 and 3 of the SCCs, and to Module 4 only where the EU processor combines the data it receives with personal data it collected in the EU [3]. The Commission says it is still developing separate clauses for importers whose processing is directly subject to the GDPR [8].

3. The six EDPB steps in practice

EDPB Recommendations 01/2020 (version 2.0, adopted 18 June 2021) set out six steps [5]. Here is what each one means for a university reviewing a vendor.

Step 1: Know your transfers

Map where the data goes, including onward transfers to sub-processors and remote access. The EDPB points to the Article 30 record, in particular points 30(1)(e) and 30(2)(c), as the place to start [5]. In practice you need the vendor's DPA, its current subprocessor list with countries, and an answer to the question "from which countries can your staff access our data?". Also check that the data transferred is adequate, relevant and limited to what is necessary. Our ROPA template has columns for this.

Step 2: Identify the transfer tool

Record the tool for each transfer, not just for the main vendor. A common pattern is SCCs Module 2 between the university and the vendor, and Module 3 SCCs or a DPF certification between the vendor and each non-EEA sub-processor. Our DPA checker helps confirm that the DPA actually incorporates the clauses and their annexes.

Step 3: Assess the law and practice of the destination

This is the core of the TIA. Focus on laws relevant to this transfer and this importer, especially laws that require disclosure to public authorities or allow access by them. The EDPB says practices matter as well, and that if problematic legislation could apply, you may suspend, add measures, or proceed without measures only if you can demonstrate and document that you have no reason to believe the legislation will be applied in practice to your data and importer [5]. The benchmark is the EDPB's European Essential Guarantees: clear, precise and accessible rules; demonstrated necessity and proportionality; independent oversight; and effective remedies for individuals [9]. Footnote 12 of the SCCs allows documented practical experience with (or the absence of) prior access requests to be considered, but only if it is supported by other objective elements and not contradicted by public information [3].

Step 4: Adopt supplementary measures

Only needed if Step 3 finds a problem. Measures can be technical, contractual or organisational, and they must address the specific risk. If no measure works, the EDPB says you "must avoid, suspend or terminate the transfer" [5]. Section 6 below covers what tends to work.

Step 5: Procedural steps

Write the measures into the contract without contradicting the SCCs, and consult the supervisory authority if your changes go beyond what the clauses allow. Update the privacy notice: Articles 13(1)(f) and 14(1)(f) GDPR require information about transfers and the safeguards relied on [1].

Step 6: Re-evaluate

The EDPB says accountability requires "continuous vigilance" [5]. Set a review date and list the events that trigger an earlier review (see section 7).

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

4. Worked example 1: a US AI tool under SCCs

Validemic's analysis This example is an illustration, not an assessment of any real vendor. Facts in brackets are assumptions you would replace with what the vendor's documents say.

Scenario. A research group wants an AI transcription service to transcribe 40 interviews with school teachers about workload. The vendor's EU entity signs the DPA, but audio is processed by the vendor's US parent [which is not on the DPF List], and the speech model runs at a US sub-processor. The DPA incorporates SCCs Module 2 between the university and the vendor, and the vendor states it has Module 3 clauses with the sub-processor.

StepExample finding
1. TransferAudio and transcripts with names, school and opinions about employers. Uploaded to the US for processing in the clear; retained [30 days]. Two importers: the US parent and the model sub-processor.
2. ToolSCCs Module 2 (university to vendor) and Module 3 (vendor to sub-processor). Check the DPF List for both US entities first: if the sub-processor's own entity is certified for this data, that leg relies on adequacy instead.
3. Law and practiceThe relevant US laws are those assessed in the DPF adequacy decision, notably Section 702 FISA, which allows collection with the compelled assistance of electronic communication service providers, and the safeguards of Executive Order 14086 [10]. The EDPB says the US national security safeguards, including the redress mechanism, apply to all data transferred to the US whatever the transfer tool, so exporters should take the Commission's assessment into account [7].
3. Points to monitorAn appeal against the General Court judgment upholding the DPF decision is pending (Case C-703/25 P) [11]. The EDPB asked the Commission on 31 July 2026 to assess the effect of the US Supreme Court's Trump v. Slaughter judgment on FTC independence [12]. The Commission's 2024 review notes that RISAA reauthorised Section 702 for two years from April 2024 [13]; we did not verify its current legislative status from a primary source on the check date, so check it before you conclude.
4. MeasuresTraining on customer data disabled by contract; shortest available retention; participants identified only by code in file names and prompts; recordings deleted after transcripts are checked; importer commitments under Clause 15 to challenge disproportionate requests and report them.
5. ProcedureParticipant information sheet updated to name the US transfer and the safeguards; ROPA row updated.
6. ReviewAnnually, on any sub-processor change, and on the outcome of C-703/25 P.

Example conclusion. Relying on the Commission's assessment of US law as the EDPB suggests, the group might conclude that the SCCs are effective for this transfer with the listed measures, and record the residual points to monitor. If the interviews involved special category data, for example health information, the same analysis would deserve more caution and an EEA-hosted alternative should be considered. Our fact sheets on transcription tools such as Otter.ai, Trint and Rev show what vendors publish about hosting and sub-processors, which is the raw material for Steps 1 and 2.

5. Worked example 2: a processor in India

Validemic's analysis Again an illustration, not an assessment of any real company.

Scenario. The university's student information system is hosted in the EU, but the vendor's second-line support team in India can log in to production to fix incidents. Support staff see student names, ID numbers, grades and, for some students, notes on study adjustments.

StepExample finding
1. TransferRemote access from India is a transfer even though the data stays on EU servers [5]. Data is viewed in the clear. Special category data (health-related adjustment notes) is in scope.
2. ToolIndia is not on the Commission's adequacy list on the check date [6]. SCCs Module 3 between the vendor's EU entity and its Indian affiliate (vendor as processor, affiliate as sub-processor).
3. LawSection 69 of India's Information Technology Act, 2000 lets the Central or a State Government, on grounds including security of the State, public order and investigation of any offence, direct an agency to intercept, monitor or decrypt information in any computer resource. Section 69(3) obliges the person in charge of the resource to give access and technical assistance, and section 69(4) makes refusal punishable by up to seven years' imprisonment [14]. Under the Digital Personal Data Protection Act, 2023, section 17(2)(a) lets the Central Government exempt notified state instrumentalities on grounds including security of the State, and section 17(1)(d) disapplies most of the Act's obligations to data of people outside India processed under a contract with a foreign party [15].
3. AssessmentAssess these powers against the European Essential Guarantees: how clearly the grounds are defined, what prior authorisation and independent oversight apply, and what remedies an EU student would have [9]. Ask the vendor for its own assessment and for its record of any access requests, and weigh that information as footnote 12 of the SCCs requires [3].
4. MeasuresBecause support staff see data in the clear, this resembles the EDPB's Use Case 7, for which the EDPB cannot envisage an effective technical measure if problematic legislation applies in practice [5]. Practical options: route incidents involving special category data to EEA staff only; mask adjustment notes and ID numbers in support views; just-in-time access approved by the university with full logging; test data instead of production data where possible.
6. ReviewAnnually, and when the vendor changes its support model or Indian law changes.

Example conclusion. A cautious conclusion would allow remote support for ordinary records under SCCs with masking and approved, logged access, and require that special category data is only accessible from the EEA. If the vendor cannot offer that, the residual risk for special category data goes to the DPO and the data owner for a decision, and the assessment records why.

6. Supplementary measures: what works and what does not

Annex 2 of the EDPB recommendations gives examples [5]. A short summary for university contexts:

MeasureWhen it can be effectiveLimits
Encryption with keys held only by the university (or in the EEA)Storage or backup abroad where the importer never needs the data in the clear (EDPB Use Case 1).Not possible for services that must read the data, such as AI processing or support.
Pseudonymisation before transferAnalysis abroad where the importer cannot re-identify people, and the key stays in the EEA (Use Case 2). Common in research.Audio, video and free text are hard to pseudonymise reliably.
Split or multi-party processingWhen no single importer can make sense of the data alone (Use Case 5).Rare in commercial software.
Transport and at-rest encryptionBasic security, always expected.The EDPB says these are not a supplementary measure where the importer needs data in the clear and holds the keys (Use Cases 6 and 7).
Contractual measures (transparency reports, commitments to challenge requests, notification)Support other measures and help with monitoring.The EDPB notes they generally cannot by themselves bind public authorities of the third country.
Organisational measures (minimisation, access only from the EEA for sensitive data, approvals, logging)Reduce the data actually exposed.Must be verifiable; a policy no one checks is weak evidence.

Validemic's analysis For many AI and support scenarios, the most effective "measure" is minimisation: send less, keep it for less time, and keep special category data out of the transfer. When that is not enough, a vendor with EEA processing for the sensitive part is often the cleaner answer.

7. Documentation and review

The EDPB says the assessment must be carried out with due diligence and documented thoroughly, because supervisory and judicial authorities may request it and hold you accountable [5]. A good TIA file contains:

Re-run the assessment early when:

Link each TIA to the ROPA row and the vendor file. Our vendor assessment guide shows where the TIA sits in the overall review, and a DPIA may be needed as well where the processing is high risk (see our DPIA template).

8. Common mistakes

  1. "EU hosting, so no transfer." Remote access from a third country is a transfer.
  2. Assessing only the main vendor. Onward transfers to sub-processors need a tool and an assessment too.
  3. Doing a TIA for a DPF-certified importer, or skipping one for an uncertified sister company. The DPF applies only to the listed entity and the data its certification covers.
  4. Copying the vendor's TIA unread. It is input, not your conclusion.
  5. Counting transport encryption as a supplementary measure when the importer reads the data in the clear.
  6. No review date. Sub-processors and laws change after signature.

9. The template

The TIA template for universities is a Word document with:

The template follows Clause 14 of the SCCs and EDPB Recommendations 01/2020 as read on 7 October 2026. It does not contain an assessment of any country's law, which you must do for your own transfer. It is not legal advice.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Articles 13, 14, 30 and 44 to 49 (retrieved 7 October 2026).
  2. Court of Justice, Judgment of 16 July 2020, Case C-311/18, Facebook Ireland and Schrems, paragraphs 134 and 135 (retrieved 7 October 2026).
  3. Commission Implementing Decision (EU) 2021/914 on standard contractual clauses, Clauses 14 and 15 and footnote 12 (retrieved 7 October 2026).
  4. EDPB Guidelines 05/2021 on the interplay between Article 3 and Chapter V, version 2.0, adopted 14 February 2023 (retrieved 7 October 2026).
  5. EDPB Recommendations 01/2020 on measures that supplement transfer tools, version 2.0, adopted 18 June 2021 (retrieved 7 October 2026).
  6. European Commission: Adequacy decisions (retrieved 7 October 2026).
  7. EDPB Information note on data transfers under the GDPR to the United States after the adoption of the adequacy decision on 10 July 2023 (retrieved 7 October 2026).
  8. European Commission: Standard contractual clauses (SCC) (retrieved 7 October 2026).
  9. EDPB Recommendations 02/2020 on the European Essential Guarantees for surveillance measures, adopted 10 November 2020 (retrieved 7 October 2026).
  10. Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework (retrieved 7 October 2026).
  11. Appeal brought on 31 October 2025 by Philippe Latombe, Case C-703/25 P, OJ C/2025/6610, and the case page on InfoCuria (retrieved 7 October 2026).
  12. EDPB letter to the European Commission on US Supreme Court judgment Trump v. Slaughter, 31 July 2026 (retrieved 7 October 2026).
  13. Report from the Commission on the first periodic review of the functioning of the adequacy decision on the EU-US Data Privacy Framework, COM(2024) 451, 9 October 2024 (retrieved 7 October 2026).
  14. India: Information Technology Act, 2000 (as amended), section 69 (retrieved 7 October 2026).
  15. India: Digital Personal Data Protection Act, 2023, sections 16 and 17 (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. EU legal texts were read in their Official Journal versions and linked on EUR-Lex; EDPB and Commission documents were read on their own sites; Indian statutes were read on Government of India sites. The worked examples are illustrations written by Validemic, and statements labelled as Validemic's analysis are our interpretation. We have not assessed the law of any country for you, and this page is not legal advice. If you spot an error or something has changed, please contact us and we will correct it.

Frequently asked questions

What is a transfer impact assessment?

A documented assessment of whether the law and practice of the destination country could stop the data importer from complying with the transfer tool you rely on, usually the EU standard contractual clauses. Clause 14 of the 2021 SCCs requires the parties to carry it out, document it and make it available to the supervisory authority on request.

Is a TIA a legal requirement under the GDPR?

The term does not appear in the GDPR. The duty comes from Article 46 GDPR as interpreted by the Court of Justice in Schrems II (C-311/18), which said exporters must verify case by case whether the destination law ensures adequate protection, and from Clause 14 of the SCCs, which makes the assessment and its documentation a contractual obligation.

Do I need a TIA for a US vendor on the Data Privacy Framework?

No, if the exact US entity receiving the data holds an active EU-U.S. DPF certification covering the type of data concerned. Transfers to certified organisations rely on the adequacy decision (EU) 2023/1795, and the EDPB says they do not need supplementary measures. You should still record the check and monitor the decision.

Do I need a TIA if the data is hosted in the EU?

Possibly. The EDPB treats remote access from a third country, for example by a vendor's support staff, as a transfer. If staff or sub-processors outside the EEA can access the data and no adequacy decision covers them, you need an Article 46 tool and an assessment.

How long should a TIA be?

Proportionate to the transfer. The EDPB asks for due diligence and thorough documentation, but a low-volume transfer of non-sensitive data can be assessed in a few pages, while special category research data sent for processing in the clear needs a fuller analysis of the destination law and the measures.

Can a vendor's own TIA replace ours?

It can be useful input, and Clause 14(c) requires the importer to make its best efforts to provide relevant information. But the exporter is responsible for the assessment of its own transfer, so read the vendor's document critically and record your own conclusion.

How often should a TIA be reviewed?

Step 6 of the EDPB recommendations asks you to re-evaluate at appropriate intervals. Many institutions review annually, and immediately when the vendor adds a sub-processor or location, notifies a change under Clause 14(e), or the destination country's law or adequacy status changes.