GDPR Article 48: Unauthorized Transfers or Disclosures by Union Law
Article 48 of the GDPR Explained
This article aims to protect the legal autonomy of the European Union in matters of data protection. Thus:
- A request for data disclosure by a non-European authority (e.g., court, administration...) is only valid if it is based on an international agreement (e.g., mutual legal assistance treaty);
- In the absence of such an agreement, a transfer based solely on this request is prohibited by the GDPR.
Why This Article Matters for Your GDPR Compliance
This article is essential for preventing abusive extraterritorial transfers, particularly those based on foreign laws incompatible with European principles (such as certain US laws). It reinforces the Union's sovereignty in data protection.
Examples of application of Article 48 of the GDPR
- A company refuses to transfer a European customer's data to a foreign authority due to lack of an international agreement;
- A company receives an injunction from a US court: it relies on Article 48 to demand a recognised legal framework;
- An organisation postpones any transmission until obtaining authorisation from the French supervisory authority or the competent authority.
Related Resources
Accelerate your compliance in a few clicks
With our all-in-one solution, you can accelerate and ensure your compliance easily:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise awareness among your teams with our GDPR training e-learning
Assess your situation in 15 minutes with our GDPR self-assessment, free and without obligation.
How to Comply with GDPR Article 48?