Skip to content

Adequate Country (GDPR Ch. V)

Definition

A country that the European Commission has determined provides a level of data protection essentially equivalent to the EU's. As of mid-2026, the list does not include the United States (at a general level) or India.

Legal basis
GDPR Chapter V
Determining body
European Commission
Effect
Free transfer of personal data without extra safeguards
US status, mid-2026
Not adequate at a general level
India status, mid-2026
Not on the adequacy list

Common questions

What happens when a company wants to transfer EU personal data to a country without an adequacy decision?+

It must rely on another GDPR Chapter V transfer mechanism, such as standard contractual clauses or binding corporate rules, to provide equivalent safeguards before the transfer can lawfully proceed.

Does a country without an adequacy decision have no lawful path for any data transfer at all?+

No, adequacy is only the simplest path; transfers can still occur lawfully under contractual safeguards, explicit consent, or other Chapter V derogations, though these require more documentation than transferring to an adequate country.

Related terms

Aadhaar Exclusion (DPDP Act S.17(2))
Provision that exempts processing covered by the Aadhaar Act 2016 from the general DPDP Act regime, meaning UIDAI biometric data is governed...
Biometric Identifier (BIPA)
Under Illinois BIPA: a retina or iris scan, fingerprint, voiceprint, or scan of a person's hand or face geometry; distinct from 'biometric...
Data Fiduciary (DPDP Act)
Any person who alone or in conjunction with others determines the purpose and means of processing personal data; the DPDP Act equivalent...
Data Protection Impact Assessment (DPIA)
A structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights...
Explicit Consent (GDPR)
A higher consent standard required for special-category data processing under Article 9(2)(a): must be freely given, specific, informed, and involve an explicit...
Per-Violation Damages (BIPA)
BIPA's statutory damages structure: USD 1,000 per negligent violation or USD 5,000 per intentional/reckless violation; confirmed by Cothron v. White Castle (2023)...
Real-Time Remote Biometric Identification (RTBI)
As defined in the EU AI Act: automated identification of natural persons at a distance by comparing their biometric data to those...
Special-Category Data (GDPR)
Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data for unique identification, health data,...
Standard Contractual Clauses (SCCs)
Pre-approved contract terms issued by the European Commission that create GDPR-compliant safeguards for cross-border data transfers to countries without an adequacy decision....

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.