Adequate Country (GDPR Ch. V)
Definition
A country that the European Commission has determined provides a level of data protection essentially equivalent to the EU's. As of mid-2026, the list does not include the United States (at a general level) or India.
- Legal basis
- GDPR Chapter V
- Determining body
- European Commission
- Effect
- Free transfer of personal data without extra safeguards
- US status, mid-2026
- Not adequate at a general level
- India status, mid-2026
- Not on the adequacy list
Common questions
What happens when a company wants to transfer EU personal data to a country without an adequacy decision?+
It must rely on another GDPR Chapter V transfer mechanism, such as standard contractual clauses or binding corporate rules, to provide equivalent safeguards before the transfer can lawfully proceed.
Does a country without an adequacy decision have no lawful path for any data transfer at all?+
No, adequacy is only the simplest path; transfers can still occur lawfully under contractual safeguards, explicit consent, or other Chapter V derogations, though these require more documentation than transferring to an adequate country.
Related terms
- Aadhaar Exclusion (DPDP Act S.17(2))
- Provision that exempts processing covered by the Aadhaar Act 2016 from the general DPDP Act regime, meaning UIDAI biometric data is governed...
- Biometric Identifier (BIPA)
- Under Illinois BIPA: a retina or iris scan, fingerprint, voiceprint, or scan of a person's hand or face geometry; distinct from 'biometric...
- Data Fiduciary (DPDP Act)
- Any person who alone or in conjunction with others determines the purpose and means of processing personal data; the DPDP Act equivalent...
- Data Protection Impact Assessment (DPIA)
- A structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights...
- Explicit Consent (GDPR)
- A higher consent standard required for special-category data processing under Article 9(2)(a): must be freely given, specific, informed, and involve an explicit...
- Per-Violation Damages (BIPA)
- BIPA's statutory damages structure: USD 1,000 per negligent violation or USD 5,000 per intentional/reckless violation; confirmed by Cothron v. White Castle (2023)...
- Real-Time Remote Biometric Identification (RTBI)
- As defined in the EU AI Act: automated identification of natural persons at a distance by comparing their biometric data to those...
- Special-Category Data (GDPR)
- Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data for unique identification, health data,...
- Standard Contractual Clauses (SCCs)
- Pre-approved contract terms issued by the European Commission that create GDPR-compliant safeguards for cross-border data transfers to countries without an adequacy decision....