Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia has no EU adequacy decision. Which SCC module applies, how to run the transfer impact assessment against Australian government access powers, and the contract path for Australian vendors.

Australia does not hold an EU adequacy decision. Verified against the European Commission’s published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of any announced adequacy negotiation, and nothing in the Privacy Act reform programme changes that — adequacy is a separate Commission process under Art. 45 GDPR, initiated by the Commission, subject to an EDPB opinion and a comitology vote.

Everything else on this page follows from that single fact. If personal data moves from the EEA to Australia — or is merely accessible from Australia, which is the same thing in law — it needs an Art. 46 safeguard, a documented assessment, and in most cases supplementary measures. This is the question that stalls European deals, and it is answerable with a defined set of documents.

Key takeaways

  • No adequacy decision means no free flow. Every EEA-to-Australia transfer needs an Art. 46 transfer tool; in practice, the Standard Contractual Clauses.
  • Remote access from Australia to data stored in the EEA is a transfer. So is support access, so is a backup replica, so is a screen-share with a European customer’s production system.
  • The SCC module is determined by the roles of the parties, not by convenience. Getting it wrong is the most common defect European counsel find.
  • Clause 14 of the SCCs makes the transfer impact assessment a contractual warranty, not an optional annex. It must address Australian government access powers by name.
  • Art. 49 derogations are for occasional transfers. They are not a structural answer for a product.

What “no adequacy decision” means in practice

Art. 45 GDPR permits transfers to a third country the Commission has found to ensure an adequate level of protection. Where no such decision exists, Art. 46 requires the exporter to provide appropriate safeguards, with enforceable data subject rights and effective legal remedies available. Our page on Art. 44 and transfers to third countries sets out the hierarchy.

Adequacy is not equivalence, and it is worth being precise about the inverse as well: the absence of a decision does not mean Australian law is weak, it means the Commission has not made a finding. What it does mean commercially is that the burden of demonstrating protection sits on you and your European counterparty rather than on a Commission instrument, and that burden is discharged in writing.

Three misconceptions to clear before the drafting starts. First, APP 8 of the Privacy Act is not a transfer tool for GDPR purposes — it governs disclosures out of Australia and is irrelevant to data coming in, as set out in our Privacy Act and GDPR comparison. Second, ISO 27001 certification is a security control set, not an Art. 46 safeguard. Third, APEC-derived instruments and national trustmarks are not recognised transfer tools under EU law.

Choosing the right SCC module

The current clauses are those in Commission Implementing Decision (EU) 2021/914 of 4 June 2021. They are modular, and the module follows the roles of the two parties:

Module Exporter → Importer Typical Australian scenario
One Controller → controller An Australian company receiving European customer data it uses for its own purposes — a clinical registry, a co-marketing arrangement
Two Controller → processor The common case: a European customer engages an Australian SaaS, hosting or support provider
Three Processor → processor An Australian sub-processor behind a European processor. Frequent for CROs, offshore support and analytics vendors
Four Processor → controller Rare; an EEA processor returning data to an Australian controller

Module Two and Module Three are where the mistakes concentrate. If your European customer is itself a service provider processing on behalf of its own clients — a hospital IT integrator, an agency, a platform — then you are a sub-processor and Module Three applies, not Module Two. Re-papering that after signature is expensive. Our Standard Contractual Clauses guide walks the annexes; the choice between clauses, binding corporate rules and adequacy-based routes is compared in our page on BCRs, SCCs and the DPF.

One clause is worth reading closely if you have no EU establishment. Clause 13 identifies the competent supervisory authority. Where the exporter is not established in an EEA member state but is subject to the GDPR under Art. 3(2), the competent authority is that of the member state in which the exporter’s Art. 27 representative is established. The representative designation and the transfer paperwork are therefore linked, and inconsistency between them is a visible defect.

The transfer impact assessment

Clause 14 of the 2021 SCCs requires both parties to warrant that they have no reason to believe the laws and practices of the destination country, applied to the specific transfer, prevent the importer from meeting its obligations. That warranty has to be evidenced. The methodology is the EDPB’s Recommendations 01/2020 on supplementary measures, version 2.0, adopted 18 June 2021: map the transfer, identify the tool, assess the tool’s effectiveness in light of third-country law and practice, adopt supplementary measures where needed, take procedural steps, and re-evaluate at intervals. Our transfer impact assessment guide sets out the template.

Australian access powers the assessment must address

A TIA that says “Australia is a rule-of-law democracy” and stops there will be rejected. Name the instruments:

The Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (“TOLA”). This inserted Part 15 into the Telecommunications Act 1997 and created three instruments directed at “designated communications providers” — a category defined broadly enough to capture providers of electronic services with end-users in Australia and developers of software used in connection with carriage services, not merely telecommunications carriers. A technical assistance request is voluntary. A technical assistance notice compels a provider to use a capability it already has. A technical capability notice compels a provider to build a new capability. Section 317ZG prohibits requiring the implementation of a systemic weakness or systemic vulnerability, or the removal of electronic protection; non-disclosure obligations attach to the notices themselves. TOLA is the single most-raised item by European counsel assessing Australian vendors, and a TIA that does not mention it reads as unresearched.

The Telecommunications (Interception and Access) Act 1979. Interception warrants, stored communications warrants, and the mandatory telecommunications data retention scheme introduced in 2015, which requires carriers and carriage service providers to retain defined metadata for two years.

The Surveillance Devices Act 2004, including computer access warrants, and the data disruption, network activity and account takeover warrants introduced by the Surveillance Legislation Amendment (Identify and Disrupt) Act 2021.

The Australia–United States CLOUD Act Agreement, signed 15 December 2021 and in force since 31 January 2024, which permits reciprocal direct production orders for serious crime — defined as offences punishable by at least three years’ imprisonment. It widens the aperture in both directions and belongs in the assessment.

The arguments available on the other side

The assessment is not a one-way exercise, and an honest TIA records the mitigating position. Australia has an independent regulator with own-motion investigation powers, and the OAIC complaint mechanism is not restricted by the complainant’s nationality or residence. TOLA notices are subject to statutory limits, decision-maker requirements and the s 317ZG systemic-weakness bar. Oversight bodies — the Inspector-General of Intelligence and Security, the Commonwealth Ombudsman, the Independent National Security Legislation Monitor — publish. What Australia does not have is a bespoke redress mechanism for EU data subjects against intelligence collection comparable to the Data Protection Review Court created for the EU-US framework, so residual risk is normally addressed by measures rather than argued away.

Supplementary measures that actually work

The measures that hold up are technical and reduce what an Australian entity can be compelled to produce in intelligible form: strong encryption in transit and at rest with keys held in the EEA by the exporter or a party in an adequate country, pseudonymisation performed before export with the re-identification key retained in the EEA, split or multi-party processing, EEA-resident storage with narrowly scoped and logged Australian support access. Contractual and organisational measures — a commitment to challenge orders, to notify where lawful, to publish transparency statistics, and to route all access requests through counsel — support the technical ones but do not substitute for them. The catalogue is in our page on Schrems II supplementary measures, and the wider architecture in our overview of cross-border data transfers.

Two limits to note. Art. 48 provides that a judgment or decision of a third-country authority is not in itself a lawful ground for transfer, absent an international agreement — so “we had to, we were ordered to” is not an answer under EU law. And the Art. 49 derogations, including explicit consent and contractual necessity, are construed narrowly and are intended for occasional, non-repetitive transfers. They will not carry a product.

The contract path for an Australian vendor selling to EU buyers

A workable sequence, in order:

  1. Fix your role. Controller or processor, per activity. This determines the module and it is a legal characterisation, not a negotiating position.
  2. Decide where the data will live. The fastest commercial answer to the whole problem is often EEA hosting, so that no transfer occurs for storage. Be honest about remote access: if your Sydney engineers can reach EEA production, that access is a transfer and needs the same paperwork, even if it is limited to support.
  3. Prepare a standing DPA containing the Art. 28(3) processor terms with the SCCs annexed, pre-populated for Modules Two and Three.
  4. Complete the annexes properly. Annex I(A) parties, I(B) a specific description of the transfer including categories of data subjects, data and purposes, I© the competent supervisory authority per clause 13. Annex II the technical and organisational measures, at the level of detail Art. 32 implies rather than a marketing summary. Annex III the sub-processor list.
  5. Write the TIA once, properly, and version it. One assessment covering your architecture, refreshed annually and on any material change, saves you from drafting a fresh one for every deal. European buyers will accept a well-made vendor TIA as an input to their own.
  6. Flow it down. Every sub-processor outside the EEA needs back-to-back clauses or accession through the clause 7 docking mechanism.
  7. Keep the Art. 27 designation consistent with the clause 13 authority named in your annexes.
  8. Automate the maintenance. Transfer registers, sub-processor lists and annexes drift within months; see our guide to GDPR compliance software for Australian companies.

Singapore-based groups face an almost identical analysis with different local statutes and one significant trap of their own; that is covered in our page on Singapore–EU data transfers.

FAQ

Is there any prospect of an Australian adequacy decision?

None has been announced as at 30 July 2026, and no adequacy negotiation with Australia has been opened. Adequacy assessments consider the whole legal order, including government access and redress, not only the commercial privacy statute — so even the completion of the Privacy Act reform programme would not make a decision automatic. Plan on SCCs.

We store everything in an EU region. Do we still need SCCs?

If no one outside the EEA can access the data, there is no transfer and no Art. 46 tool is required. That is rarely the real architecture. Australian administrator accounts, offshore support rotations, backup replication, telemetry and vendor-managed monitoring all constitute access. Map it before you claim it, and check whether the scope tests in GDPR for Australian companies apply to you in any event.

Only for occasional transfers, and the consent must be explicit and informed as to the specific risks arising from the absence of an adequacy decision and appropriate safeguards. It is unworkable as the basis for a service that transfers data continuously, and supervisory authorities have consistently said so.

Does a European customer’s own DPA cover us?

It covers the relationship between you and them. It does not discharge your obligations to sub-processors, it does not produce your TIA, and it will usually contain the module they assumed applies. Read the module against your actual role before signing.

Legiscope automates this for you

Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.

Start free trial
TD
Written by
Fondateur de Legiscope et expert RGPD

Docteur en droit de l'Université Panthéon-Assas (Paris II), 23 ans d'expérience en droit du numérique et conformité RGPD. Ancien conseiller de l'administration du Premier ministre sur la mise en œuvre du RGPD. Thiébaut est le fondateur de Legiscope, plateforme de conformité RGPD automatisée par l'IA.

View full author profile →