This Practice Note considers the general prohibition under Chapter V of the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) on the cross-border transfer of personal data outside of the EEA or to an international organisation. Among other things, it considers how to identify a restricted international transfer, onward transfers, data export restrictions, adequacy decisions, standard contractual clauses (Model Clauses or SCCs), Binding Corporate Rules (BCRs) and other appropriate safeguards (ie using Article 46 tools) and derogations. It also includes guidance on amending SCCs and links to further practical guidance on how to use SCCs. In brief Data protection law in the EEA seeks to ensure information about living individuals (ie within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU GDPR imposes a large number of obligations on those undertaking or controlling the ‘processing’ of personal data. In summary, ‘processing’ includes doing almost anything with personal data, including storing, sharing, deleting, using or transferring it. One of the key protections under