Content library
TISAX: Information security
9.5.3: Management of data transfers to third countries

Requirement description

Objective: The company is aware of and secures data transfers to third countries.

Requirements (must): Transfers to third countries are known and systematically recorded.
- e.g. through corresponding documentation in the processing directory
Sufficient guarantees (Chapter V GDPR, consideration of decisions of the ECJ on international data transfer, Transfer Impact Assessment in case of relevance, especially in the role of data exporter) are available for data transfers.
In the case of data transfers to third countries, it is determined whether the consent of the person responsible is to be obtained for each transfer to third countries.

How to fill the requirement

TISAX: Information security

9.5.3: Management of data transfers to third countries

Task name
Priority
Status
Theme
Policy
Other requirements
Documentation of bases for personal data transfer for relevant partners
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Privacy
Data transfer and disclosure
16
requirements

Examples of other requirements this task affects

44. General principle for transfers
GDPR
45. Transfers on the basis of an adequacy decision
GDPR
46. Transfers subject to appropriate safeguards
GDPR
47. Binding corporate rules
GDPR
48. Transfers or disclosures not authorised by Union law
GDPR
See all related requirements and other information from tasks own page.
Go to >
Documentation of bases for personal data transfer for relevant partners
1. Task description

GDPR defines the conditions for the lawful transfer of personal data outside the EU or the EEA.

The organization shall document all data transfers and the applicable transfer criteria. Data transfers can occur, for example, based on the location of the data system, the data processing partner or the recipient of the data disclosure.

Legal bases for personal data transfers between different legal zones
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Privacy
Data transfer and disclosure
2
requirements

Examples of other requirements this task affects

A.7.5.1: Identity basis for PII transfer between jursdictions
ISO 27701
9.5.3: Management of data transfers to third countries
TISAX
See all related requirements and other information from tasks own page.
Go to >
Legal bases for personal data transfers between different legal zones
1. Task description

The organization has identified possible transfers of personal data between jurisdictions.

There are identified and documented legal bases for transfers of personal data between jurisdictions.

Records of personal data transfers to third parties
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Privacy
Data transfer and disclosure
3
requirements

Examples of other requirements this task affects

A.7.5.3: Records of transfer of PII
ISO 27701
A.8.5.3: Records of PII disclosure to third parties
ISO 27701
9.5.3: Management of data transfers to third countries
TISAX
See all related requirements and other information from tasks own page.
Go to >
Records of personal data transfers to third parties
1. Task description

The organization should record transfers of personal data to and from third parties. The organization should also ensure the cooperation of the relevant parties in order to enable the implementation of requests regarding obligations related to data subjects in the future as well.

The principle of data minimization must be taken into account in recordings concerning transfers and only the information that is actually needed must be kept.

Tasks included in the policy

Task name
Priority
Status
Theme
Policy
Other requirements
No items found.

Universal cyber compliance language model: Comply with confidence and least effort

In Cyberday, all frameworks’ requirements are mapped into universal tasks, so you achieve multi-framework compliance effortlessly.

Security frameworks tend to share the common core. All frameworks cover basic topics like risk management, backup, malware, personnel awareness or access management in their respective sections.
Cyberday’s universal cyber security language technology creates you a single security plan and ensures you implement the common parts of frameworks just once. You focus on implementing your plan, we automate the compliance part - for current and upcoming frameworks.
Start your free trial
Get to know Cyberday
Start your free trial
Cyberday is your all-in-one solution for building a secure and compliant organization. Whether you're setting up a cyber security plan, evaluating policies, implementing tasks, or generating automated reports, Cyberday simplifies the entire process.
With AI-driven insights and a user-friendly interface, it's easier than ever to stay ahead of compliance requirements and focus on continuous improvement.
Clear framework compliance plans
Activate relevant frameworks and turn them into actionable policies tailored to your needs.
Credible reports to proof your compliance
Use guided tasks to ensure secure implementations and create professional reports with just a few clicks.
AI-powered improvement suggestions
Focus on the most impactful improvements in your compliance with help from Cyberday AI.