The classic trap
Recital 102 reminds us that the GDPR coexists with international agreements (judicial cooperation, tax, customs, social security). The trap: assuming a bilateral treaty is enough to transfer data outside the EU when it must provide an appropriate level of protection equivalent to GDPR. The CNPD and CNIL regularly sanction transfers made under tax conventions (FATCA, CRS) or mutual assistance agreements without complementary article 46 safeguards. Since Schrems II (CJEU 2020), no international agreement exempts you from a transfer impact assessment (TIA) if effective protection in the destination country is insufficient.
The international agreements at stake and their blind spots
- FATCA (USA): annual transfer of US persons' banking data by Luxembourg banks to the IRS, without individual remedy equivalent to GDPR.
- CRS / DAC (OECD, EU): automatic exchange of tax information with around a hundred jurisdictions, some without adequacy decisions.
- Criminal mutual legal assistance treaties (US-EU MLAT): transmission of data to foreign authorities upon request.
- US Cloud Act: direct conflict with GDPR, not covered by an EU-US executive agreement.
- Sectoral agreements (PNR, TFTP): closely monitored by the EDPB and regularly challenged before the CJEU.
- Social security conventions: transfer of cross-border workers' data, often without documented TIA.
The practical rule: an international agreement NEVER replaces the article 44-49 analysis. At best it provides a legal basis under article 6, never an appropriate safeguard within the meaning of article 46.
How Luxgap automates this risk
Our Luxgap Treaty Transfer Radar maps in real time all your data flows subject to an international agreement (FATCA, CRS, MLAT, social conventions, PNR) and automatically confronts them with residual GDPR requirements, turning these so-called 'legal' transfers into documented and defensible transfers. The tool connects to your core banking, payroll, tax declaration systems and encrypted messaging to detect every transmission subject to a treaty, without asking your DPO to manually inventory anything.
- Automatically detects every flow subject to an international agreement by analysing outbound payloads from your core banking, SAP, Sage BOB 50 and Workday LU towards foreign tax recipients.
- Classifies each transfer by its actual legal basis (EU-third country agreement, bilateral Member State agreement, adequacy decision, standard contractual clauses) and flags obsolete or contested grounds.
- Generates a pre-filled transfer impact assessment (TIA) by destination, integrating EDPB 01/2020 recommendations and post-Schrems II case law.
- Instantly alerts via Teams or Slack when a new destination country appears without prior assessment (typical of CRS extensions and new mutual assistance partners).
- Cross-references your recipients with the EDPB database of notified agreements and flags transfers based on agreements non-compliant with article 96 GDPR.
- Produces a time-stamped, cryptographically signed transfer register, defensible before the CNPD and CSSF during a joint inspection.
Available as part of a Luxgap DPO mandate or as a dedicated SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual international flows, with a free 48h blank audit to measure your treaty-based transfer exposure before any commitment.