Cross-Border Transfer Mechanism
also called SCCs, Adequacy Decision, Transfer Impact Assessment
The legal basis required to move personal data from one jurisdiction to another, and the architectural evidence needed to support it.
Transferring personal data out of a protective regime is prohibited unless a specific mechanism applies, and architects encounter this whenever a system uses a service hosted elsewhere — which, given the shape of the cloud and SaaS market, is most systems.
The mechanisms in practice: an adequacy decision where the destination country is deemed to offer equivalent protection, which is the simplest and is subject to political change; standard contractual clauses, the common route, which since the Schrems II judgment must be accompanied by a transfer impact assessment considering whether the destination's surveillance laws undermine the clauses; and binding corporate rules for intra-group transfers, which are robust and take years to approve.
What this means concretely for design is that a transfer impact assessment frequently concludes that supplementary technical measures are required, and those measures are architecture: strong encryption with keys held in the originating jurisdiction so the recipient cannot decrypt unilaterally, pseudonymisation before transfer, or simply keeping the data in region and transferring only derived results.
The practical discipline is maintaining a data flow map that records where personal data goes, including sub-processors, because a transfer through a vendor's support tooling or a third-party analytics tag is still a transfer and is the kind that appears in enforcement actions rather than in the architecture diagram.