Key takeaway
Start with who can access which material, for what purpose and where. A named buyer alone is not a complete recipient map.
Draw the entities before choosing a mechanism
An evaluation may begin with one prospective buyer but involve a separate cloud provider, an affiliate and an overseas support team. The privacy lead needs a map of actual legal entities and access paths. A headquarters address or the label European buyer does not describe that architecture.
As reviewed on 7 October 2026, the EDPB’s final Guidelines 05/2021 describe a transfer through three criteria: a GDPR-subject exporter, disclosure to another controller or processor, and an importer in a third country. Its examples distinguish another entity from the controller’s own employee abroad. Other obligations can remain even without a Chapter V transfer.
This is an educational recipient-mapping agenda grounded in final EDPB guidance and current Commission transfer information. It does not verify every current statutory duty or provide transaction clearance. Counsel must review the actual processing facts and applicable law before a proposed disclosure.
Worked example: one package, five access situations
The following fictional arrangement starts with a German service company and an archive containing identifiable support records. A French evaluation entity is considering a defined use. The package has not been disclosed; access facts below are hypothetical inputs to review, not verified findings about real companies.
Each row names a separate legal identity rather than treating every company in a group as the same recipient. The columns record both intended access and unresolved evidence. No role classification, certification or transfer tool is approved by this table.
| Legal entity or person | Location and proposed access | Completed review entry |
|---|---|---|
| Example Service GmbH, archive owner | Germany; controls source archive | Identify exporter role and authority for this use |
| Example Evaluation SAS | France; proposed evaluation viewer | Define purpose, actual role and permitted fields |
| Example Cloud Inc, separate provider | United States; stores evaluation package | Verify entity/scope, subprocessors and actual access; mechanism unresolved |
| Example Support Pvt Ltd, separate provider | India; remote support may inspect records | Treat as a separate access path; require necessity and onward-access details |
| Archive owner’s own employee | Temporary travel outside the EEA; accesses for employer | Document same-entity relationship and security; do not conflate with a separate affiliate |
Include support access and copies that never leave the host
The EDPB’s final Recommendations 01/2020 tells exporters to map onward transfers and remote support access. A storage-region setting therefore cannot complete this map. Ask which legal entity operates support, what staff can see, whether access is exceptional or continuous, and what logs demonstrate the boundary.
In the hypothetical arrangement, engineering confirms the cloud service can restrict routine support access but cannot yet explain incident escalation. The completed decision is hold the personal-record package. The privacy lead requests the support-entity list and access description, and the engineering owner assesses whether a synthetic schema can answer the evaluation question first.
If access is described as impossible, ask what evidence supports that assertion: key ownership, operator permissions, emergency procedures and system behavior may matter. A sales statement that data stays in Europe does not answer a separate overseas person’s viewing capability. The map should identify unknowns rather than converting them into reassuring geography labels.
Apply adequacy and clauses to the actual entity
The Commission’s current adequacy list limits the US entry to participating commercial organisations in the EU-US Data Privacy Framework. It does not establish that every US recipient is covered. The hypothetical cloud company’s participation, covered activities and relevant scope have not been verified.
The Commission also presents scoped standard contractual safeguards. Naming SCCs does not approve this package, define every party’s role or demonstrate effectiveness for the circumstances. The EDPB recommendations call for assessment of the tool and situation, including needed supplementary measures.
For this example the decision record leaves the US and Indian routes unresolved. Counsel needs the actual entities, purposes, roles, agreement architecture and current mechanism evidence. A copied clause title cannot complete those entries. Separately confirm whether a proposed mechanism’s described scope fits the importer rather than assuming one form covers all cases.
Make changes visible before granting access
Version the map with the package and proposed evaluation. If a new affiliate joins, support moves or the recipient begins a different use, record the changed access path before relying on an earlier decision. Keep the actual access log and approved entity list available to the owner handling later questions.
The completed hypothetical outcome is to withhold personal-record access while preparing an internal synthetic schema and requesting entity-specific evidence. The same-controller travel row gets a security review; it is not used to exempt access by a separate group company. Evaluation permission and a later training license remain separate decisions.
Use due diligence for the entity and access questions and rights review for parallel authority issues. VOID can coordinate a named, permissioned introduction using approved metadata without taking custody of the archive or certifying a transfer. The reader leaves with a map that counsel and engineering can inspect together, not a country checkbox.
Use this review agenda with your legal and privacy advisers. Requirements depend on the records, jurisdictions and intended use.