Guide
Influencer Marketing Basics
Brands
Sending campaign data — audience insights, shipping details, or a briefing pack — to an influencer or agency based outside the EU/EEA is a standalone "international transfer" under GDPR's Chapter V, not just ordinary processing. It needs its own legal ground: either an EU adequacy decision covering that country, the European Commission's Standard Contractual Clauses (SCCs), or, in narrow cases, one of the specific derogations in Article 49.
When you send campaign data — an audience-insights summary, shipping details for a gifted product, or a briefing pack with contact information — to an influencer or agency established outside the EU/EEA, that isn't just ordinary processing under GDPR's Article 6. It's an international transfer under GDPR's Chapter V, and it needs its own, separate legal ground — regardless of whether you already have the Article 6 basis for the processing itself sorted out. That applies whether the recipient is a large agency or a single influencer, and whether the transfer happens once or repeatedly.
This is practical guidance from Make Influence, not legal advice. Use it as a checklist of what to consider — get the specific legal assessment of your own transfer from a lawyer.
Influencer Marketing and GDPR: What Brands Need to Know covers day-to-day processing — which legal basis applies to which data, who's the controller, and when you need a data processing agreement. That article briefly mentions transferring data to US-based tools and platforms under the EU-U.S. Data Privacy Framework. This article covers something more specific: the transfer itself, of data to an influencer or agency physically located outside the EU/EEA — the recipient itself, not a tool you use along the way. It's a separate rulebook (Chapter V, Articles 44-49) that sits on top of your ordinary Article 6 basis, not instead of it.
The European Data Protection Board (EDPB), in its Guidelines 05/2021 on the concept of transfer, sets out three cumulative criteria for when something is an international transfer:
If all three are met, it's a transfer — whether it happens by email, a shared folder, a briefing platform, or verbally on a video call. Some concrete examples from influencer marketing:
| Situation | Is it a transfer? |
|---|---|
| You send a PDF of audience insights (aggregated, non-identifiable figures) to a US agency | No — aggregated, non-identifiable figures aren't personal data and fall outside GDPR in the first place |
| You send a name, address and phone number to an influencer in the Philippines to ship a gifted product | Yes — name and address are personal data, and the influencer is an independent controller for their own content and their own address |
| You share a contact list of competition entrants with a UK-based agency handling the giveaway | Technically yes, but the UK has its own adequacy decision (see below), so the requirement is already met with no extra steps |
| You brief a US talent agency representing a creator, including campaign details and the creator's own tax ID number, for fee payout | Yes — and with a higher sensitivity level, because tax data typically needs extra care |
Just as ordinary processing needs a legal basis, the transfer itself needs one of three grounds under Chapter V:
| Ground | How it works | Administrative burden |
|---|---|---|
| Adequacy decision (Article 45) | The European Commission has decided the whole country offers an adequate level of protection. You can transfer data as if the recipient were in the EU/EEA — no further contractual steps required. | None — provided the country is genuinely on the list |
| Standard Contractual Clauses, SCCs (Article 46) | The European Commission's own standard clauses, signed between you and the recipient, supplemented by a concrete assessment of whether the third country's own laws genuinely provide equivalent protection (a "transfer impact assessment") | Moderate to high — requires documentation, and needs re-assessing if circumstances change |
| Derogations for specific situations (Article 49) | A narrow set of exceptions — e.g. the data subject's explicit consent, or necessity for performing a contract with the data subject themselves — that can only be used for occasional, non-repetitive transfers | Low per transfer, but can't carry an ongoing relationship |
Per the European Commission's own list, as of this article's most recent update (27 August 2026), the following countries and territories have an adequacy decision: Andorra, Argentina, Brazil (the newest, from 26 January 2026), Canada (commercial organisations only), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, the United States (only companies certified under the EU-U.S. Data Privacy Framework — not automatically the whole country) and Uruguay, plus the European Patent Organisation.
Important: this list changes over time — the Commission can add, amend or suspend a decision. Always check the Commission's own, current list before relying on a specific country — don't assume a country is still "safe" just because it was on the list last year. Note the US carve-out especially: it isn't the whole United States that's covered — only the specific companies actually certified under the EU-U.S. Data Privacy Framework. A US agency that hasn't certified itself is not covered by the adequacy decision, even though it's based in the US.
If the recipient's country isn't on the adequacy list — which covers most countries influencer marketing typically works with outside Europe, such as India or most Asian markets — Standard Contractual Clauses are the most common ground. The European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 sets out four modules, depending on each party's role:
Following the CJEU's Schrems II ruling, signing the SCCs alone isn't enough — you also have to concretely assess whether the recipient country's own laws (e.g. government access to data) genuinely undermine the protection the clauses provide, and supplement with technical measures such as encryption if needed. That's called a transfer impact assessment (TIA), and it has to be documented, not just assumed.
If an SCC agreement isn't practically possible — for example, for a one-off, small campaign with a single influencer in a country with no adequacy decision — one of the Article 49 derogations can come into play. The most relevant ones for influencer marketing are typically:
Both Datatilsynet and the EDPB stress that the Article 49 derogations are meant as exceptions, not a standing substitute for SCCs in an ongoing or repeated relationship. If you use the same influencer or agency in a country with no adequacy decision month after month, you should have an SCC agreement in place rather than leaning on consent every time.
IF the recipient's country is on the Commission's current adequacy list → no further contractual steps are needed beyond your ordinary Article 6 basis.
IF you're sending data to a US agency or influencer who is not themselves certified under the EU-U.S. Data Privacy Framework → the adequacy decision doesn't automatically cover it, even though the US is partly on the list — check the specific certification, or use SCCs.
IF the recipient's country isn't covered by any adequacy decision, and the relationship is ongoing → put an SCC agreement in place with the relevant module, and document a transfer impact assessment.
IF it's a one-off, occasional transfer and an SCC agreement isn't practically possible → assess whether one of the Article 49 derogations — typically explicit, informed consent — can carry that single transfer.
The example below is invented for illustration only — not a real Make Influence customer.
A Danish brand runs a campaign through a boutique talent agency based in Los Angeles, representing five American lifestyle creators. The agency itself isn't certified under the EU-U.S. Data Privacy Framework — it's a small, independent player, not a large platform. The brand sends a briefing pack with campaign details, plus each creator's mailing address for product shipping, and also has to share tax-relevant information for fee payout.
Because the agency isn't certified, the US's partial adequacy decision doesn't automatically cover the transfer. Since the relationship is planned as an ongoing, multi-campaign arrangement — not a one-off transfer — the Article 49 derogations aren't the right ground either. The brand instead signs an SCC agreement with the agency under Module 1 (controller to controller, because the agency decides for itself how it manages its own creators' data), and documents a short transfer impact assessment noting that none of the specific data transferred (contact details, tax ID) is assessed as particularly exposed to US government access in this context.
In our experience, international transfers get overlooked for exactly the same reason as general GDPR processing — it doesn't feel like "real" data transfer, it's "just" a briefing pack or a shipping address sent to an agency you already have a commercial relationship with. But commercial trust and a legal transfer ground are two different things. Our recommendation: make "is the recipient outside the EU/EEA, and do we have a ground for it?" a standing question in onboarding any international agency or creator — alongside what you should already be asking about data processing agreements, see influencer marketing and GDPR.
The payment details themselves (bank details, address) are personal data, so yes — send them to a recipient outside the EU/EEA, and the rules in this article apply. See how to pay international influencers for the payment mechanics themselves, a separate question from the data transfer.
Usually not — as the general GDPR article explains, an influencer is typically an independent controller for their own content, not a processor for the brand. That means SCC Module 1 (controller to controller) is usually the right choice, not Module 2.
No. If the country has a valid adequacy decision, you can transfer data as if the recipient were in the EU/EEA, with no further contractual steps — but check the Commission's list every time, since a decision can be amended or withdrawn.
Then it depends which office actually receives and processes the data. If the transfer goes exclusively to the EU office, which is itself directly subject to GDPR, it isn't an international transfer in this article's sense — but assess it concretely, not based on where the agency's head office is formally located.
The UK has its own adequacy decision from the European Commission, so a transfer there can happen with no further steps, the same as to an EU/EEA country — but always check the decision is still valid, since it can be reviewed.
Nothing directly — they're two different rulebooks. This article is about sending campaign data to a foreign recipient; cookie consent is about setting a cookie in a visitor's browser. See Consent Mode and influencer tracking in the EU for that separate question.
Make Influence
Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.
Book a demoCreate accountMake Influence
Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.
Create creator profileMore creator guidesMake Influence
Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.
See how it worksBrowse the Academy