Academy

/

Sending Campaign Data to a Non-EU Influencer or Agency: GDPR's International Transfer Rules

Guide

Influencer Marketing Basics

Brands

Sending Campaign Data to a Non-EU Influencer or Agency: GDPR's International Transfer Rules

Sending campaign data — audience insights, shipping details, or a briefing pack — to an influencer or agency based outside the EU/EEA is a standalone "international transfer" under GDPR's Chapter V, not just ordinary processing. It needs its own legal ground: either an EU adequacy decision covering that country, the European Commission's Standard Contractual Clauses (SCCs), or, in narrow cases, one of the specific derogations in Article 49.

Short answer: yes, it's an international transfer — and GDPR has its own requirements for it

When you send campaign data — an audience-insights summary, shipping details for a gifted product, or a briefing pack with contact information — to an influencer or agency established outside the EU/EEA, that isn't just ordinary processing under GDPR's Article 6. It's an international transfer under GDPR's Chapter V, and it needs its own, separate legal ground — regardless of whether you already have the Article 6 basis for the processing itself sorted out. That applies whether the recipient is a large agency or a single influencer, and whether the transfer happens once or repeatedly.

This is practical guidance from Make Influence, not legal advice. Use it as a checklist of what to consider — get the specific legal assessment of your own transfer from a lawyer.

How is this different from the general GDPR article?

Influencer Marketing and GDPR: What Brands Need to Know covers day-to-day processing — which legal basis applies to which data, who's the controller, and when you need a data processing agreement. That article briefly mentions transferring data to US-based tools and platforms under the EU-U.S. Data Privacy Framework. This article covers something more specific: the transfer itself, of data to an influencer or agency physically located outside the EU/EEA — the recipient itself, not a tool you use along the way. It's a separate rulebook (Chapter V, Articles 44-49) that sits on top of your ordinary Article 6 basis, not instead of it.

When does this actually count as a "transfer" under GDPR?

The European Data Protection Board (EDPB), in its Guidelines 05/2021 on the concept of transfer, sets out three cumulative criteria for when something is an international transfer:

  1. The controller or processor sending the data (the exporter) is itself subject to GDPR for that specific processing.
  2. The exporter discloses the data — by transmitting it or making it available — to another controller, joint controller or processor (the importer).
  3. The importer is located in a third country, or is an international organisation.

If all three are met, it's a transfer — whether it happens by email, a shared folder, a briefing platform, or verbally on a video call. Some concrete examples from influencer marketing:

SituationIs it a transfer?
You send a PDF of audience insights (aggregated, non-identifiable figures) to a US agencyNo — aggregated, non-identifiable figures aren't personal data and fall outside GDPR in the first place
You send a name, address and phone number to an influencer in the Philippines to ship a gifted productYes — name and address are personal data, and the influencer is an independent controller for their own content and their own address
You share a contact list of competition entrants with a UK-based agency handling the giveawayTechnically yes, but the UK has its own adequacy decision (see below), so the requirement is already met with no extra steps
You brief a US talent agency representing a creator, including campaign details and the creator's own tax ID number, for fee payoutYes — and with a higher sensitivity level, because tax data typically needs extra care

The three ways to make the transfer lawful

Just as ordinary processing needs a legal basis, the transfer itself needs one of three grounds under Chapter V:

GroundHow it worksAdministrative burden
Adequacy decision (Article 45)The European Commission has decided the whole country offers an adequate level of protection. You can transfer data as if the recipient were in the EU/EEA — no further contractual steps required.None — provided the country is genuinely on the list
Standard Contractual Clauses, SCCs (Article 46)The European Commission's own standard clauses, signed between you and the recipient, supplemented by a concrete assessment of whether the third country's own laws genuinely provide equivalent protection (a "transfer impact assessment")Moderate to high — requires documentation, and needs re-assessing if circumstances change
Derogations for specific situations (Article 49)A narrow set of exceptions — e.g. the data subject's explicit consent, or necessity for performing a contract with the data subject themselves — that can only be used for occasional, non-repetitive transfersLow per transfer, but can't carry an ongoing relationship

Which countries currently have an adequacy decision?

Per the European Commission's own list, as of this article's most recent update (27 August 2026), the following countries and territories have an adequacy decision: Andorra, Argentina, Brazil (the newest, from 26 January 2026), Canada (commercial organisations only), the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, the United States (only companies certified under the EU-U.S. Data Privacy Framework — not automatically the whole country) and Uruguay, plus the European Patent Organisation.

Important: this list changes over time — the Commission can add, amend or suspend a decision. Always check the Commission's own, current list before relying on a specific country — don't assume a country is still "safe" just because it was on the list last year. Note the US carve-out especially: it isn't the whole United States that's covered — only the specific companies actually certified under the EU-U.S. Data Privacy Framework. A US agency that hasn't certified itself is not covered by the adequacy decision, even though it's based in the US.

No adequacy? SCCs have four modules — pick the right one

If the recipient's country isn't on the adequacy list — which covers most countries influencer marketing typically works with outside Europe, such as India or most Asian markets — Standard Contractual Clauses are the most common ground. The European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 sets out four modules, depending on each party's role:

  • Module 1 (controller to controller): typically fits when an influencer or an independent agency decides for itself how it uses the data for its own content — they're not your processor.
  • Module 2 (controller to processor): fits when the agency acts on your instructions — for example, an administrative agency that purely manages payouts and logistics on your behalf.
  • Modules 3 and 4 cover more complex chains with multiple processors or sub-processors and are less often relevant for an ordinary influencer campaign.

Following the CJEU's Schrems II ruling, signing the SCCs alone isn't enough — you also have to concretely assess whether the recipient country's own laws (e.g. government access to data) genuinely undermine the protection the clauses provide, and supplement with technical measures such as encryption if needed. That's called a transfer impact assessment (TIA), and it has to be documented, not just assumed.

The Article 49 derogations — for occasional use only

If an SCC agreement isn't practically possible — for example, for a one-off, small campaign with a single influencer in a country with no adequacy decision — one of the Article 49 derogations can come into play. The most relevant ones for influencer marketing are typically:

  • Explicit consent from the data subject themselves, after being informed of the specific risks of the transfer (not just a general agreement to collaborate)
  • Necessity for performing a contract with the data subject — e.g. the influencer needing to receive their own contact details back as part of the collaboration agreement itself

Both Datatilsynet and the EDPB stress that the Article 49 derogations are meant as exceptions, not a standing substitute for SCCs in an ongoing or repeated relationship. If you use the same influencer or agency in a country with no adequacy decision month after month, you should have an SCC agreement in place rather than leaning on consent every time.

Decision framework

IF the recipient's country is on the Commission's current adequacy list → no further contractual steps are needed beyond your ordinary Article 6 basis.

IF you're sending data to a US agency or influencer who is not themselves certified under the EU-U.S. Data Privacy Framework → the adequacy decision doesn't automatically cover it, even though the US is partly on the list — check the specific certification, or use SCCs.

IF the recipient's country isn't covered by any adequacy decision, and the relationship is ongoing → put an SCC agreement in place with the relevant module, and document a transfer impact assessment.

IF it's a one-off, occasional transfer and an SCC agreement isn't practically possible → assess whether one of the Article 49 derogations — typically explicit, informed consent — can carry that single transfer.

Practical checklist before briefing an influencer or agency outside the EU

  • Map exactly what personal data is actually being sent — name, address, tax details, contact lists, or only aggregated figures that don't trigger the rules at all
  • Check whether the recipient's country is on the Commission's current adequacy list — not last year's list
  • If the recipient is in the US: check concretely whether that specific company is certified under the EU-U.S. Data Privacy Framework, not just that it's based in the US
  • No adequacy and an ongoing relationship: get an SCC agreement with the right module signed before the first transfer happens
  • Document a transfer impact assessment if SCCs are used
  • Assess whether children's data is involved (e.g. a family creator's own children) — that raises the bar further, see family vlogging and sharenting

Hypothetical example

The example below is invented for illustration only — not a real Make Influence customer.

A Danish brand runs a campaign through a boutique talent agency based in Los Angeles, representing five American lifestyle creators. The agency itself isn't certified under the EU-U.S. Data Privacy Framework — it's a small, independent player, not a large platform. The brand sends a briefing pack with campaign details, plus each creator's mailing address for product shipping, and also has to share tax-relevant information for fee payout.

Because the agency isn't certified, the US's partial adequacy decision doesn't automatically cover the transfer. Since the relationship is planned as an ongoing, multi-campaign arrangement — not a one-off transfer — the Article 49 derogations aren't the right ground either. The brand instead signs an SCC agreement with the agency under Module 1 (controller to controller, because the agency decides for itself how it manages its own creators' data), and documents a short transfer impact assessment noting that none of the specific data transferred (contact details, tax ID) is assessed as particularly exposed to US government access in this context.

Common mistakes

  • Assuming "American = covered by adequacy." Only companies actually certified under the EU-U.S. Data Privacy Framework are covered — not automatically the whole US.
  • Using consent as a standing basis for an ongoing relationship. The Article 49 derogations are meant for occasional, not repeated, use.
  • Signing SCCs without a transfer impact assessment. The clauses alone aren't enough after Schrems II — the assessment of the recipient country's laws also has to be documented.
  • Overlooking that aggregated, non-identifiable figures don't trigger the rules at all. Not all data shared with a foreign agency is necessarily personal data — but when in doubt, treat it as if it is.

Make Influence's operational perspective

In our experience, international transfers get overlooked for exactly the same reason as general GDPR processing — it doesn't feel like "real" data transfer, it's "just" a briefing pack or a shipping address sent to an agency you already have a commercial relationship with. But commercial trust and a legal transfer ground are two different things. Our recommendation: make "is the recipient outside the EU/EEA, and do we have a ground for it?" a standing question in onboarding any international agency or creator — alongside what you should already be asking about data processing agreements, see influencer marketing and GDPR.

FAQ

Does this also apply when we're just paying an influencer abroad, without sharing any other data?

The payment details themselves (bank details, address) are personal data, so yes — send them to a recipient outside the EU/EEA, and the rules in this article apply. See how to pay international influencers for the payment mechanics themselves, a separate question from the data transfer.

Is an influencer themselves a "processor" when we send them data?

Usually not — as the general GDPR article explains, an influencer is typically an independent controller for their own content, not a processor for the brand. That means SCC Module 1 (controller to controller) is usually the right choice, not Module 2.

Do we need SCCs even if the recipient's country has an adequacy decision?

No. If the country has a valid adequacy decision, you can transfer data as if the recipient were in the EU/EEA, with no further contractual steps — but check the Commission's list every time, since a decision can be amended or withdrawn.

What if the agency also has an EU office?

Then it depends which office actually receives and processes the data. If the transfer goes exclusively to the EU office, which is itself directly subject to GDPR, it isn't an international transfer in this article's sense — but assess it concretely, not based on where the agency's head office is formally located.

Is it different if we're sending data to an influencer in the UK?

The UK has its own adequacy decision from the European Commission, so a transfer there can happen with no further steps, the same as to an EU/EEA country — but always check the decision is still valid, since it can be reviewed.

What does this have to do with cookie consent?

Nothing directly — they're two different rulebooks. This article is about sending campaign data to a foreign recipient; cookie consent is about setting a cookie in a visitor's browser. See Consent Mode and influencer tracking in the EU for that separate question.

Make Influence

Want influencer marketing to be easier?

Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.

Book a demoCreate account

Make Influence

Get paid for the audience you built

Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.

Create creator profileMore creator guides

Make Influence

One place for the whole collaboration

Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.

See how it worksBrowse the Academy