Skip to content
Innopulse Consulting
Data protection

What is an adequacy decision?

Short definition

An adequacy decision is the formal finding that a third country offers a level of data protection equivalent to one's own. In the EU it is adopted by the European Commission under Article 45 GDPR, in Switzerland by the Federal Council under the revFADP. Where it exists, personal data may be transferred to that country without additional safeguards.

Personal data cannot be transferred across borders at will. Both the GDPR and Swiss data protection law require the data to be adequately protected in the destination country. The simplest way to ensure this is an adequacy decision: a formal finding by a public authority that a given country as a whole offers an equivalent level of protection. Transfers to such a country need no further safeguards.

Who decides in the EU

In the European Union, the European Commission adopts adequacy decisions under Article 45 GDPR. It examines, among other things, the rule of law, data subjects' rights, the existence of independent supervisory authorities and public authorities' access to data. Decisions are reviewed regularly and can be amended or revoked. For countries of the European Economic Area such as Liechtenstein, Norway and Iceland the GDPR applies directly; transfers there are not third-country transfers.

Switzerland from the EU's perspective

Switzerland has held an adequacy decision from the Commission since 2000. The review whose results the Commission published in January 2024 confirmed it, and the revised Swiss data protection act has further strengthened alignment with European standards. For companies in Germany, Austria or other EU states this means they may transfer personal data to Swiss service providers without concluding standard contractual clauses or carrying out a transfer impact assessment.

The Swiss perspective

Conversely, in Switzerland the Federal Council decides which countries offer adequate protection. The list is set out in an annex to the Data Protection Ordinance and includes in particular the states of the EU and EEA. Swiss companies can therefore transfer data to service providers in the EU without additional safeguards. Transfers to other countries follow the revFADP's rules for third countries.

The special case of the US

There is no blanket adequacy for the United States. Instead it applies only to companies certified under a data privacy framework. The European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework in July 2023; Switzerland recognised the Swiss-U.S. Data Privacy Framework with effect from 15 September 2024. The Court of Justice of the EU struck down two predecessor arrangements, most recently Privacy Shield in 2020 in the Schrems II judgment. Anyone using US services should check whether the specific provider is certified and keep an eye on developments.

What still needs to be settled despite adequacy

An adequacy decision only answers whether data may be transferred to a country. It does not replace the other obligations. If a provider in the destination country processes data on your behalf, a data processing agreement is still required. The privacy policy must name recipients and countries, and principles such as purpose limitation and data minimisation apply unchanged. A German company engaging a Swiss provider therefore still concludes a contract under Article 28 GDPR — just without additional transfer safeguards.

When there is no decision

Without an adequacy decision a transfer is not prohibited but needs another legal basis. Most common are standard contractual clauses, used together with an assessment of the law in the destination country. Groups of companies can use binding corporate rules. In narrowly defined exceptional cases explicit consent or necessity for performing a contract may suffice; these exceptions are not a permanent solution for regular transfers.

Which countries have a decision

The Commission has adopted adequacy decisions for, among others, Andorra, Argentina, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, Canada for organisations within the scope of its private-sector privacy law, New Zealand, South Korea, Switzerland, Uruguay and the United Kingdom, plus the framework for certified US companies described above. The list is occasionally extended, and individual decisions are time-limited or under review. The authoritative source is always the Commission's current list or the annex to the Swiss Data Protection Ordinance, not a list copied once.

A decision can disappear

The history of transfers to the US shows that a decision is no guarantee for eternity. In 2015 the Court of Justice invalidated the Safe Harbor arrangement, and in 2020 its successor Privacy Shield. Companies that relied solely on them had to find alternatives overnight. Anyone who bases important data flows on a politically contested adequacy decision today should know which fallback would apply — often standard contractual clauses, which many providers include in their contracts as a precaution.

Practical meaning for DACH companies

For the German-speaking region the situation is favourable: Germany, Austria and Liechtenstein belong to the EU or EEA, and mutual recognition exists between this area and Switzerland. Data flows within the DACH region are therefore straightforward under data protection law. The real checks concern services outside this area, above all US cloud providers, their certification and their sub-processors.

How we apply this in projects

At Innopulse we choose storage locations deliberately: databases in Zurich or Frankfurt, services based or hosted in the EU or Switzerland, and a certification check for unavoidable US services. In every project we document per service where data sits and on what basis it is transferred. That overview later answers most questions from customers, supplier audits and regulators within minutes.

Data protection is our specialty

Innopulse doesn't just explain terms — we put them into practice for DACH companies.