Transfers outside the EU: where your mobile app’s data actually lands
Sending personal data outside the European Union is not forbidden. The CNIL puts it simply: it is possible, provided you ensure a sufficient and appropriate level of protection for the data. The whole difficulty lies in demonstrating that condition.
In July 2025 the authority published the final version of its guide on transfer impact assessments. The document is precise: the assessment falls on the exporter, meaning whoever sends the data out of the Union, whether it acts as controller or as processor. It must be carried out before any transfer outside the European Economic Area that relies on Standard Contractual Clauses or an equivalent tool.
That guide never mentions mobile apps, nor SDKs. The doctrine exists, but no one has applied it to the one place where the publisher sees nothing go by. An app contacts servers directly, with nothing on screen to say which country they sit in. Here is what the law actually requires, and how to answer the question with facts rather than with a contractual clause.
A signed contract is not a guarantee
On 2 May 2025 the Irish data protection authority issued its final decision against TikTok, following an inquiry into transfers of European users’ data to China. The fine totals 530 million euros.
The grounds deserve a careful reading, because they are not about a missing contract. TikTok had Standard Contractual Clauses in place. The authority found it had infringed Article 46(1) GDPR because it failed to verify, guarantee and demonstrate that those clauses and the supplementary measures were effective, that is, that they gave the transferred data a level of protection essentially equivalent to the one guaranteed within the Union.
The split of the fine says the rest. The transfer breach weighs ten times the one on informing users.
The lesson transposes directly to an app. The obligation is not to sign, it is to demonstrate. And nothing can be demonstrated about a flow whose destination is unknown.
Three regimes, and only one that leaves you alone
The first is adequacy. Through its adequacy decisions, the European Commission recognises that a country protects data in an equivalent way, and data may then flow there without any further safeguard being necessary. It is the only case where you have nothing to demonstrate.
The list is short, closed, and currently holds seventeen entries: Andorra, Argentina, Brazil since 26 January 2026, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom, Uruguay, the United States for certified organisations only, and the European Patent Organisation. Any country absent from that list falls under the two regimes below.
The second rests on a contract, most often the Commission’s Standard Contractual Clauses, sometimes binding corporate rules. That is what triggers the transfer impact assessment, and what TikTok was sanctioned on. The origin of the obligation is well known: on 16 July 2020 the Court of Justice handed down the ruling known as Schrems II, which invalidated the framework then in force with the United States and required a case-by-case check that the destination country’s law does not empty the contract of its effect.
The third covers the Article 49 derogations, such as explicit consent to a specific transfer. The CNIL recalls that they may only be relied on in particular situations. It is not a regime for everyday operation, and invoking it for a daily advertising flow would be a misreading.
In short: outside the adequacy list, every transfer requires a contract and an assessment demonstrating its effectiveness. Which still assumes you know which countries you transfer to.
The American case is not the one people think
A stubborn belief holds that transfers to the United States are prohibited. That has not been accurate since 10 July 2023: the Commission adopted an adequacy decision for the transatlantic data protection framework. But it does not cover the United States as a whole. It covers the organisations that participate in the framework, meaning those that have certified and appear on the public list maintained by the US administration.
So the right question is not whether data goes to the United States, but whether this specific recipient is certified. For an app publisher, that means knowing the actual recipient, not just the name of the SDK that was integrated.
Nor is the regime settled. The Commission published its report on the first periodic review of the framework on 9 October 2024. And on 3 September 2025 the General Court of the European Union dismissed the action seeking annulment of that adequacy decision, recalling that the Commission is required to monitor continuously the application of the legal framework the decision rests on. The framework holds, but it holds under permanent watch, and a certified organisation can stop being one.
Why the question is harder on mobile
On a website the answer comes from opening the browser tools: the requests are there, and so are the domains. Nothing of the kind inside an app. The traffic belongs to the app itself, it is encrypted, and it is displayed nowhere. It is the same asymmetry that makes auditing a mobile app harder than a website.
Reading the code does not fill that gap. It gives you the name of a library, not the country of the server it contacts. And the address that SDK calls can change on the vendor’s side without a single line of your repository moving. Your record of processing would stay accurate and your transfer mapping would be wrong.
On top of that, the actual recipient is not always the expected one: an advertising flow reaches companies the publisher never signed anything with. A transfer assessment built on the list of integrated SDKs alone misses those recipients.
What a publisher can establish, and the caution to keep
Three things can be observed by running the app and recording its traffic. The country of the contacted server, from its address. The organisation hosting that server, behind the address. And the level of protection recognised for that country, adequate or not, which tells you which of the three regimes applies.
One caution matters, and it counts for the honesty of the file. A server located in Europe does not mean the data stays there. Content delivery networks, the infrastructure that brings servers closer to users, keep relays in many countries, and a European relay can perfectly well pass data to a machine sitting elsewhere. A geolocation finding therefore establishes the first point of contact, not the full path. Saying so is more useful than implying otherwise: an honest assessment separates what was measured from what must be asked of the vendor.
That is precisely what the reasoning in the TikTok decision calls for. The exporter must verify, guarantee and demonstrate. Measurement supplies the first brick, vendor documentation supplies the second.
From a processor list to a transfer file
Most transfer mappings start from a list of declared vendors and their privacy policies. That is a starting point, not evidence. The declared list and the actual activity diverge, and that gap is exactly what an inspection comes looking for.
Skanopy runs the app on a real phone and records every server contacted, with its country and the organisation hosting it. You get the factual material missing upstream of a transfer assessment: which actors receive data, from which app, and towards which jurisdictions. The report establishes the facts, it does not rule on compliance; the qualification stays with the DPO.
And because an endpoint can be moved without notice, this verification is worth more repeated than one-off. It is also one of the points an inspector examines, alongside consent and permissions: enough to prepare the file before anyone asks for it.
Sources
Every finding in this article traces back to one of these documents.
- CNIL ’25Transfer impact assessment: final version of the guideCNIL, 9 July 2025
- CNILTransferring data outside the European UnionCNIL, compliance tools
- EDPB ’25Irish authority fines TikTok 530 million euros over transfers to ChinaEuropean Data Protection Board
- DPC ’25Final decision of the Irish authority on TikTok transfersData Protection Commission, 2 May 2025
- CommissionAdequacy decisions: the list of recognised countriesEuropean Commission
- DPFPublic list of certified organisationsData Privacy Framework, US administration
- General Court ’25The General Court dismisses the challenge to transatlantic adequacyIAPP, 3 September 2025
- CNIL ’25Mobile app recommendation, amended versionCNIL, deliberation no. 2025-024