Data Transfer Impact Assessment
aka DTIA, Transfer Impact Assessment, TIA
Documented assessment of whether a non-EEA jurisdiction provides essentially equivalent protection for personal data, required after Schrems II for transfers under SCCs.
Last reviewed April 2026
Definition
A Data Transfer Impact Assessment (DTIA) is the documented analysis a data exporter must complete after Schrems II (Case C-311/18, July 2020) before relying on Standard Contractual Clauses or other Article 46 mechanisms to send personal data outside the EEA. The DTIA assesses the laws and practices of the third country (particularly its surveillance and government-access regime), the categories of data being transferred, the technical and organisational measures in place (encryption in transit and at rest, key management, access controls, pseudonymisation), and contractual measures (SCCs, audit rights, breach notification). If the assessment concludes the third country does not offer essentially equivalent protection, the exporter must apply supplementary measures (typically encryption with EEA-held keys, anonymisation, or splitting of data) to bridge the gap. The European Data Protection Board (EDPB) Recommendations 01/2020 set out the methodology. DTIAs do not need to be filed with the DPC but must be available on request and must be re-assessed when the law of the third country changes.
Why it matters for software choice
Most Irish SMEs rely on a vendor's published DTIA template rather than completing their own. Vendors that publish a downloadable DTIA, list the supplementary measures they apply, and update it when transfer law changes save days of compliance work and limit DPC-investigation risk.
Authority sources
- EDPB Recommendations 01/2020 on supplementary measures (edpb.europa.eu)
- DPC: International data transfers (www.dataprotection.ie)
Software categories this affects
Vendors covered by this term
HubSpot CRM
Free CRM with marketing automation, widely adopted by Irish tech and services firms
Salesforce
Enterprise CRM with EU data centres and a strong Irish partner ecosystem
Microsoft Copilot
AI assistant integrated into Microsoft 365, with EU data boundary for European customers
ChatGPT Enterprise
OpenAI's enterprise AI assistant with advanced reasoning, data analysis, and custom GPTs
Claude for Business
Anthropic's AI assistant with strong safety focus, long context handling, and business-grade data privacy
Related terms
Standard Contractual Clauses
Pre-approved contractual templates issued by the European Commission for transferring personal data outside the EEA. The default fallback when no adequacy decision applies.
Data Residency (EU vs US)
Where customer personal data is stored and processed. Storing inside the EU/EEA simplifies GDPR compliance; processing in the US triggers transfer-mechanism obligations under Schrems II.
Data Protection Commission
Ireland's national data protection authority. Lead supervisory authority for many large US tech companies headquartered in Dublin under the GDPR's one-stop-shop mechanism.