CROSS-BORDER TRANSFERS OF PERSONAL DATA UNDER THE GDPR
SCOPE AND LIMITATIONS OF THE “BLOCKING STATUTE”
DOI:
https://doi.org/10.25234/eclic/44801Abstract
The General Data Protection Regulation (GDPR) establishes a comprehensive framework for personal data protection within the European Union, with particular emphasis on cross-border data transfers. The GDPR addresses cross-border data protection through two complementary regulatory approaches. First, the rules on territorial scope extend the GDPR’s application to certain processing activities conducted by controllers or processors established outside the EU, provided these activities relate to the data of individuals located within the Union. These provisions are intended to protect EU data subjects from external threats posed by non-EU actors. Second, the GDPR sets forth a regime for transfers of personal data to third countries or international organisations. The transfer regime is preventive in nature, as it requires that personal data exported outside the EU continue to benefit from safeguards that are essentially equivalent to those provided under EU law. Prior to any transfer, the parties involved must ensure that appropriate legal safeguards are in place. Among the relevant provisions, Article 48 of the GDPR, often referred to as the “blocking statute,” plays a distinctive role in regulating transfers of personal data in response to requests from authorities of third countries or international organisations. This provision clarifies that judgments or decisions of courts or administrative authorities of third countries requiring a controller or processor to transfer or disclose personal data do not, in themselves, constitute a legal basis for such transfers. In this way, the EU asserts its legal sovereignty in relation to the laws of third countries, establishing as a general rule that recognition and enforcement of such foreign judgments or decisions may occur only through the application of international agreements. Throughout the paper, the extraterritorial effects of the GDPR are examined and clarified, with particular emphasis placed on the “blocking statute” rule, as interpreted in relevant legal doctrine, guidance, and the CJEU case law.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Martina Drventić Barišin

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Authors retain the copyright on the papers published in the Journal, but grant the right of first publication to the Journal. Papers accepted for publication or already published in ECLIC of the Faculty of Law in Osijek may be published by the author(s) in other publications only with proper notice of its previous publication in ECLIC.
