What is a third-country transfer?
The legal term behind the question 'do our data end up in the US?'. What counts as a transfer, what makes it legal, and why AI tools are often involved.
A third-country transfer is when personal data is moved from the EU/EEA to a country outside it, a "third country". The word sounds like moving trucks but covers much more: if a support technician in the US logs into a system with European data, that counts, just as when an AI service with US servers processes a question containing a person’s name.
GDPR doesn’t ban transfers but requires a legal basis: a decision from the European Commission that the country has an adequate level of protection (like the EU-US Data Privacy Framework for participating US companies), standard contractual clauses, or other safeguards. The practical challenge is often even knowing a transfer is happening: it hides in sub-processors of sub-processors.
The easiest way to avoid the question is to make sure it never comes up. In EuroWork, all processing happens within the EU by default, so no third-country transfer takes place. The only route to the US is if a user actively chooses ChatGPT or Claude for a single, harmless message, a choice your administrator can turn off completely. That’s exactly what our policy says, with all sub-processors listed.
Your employees are already using AI, often in private accounts where no one sees what gets pasted in. EuroWork gives the same AI help in one place where you are in control: sensitive data is caught before it is sent, processing stays in the EU, every answer shows its price and management sets the rules.
See how EuroWork works →