Back to Blog Lobby

Cross-Border Data Transfer: How to Collaborate Without Moving Sensitive Data

cross-border data transfer

Cross-border data transfer has always been a compliance headache. In 2026, it is also becoming an AI problem, since training a global model often means pulling in data from countries whose laws will not let that data leave in the first place. Most guidance still focuses on legal transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, and Binding Corporate Rules.

Those frameworks remain essential, but all of them answer the same question: how to move sensitive data legally across borders. Right now that question is shakier than usual.

The EU-U.S. Data Privacy Framework, the mechanism over 2,800 American companies rely on to receive data from Europe, is facing a fresh legal challenge after a U.S. Supreme Court ruling undercut the independence of the regulator the whole framework depends on.

Increasingly, organizations are asking a different question: how can they collaborate without moving sensitive data at all? Privacy enhancing technologies answer that question directly.

This guide explains how today’s cross-border data transfer rules work, where traditional compliance approaches fall short, and how organizations can collaborate across jurisdictions while keeping sensitive data exactly where it belongs. 

What is cross-border data transfer?

Cross-border data transfer is the movement of personal data from one country to another, whether that means storing it on a server abroad, giving an overseas team access to it, or sending it to a partner organization in another jurisdiction. It happens more often than most people realize.

A London company using a cloud provider based in Singapore has transferred data internationally the moment that provider can access it, even if no file is ever emailed anywhere.

Data protection laws generally treat this movement as risky by default. The concern is not the technology used to move the data. It is that once personal data leaves its country of origin, the people it describes lose the legal protections that country’s laws gave them.

A hospital record protected by strict EU privacy rules does not carry those same protections once it lands on a server in a country with weaker safeguards or broader government access to private data.

That is why most data privacy laws, including the GDPR, the CCPA, and China’s PIPL, require organizations to justify every cross-border transfer with a specific legal basis before it happens, not after.

 Encrypted data transfer

Cross-border data transfer law is not one law. It is a patchwork of national and regional rules, and the patchwork keeps changing. Here is where things stand as of mid-2026:

United States

The United States still has no single federal privacy law. Instead, the Federal Trade Commission enforces privacy at the national level while states fill the gaps. As of 2026, around 20 states, including California, Colorado, Connecticut, Texas, Virginia, and new entrants like Indiana, Kentucky, and Rhode Island, have their own comprehensive privacy laws.

The California Consumer Privacy Act remains the strictest, giving residents rights to know what data is collected about them, request its deletion, and opt out of having it sold or shared, including with foreign entities.

For data moving from the EU into the US, the EU-U.S. Data Privacy Framework has been the primary legal bridge since 2023, replacing the invalidated Privacy Shield. As mentioned above, that framework is now facing its most serious challenge yet.

Companies that depend on it exclusively should have Standard Contractual Clauses ready as a backup, and should watch this space closely through the rest of 2026.

Move Beyond Cross-Border Data Transfers

Eliminate dependency on SCCs, adequacy decisions, and data movement by enabling secure collaboration directly on encrypted and distributed data.

European Union and United Kingdom

The GDPR remains the world’s most influential privacy law and sets the benchmark that many other countries model their own rules on. Under GDPR, personal data cannot leave the European Economic Area unless the destination country has an adequacy decision, the exporter has put contractual safeguards in place, or a narrow exception applies.

Since the 2020 Schrems II ruling, organizations must also run a transfer impact assessment for many of these transfers, checking whether the receiving country’s surveillance laws could undermine the safeguards on paper.

The UK left the EU but kept a near identical version of GDPR, and the two sides currently recognize each other as adequate. The UK created its own International Data Transfer Agreement for transfers to countries without adequacy status, working alongside the UK’s version of Standard Contractual Clauses.

China

China’s Personal Information Protection Law, often called China’s answer to the GDPR, takes a stricter approach than most Western frameworks. It requires many categories of data collected in China to stay there unless the exporting company passes a government security assessment, signs China’s own standard contract, or obtains a specific certification.

Large volumes of data or anything classified as sensitive typically trigger the toughest of these three routes. Getting this wrong is not just a compliance headache. Penalties can reach 5 percent of a company’s annual revenue in China.

Canada, Brazil, and beyond

Canada’s PIPEDA does not ban international transfers outright, but it holds Canadian companies accountable for making sure a foreign recipient protects the data to a comparable standard, and the EU has granted Canada an adequacy finding on this basis.

Brazil’s LGPD mirrors GDPR’s structure closely, permitting transfers to countries with an adequacy decision from Brazil’s data authority or under approved contractual safeguards. Expect more countries, particularly across Latin America, the Gulf, and Southeast Asia, to introduce similar frameworks over the next few years as global data volumes keep climbing.

Data transfer

How do you transfer sensitive data across borders without violating GDPR?

If you do need to move personal data out of the EU, GDPR gives you four main paths, in rough order of how commonly they are used.

  • Adequacy decisions. The European Commission has approved a short list of countries, including the UK, Japan, South Korea, Canada, and New Zealand, as providing protection equivalent to the GDPR. Transfers to these countries need no extra paperwork.
  • Standard Contractual Clauses. Pre-approved contract templates that bind the receiving party to GDPR-level protections. These are the most widely used mechanisms precisely because they do not depend on a government-to-government adequacy decision that could later be challenged in court.
  • Binding Corporate Rules. Internal policies a multinational group gets approved by a data protection authority, allowing free data flow between its own entities worldwide. BCRs take months to approve but remove the need for contract-by-contract review once in place.
  • Derogations. Narrow, one-off exceptions such as explicit informed consent or a transfer necessary to fulfill a contract. Regulators expect these to be the exception, not the backbone of a transfer program.

Whichever mechanism you use, GDPR expects you to document it, keep it current, and be ready to prove that the destination country’s laws do not undermine it in practice. That last part is where many companies get caught out.

A contract that looks solid on paper does not protect you if the receiving country’s government can legally compel access to the data regardless of what the contract says.

This is precisely the exposure that has fueled three rounds of legal challenges to US transfer mechanisms since 2015.

Secure data transfer platform

Can you collaborate on data across borders without actually transferring it?

Yes, and this is the shift most compliance guides skip entirely. The legal mechanisms above all assume the same starting premise: personal data has to physically move, or at least become accessible, to the party that wants to use it. Privacy enhancing technologies remove that premise.

With technologies like fully homomorphic encryption, secure multiparty computation, and federated learning, an organization in Germany and an organization in Singapore can jointly train a model, run a statistical analysis, or match records against each other, all without either party ever seeing the other’s raw, identifiable data.

The computation happens on encrypted or locally held data. Only the final result, an aggregated insight, a risk score, a trained model, crosses the border. The personal data itself stays exactly where it started.

This matters because most data protection laws, GDPR included, are built around the concept of a transfer: data leaving the control of one party and landing with another. When the raw data never leaves and no outside party can reconstruct it from what does move, you have fundamentally changed the compliance question.

You are no longer asking whether your Standard Contractual Clauses will survive the next legal challenge. You are asking a much simpler question: did any personal data leave the country at all?

Regulators are already catching up to this distinction. Singapore’s Infocomm Media Development Authority ran a sandbox program specifically to test privacy enhancing technologies in cross-border data collaboration and found clear benefits for compliance across multiple jurisdictions at once.

The European Data Protection Board has likewise recognized PETs as a legitimate way to strengthen, and in some cases replace the need for, traditional transfer safeguards.

What privacy enhancing technologies enable compliant cross-border data collaboration?

A handful of these technologies do the heavy lifting, and each solves a slightly different version of the same problem.

Fully homomorphic encryption

Think of it as a locked box that you can still do math inside of without ever opening it. Fully homomorphic encryption allows computations to run directly on encrypted data, producing an encrypted result that only the data owner can unlock. Nobody performing the calculation, not even the organization running the analysis, ever sees the actual numbers, names, or records.

Federated learning

Instead of pooling raw data from multiple locations into one place to train an AI model, federated learning sends the model to the data. Each location trains a local copy on its own data, and only the resulting model updates, not the underlying records, get combined into a shared, improved model.

Confidential computing

Confidential computing protects data while it is actively being used, not just while it is stored or in transit. It relies on secure, isolated hardware environments that even the cloud provider running the server cannot peer into, closing one of the more overlooked gaps in cross-border data security.

Secure multiparty computation

Secure multiparty computation lets several organizations jointly calculate a result, such as a shared risk score across banks trying to spot the same fraud ring, without any of them revealing their individual input data to the others.

None of these require organizations to trust each other’s security posture blindly, which is the quiet risk baked into a lot of traditional cross-border data sharing agreements. The math itself enforces the privacy guarantee.

How do data localization laws affect AI training across multiple countries?

This is where cross-border data transfer and AI collide, and it is a problem most compliance content has not caught up to yet.

Training a capable AI model usually benefits from as much diverse data as possible. But data localization laws in China, Russia, Vietnam, and a growing list of other countries require certain categories of data, particularly anything tied to health, finance, or government, to stay within national borders.

A global company trying to build one AI model that reflects patient outcomes across five countries runs straight into this wall. It cannot legally centralize the training data the way traditional machine learning pipelines expect.

Layer the EU AI Act on top of this, and the picture gets more complicated. High-risk AI systems now carry their own documentation and data governance obligations, on top of whatever GDPR already requires for any personal data involved in training.

Federated learning is the most direct answer to this specific problem. A pharmaceutical company can train a single model on patient response data held separately in a US hospital, a German research center, and a Japanese lab, with each location’s data never leaving its own servers.

The model travels between locations, not the patients’ records. This lets multinational organizations build genuinely global AI systems while still satisfying each country’s data localization requirements individually, rather than trying to negotiate an exception to all of them at once.

What does a cross-border data collaboration deployment look like in regulated industries?

Theory is easier to grasp with a real example.

In one recent case, NHS England, the US National Cancer Institute, and the UK’s Department for Science, Innovation and Technology needed to collaborate on international cancer research, comparing patient outcomes and treatment data across two countries with different privacy regimes.

There was no appetite for centralizing sensitive medical records in one place.

Using privacy enhancing technology, researchers were able to run the joint analysis they needed while each country’s patient data stayed within its own legal jurisdiction throughout.

A similar pattern shows up in financial services.

Banks across different countries frequently need to compare notes on suspected money laundering or fraud rings that operate across borders, but banking secrecy laws and data protection rules in each country typically prevent them from simply pooling customer records.

Secure computation lets them match against a shared risk signal, flagging the accounts and transactions worth a closer look, without any bank exposing its full customer data set to a foreign counterpart.

In practice, a deployment like this tends to follow the same rough sequence regardless of industry:

  • Map exactly what personal data exists, where it lives, and which jurisdiction’s rules apply to it.
  • Identify what insight the collaboration actually needs to produce, rather than what raw data everyone assumes they need to share.
  • Choose the privacy enhancing technology that matches the use case: federated learning for shared model training, secure multiparty computation for joint risk scoring, homomorphic encryption for outsourced analysis on sensitive records.
  • Run a pilot with one partner and one narrow question before scaling to a full multi-country rollout.
  • Layer in traditional legal mechanisms, such as a data processing agreement, for whatever limited metadata or results do need to cross borders.
Federated learning platform

How Duality helps organizations collaborate across borders

Duality Technologies was founded by cryptographers and data scientists who have spent their careers on exactly this problem: how to let organizations get value from data they cannot legally or practically centralize.

Our platform applies fully homomorphic encryption, federated learning, and confidential computing so that healthcare providers, banks, insurers, and government agencies can collaborate on sensitive data across borders without that data ever leaving its country of origin in a usable form.

We have worked with organizations including the US NCI (national cancer institute), UK NHS (National health service), Dana Farber,  Mastercard and others, on exactly this kind of cross-border collaboration, in sectors where a single data breach or compliance failure carries real consequences for real people.

If your organization needs to collaborate across jurisdictions without gambling on which legal mechanism survives the next court challenge, we would be glad to walk you through how this works for your specific data.

Cross-Border Data Transfer, Without the Risk

Enable secure collaboration across jurisdictions using privacy-preserving computation instead of moving sensitive personal data through traditional transfer mechanisms.

Frequently Asked Questions

What is the difference between data residency and data localization?

Data residency refers to where an organization chooses to store its data, often for performance or contractual reasons, without a specific legal requirement forcing that choice. Data localization is a legal mandate: a law that requires certain data to be stored or processed within a country’s borders, regardless of what the organization would otherwise prefer. Every localization requirement creates a residency outcome, but not every residency choice is driven by localization law.

Sign up for more knowledge and insights from our experts