Is data entered on our site by an EU visitor a transfer?

Why a person in the EU submitting data directly to your site usually is not a restricted transfer, and where GDPR's transfer rules actually apply.

The short answer

Usually no. When a person in the EU types their own information into your website (a checkout form, an account signup, a contact form), that is direct collection, not a “restricted transfer” under GDPR’s international transfer rules. This is one of the most common misconceptions in GDPR scoping, and it drives a lot of unnecessary transfer projects.

The catch: GDPR itself may still apply to that data. “No transfer” does not mean “no GDPR.” These are two separate questions, and this guide walks through both.

What counts as a restricted transfer

GDPR Chapter V (Articles 44 to 49) restricts sending personal data out of the EU. The European Data Protection Board (EDPB), the body that coordinates EU data protection regulators, defined what qualifies in its Guidelines 05/2021. A restricted transfer needs all three of these:

  1. A controller or processor (the exporter) is subject to GDPR for that processing.
  2. That exporter discloses or makes the data available to a different controller or processor (the importer).
  3. The importer is in a third country (outside the EU/EEA) or is an international organisation.

The key word in the second criterion is different organization. A transfer is one organization handing data to another across the EU border.

Why direct collection fails the test

A data subject (the person the data is about) is not a controller or processor, so they cannot be an exporter. When someone in the EU fills in your form, no EU organization is sending you anything. Criterion 2 fails, so there is no restricted transfer, and Chapter V does not apply to that collection.

The EDPB’s own example in Guidelines 05/2021 is essentially this fact pattern: an EU resident submits their name and address on a non-EU retailer’s website. The Board’s conclusion is that this is collection, not a transfer.

What still applies

GDPR can apply to your processing even with no transfer in sight. Under Article 3(2), GDPR reaches non-EU companies that offer goods or services to people in the EU, or monitor their behavior there. If that describes your site, you need to run the day-to-day GDPR program: privacy notices, a lawful basis for processing, individual rights handling, security, breach response, and contracts with your processors.

What you do not need, for the direct collection itself, is a transfer tool. Joining the EU-US Data Privacy Framework (DPF) or signing standard contractual clauses (SCCs) does nothing for that hop, because there is no restricted transfer happening on it.

Where transfer rules do show up

Most organizations that collect EU data directly still have restricted transfers somewhere else in the picture:

FlowRestricted transfer?What usually fixes it
EU customer submits data on your siteNoNothing needed for this hop; run your GDPR program
You hand data to processors and vendors outside the EU/EEA, including in your own countryOften yes, with you as exporterVendor SCCs, or the vendor’s DPF listing
An EU company (customer, affiliate, vendor) sends personal data to youYesYour DPF listing, or SCCs signed with the sender

The second row surprises people: the transfer rules can catch a hop that never crosses a border. Say a US company subject to GDPR collects EU customer data directly, then hands it to a US email or analytics vendor. The vendor is a different organization located in a third country, and that is all the definition requires. The EDPB spelled this out in the same guidelines: disclosures by a non-EU organization subject to GDPR to a controller or processor “in the same or another third country” must comply with the transfer rules.

If either of the last two rows describes you, see Choosing a GDPR transfer tool for how to pick between the options.

Map your flows before you buy a fix

The transfer rules apply hop by hop, so scope them hop by hop:

  1. List where personal data from people in the EU, UK, or Switzerland enters your organization, and from whom.
  2. For each flow, ask: is an organization on the EU side sending this, or is the person giving it to us directly?
  3. List where that data goes next: processors, vendors, affiliates, and their countries.
  4. A hop needs a transfer tool when it runs between two organizations, the sender is subject to GDPR for that processing, and the receiver is outside the EU/EEA (even in the sender’s own country).

Note that the UK and Switzerland run parallel regimes (UK GDPR and the Swiss FADP) with the same basic transfer logic, so map those flows too.

Published August 12, 2026.