A transfer of data outside the European Union occurs whenever personal data is made accessible to an entity in a third country – which happens with most commonly used tools, often without the company being aware of it. A transfer is possible, but it requires a legal mechanism. The simplest situation arises with countries for which the European Commission has decided they provide an adequate level of protection. In other cases, standard contractual clauses are used, supplemented by a risk assessment for the destination country and additional measures. In practice, this means finding out where the individual tools store and process data, verifying which mechanism the supplier uses, and stating the information about the transfer in the privacy policy. Leave the legal assessment of specific tools to a lawyer.
See also: Data processing agreement, Privacy policy, Internal AI usage policy.