Cross-border transfer is passing personal data into a foreign state's territory: to a foreign company, server or authority. Since March 2023 a notification regime applies: before the transfer starts, the operator files a dedicated notification with Roskomnadzor — distinct from the base processing notification. For countries with adequate data protection the transfer may proceed once filed; for the rest, RKN may prohibit it after review. On a website, cross-border transfer usually comes not from "database exports" but from everyday things: foreign analytics, CRMs and forms.
Free online tool — compliance checker: instant results, no signup.
The criterion is where the data actually lands, not where the contract is registered. Loading a script from a foreign CDN is not yet a transfer by itself; sending visitor data there is.
The dedicated cross-border notification is filed before the transfer begins. Countries then split in two: those ensuring adequate protection of subjects' rights (Convention 108 parties plus the RKN-approved list) — transfer is allowed once the notification is filed; other countries — Roskomnadzor reviews the filing and may prohibit or restrict the transfer. The practical takeaway: the recipient-country list is not a reference line in the policy but a parameter the scheme's very legality depends on.
Most operators do not know their full list of foreign recipients — it accretes from counters, widgets and integrations. The compliance scanner builds that list automatically: every third-party service on the pages is identified against a catalogue with vendor and jurisdiction, foreign ones flagged separately — including those loading before consent. With that list, the notification is filled from facts, not from memory.
Regulators fine sites for processing personal data without consent — and a site starts processing earlier than it seems: analytics, pixels and widgets write cookies the moment the page loads. The scanner shows the auditor's view: what leaves for third parties before consent, whether the banner works, and whether forms collect data correctly.
Three sessions per page: no action, banner accepted, banner rejected.
Service catalogue: who receives visitor data and in which country.
The policy link and consent element are checked next to the form, not in the footer.
Report with an HMAC integrity stamp — hand it to your lawyer or contractor.
preparing for an audit
technical facts for an opinion
client site handover
consent regression monitoring
Scheduled re-checks with an alert when pre-consent trackers appear on your site.
Sign up freeNo, they are independent requirements: consent legalises the processing, the notification covers the transfer abroad itself. Both are needed.
Yes, when the recipient is abroad: corporate affiliation does not cancel the data crossing the border.
If no foreign recipients remain — no. But verify the actual picture: a forgotten pixel or a backup on a foreign server brings the duty back.
Free plan — 10 monitors, checks every 5 min, no card required. Upgrade for 1-minute interval and multi-region monitoring.