Illustration showing a data processing contract connected to cross-border data governance controls, including monitoring, evidence, subprocessors visibility, approvals, and accountability.

Contracts Alone May Not Be Enough for Cross-Border Data Governance

When organizations rely on external technology providers, one of the first questions Legal may ask is whether the right contractual safeguards are in place.

That question matters. But it may not be the last one.

This was another reflection from the “Certification as a Trusted Mechanism for Cross-border Data Transfers” session at IAPP Asia Forum 2026 in Singapore.

The session compared different GDPR mechanisms for international data transfers, including Standard Contractual Clauses, Binding Corporate Rules, Codes of Conduct and certification.

What stood out to me was a broader governance distinction:

A contract can establish obligations. It does not, by itself, demonstrate that those obligations are being carried out effectively.

For organizations using AI, cloud services or other external technology providers, this distinction matters.

A contract may define what a provider is required to do. But governance and compliance also need to ask what happens operationally:

Are the agreed controls actually implemented, and can the organization obtain evidence of that?

Are responsibilities clear across providers and subprocessors?

If the technology, processing arrangement or data flow changes, who is expected to detect it and respond?

Under the GDPR, contractual clauses remain an established mechanism for providing appropriate safeguards for certain international transfers. Certification can also play a role under the regulatory framework.

The point is therefore not that contracts are unimportant, or that one mechanism is inherently superior to another.

It is that documented obligations and effective controls are not the same thing.

For cross-border AI and data governance, organizations may need both:

legal mechanisms that define responsibilities and governance processes that provide confidence those responsibilities are actually being performed.

Because good governance does not end when the contract is signed.