Cross-border transfers: consent is not your only (or best) tool
SCCs, adequacy, and localization sit beside consent. Mixing them up is how global products fail DPIAs.

GDPR Chapter V, PIPL, DPDP, and many APAC laws restrict exporting personal data. Consent can sometimes legitimize a transfer, but it is brittle: it must be informed about the destination and risks, and it can be withdrawn.
Standard contractual clauses, adequacy decisions, and certification mechanisms are usually more durable for core infrastructure.
Still connect it to the CMP
Even when SCCs carry the transfer, the user may still need to consent to the purpose that causes the transfer (for example, a US ad network). Show that honestly. Block the vendor when consent is absent.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


