Christopher Farmer
CF
Christopher Farmer
Case studies
All case studies ← Back to portfolio
Case study 05 · Cross-border data transfer

Frontier — Cross-Border Data-Transfer & TIA Assessor

Is this cross-border transfer of personal data lawful — and can you prove it? Three regimes in one rules engine, a Schrems II-style impact assessment, and a record built for audit.

EU GDPR Chapter VSwiss FADPUK GDPRSchrems II TIAAdequacy · SCCs · derogationsOffline
Frontier workbench — transfer form with worked examples and dated legal-basis banner
Frontier — assessment workbench of the live build: describe a transfer, get the lawful basis, a Schrems II-style TIA and an exportable control record; the encoded legal position is dated and flagged for re-verification. Captured from the running application.

01The problem

Since Schrems II, an international transfer of personal data needs more than a signed mechanism — it needs a documented Transfer Impact Assessment of the destination and evidence of the supplementary safeguards applied. A Geneva-based organisation feels this three times over, because it typically straddles EU GDPR Chapter V, the Swiss FADP and the UK GDPR at once, and the three regimes diverge in detail: adequacy lists, the “Swiss finish”, the UK's IDTA and Data Bridge. Two failure modes dominate in practice. Teams treat the transfer question as settled once SCCs are signed, leaving no assessment to show a supervisory authority; and they miss that physical carriage is a transfer too — paper HR files, original passports, a laptop in hand luggage. The compliance failure is rarely ignorance of the law; it is the absence of a defensible record.

02What I built

Frontier takes a seven-input description of a transfer — exporter regime, destination, data categories and sensitivity, purpose, mechanism, context, and mode of movement, electronic or physical — and returns a reasoned determination.

  • Three regimes in one engine: it resolves adequacy (Art 45), Art 46 tools — SCCs 2021/914, BCRs, the UK IDTA — and Art 49 derogations, alongside the Swiss revFADP (Arts 16–18) with its Swiss-specific divergences and the UK-US Data Bridge interplay.
  • A Schrems II-style TIA scores government access, rule of law, redress and onward-transfer risk, uplifted for data sensitivity, and maps to a verdict: lawful, lawful with safeguards, or unlawful as configured — with the required technical, contractual and organisational measures listed.
  • It produces an audit-ready control record, exportable to self-contained HTML, JSON or print/PDF.
  • Pure HTML/CSS/JS with no framework and no network — it runs from file://, so no transfer details ever leave the machine that types them.

03Where the law stops and judgement starts

The engine is a lawyer's decision tree made executable, and its most important property is epistemic honesty about the boundary between law and judgement. Every line of a determination is tagged legal fact or reasoned assessment; country-risk ratings are explicitly the latter. The encoded adequacy lists and case-law positions are dated (July 2026) and carry a standing instruction to verify against the current Commission, FDPIC and ICO sources before reliance — because transfer law is a moving target. Where the law is genuinely unstable, Frontier says so: the EU/Swiss/UK-US Data Privacy Framework is treated as fragile, not safe, with the Latombe appeal and Trump v Slaughter flagged rather than smoothed over. And the scope line is drawn precisely: personal data only — not money, goods or property — but personal data in any form, including the paper and devices people carry across borders.

04What it proves for a privacy function

Transfer assessments are recurring, high-volume counsel work: vendor onboarding, intragroup agreements, SaaS support access, HR data moving between entities. Frontier shows I can take Chapter V from advice to operation — a control a privacy function can actually run, producing the record a supervisory authority will ask for — and that I hold the tri-regime fluency (EU, Swiss, UK) a Geneva employer needs daily. More broadly, it demonstrates the habit that matters most in regulated advisory work: separating what the law says from what I assess, dating both, and never letting a tool's confidence outrun its sources.

Status & dataLive in this portfolio; runs fully offline with no network calls — nothing typed into it leaves the page. Worked examples are synthetic. Encoded legal positions are dated July 2026, tagged legal-fact vs reasoned-assessment, and must be re-verified against current sources before reliance. Frontier is decision-support, not legal advice.