Frontier — Cross-Border Data-Transfer & TIA Assessor
Is this cross-border transfer of personal data lawful — and can you prove it? Three regimes in one rules engine, a Schrems II-style impact assessment, and a record built for audit.
01The problem
Since Schrems II, an international transfer of personal data needs more than a signed mechanism — it needs a documented Transfer Impact Assessment of the destination and evidence of the supplementary safeguards applied. A Geneva-based organisation feels this three times over, because it typically straddles EU GDPR Chapter V, the Swiss FADP and the UK GDPR at once, and the three regimes diverge in detail: adequacy lists, the “Swiss finish”, the UK's IDTA and Data Bridge. Two failure modes dominate in practice. Teams treat the transfer question as settled once SCCs are signed, leaving no assessment to show a supervisory authority; and they miss that physical carriage is a transfer too — paper HR files, original passports, a laptop in hand luggage. The compliance failure is rarely ignorance of the law; it is the absence of a defensible record.
02What I built
Frontier takes a seven-input description of a transfer — exporter regime, destination, data categories and sensitivity, purpose, mechanism, context, and mode of movement, electronic or physical — and returns a reasoned determination.
- Three regimes in one engine: it resolves adequacy (Art 45), Art 46 tools — SCCs 2021/914, BCRs, the UK IDTA — and Art 49 derogations, alongside the Swiss revFADP (Arts 16–18) with its Swiss-specific divergences and the UK-US Data Bridge interplay.
- A Schrems II-style TIA scores government access, rule of law, redress and onward-transfer risk, uplifted for data sensitivity, and maps to a verdict: lawful, lawful with safeguards, or unlawful as configured — with the required technical, contractual and organisational measures listed.
- It produces an audit-ready control record, exportable to self-contained HTML, JSON or print/PDF.
- Pure HTML/CSS/JS with no framework and no network — it runs from file://, so no transfer details ever leave the machine that types them.
03Where the law stops and judgement starts
The engine is a lawyer's decision tree made executable, and its most important property is epistemic honesty about the boundary between law and judgement. Every line of a determination is tagged legal fact or reasoned assessment; country-risk ratings are explicitly the latter. The encoded adequacy lists and case-law positions are dated (July 2026) and carry a standing instruction to verify against the current Commission, FDPIC and ICO sources before reliance — because transfer law is a moving target. Where the law is genuinely unstable, Frontier says so: the EU/Swiss/UK-US Data Privacy Framework is treated as fragile, not safe, with the Latombe appeal and Trump v Slaughter flagged rather than smoothed over. And the scope line is drawn precisely: personal data only — not money, goods or property — but personal data in any form, including the paper and devices people carry across borders.
04What it proves for a privacy function
Transfer assessments are recurring, high-volume counsel work: vendor onboarding, intragroup agreements, SaaS support access, HR data moving between entities. Frontier shows I can take Chapter V from advice to operation — a control a privacy function can actually run, producing the record a supervisory authority will ask for — and that I hold the tri-regime fluency (EU, Swiss, UK) a Geneva employer needs daily. More broadly, it demonstrates the habit that matters most in regulated advisory work: separating what the law says from what I assess, dating both, and never letting a tool's confidence outrun its sources.
