Cross-Border Data Transfers: What Your Website Quietly Sends Abroad
Every hosted font, analytics tag and pixel can ship a visitor's data to another country. A tour of KVKK Art. 9, GDPR Chapter V, and why the destination matters as much as the consent.
When a visitor opens your site, their IP address — and often much more — can be sent to servers in the US, Russia, or elsewhere before they have done anything. Consent is only half the story. Even with perfect consent, sending personal data across a border engages a separate regime: KVKK Art. 9 in Türkiye and Chapter V of the GDPR in the EU. The destination matters as much as the permission.
Why transfers are regulated separately
The logic is simple: data that leaves the country may land somewhere with weaker protection, beyond the reach of your regulator. So the law asks for a mechanism before the data travels — not just a legal basis for processing, but a specific basis for the transfer.
- Adequacy — the destination country is recognised as offering equivalent protection.
- Standard contractual clauses (or KVKK's binding undertakings) — a contract that carries the obligations across the border.
- Explicit consent — the visitor is told about the transfer and its risks and agrees to it specifically.
Where your website actually sends data
The usual suspects on a normal marketing site:
- Google Analytics / Ads → United States.
- Meta (Facebook) Pixel → United States.
- Yandex Metrica / Webvisor → Russia (no EU adequacy decision).
- Google Fonts, hosted CDNs → wherever the CDN edge resolves — and the visitor's IP goes with the request. A German court found that transmitting an IP to Google via hosted fonts, without consent, was an unlawful transfer.
The double failure
Most cross-border problems are also pre-consent problems: the font, the pixel, the analytics tag all fire on page load. That means the same request can breach the consent rule and the transfer rule simultaneously. Fixing the consent gate often fixes both — but not always. Fonts are essential to rendering, so the answer there is not a banner but to self-host and stop the transfer entirely.
What to do now
Map what your site sends and where. Self-host fonts and assets so essential requests never leave your domain. Gate everything non-essential behind consent, and for the transfers that remain, document the mechanism. If you cannot justify a transfer to a country without adequacy, prefer a tool that keeps the data local.
General information, not legal advice for any specific jurisdiction. A PrivaScan report shows which regions your site transmitted to at scan time and the articles that engages — it does not certify a transfer as lawful.