figma guide
Designing cross-border data transfer and SCC management UI in Figma: TIA records, vendor flows, and transfer registers
Design cross-border data transfer admin UI in Figma with SCC libraries, transfer impact assessments, vendor flow maps, adequacy flags, and DPA linkage for global Privacy teams.
- Published
- Updated
- Aug 03, 2026
- Read time
- 9 min
- Level
- Intermediate
Quick answer
Cross-border data transfer UI tracks when personal data leaves its origin country—and documents the legal mechanism (SCCs, adequacy, BCRs) plus supplementary measures for each flow. Design a transfer register listing exporter, importer, data categories, mechanism, and TIA status; an SCC library with module type, signing dates, and amendment tracking; and vendor flow diagrams linked to ROPA activities and DPA records. Start from the Figma guides hub and pair with subprocessor management, trust center, DSAR portal, security posture dashboard, and Dev Mode handoff.
Who this is for
- Product designers building global compliance consoles for SaaS with EU customers and US infrastructure.
- Design system teams standardizing transfer badges, SCC status chips, and country flag components.
- Privacy and Legal teams managing post-Schrems II transfer impact assessments without email threads per vendor.
Transfer hub (internal admin overview)
TransferHub — Acme Global Privacy · 89 active transfers · 6 TIA overdue
├── Header: EU→US flows 52 · UK IDTA 8 · Adequacy (Japan) 3 · BCR intra-group 2
├── Actions: [ New transfer ] [ Import from ROPA ] [ SCC template library ] [ Bulk TIA reminder ]
├── Tabs: Transfer register · SCC agreements · TIA queue · Supplementary measures · Vendor map · Reports
├── Alert: Transfer TR-881 · Analytics vendor · SCC Module 3 unsigned · Blocks new data categories
├── Filters: Source region · Destination · Mechanism · Risk tier · Subprocessor
└── Link: [DPA hub](/designing-data-processing-agreements-and-subprocessor-management-ui-in-figma/) · ROPA · Trust center · Compliance exports
| Section | Purpose |
|---|---|
| Transfer register | Every cross-border flow with mechanism and status |
| SCC agreements | Executed clauses, modules, parties, amendment history |
| TIA queue | Transfer impact assessments due or blocked |
| Supplementary measures | Encryption, pseudonymization, access controls per flow |
| Vendor map | Visual exporter → importer → onward transfers |
| Reports | Regulator-ready export; changes since last quarter |
Verdict: Transfer UI connects legal paperwork to engineering reality—unsigned SCCs should block new subprocessor categories in the same console where Legal uploads signatures.
Transfer register record
TransferDetail — TR-442 · EU customer PII → US AWS us-east-1 · Status: Active
├── Route: EEA (controller) → United States (processor) · Onward: None
├── Data categories: Account profile · Usage logs · Support tickets · From [ROPA PA-118](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/)
├── Mechanism: SCC 2021 Module 2 (controller-to-processor) · Signed Jun 2024
├── TIA: TIA-2024-11 · Approved · Supplementary: TLS + AES-256 · Re-review Jun 2025
├── Subprocessor: Amazon Web Services · DPA + SCC Exhibit · [Open DPA record]
├── Volumes: ~2.1M users · Continuous transfer · Not occasional
├── Risk tier: Medium · Government access assessment documented
├── Change log: Added "session replay" category Jul 2026 · TIA addendum required
└── [ Request Legal review ] [ Flag for deprecation ] [ Export transfer summary ]
| Field | UI pattern |
|---|---|
| Route | Source/destination country with flag + adequacy badge if applicable |
| Mechanism | SCC module, UK IDTA, BCR, consent, derogation—controlled list |
| TIA status | Not started · In progress · Approved · Overdue · Blocked |
| Categories | Sync from ROPA; warn on category add without TIA update |
| Subprocessor | Deep link to DPA hub |
| Risk tier | Drives review cadence and approver role |
Occasional vs systematic transfer affects mechanism choice—capture frequency and scale explicitly.
Deprecated transfers need end date and confirmation that data was deleted or repatriated.
SCC library and signing workflow
SCCLibrary — Module 2 controller-to-processor · 24 executed · 3 draft
├── Template: EU Commission 2021 SCC · Module selector · Optional clauses checklist
├── Agreement SCC-2024-088 · Parties: Acme EU Ltd → AWS · Executed Jun 12, 2024
├── Annex I: Description of transfer · Linked TR-442 · Auto-fill from ROPA
├── Annex II: Technical measures · Link [security posture controls](/designing-security-posture-dashboard-and-compliance-checklist-ui-in-figma/)
├── Annex III: Sub-processor list · Sync subprocessors tab
├── Amendment track: 2021 SCC + UK Addendum Aug 2024 · DocuSign envelope ID
├── Unsigned: SCC-2026-014 · New analytics vendor · Blocks category "heatmaps"
└── [ Generate from template ] [ Send for signature ] [ Attach executed PDF ]
| SCC element | Design note |
|---|---|
| Module picker | Module 1 (C2C), 2 (C2P), 3 (P2P), 4 (P2C)—plain labels |
| Annex auto-fill | Pull categories and purposes from linked ROPA row |
| Signature state | Draft · Out for signature · Executed · Superseded |
| Version drift | Alert when EU publishes new SCC set—migration queue |
| Onward transfer | Module 3 chain visualization for sub-processor subprocessors |
Unsigned SCC should surface as blocking badge on vendor onboarding in app approvals and vendor risk queues.
Transfer impact assessment (TIA) workspace
TIAWorkspace — TIA-2026-03 · TR-442 addendum · Session replay category
├── Context: Schrems II supplementary measures · US CLOUD Act consideration
├── Data sensitivity: Identifiable usage events · Not special category
├── Importer practices: AWS compliance docs · Link trust center vendor section
├── Supplementary measures checklist:
│ ├── [x] Encryption in transit TLS 1.2+
│ ├── [x] Encryption at rest customer-managed keys
│ ├── [ ] Pseudonymization before transfer · Not implemented · Gap noted
│ └── [x] Access logging and anomaly alerts
├── Residual risk: Medium-Low · DPO sign-off required
├── Actions: [ Submit for DPO ] [ Request engineering measure ] [ Defer category launch ]
└── History: Original TIA Nov 2024 approved · This addendum for new category
| TIA section | Handoff detail |
|---|---|
| Context | Legal framework version, destination law summary |
| Measures | Checkbox + evidence link (architecture diagram, KMS policy) |
| Gaps | Explicit open items with owner and due date |
| Approval | DPO + Legal states; cannot mark transfer Active until Approved |
| Re-review | Calendar trigger; auto-task when vendor region changes |
TIAs are living documents—design addendum flows when product adds data categories without creating duplicate transfer rows.
Link engineering gaps to vulnerability findings only when measure relates to access control—not every TIA needs VM integration.
Vendor flow map
TransferMap — Global view · Q3 2026
├── Origin: EEA controller (Acme EU Ltd)
├── Processors: AWS US · Stripe US · Zendesk EU (no transfer) · Segment US
├── Onward: AWS → CloudFront logs US · Segment → 2 ad partners US (Module 3 chain)
├── Adequacy: Japan analytics partner · Adequacy decision badge · No SCC
├── Intra-group: BCR covers Acme US ↔ Acme EU · BCR policy link
├── Unresolved: New AI vendor India · Mechanism not selected · Red node
└── Export: PNG for [compliance audit evidence](/designing-compliance-audit-evidence-and-certification-renewal-ui-in-figma/)
| Map element | Design rule |
|---|---|
| Node color | Green active · Amber review due · Red blocked/unsigned |
| Edge label | Mechanism abbreviation + data category count |
| Onward transfers | Dashed edges; require Module 3 documentation |
| Click-through | Node opens DPA; edge opens transfer record |
| List fallback | Accessible table view of same graph data |
The map answers executive questions faster than scrolling the register—keep both views in sync from one API.
Adequacy, derogations, and edge cases
EdgeCasesPanel — Non-SCC mechanisms
├── Adequacy: Japan · UK extension countries · Show decision date + expiry watch
├── BCR: Intra-group policy BCR-2019 · Covers 12 entities · Annual compliance report
├── Derogation (Art. 49): Explicit consent · Occasional HR payroll one-off · Rare use banner
├── UK IDTA + Addendum: Post-Brexit UK transfers · Separate template track
├── US state laws: CPRA service provider · Not a "transfer" UI but flag for disclosure
└── Warning: Derogation overuse · Legal review gate for repeat derogation requests
| Mechanism | UI guardrail |
|---|---|
| Adequacy | Auto-suggest when destination on EU list; monitor commission updates |
| BCR | Entity picker; show coverage gaps |
| Consent (Art. 49(1)(a)) | Link cookie/consent UI; not for systematic transfers |
| Contract necessity | One-off transfer wizard with expiry |
| Derogation repeat | Block third use—force SCC or adequacy path |
Design jurisdiction-aware copy for trust center public pages—summarize transfer regions without leaking vendor contract details.
Handoff checklist (Dev Mode)
- Transfer — id, source_region, destination_country, status, risk_tier, ropa_activity_ids[].
- Mechanism — type (scc, adequacy, bcr, derogation), scc_module, agreement_id.
- TIA — id, status, approved_at, re_review_date, residual_risk, dpo_signoff.
- Categories — data_types[], special_category, volume_estimate.
- Measures — encryption_transit, encryption_rest, pseudonymization, access_controls[], evidence_urls[].
- Subprocessor — vendor_id, dpa_id, onward_transfer_ids[].
- SCC agreement — parties[], executed_date, annex_i_text, annex_ii_measures, signature_envelope_id.
- Accessibility — register supports screen reader row expansion; map has table alternate.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| SCC PDF stored without structured record | Cannot query unsigned or expiring | SCC library with status |
| Transfer not linked to ROPA | DSAR and deletion miss US copies | Bidirectional ROPA link |
| TIA one-time only | Schrems II requires ongoing review | Re-review calendar + change triggers |
| Module mismatch (C2P vs P2P) | Invalid legal mechanism | Module wizard with role questions |
| Onward transfers invisible | Article 28 chain broken | Map dashed edges + Module 3 docs |
| Engineering launches region before Legal | Unlawful transfer | Block vendor category until SCC Executed |
| Adequacy assumed from T&C | Wrong mechanism | Country picker with adequacy lookup |
| Same transfer row per SKU | Register bloat | One transfer per exporter-importer pair |
| Public trust center over-specific | Vendor contract leak | Summarized regions only |
| No change log on category add | Missed TIA addendum | Auto-open TIA when ROPA categories change |
Recommended workflow
- Design transfer register with mechanism, TIA status, and ROPA category sync.
- Build SCC library with annex auto-fill and signature workflow states.
- Create TIA workspace with supplementary measures checklist and DPO approval.
- Add vendor flow map with blocking states for unsigned agreements.
- Wire DPA hub so subprocessor changes flag affected transfers.
- Connect trust center public summaries for international data transfers section.
- Export quarterly transfer report for compliance audit evidence.
FAQ
Transfer register vs ROPA?
ROPA describes processing activities. Transfer register documents cross-border legal mechanisms for flows that leave a jurisdiction—many ROPA rows link to one or more transfer records.
When is a TIA required?
When relying on SCCs or similar mechanisms to EU/UK personal data—especially US destinations. UI should default to TIA required for non-adequacy SCC routes.
Link to DSAR portal?
Access requests must include data held in transfer destinations—fulfillment checklist pulls systems from transfer + ROPA linkage.
UK vs EU SCC?
Support UK IDTA + Addendum as separate template track post-Brexit—filter hub by regulatory framework.
Subprocessor onboarding gate?
New US subprocessor for EU data cannot go Active until SCC Executed + TIA Approved—show unified blocker in both hubs.
Next steps
- Design records of processing activities and data mapping UI in Figma — categories and flows source data
- Design data processing agreements and subprocessor management UI in Figma — SCC exhibits and vendor records
- Design trust center and security documentation UI in Figma — public international transfers section
- Design compliance audit evidence and certification renewal UI in Figma — regulator exports
- Design security posture dashboard and compliance checklist UI in Figma — supplementary technical measures evidence
§ Keep reading