It is part of our daily lives that our data is exchanged and processed worldwide. Less attention is paid to the legal requirements with which companies falling within the scope of the GDPR are confronted in order to make data transfers to so-called third countries outside the EU legally compliant. These requirements are becoming stricter, particularly as a result of rulings by the ECJ. However, many companies rely on data transfers to third countries, especially to the US. This topic is also becoming more important against the background of the Brexit. It is therefore necessary for companies to be aware of the legal requirements and to comply with them accordingly. This thesis therefore shows possibilities to make data transfers to third countries legally compliant. At the same time, this work criticizes the increasingly strict requirements, which are hardly realizable for companies and shows ways for practical solutions, e.g. with regard to the important topic of cloud computing.