Do US Controllers Need to Use SCCs When Receiving Eurpoean Data?
Companies are allowed to transfer personal data outside the EEA if they are transferring data to an entity within a country recognized by the European Commission or they have put in place a safeguard imposing many of the substantive provisions found within the GDPR.
United States European Commission European Economic Area European Commission Approved Contractual Clauses Privacy Directive
Source: natlawreview.com