Companies are allowed to transfer personal data outside the EEA if they are transferring data to an entity within a country recognized by the European Commission or they have put in place a safeguard imposing many of the substantive provisions found within the GDPR.