Knowledge Hub
for Growth


UK GDPR and cross border data transfers

Cross-border data transfers under UK GDPR are a common feature of modern business operations, whether you're working with offshore developers in Romania, IT support teams in India, or international payroll providers. But transferring personal data internationally introduces complex legal obligations, especially when the data flows across multiple jurisdictions. Understanding how to manage these transfers and remain compliant with the UK GDPR requires careful planning, contractual protections, and thorough risk assessment.

Our experienced data protection solicitors can help you navigate these challenges by identifying your legal responsibilities, drafting robust data processing agreements, and ensuring your international data transfers meet the necessary safeguards. Whether you’re outsourcing IT functions or handling sensitive data globally, we’ll help you stay compliant while supporting your commercial goals.

How should businesses identify what they need and who’s responsible for what?

Each business is different. Requirements vary based on your business model; what your business can afford; what expertise it requires; and whether the service provider of your choice can provide you the service with optimal security. Although, the ultimate deal breaker - is usually cost.

In order to understand what your responsibilities are, it’s important to recognise yourself as which one of the two roles you are, involving data processing.

The first role is of the data controller; this is the organisation that determines the reason for processing data, the second, if you are actually processing the data on behalf of the controller, then you are likely to be a data processor.  A service provider acting on instructions of the client controller, is likely to fall into the latter category.

As a controller, you are responsible for ensuring your processing, including that of the processing conducted on your behalf, complies with the General Data Protection Regulation (UK GDPR).

So, in essence, not only are you; the controller, accountable for your own compliance, but also the compliance of your processors.  It’s, therefore, necessary that you choose a processor that provides sufficient guarantees that they will implement appropriate technical and organisational measures to ensure their processing meets UK GDPR requirements.     

Organisations should understand that, regardless of where the service provider is located, the UK GDPR extends to third countries in the following scenarios:

  • processing personal data outside the EU or UK by controllers or processors established in the EU, regardless of whether the actual processing takes place in the EU or UK;
  • processing personal data of EU or UK data subjects by non-EU/UK controllers or processors, where the processing activities are related to the offering of goods or services or the monitoring of behaviour

Your Information Security function would be a key player in deciding whether the chosen service provider can provide you with what your business needs to keep data safe. It’s therefore necessary to explicitly state what your processors’ obligations are, in line with article 28 of the GDPR, which states the Controller must impose to its’ Processor a list of obligations, such as imposing technical and organisational procedures on the processor, as well as only following the instructions of the controller.

What are the necessary safeguards and when are they used?

Once caught by the UK GDPR, offshore providers must ensure compliance with rights and obligations created under the GDPR regime, the most important being:

  • The Data Processing Agreement - ensuring there is a contract between your organisation (controller) and the service provider (processor);
  • Cross-border transfers - Risk assessments must be conducted before any transfer of personal data cross-border to countries that are not deemed adequate. It’s not always the case that processors are based in the EEA or the UK; many service providers are based across the waters, such as in the US. It is necessary to ensure you have adequate safeguards in place to be able to transfer personal data to your processor cross-border. Data transfers to certain third countries which are considered adequate are permissible without any further safeguards. However, transfers to other third countries are permitted so long as one of the transfer mechanisms in Chapter 5 of the GDPR is met.  One of those is signing and complying with standard contractual clauses (SCCs), the UK has its own version referred to as the International Data Transfer Agreement (IDTA) as do other countries, inspired by the EU SCCs;  the version you agree would be dependent on where the personal data and of whom, is being transferred. The following are risk assessments that need to be considered: -
  • Data Protection Impact Assessments (DPIA) - where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, a controller must assess the impact of the envisaged processing operations on the protection of personal data.
  • Transfer Impact Assessment or Transfer Risk Assessment - This enables data exporters (controllers) to determine whether the mechanism they intend to use for an international data transfer provides an adequate level of protection in the circumstances of that transfer.
  • Security of processing – you must ensure that you implement appropriate technical and organisational measures to achieve a level of security commensurate with the risk.

Some examples of Processors

  • Payroll provider – to assist with aspects of payroll on behalf of a controller;
  • Market research companies- that collect and analyse, and share data under the instructions of a controller;
  • IT service providers;
  • Software as a Service (SaaS) providers;
  • IT consulting companies, and
  • More generally, it’s any organisation that provides a service which requires personal data to be processed on behalf of a controller.

Data processing agreements are carefully drafted documents, and it’s important to get them right. It can sometimes be the case, that a service provider is not a processor but either a joint or independent controller. Our specialist data protection solicitors can assist in assessing what role you or the service provider plays, as well as the actual risk against the nature and purpose of processing and provide specific advice on how to deal with any risk. We can then assist in drafting bespoke data processing agreements that fall out of the normal Article 28 GDPR (controller to processor) relationship.

How can we help you remain compliant?

Getting international data transfers right is critical, both for operational effectiveness and legal compliance. From assessing your role as controller or processor to choosing the proper transfer mechanisms and drafting tailored data processing agreements, our data protection solicitors offer strategic and practical advice to protect your business. We also support clients with complex structures by drafting compliant inter-affiliate agreements for global operations.

If you're transferring data across borders and want to ensure you're aligned with UK GDPR, we’re here to help you take the proper steps.

About our expert

Lillian Tsang MBA

Lillian Tsang MBA

Senior Data Protection and Privacy Solicitor
Lillian is an experienced data protection and privacy lawyer who qualified in 2008. She advises clients on a broad range of matters - from strategic compliance with a global stance to day-to-day operations. Her role also includes Harper James' Head of DPOaaS division (Data Protection Officer as a Service), where we act as the external DPO for a business or provide support to existing DPOs.


What next?

Please leave us your details and we’ll contact you to discuss your situation and legal requirements. There’s no charge for your initial consultation, and no-obligation to instruct us. We aim to respond to all messages received within 24 hours.

Your data will only be used by Harper James. We will never sell your data and promise to keep it secure. You can find further information in our Privacy Policy.


Our offices

A national law firm

A national law firm

Our commercial lawyers are based in or close to major cities across the UK, providing expert legal advice to clients both locally and nationally.

We mainly work remotely, so we can work with you wherever you are. But we can arrange face-to-face meeting at our offices or a location of your choosing.

Head Office

Floor 5, Cavendish House, 39-41 Waterloo Street, Birmingham, B2 5PP
Regional Spaces

Capital Tower Business Centre, 3rd Floor, Capital Tower, Greyfriars Road, Cardiff, CF10 3AG
Stirling House, Cambridge Innovation Park, Denny End Road, Waterbeach, Cambridge, CB25 9QE
13th Floor, Piccadilly Plaza, Manchester, M1 4BT
10 Fitzroy Square, London, W1T 5HP
Belsyre Court, 57 Woodstock Road, Oxford, OX2 6HJ
1st Floor, Dearing House, 1 Young St, Sheffield, S1 4UP
White Building Studios, 1-4 Cumberland Place, Southampton, SO15 2NP
A national law firm

Like what you’re reading?

Get new articles delivered to your inbox

Join 8,153 entrepreneurs reading our latest news, guides and insights.

Subscribe


To access legal support from just £149 per hour arrange your no-obligation initial consultation to discuss your business requirements.

Make an enquiry