Knowledge Hub
for Growth


Transferring personal data out of the UK to the EU: the IDTA and UK addendum explained 

International data transfers can often sit quietly inside everyday business arrangements. Your cloud provider may be established overseas, an external international support team may access UK systems remotely, or personal data may move between separate companies in your group. Each arrangement needs to be checked carefully because the UK’s data transfer rules may apply even when personal information is made accessible to separate organisations outside the UK, but never physically leaves a UK server.

This article provides a high-level introduction to how to identify a restricted transfer, when the UK’s International Data Transfer Agreement (IDTA) or International Data Transfer Addendum (UK Addendum) may be needed, and where a transfer risk assessment fits into the wider compliance process.

Our data protection solicitors can provide advice tailored to your organisation, its data flows and the wider commercial contracts supporting them. 

What is a restricted transfer?

UK data protection laws contain strict rules around the transfer of personal data outside of the UK. This year the UK ICO updated its guidance on international data transfers, which businesses should review.

Firstly, it’s important to establish whether your organisation is making a ‘restricted transfer’, as the UK General Data Protection Regulation (UK GDPR) places specific requirements on these arrangements.

Once an organisation identifies a restricted transfer, it needs to identify a suitable data transfer mechanism.

The ICO uses a three-step test. Broadly, a restricted transfer arises where:

  • the UK GDPR applies to your processing of the personal information
  • your organisation initiates the transfer of personal information, either by sending the information or making it accessible to an organisation located outside the UK
  • the organisation receiving the information is a separate legal entity from yours

This can include allowing an overseas supplier or a separate overseas group company to access information remotely, even where the information remains on systems hosted in the UK.

A restricted transfer must be covered by limited, permitted transfer mechanisms:

  • UK adequacy regulations
  • appropriate safeguards
  • an applicable exception (known as a ‘derogation’ under law) which can cover explicit consent

As a practical first step, check if adequacy applies.

The UK’s adequacy regulations, put simply, set out which countries, territories or specified sectors within a country, or international organisations the UK government has assessed as having a level of protection that’s ‘not materially lower’ than UK law.

This is essentially about making sure that the standard of protection for individuals is not worse after you transfer their personal data.

Where the transfer is covered by UK adequacy regulations and you rely on them, the information can flow freely without you needing to put in place appropriate safeguards (explained below) or rely on an exception.

Your other UK GDPR responsibilities still apply, however, including running appropriate checks on the recipient and how it will protect the information and following broader rules relating to lawful and fair processing, transparency, data minimisation, security and appropriate controller-processor arrangements where required.

Adequacy regulations can change or apply only to particular sectors, organisations or types of personal information. Don’t rely only on the country in which the recipient is based. Check that the precise scope of the regulation covers the proposed transfer first.

If no adequacy regulation, appropriate safeguard or exception applies, the restricted transfer must not proceed.

When do you need the IDTA or UK Addendum?

Safeguards are set out in Article 46 of the UK GDPR and are intended to ensure that the sender and receiver of personal data both required to protect such information.

The IDTA or UK Addendum are standard contractual clauses which many businesses use as Article 46 safeguard. These can become relevant where your organisation is making a restricted transfer, adequacy doesn’t cover it, and you have decided to use standard data protection clauses as your Article 46 safeguard.

They aren’t the only Article 46 safeguards. Depending on the arrangement, alternatives may include binding corporate rules or another safeguard permitted under the UK GDPR.

For many commercial relationships with overseas suppliers, service providers or group companies, however, the IDTA and UK Addendum are likely to be the most familiar, cost-effective and easy to use options.

All European Economic Area (EEA) countries currently have full UK adequacy.

This means that safeguards such as an IDTA and UK Addendum aren’t required for a restricted transfer to an EEA recipient where you rely on the adequacy regulations.

Where only partial adequacy applies, you must check that the recipient and transfer fall within the scope of the adequacy regulations. If not, you will need to consider appropriate safeguards or an applicable exception.

What are the UK’s international data transfer documents?

The IDTA and UK Addendum are standard data protection clauses issued by the ICO. They can be used as appropriate safeguards supporting a restricted transfer under Article 46 of the UK GDPR.

The IDTA is a standalone, UK-specific agreement.

The UK Addendum works alongside the European Commission’s Standard Contractual Clauses (EU SCCs), adapting them so they can also support transfers governed by UK data protection law.

What are the EU SCCs?

The EU SCCs are contractual clauses produced by the European Commission to safeguard certain transfers of personal data governed by the EU GDPR.

They have a modular structure covering four relationships:

  • controller to controller
  • controller to processor
  • processor to processor
  • processor to controller.

This allows the parties to select provisions reflecting their respective roles in the particular transfer. These EU SCCs can be used as a standalone agreement, or they can be built into a wider commercial contract.

The EU SCCs aren’t, on their own, a valid UK transfer tool. Where an organisation wants to use the EU SCC framework for a transfer governed by the UK GDPR, needs to use the UK Addendum with the EU SCCs.

What is the IDTA?

The IDTA is a standalone transfer agreement published by the ICO. Controllers, processors and sub-processors can use it to support restricted transfers where an Article 46 safeguard is required. It’s intended to be more of a flexible and user-friendly option for businesses.

Key points to note around the IDTA include:

  • it can be used alone, or you can link it to a wider agreement e.g. a master services agreement or a data processing agreement
  • it’s generally more flexible than the EU SCCs
  • it covers mandatory clauses which you generally can’t change or remove

Should you use the IDTA or the EU SCCs with the UK Addendum?

The IDTA and UK Addendum provide alternative contractual approaches for making a restricted transfer using standard data protection clauses.

Depending on the circumstances your business can use either:

  • the IDTA as a standalone document
  • the EU SCCs together with the UK Addendum (note that the EU SCCs alone aren’t valid for UK transfers)

The most suitable approach will depend on your organisation’s operations, existing data transfer arrangements and use of personal data in practice.

For instance:

  • If your business operates in both the UK and the EU, you may wish to use EU SCCs and the UK Addendum to help you comply with both EU and UK data protection laws - this is likely to be the most common use for this documentation
  • If you already use EU SCCs, it may be quicker and easier for you to implement the UK Addendum.
  • If your business only operates in the UK, the standalone IDTA may be the better option (where only the UK GDPR rules apply to your business).

The decision isn’t based only on which document is legally available. There’s a practical question too around where your business operates and handles personal data in practice. 

Specialist legal advice is recommended on this point - especially where your organisation has complex data flows, several overseas suppliers or operations across multiple jurisdictions.

Do I still need to carry out a transfer risk assessment?

Yes. If your organisation initiates a restricted transfer and relies on an Article 46 transfer tool, it must complete a transfer risk assessment. This exercise can be complex and should be reasonable, proportionate and documented.

The ICO continues to use the terms ‘transfer risk assessment’ and ‘TRA’. Following the Data (Use and Access) Act 2025, note that the legislation refers to the underlying requirement as the ‘data protection test’ so be aware of this terminology.

The key purpose of this assessment is to make sure that the standard of data protection for people’s information after the transfer isn’t materially lower than the UK’s own standard.

The assessment should be documented and carefully consider the particular circumstances of the transfer, including:

  • risks to the rights of individuals in the destination country in respect of third parties accessing their information (e.g. governments and public bodies)
  • risks to the rights of individuals in respect of enforcing the safeguard

The ICO highlights that there are various approaches to conducting this assessment (including the ICO’s own ‘TRA Tool’ and the European Data Protection Board’s approach, and businesses should take advice if they’re unsure which route to follow.

Where additional protections are identified, they need to be implemented before the transfer occurs.

If the assessment identifies an issue, you may need to put additional protections in place and repeat the assessment. If the required level of protection still can’t be achieved, the transfer can’t go ahead based on that Article 46 tool.

You don’t need to complete a TRA where you rely on UK adequacy regulations or an applicable exception. Your other UK GDPR duties still apply, and exceptions should be used carefully because their own legal conditions must be met.

The term ‘transfer impact assessment’ is commonly used for transfers governed by the EU GDPR. The ICO continues to use ‘transfer risk assessment’ in its UK guidance. If your organisation operates across both regimes, make clear which assessment and legal framework applies and comply with all relevant obligations, taking legal advice if needed.

Are the current IDTA and UK Addendum still valid?

Yes. Organisations should continue to use the existing versions of the IDTA and UK Addendum.

The ICO has also said that it plans to update both documents during 2026 following the changes made by the Data (Use and Access) Act 2025. Until revised versions are issued, the current documents remain the relevant ICO-approved standard clauses.

The IDTA and UK Addendum contain mechanisms through which the parties can choose for the agreement to update automatically when the ICO issues a revised approved version.

Because the position may change during 2026, check the latest ICO documents when entering into, renewing or materially changing an international transfer arrangement.

Key stages for compliant international data transfers

Organisations transferring personal information from the UK should generally:

  • map the contracts, systems and flows of personal information between the organisations involved, including what data you transfer and to whom
  • make sure you comply with all data protection principle e.g. ensuring that the personal data you’re proposing to transfer is relevant and limited to what’s necessary and that you’ve informed data subjects about the transfers as required
  • identify which organisation initiates each transfer and the capacity in which each party acts e.g. as a controller, processor or sub-processor
  • confirm whether each data flow is a restricted transfer
  • consider whether the transfer is necessary for the relevant purpose
  • check whether UK adequacy regulations cover the specific recipient, destination and transfer
  • if adequacy doesn’t apply or isn’t relied on, identify an appropriate Article 46 safeguard or consider whether an exception is available for the particular transfer
  • where standard data protection clauses are used, select the IDTA or the EU SCCs with the UK Addendum as appropriate
  • complete and document the transfer risk assessment to determine if the data protection test is satisfied, where required
  • ensure transfer agreements are entered into correctly and legally binding
  • put any additional contractual, technical or organisational protections identified by the assessment in place
  • carry out due diligence on data recipients, their use of sub-processors and any onward transfers carried out
  • review data transfer arrangements, such as when the parties, processing locations, data types, technology or applicable laws change
  • remember to also put other required data protection contracts in place - such as data processing terms required under Article 28 of UK GDPR

This shouldn’t be treated as a paperwork exercise. A transfer arrangement may look compliant initially but need to be revisited as the circumstances of the transfer and the level of protection afforded to the information change.

When should you review your transfer arrangements?

International transfer arrangements should be kept under regular review.

If an Article 46 transfer tool is used, then the level of protection which is afforded to the personal information should be re-evaluated at appropriate intervals and monitored on an ongoing basis.

Some examples of review triggers may include (but are not limited to):

  • you want to appoint a new overseas supplier who will handle personal data on your behalf
  • a recipient of personal data changes how or where it processes the information
  • a new sub-processor or destination country is introduced into your supply chain
  • technical developments affect the effectiveness of your security measures
  • the legal framework in the destination country changes
  • the ICO issues revised versions of the IDTA or UK Addendum
  • the types or volumes of personal information increase
  • the transfer begins to involve higher-risk or more sensitive information
  • legal rules impacting international data transfers change

Where an Article 46 safeguard covers repeated or ongoing transfers, the TRA and any additional steps or protections must be reassessed regularly. The ICO considers an annual review proportionate for most ongoing transfers unless the information is particularly high risk.

A review is particularly important where the transfer involves changes to the recipient’s processing, security developments, sensitive information, large volumes of personal data, onward transfers, data moving through several jurisdictions or a supplier that relies on overseas changing sub-processors or where there is a change to the legal framework within the destination country. Early advice can also prevent transfer requirements from delaying procurement, investment or a transaction.

Conducting transfer risk assessments and deciding whether to use the IDTA or UK Addendum can be complex.

This guide is a simplified introduction to a highly complex and high-risk area of the law. Our specialist data protection solicitors can help you with tailored advice to identify restricted transfers, assess the available mechanisms and put required safeguards in place under the UK GDPR.

About our expert

Lillian Tsang MBA

Lillian Tsang MBA

Senior Solicitor - Data Protection & Privacy
Lillian is an experienced data protection, privacy and AI lawyer, qualified since 2008 (England and Wales). She advises clients on a broad range of matters, from complex data protection issues to strategic compliance with a global perspective, as well as day-to-day operations.


What next?

Please leave us your details and we’ll contact you to discuss your situation and legal requirements. There’s no charge for your initial consultation, and no obligation to instruct us. We aim to respond to all messages received within 24 hours.


Our offices

A national law firm

A national law firm

Our commercial lawyers are based in or close to major cities across the UK, providing expert legal advice to clients both locally and nationally.

We mainly work remotely, so we can work with you wherever you are. But we can arrange face-to-face meeting at our offices or a location of your choosing.

Head Office

Floor 5, Cavendish House, 39-41 Waterloo Street, Birmingham, B2 5PP
Regional Spaces

Capital Tower Business Centre, 3rd Floor, Capital Tower, Greyfriars Road, Cardiff, CF10 3AG
Stirling House, Cambridge Innovation Park, Denny End Road, Waterbeach, Cambridge, CB25 9QE
13th Floor, Piccadilly Plaza, Manchester, M1 4BT
10 Lower Thames Street, London, EC3R 6AF
Belsyre Court, 57 Woodstock Road, Oxford, OX2 6HJ
1st Floor, Dearing House, 1 Young St, Sheffield, S1 4UP
White Building Studios, 1-4 Cumberland Place, Southampton, SO15 2NP
A national law firm

Like what you’re reading?

Get new articles delivered to your inbox

Join 8,153 entrepreneurs reading our latest news, guides and insights.

Subscribe


Speak to a lawyer

Speak to a lawyer