# International transfers of personal data under UK GDPR

> **Key takeaway:** Restricted transfer (data leaving the UK to a receiver outside UK GDPR's reach) needs: UK adequacy decision, OR an appropriate safeguard (IDTA / UK Addendum to EU SCCs) plus a transfer risk assessment, OR a narrow Art 49 derogation for genuinely one-off transfers.

- **Jurisdiction:** England & Wales
- **Practice area:** Commercial
- **Last reviewed:** 2026-09-05
- **Interactive page:** https://www.kttclegal.info/library/notes/Commercial/international-transfers-uk-gdpr
- **Keywords:** international transfers, restricted transfer, adequacy, IDTA, standard contractual clauses, SCCs, transfer risk assessment, Chapter V, UK GDPR

## What is this about?

Transferring personal data outside the UK is restricted unless the destination country, or the transfer mechanism used, provides an adequate level of protection. The framework runs through UK adequacy regulations, standard contractual safeguards, and a narrow set of derogations for one-off or non-repetitive transfers.

## What is the core rule?

Chapter V UK GDPR restricts 'restricted transfers' — transfers of personal data to a receiver outside the UK where UK GDPR would otherwise not apply to that receiver's processing. A restricted transfer may proceed if: (a) the destination is covered by UK adequacy regulations (the Secretary of State has determined it provides adequate protection); (b) appropriate safeguards are in place, most commonly the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; or (c) a specific Article 49 derogation applies (e.g. explicit consent, necessity for contract performance, or one-off transfers not repetitive and involving a limited number of data subjects). Safeguard-based transfers generally require a transfer risk assessment (TRA) considering the law and practice of the destination country.

## What are the elements or test?

1. Is this a 'restricted transfer' — data going to a receiver outside the UK to whom UK GDPR does not directly apply?
2. Is the destination covered by current UK adequacy regulations?
3. If not adequate: is an appropriate safeguard in place (IDTA, UK Addendum to EU SCCs, or Binding Corporate Rules)?
4. Has a transfer risk assessment been carried out and documented where a safeguard mechanism is relied on?
5. If no adequacy decision and no safeguard: does a narrow Art 49 derogation apply (and is it being used only for genuinely occasional, non-repetitive transfers)?

## Which authorities matter?

- **UK GDPR, Chapter V (Arts 44-49)** — The general framework restricting transfers outside the UK and setting out adequacy, safeguards, and derogations as the three routes to lawful transfer.
- **Data Protection Act 2018, s.17A and UK adequacy regulations** — The domestic mechanism by which the Secretary of State designates adequate third countries, replacing reliance on retained EU Commission adequacy decisions over time.
- **ICO International Data Transfer Agreement (IDTA) and UK Addendum to the EU SCCs** — The ICO's approved safeguard documents for contractual transfers where no adequacy decision applies; effective from 21 March 2022.
- **UK GDPR, Art 49** — Lists narrow derogations (explicit consent, contract necessity, important public interest, one-off transfers) available only where adequacy and safeguards are unavailable or impractical.

## How does this apply in practice?

This note addresses the transfer-mechanism framework, not the detailed content of a transfer risk assessment or the specific clauses of the IDTA/UK Addendum. Group intra-company transfers, cloud hosting arrangements, and use of overseas sub-processors are the most common practical triggers for this analysis. Derogations under Art 49 are meant to be exceptional and are not a substitute for putting a proper safeguard in place for repeated or structural transfers.

## What are common pitfalls?

- Assuming a US-based supplier is automatically covered by an adequacy mechanism without checking current UK adequacy regulations
- Relying on Art 49 consent or contract-necessity derogations for routine, repeated transfers rather than genuinely one-off situations
- Failing to carry out or document a transfer risk assessment when relying on the IDTA or UK Addendum
- Overlooking onward transfers by a processor to its own sub-processors in a different country
- Treating an EU adequacy decision or EU SCCs as automatically valid for UK transfers without checking the UK-specific equivalent

## When would a practitioner use this?

Relevant whenever personal data is shared with an overseas group company, supplier, or cloud provider, and in due diligence on cross-border data flows in commercial contracts and outsourcing arrangements.

## Quick reference

Restricted transfer (data leaving the UK to a receiver outside UK GDPR's reach) needs: UK adequacy decision, OR an appropriate safeguard (IDTA / UK Addendum to EU SCCs) plus a transfer risk assessment, OR a narrow Art 49 derogation for genuinely one-off transfers.

---

*Reference material from [KTTC Legal](https://www.kttclegal.info/), not legal advice. Work product supports instructing solicitors and barristers under their supervision. England & Wales.*
