Search

How can we help?

Privacy and Data Protection

International transfers

 

Political and legal developments mean that the rules underpinning international transfers of personal data are constantly evolving. Our data protection team ensure that our clients are able to carry out global data transfers and data sharing arrangements in full compliance with current laws and regulatory guidance.

What is an international transfer?

There is no legal definition for this. However, the UK General Data Protection Regulation (UK GDPR) and other UK data protection laws  specify mandatory requirements for any “restricted transfer” to be carried out legally.

Restricted transfers are those where:

  • The UK GDPR applies to the processing of personal data to be transferred.
  • The personal data is being sent to (or will be accessible to) a party to whom the UK GDPR does not apply.
  • The receiving party is a separate organisation or individual legally distinct from the transferor.

How can personal data be transferred internationally?

If the transfer is a restricted transfer, the data can still be transferred but organisations have to consider the relevant requirements under the UK GDPR.

Where the recipient is in a country in receipt of an ‘adequacy decision’ (for example, one in the EEA), meaning it’s been judged to have an adequate level of protection, transfer is relatively straightforward.

Failing this, organisations can still transfer personal data, provided the recipient has adequate safeguards in place (as set out in the UK GDPR) and on condition that any individual to whom the personal data relates has enforceable rights and effective legal remedies available to them.

If there’s no adequacy decision or adequate safeguards then a transfer can only be made in very limited further circumstances set out in the UK GDPR.

What are adequate safeguards?

There’s a list of adequate safeguards in the UK GDPR but common ones relied upon include binding corporate rules (i.e. agreements governing transfers between companies in a group) and standard data protection clauses.

There are generally now two types of approved standard clauses, these being:

  • For transfers of data from both the UK and EEA – standard clauses approved by the EU with a UK Information Commissioner’s Office (ICO) addendum attached.
  • For transfers of data from the UK only – the ICO’s International Data Transfer Agreement (IDTA).

In addition, the ICO advises organisations that are making restricted transfers from the UK, to conduct a Transfer Risk Assessment before they enter into an IDTA and establish any necessary measures to ensure data is adequately protected.

Why You Need a Solicitor

The rules on international data transfers are complex and constantly changing.  Our team of experts can help you:

  • Identify if there is a restricted transfer
  • Consider whether the transfer of personal data is permitted under the UK GDPR
  • Draft and advise on contractual documentation including IDTAs
  • Assist you in conducting the required Transfer Risk Assessment

Contact Our Expert Data Protection Solicitors

If you need any assistance with international transfers, please contact our data protection team who will be happy to help.

“Very professional, knowledgeable and accessible lawyers.” 

Chambers and Partners

FAQs – International transfers

This refers to the act of sending or transmitting personal data from one country to another. It also covers when an organisation makes personal data available to another entity located in another country, i.e. such data being accessible from overseas.

The UK GDPR contains rules on the transfer of personal data to outside the UK, where these rules apply to all transfers, no matter the size of the transfer or how often you carry them out.

Yes, you can provided you have the correct arrangements in place. Transfers from the UK to the EEA do not require any new arrangements, however transfers (known as ‘restricted transfers’) to ‘third countries’, will require additional safeguards.

This will depend on a case-by-case basis, however before making a restricted transfer, you should consider if the personal data needs to be sent, and whether any personal data could be anonymised so that it is not possible to identify individuals.

Broadly, the following questions should be considered under the UK GDPR before a restricted transfer is made:

  • Is the restricted transfer covered by ‘adequacy regulations’?
  • Is the restricted transfer covered by appropriate safeguards?
  • Is the restricted transfer covered by an exception?

Key contacts

Louise Keenan

Associate

View profile

+44 118 960 4614

Read, listen and watch our latest insights

Pub
  • 10 February 2025
  • Privacy and Data Protection

Frequently asked questions on data retention

In this podcast, Jesse Akiwumi and Harry Berryman, members of the Data Protection team at Clarkslegal, address the top frequently asked questions we receive about data retention.

art
  • 06 February 2025
  • Privacy and Data Protection

Cookies and Consent: the ICO’s Cookie Review

In the digital age, cookies play a crucial role in how websites operate and interact with users.

art
  • 24 January 2025
  • Privacy and Data Protection

UK Data Protection: A look back at 2024 and what to expect in 2025

On 15 January 2025, Louise Keenan and Shauna Jones hosted our webinar “UK Data Protection: what happened in 2024 and what’s in store for 2025.” Our webinar is available for you to watch, but in this article, we will provide a brief summary of what was discussed.

art
  • 20 January 2025
  • Employment

AI Opportunities Action Plan – The impact of AI on employment

The Government has announced its ‘AI Opportunities Action Plan’ in which it plans to increase the use of AI across the UK to ensure the UK is a world leader in the field. 

art
  • 16 January 2025
  • Corporate and M&A

Business Asset Disposal Relief: Changes to CGT Relief and the Consequences for Business Owners

Developing a robust cybersecurity strategy is essential to ensuring value retention, securing sensitive data, minimising risks and a seamless transfer during and after the merger or acquisition.

Pub
  • 10 January 2025
  • Privacy and Data Protection

UK Data Protection: What happened in 2024 and what’s in store in 2025?

It’s been a year of political change and uncertainty for data protection. Join our data protection webinar, where we will discuss the implications of the Data Protection and Digital Information Bill not passing and the upcoming Digital Information and Smart Data Bill from the King’s Speech, which will affect existing laws.