Search

How can we help?

Privacy and Data Protection

International transfers

 

Political and legal developments mean that the rules underpinning international transfers of personal data are constantly evolving. Our data protection team ensure that our clients are able to carry out global data transfers and data sharing arrangements in full compliance with current laws and regulatory guidance.

What is an international transfer?

There is no legal definition for this. However, the UK General Data Protection Regulation (UK GDPR) and other UK data protection laws  specify mandatory requirements for any “restricted transfer” to be carried out legally.

Restricted transfers are those where:

  • The UK GDPR applies to the processing of personal data to be transferred.
  • The personal data is being sent to (or will be accessible to) a party to whom the UK GDPR does not apply.
  • The receiving party is a separate organisation or individual legally distinct from the transferor.

How can personal data be transferred internationally?

If the transfer is a restricted transfer, the data can still be transferred but organisations have to consider the relevant requirements under the UK GDPR.

Where the recipient is in a country in receipt of an ‘adequacy decision’ (for example, one in the EEA), meaning it’s been judged to have an adequate level of protection, transfer is relatively straightforward.

Failing this, organisations can still transfer personal data, provided the recipient has adequate safeguards in place (as set out in the UK GDPR) and on condition that any individual to whom the personal data relates has enforceable rights and effective legal remedies available to them.

If there’s no adequacy decision or adequate safeguards then a transfer can only be made in very limited further circumstances set out in the UK GDPR.

What are adequate safeguards?

There’s a list of adequate safeguards in the UK GDPR but common ones relied upon include binding corporate rules (i.e. agreements governing transfers between companies in a group) and standard data protection clauses.

There are generally now two types of approved standard clauses, these being:

  • For transfers of data from both the UK and EEA – standard clauses approved by the EU with a UK Information Commissioner’s Office (ICO) addendum attached.
  • For transfers of data from the UK only – the ICO’s International Data Transfer Agreement (IDTA).

In addition, the ICO advises organisations that are making restricted transfers from the UK, to conduct a Transfer Risk Assessment before they enter into an IDTA and establish any necessary measures to ensure data is adequately protected.

Why You Need a Solicitor

The rules on international data transfers are complex and constantly changing.  Our team of experts can help you:

  • Identify if there is a restricted transfer
  • Consider whether the transfer of personal data is permitted under the UK GDPR
  • Draft and advise on contractual documentation including IDTAs
  • Assist you in conducting the required Transfer Risk Assessment

Contact Our Expert Data Protection Solicitors

If you need any assistance with international transfers, please contact our data protection team who will be happy to help.

“Very professional, knowledgeable and accessible lawyers.” 

Chambers and Partners

FAQs – International transfers

This refers to the act of sending or transmitting personal data from one country to another. It also covers when an organisation makes personal data available to another entity located in another country, i.e. such data being accessible from overseas.

The UK GDPR contains rules on the transfer of personal data to outside the UK, where these rules apply to all transfers, no matter the size of the transfer or how often you carry them out.

Yes, you can provided you have the correct arrangements in place. Transfers from the UK to the EEA do not require any new arrangements, however transfers (known as ‘restricted transfers’) to ‘third countries’, will require additional safeguards.

This will depend on a case-by-case basis, however before making a restricted transfer, you should consider if the personal data needs to be sent, and whether any personal data could be anonymised so that it is not possible to identify individuals.

Broadly, the following questions should be considered under the UK GDPR before a restricted transfer is made:

  • Is the restricted transfer covered by ‘adequacy regulations’?
  • Is the restricted transfer covered by appropriate safeguards?
  • Is the restricted transfer covered by an exception?

Key contacts

Louise Keenan

Associate

View profile

+44 118 960 4614

Read, listen and watch our latest insights

art
  • 14 August 2024
  • Privacy and Data Protection

Data protection audit – what you need to know

A data protection audit is the process of auditing all of your data protection processes and procedures to understand your current levels of compliance and identify any areas for improvement.

art
  • 05 August 2024
  • Employment

AI and Recruitment

To assist employers who are using, or considering the use of, AI in recruitment, we have put together a summary of the key risks that employers should be aware of.

art
  • 15 July 2024
  • Privacy and Data Protection

The duty to protect third parties: is your DSAR response compliant?

Responding to a data subject access request (DSAR) may feel like a daunting process. It requires a solid understanding of the data subject’s rights, and of the meaning of personal data.

Pub
  • 02 July 2024
  • Privacy and Data Protection

Data protection unlocked for HR: Introduction to data protection

Members of the data protection team will discuss data protection issues encountered by HR professionals in the first episode of the ‘Data Protection Unlocked for HR’ podcast series.

art
  • 27 June 2024
  • Privacy and Data Protection

What could a Labour Government mean for Data Protection?

As we approach the 2024 General Election, the polls are suggesting a likely win for Labour and a resulting change in government. In the last week, parties including Labour have released their election manifestos.

art
  • 12 June 2024
  • Privacy and Data Protection

UK data protection: Important basics

Sometimes, data protection can seem like unhelpful red tape. At other times, it is critical to cultivating a trustworthy reputation.