Search

How can we help?

Icon

21 March 2024 Deadline: Are your international data transfer agreements compliant?

If your organisation transfers personal data from the UK to another country, it needs to comply with statutory requirements to ensure adequate levels of protection for that data are in place.

Some countries have an ‘adequacy decision’ which means they have been judged as having adequate protections in place and so you can transfer personal data to these countries without needing any further specific approval.  A normal, commercial data sharing agreement will be enough in those circumstances.

However, in the absence of an adequacy decision, adequate safeguards will need to be put in place before you can transfer data (unless you are able to rely on one of the limited exemptions in the UK GDPR and Data Protection Act 2018).

One of the most common safeguards used are standard contractual clauses.

Standard Contractual Terms

Prior to 2021, the EU had its own set of standard contractual clauses for data transfers which companies in the UK often used (‘Old EU Clauses’).   It updated these in 2021 (‘New EU Clauses’).

The ICO has since developed two sets of standard contractual clauses for the UK.  Which one is appropriate to use depends on whether data is being transferred from the UK only or the UK and EEA.

UK Only – International Data Transfer Agreement

The ICO’s International Data Transfer Agreement (‘IDTA’) is most appropriate for data transfer agreements concluded after 21 March 2022 where data is being transferred from the UK only to another country.

For older agreements based on the Old EU Clauses, there were some transitional provisions allowing organisations time to move onto the new IDTA model, but these expire on 21 March 2024 and, as such, all organisations need to ensure that they are on the new IDTA model from 21 March 2024.

The ICO has since developed two sets of standard contractual clauses for the UK.

UK and EEA – New EU Clauses and Addendum

Organisations who transfer data from the UK and EEA to other countries will usually need to use the second set of standard contractual clauses produced by the ICO known as the International Data Transfer Agreement Addendum (‘Addendum’).  This Addendum is used alongside the New EU Clauses.

Companies should have already moved onto the New EU Clauses and Addendum model as all transitional provisions expired in 2022.

Steps you should take now!

Companies need to review their data transfer practices and agreements to understand what international transfers occur and the agreements that govern these.  They need to understand if data is being transferred from the UK only, or from the UK and EEA, and whether any of their agreements are based on the Old EU Clauses. They should also check if any of their agreements are based solely on the New EU Clauses, without the Addendum.

Any which are now out of date will need to be transferred onto the new models to ensure they remain valid and legally compliant.  If not, the organisation runs the risk of not having adequate safeguards in place for the data transfer in breach of the legislation.  Alternatively, organisations will need to consider if an alternative safeguard should be used, such as binding corporate rules or whether it is able to rely on any of the exemptions in the legislation.

Companies should also carry out transfer risk assessments before relying on the standard contractual clauses (or other safeguards) and so this will also need to be considered as part of the updating.

Our data privacy lawyers are on hand to advise you through this process and to help draft up new agreements as needed.

FAQs – International Transfers

This refers to the act of sending or transmitting personal data from one country to another. It also covers when an organisation makes personal data available to another entity located in another country, i.e. such data being accessible from overseas.

The UK GDPR contains rules on the transfer of personal data to outside the UK, where these rules apply to all transfers, no matter the size of the transfer or how often you carry them out.

Yes, you can provided you have the correct arrangements in place. Transfers from the UK to the EEA do not require any new arrangements, however transfers (known as ‘restricted transfers’) to ‘third countries’, will require additional safeguards.

This will depend on a case-by-case basis, however before making a restricted transfer, you should consider if the personal data needs to be sent, and whether any personal data could be anonymised so that it is not possible to identify individuals.

Broadly, the following questions should be considered under the UK GDPR before a restricted transfer is made:

  • Is the restricted transfer covered by ‘adequacy regulations’?
  • Is the restricted transfer covered by appropriate safeguards?
  • Is the restricted transfer covered by an exception?

About this article

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

About this article

Read, listen and watch our latest insights

art
  • 15 May 2025
  • Privacy and Data Protection

Ashley v HMRC – The High Court clarifies the scope of Data Subject Access Requests

DSARs are very rarely the subject of litigation, and they are even rarer in the High Court, so the case of Ashley v HMRC is a valuable decision for both data subjects and data controllers.

art
  • 29 April 2025
  • Privacy and Data Protection

Use of Personal Devices at Work: Why a Bring Your Own Device Policy is Essential

If you have employees who bring their own devices into the workplace and use said devices to deal with company data, you may want to consider a Bring Your Own Device (“BYOD”) policy.

art
  • 29 April 2025
  • Privacy and Data Protection

Update on the Data (Use and Access) Bill

We will highlight in this article what changes have been made to the DUAB since the early stages of the Bill.

art
  • 07 April 2025
  • Privacy and Data Protection

Can an employer monitor employees at work?

Can an employer lawfully monitor their employee, without their knowledge, if they suspect wrongdoing?

art
  • 06 March 2025
  • Privacy and Data Protection

Recent data breaches and their impact on organisations

Organisations of all sizes are susceptible to data breaches and the damage caused by these breaches, both reputationally and financially, can be very significant.

Pub
  • 03 March 2025
  • Privacy and Data Protection

Privacy matters: How the 8 data subject rights protect personal data

In this guide we explore the 8 data subject rights under the UK GDPR and discover how they play a vital role in preserving your organisation’s privacy standards in an increasingly interconnected world.