It is now increasingly common for businesses to operate across borders. For example,  employee information may be shared with a parent company based abroad and service providers may provide services from multiple international locations. Transferring personal data across international borders has become part of everyday operations.

UK data protection law requires organisations to ensure that personal data remains adequately protected when it is transferred outside the UK. Without appropriate safeguards, international transfers of personal data risk breaching compliance obligations and exposing businesses to significant regulatory fines and reputational damage.

This article provides an overview of international transfers of personal data, and the practical steps organisations should take to remain compliant.

What is a restricted international transfer of personal data?

A restricted international transfer occurs where personal data that is protected under the UK GDPR is sent or made accessible to a separate legal entity located outside the UK.

Common examples of what may constitute restricted international transfers include:

  • Sharing employee data with a parent company or affiliate overseas;
  • Using an overseas payroll, HR or IT service provider; or
  • Storing personal data on cloud-based systems hosted outside the UK.

Many organisations assume that a transfer only occurs when data is physically sent to another country. However, remote access from outside the UK may also constitute an international transfer and should therefore be assessed in the same way.

What is the new approach to adequacy?

The simplest lawful method to transfer personal data internationally is to transfer it to a country that has been recognised by the UK government as providing an adequate level of data protection.

Historically, adequacy assessments focused on whether another country's legal framework essentially mirrored UK and European data protection standards. Although this is still the case for transfers from European countries to countries outside of Europe, the UK approach has recently changed following the Data (Use and Access) Act 2025 (“DUAA”) so that an adequacy decision may be made where the standard of data protection in the recipient country is not materially lower than the UK. This change is meant to allow a more flexible and outcomes-based assessment to support international data flows while maintaining protection of personal data.

Appropriate Safeguards

If a recipient country does not benefit from a UK adequacy decision, the next step is to implement appropriate safeguards before transferring personal data. Appropriate safeguards are mechanisms for compliant international transfer of personal data outside of the UK.

The most commonly used safeguards include:

  1. International Data Transfer Agreement (IDTA)

The IDTA is the standard contractual mechanism approved for transfers from the UK to countries without adequacy status. The IDTA imposes contractual obligations on both parties and is designed to ensure that transferred personal data receives appropriate protection.

  1. UK Addendum to the EU Standard Contractual Clauses (SCCs)

Many multinational organisations use the European Commission's SCCs when transferring personal data from a European country to a recipient based in a country outside of Europe. The UK Addendum is designed to enable continued use of SCCs for transfer of personal data outside of the UK following the UK leaving Europe as a result of Brexit. This can be particularly useful where both UK GDPR and EU GDPR requirements need to be addressed within a single contractual framework.

  1. Binding Corporate Rules (BCRs)

Large multinational groups may adopt BCRs to allow internal transfers of personal data between group companies located in different countries with an appropriate level of data protection. Although obtaining approval can be resource-intensive, BCRs may provide an effective long-term solution for organisations with substantial international operations.

Transfer Risk Assessments

Organisations must also complete a Transfer Risk Assessment (TRA) to ensure that the standard of protection for the personal data being transferred is not materially lower once it is transferred.

Until recently, the TRA needed to establish that the standard of data protection in the recipient country was essentially equivalent to that in the UK, but following DUAA this has also been changed so that the TRA needs to establish that the standard of protection is not materially lower than that in the UK. This change should enable a more flexible approach to restricted transfers. If the TRA determines that the standard of protection is materially lower than in the UK, then the transfer cannot proceed.

Practical considerations for businesses

In light of the changes to adequacy decisions and TRAs, you should review your privacy governance documents and templates to see if you need to make any changes.

Businesses operating in both the UK and EU should also be aware that UK GDPR and EU GDPR transfer requirements are similar but not identical. A transfer solution that works for one jurisdiction may not automatically satisfy the requirements of the other.

How Can 3CS Help?

International data transfer compliance can be complex, particularly where organisations operate across multiple jurisdictions or rely on several third-party providers. We can help you to conduct and document TRAs under UK GDPR and EU GDPR, as well as mapping data flows, preparing and reviewing IDTAs, implementing SCCs and advising on cross-border compliance strategies.

We also provide privacy compliance audits, staff training, governance reviews and drafting support for privacy notices, data processing agreements, records of processing activities and other key data protection documentation.

Whether you are sharing employee information within a corporate group, onboarding a new overseas service provider or reviewing your global compliance framework, we can help you identify practical and proportionate solutions.

For advice and guidance, please get in touch.

Atiq Bhagwan

GET IN TOUCH

3CS Corporate Solicitors

Providing solutions, not just legal advice
Contact Us

GET IN TOUCH

Contact Us

3CS Corporate Solicitors Ltd


London Office
English (United Kingdom)
60 Moorgate, London EC2R 6EJ
+44 (0)20 4516 1260
info@3cslondon.com
To view a map of where to find us, please click here.


Japan Representative Office
Japanese
The Japan Representative Office does not provide legal services, whether under the laws of England and Wales, Japan, or any other jurisdiction.
Level 20, Marunouchi Trust Tower – Main
1-8-3 Marunouchi Chiyoda-ku, Tokyo, 100-0005
+81 (0) 3 5288 5239
info@3cstokyo.com
To view a map of where to find us, please click here.

 

 

Please enter your name
Please enter your phone number
Please enter your email
Invalid Input
Invalid Input
Please enter how you heard about 3CS

Sample Clients


We have advised more than 600 international clients – see others here
The Legal 500 - Leading Firm 2025 world link for law logo

Registered in England & Wales | Registered office is 60 Moorgate, London, EC2R 6EJ
3CS Corporate Solicitors Ltd is registered under the number 08198795
3CS Corporate Solicitors Ltd is a Solicitors Practice, authorised and regulated by the Solicitors Regulation Authority with number 597935


Registered in England & Wales | Registered office is 60 Moorgate, London, EC2R 6EJ
3CS Corporate Solicitors Ltd is registered under the number 08198795
3CS Corporate Solicitors Ltd is a Solicitors Practice, authorised and regulated by the Solicitors Regulation Authority with number 597935