Mitigating Risks Related to International Data Transfers 

Business partners shaking hands in front of a world map, representing an international business partnership.

Complying with the UK GDPR’s rules around international transfers of personal data is perhaps one of the most important topics organisations need to take into consideration to uphold high standards of data protection and information governance. In an increasingly connected world that is highly dependent on data flows, most organisations processing personal data will interact with international data transfers in one way or another. This article aims to explore the applicable rules to these transfers and provide a brief guide on how to ensure that associated risks can be properly mitigated.  

1. Why are international transfers of personal data important?  

We live in a data-driven economy, meaning we live in an ecosystem where data is an indispensable asset for organisations, individuals and institutions to create and extract economic value. The use of information in an increasingly digitised and interconnected world means data is frequently transferred between parties located in different countries, which is known as international or cross-border transfers of data.  

At a first glance, the use of the term “transfer” may sound like the concept of international transfers only applies to situations where one party is directly sending information to another party located in a different country. However, this is only one activity that falls within that definition. International data transfers may also occur when the party located in another country can remotely access the organisation’s information, even if there was no “movement” of the data. Similarly, storing information in a data centre located in another country also meets the threshold of an international data transfer, which is why data storage providers frequently implement international data transfer agreements. In practice, if your organisation uses cloud services, then it is most likely involved in an international data transfer.  

A lot of the data that organisations transfer to each other happens to be personal data under the UK GDPR, that is, data that relates to identified or identifiable individuals. However, data protection standards can vary significantly between countries. If personal data is transferred from the UK to other countries without proper security measures or adequate legislative protections in place, individuals risk not having their data protected to a sufficient level in the other country. This can expose them to data breaches which can cause harm, as well as having their right to privacy violated. 

This is where the UK GDPR’s rules on international data transfers come in.  

2. The UK approach to regulating international data transfers 

2.1 Which transfers are restricted by the UK GDPR? 

According to the Information Commissioner’s Office (ICO), the UK regulator and supervisory authority on data protection, the UK GDPR’s rules on international data transfers apply to transfers that consecutively meet the following requirements: 

a) The data being transferred is subject to the UK GDPR (i.e. it is personal data); 

b) The data is being exported from the UK, that is, it is transferred from the UK to a third country (a country or territory outside the UK);  

C) The party receiving the data in the third country is a separate legal entity from the exporter (this includes transfers between companies within the same corporate group). 

The opposite data flow – incoming data from another country to the UK – would be subject to any relevant legislation from the third country.  

2.2 What are the conditions for restricted international transfers? 

The UK GDPR takes a restrictive approach to international data transfers. In other words, cross-border transfers are prohibited unless the organisation can demonstrate they meet one of the conditions outlined between articles 44 and 49 of the UK GDPR. Transfers are only allowed if they meet one of the following criteria:  

  1. The UK government has issued an “adequacy decision” (article 45 UK GDPR) that concludes the third country has an adequate data protection regime to protect personal data; 

  2. In the absence of an adequacy decision, if the organisation has provided “appropriate safeguards” (article 46 UK GDPR) to ensure the data being transferred is protected. Appropriate safeguards can take the form of:

    • a legally binding and enforceable instrument with a public body, an international organisation, or an organisation carrying out public functions, if the organisation exporting data is a public body; 

    • a code of conduct approved by the ICO; 

    • a certification under a certification scheme approved by the ICO; 

    • contractual clauses authorised by the ICO; and 

    • administrative arrangements, authorised by the ICO, between a public body and another public body, an international organisation, or an organisation carrying out public functions. 

  3. If the third country does not have an adequacy decision, and the organisation cannot rely on the appropriate safeguards listed above, international data transfers are only allowed in exceptional circumstances outlined in article 49 UK GDPR, also known as “derogations”. See them summarised below:  

  • The data subject has explicitly consented to the proposed transfer, after being informed of the possible risks due to the absence of an adequacy decision and appropriate safeguards; 

  • The transfer is necessary for the performance of a contract between the data subject and the controller, or a contract between the controller and a third party concluded in the interest of the data subject;  

  • The transfer is necessary for important reasons of public interest, recognised in UK law; 

  • The transfer is necessary for the establishment, exercise or defence of legal claims; 

  • The transfer is necessary to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent; 

  • The transfer is from a public register; or 

  • The transfer is a one-off transfer necessary for the controller’s compelling legitimate interests.  

The derogations of article 49 can only be used as a last resource, as organisations are not allowed to rely on them to bypass the need to adopt an appropriate safeguard. Any reliance on derogations needs to be justified by demonstrating that the transfer is both necessary (i.e. indispensable) to achieve one of the purposes listed above and proportionate to protect individuals’ rights and freedoms.   

2.3 Countries with adequacy decisions  

The ICO maintains an updated list of all countries contemplated by adequacy decisions. Currently, the UK has issued adequacy decisions for the following countries: 

  • All countries in the European Economic Area (EEA): Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, Iceland, Norway and Liechtenstein; 

  • EU and EEA institutions, bodies, offices or agencies; 

This list shows that, outside of Europe, few countries have an adequacy decision in place with the UK. In practice, this means that organisations may frequently need to rely on the appropriate safeguards of article 46 to keep their international data transfers compliant with the law. 

3. Risks and challenges to organisations when engaging with international data transfers 

There are several operational obligations that organisations need to consider to ensure effective compliance with rules around international data transfers, for example, which agreements need to be signed and ensuring responsibilities are properly allocated between parties.  

Proper oversight is required even when transferring data to countries with adequacy decisions. These decisions are not a blanket authorisation to process data without care, and these transfers are not devoid of risk simply because the third country has been deemed adequate. Organisations transferring data to adequate countries still need to comply with other rules of the UK GDPR, including: 

  • ensuring security of processing (article 32);  

  • respecting the overarching principles of data processing (article 5);  

  • having a lawful basis to cover all processing activities (article 6);  

  • following requirements for processing special categories of personal data (article 9); 

  • ensuring data subjects can exercise their rights (articles 15 to 22); among others. 

3.1 Practical example: adequacy decision

Company A is based in the UK and collects personal data of customers who live in the UK. Company A contracts a firm based in Germany to carry out periodic audits of its operations. As part of the audit procedures, the firm requests a sample of invoices which contain the first and last names of certain customers. 

This is a restricted transfer of personal data from the UK to Germany. However, since Germany is contemplated by an adequacy decision, Company A does not need to adopt additional safeguards. 

Company A must still comply with all other rules of the UK GDPR. For example, Company A must ensure the processing has a lawful basis under article 6 UK GDPR and only share the minimum data necessary to fulfil the purposes of the sharing (in addition to respecting all other data protection principles). Since the Germany-based firm is processing data on behalf of Company A, both organisations must also ensure a Data Processing Agreement (DPA) is in place, with clear allocation of roles and responsibilities in accordance with article 28 UK GDPR.  

To simplify compliance and reduce the administrative burden associated with DPAs, organisations can automate the entire DPA lifecycle with Zolteria. The platform provide pre-built, customisable templates as consistent starting point for organisations to streamline their processes for drafting, signing and updating agreements while still complying with legislative requirements. 

3.2 Requirements to use appropriate safeguards 

For international data transfers to countries without adequacy decisions, organisations must comply with the general obligations of the UK GDPR as outlined above, as well as implement appropriate safeguards for the transfers under article 46 UK GDPR. Although the appropriate safeguards listed in the UK GDPR are not limited to contractual instruments (as codes of conduct and certification schemes can also be used), in practice, many organisations opt to adopt contractual agreements to validate the transfer.  

Many organisations prefer to adopt standard data protection clauses drafted by their country’s supervisory authority to validate international data transfers. These are known as Standard Contractual Clauses (SCCs) in the EU, or International Data Transfer Agreement (IDTA) in the UK. Alternatively, parties can choose to adopt their own contractual clauses, but in the UK, these must be approved separately by the ICO. 

Organisations with multiple branches in different countries can also adopt Binding Corporate Rules (BCRs), which are internal policies that can be used for international data transfers between organisations part of the same corporate group. 

However, simply implementing an agreement is not enough to ensure compliance with the UK GDPR. With the advent of the Court of Justice of the European Union’s landmark decision in Case C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (also known as Schrems II), prior to any transfers, the data exporter needs to evaluate not only the level of protection afforded by existing contractual clauses, but also materially by the legal system of the third country.  

The Schrems II decision required this when organisations incorporate SCCs into their transfer agreements. Since then, the UK approach has been to require this material evaluation whenever appropriate safeguards under article 46 are used to validate international data transfers, not just SCCs. This assessment is known as a Transfer Risk Assessment, also referred to as a “Data Protection Test” under the Data (Use and Access Act) 2025.  

The Data Protection Test aims to ensure that the standard of data protection in the third country will not be “materially lower” than in the UK after the transfer. If the test determines that the chosen safeguard does not provide enough protection as it is, the organisation must not proceed with the transfer if it cannot implement additional protections or if the transfer does not fall under one of the derogations from article 49.  

Breach of the UK GDPR’s rules on international data transfers can lead to application of severe penalties by the ICO. Infringements of this nature fall under article 83(5) UK GDPR, which establishes penalties up to £17.5 million or, in the case of an undertaking, 4% of its total worldwide annual turnover in the preceding financial year, whichever is higher.  

3.3 Practical example: appropriate safeguards 

Company A contracts Company B, which is based in India, to carry out data analytics services to streamline Company A’s operations. As part of its services, Company B can access personal data from Company A’s customer database. 

This is a restricted transfer of personal data from the UK to India. Since India does not have an adequacy decision, Company A must implement appropriate safeguards under article 46 UK GDPR to ensure the transfer is lawful.  

Company A decides that the best way to validate the transfer is to incorporate the UK Addendum to the EU SCCs, as drafted by the ICO, into its existing DPA with Company B. 

Simply incorporating the standard clauses into the agreement is not sufficient to fully comply with the UK GDPR. Company A must conduct a Data Protection Test to assess that the level of protection to the data in India will not be materially lower than in the UK after the transfer.  

Additionally, Company A is still required to comply with all other rules of the UK GDPR that are applicable to the processing, similarly to the transfer to Germany described in the previous example.  

4. How to mitigate risks and ensure compliance?  

The mandatory requirements, from assessing risks to signing agreements and keeping track of legislative changes in the UK and abroad, can make compliance feel challenging and overwhelming, but it does not need to be this way. Finding an effective way to operationalise rules into concrete and practical steps is the key element to mitigate risks and ensure compliance.  

The first step to ensure risks can be properly mapped, evaluated and managed is to have good record-keeping procedures in place. Keeping track of all operations that process personal data is important not only to comply with the UK GDPR’s obligation for controllers to maintain records of processing activities (article 30), but it is also essential for organisations to have control over their data flows by understanding which data categories are processed, who might receive them, where they are based and envisaged time limits for data retention.  

Knowing where each data recipient is located and where data will be processed will then inform what may be the most appropriate route to ensure compliance with the UK GDPR’s specific rules on international data transfers. 

As a first step, make sure to verify whether the third country has been subject to an adequacy decision in the UK, or, for countries with partial adequacy (such as the US, Canada and Japan), if the proposed transfer falls under the scope of an existing decision. Only in the absence of an adequacy decision will the organisation be required to implement one of the appropriate safeguards of article 46.  

There is no hierarchy between appropriate safeguards, so choosing between them is up to the organisation. Consider which safeguard best fits the organisation’s data flows, the specific international transfer and the envisaged relationship with the recipient. For example, if the organisation’s activities would lead to regular transfers to overseas entities part of the same corporate group, it may be worth considering implementing BCRs across the entire group. 

Alternatively, if the organisation is transferring data to the recipient in the context of a controller-processor relationship, this relationship must be formalised in a Data Processing Agreement. The requirement for a DPA is independent from the rules of international data transfers, so they apply for any controller-processor relationship. In practice, instead of implementing another agreement between the same parties just to regulate the international transfer, it may be more useful to implement the ICO’s UK Addendum to the EU SCCs, or the ICO’s International Data Transfer Agreement, into the main DPA.  

If the processing activities are so specific that the use of standard clauses may not be the most adequate, the parties can agree to implement a tailored agreement to cover international data transfers between them. However, these must be separately approved by the ICO. Again, it all depends on the context of the relationship and the specificities of the envisaged transfer. 

Once the appropriate safeguard is chosen, the organisation must complete the Data Protection Test to evaluate the circumstances of the proposed transfer and whether there are sufficient legal, technical and organisational measures in place to guarantee individuals will have their information protected to a similar level as the UK. This will help the organisation to determine the most appropriate ways to mitigate risks that have been identified during the assessment. 

Conclusion 

The UK GDPR’s rules on international data transfers do not exist in a vacuum. They are part of an overarching framework designed to ensure that personal data is protected to a high standard regardless of where it is located or accessed from, while still recognising the importance of cross-border information flows in a world increasingly more interconnected. 

FAQ

When designing your organisation’s compliance framework for data protection, the following questions may arise: