Statutory restriction — Article 44A UK GDPR and the Data (Use and Access) Act 2025 reform
The United Kingdom restricts international transfers of personal data under Chapter V of the UK General Data Protection Regulation (UK GDPR), as amended by the Data (Use and Access) Act 2025 (c. 18). The Data (Use and Access) Act 2025 received Royal Assent on 13 March 2025 and fundamentally reformed the UK's transfer regime by omitting the original Article 44 and inserting a new Article 44A, alongside a "not materially lower" standard that diverges from the EU GDPR's essential-equivalence requirement.
Article 44A — the general transfer restriction
Schedule 7 paragraph 2 of the Data (Use and Access) Act 2025 omitted the original Article 44 and inserted a replacement provision, Article 44A. Under Article 44A, a controller or processor may transfer personal data to a third country or an international organisation only if one of three conditions is met:
- Adequacy regulations under Article 45A — the Secretary of State has made regulations approving transfers to the third country or international organisation, and the transfer is approved by or falls within the description of transfers approved by those regulations;
- Appropriate safeguards under Article 46 — the transfer is made subject to appropriate safeguards; or
- A derogation under Article 49 — the transfer falls within one of the enumerated derogations for specific situations.
Article 44A paragraph 3 provides that a transfer may not be made in reliance on the appropriate-safeguards or derogation grounds if doing so would breach a restriction imposed by regulations under Article 49A.
The "not materially lower" standard — Articles 45A and 45B
Schedule 7 of the 2025 Act omitted the original Article 45 (transfers on the basis of an adequacy decision) and replaced it with a new two-article regime comprising Article 45A (power to make adequacy regulations) and Article 45B (the data protection test). The critical shift is the replacement of the "essential equivalence" standard historically applied by the European Commission under EU GDPR Article 45 with a "not materially lower" threshold.
Article 45B paragraph 1 provides that the data protection test is met in relation to transfers if "the standard of the protection provided for data subjects with regard to general processing of personal data in the country or by the organisation is not materially lower than the standard of the protection provided for data subjects" by the UK GDPR and Parts 5 to 7 of the Data Protection Act 2018, so far as relevant to general processing. Article 45B paragraph 2 requires the Secretary of State to consider, among other things, the rule of law, enforceable data subject rights, oversight mechanisms, and the country's rules about onward transfers to other countries or international organisations.
Article 45A empowers the Secretary of State to make regulations approving transfers by reference to a third country (in whole or as to a territory or sector within that country) or to an international organisation. Article 45A(4) permits the Secretary of State to approve all transfers to a jurisdiction or to limit approval only to transfers specified or described in the regulations, including by reference to a sector, geographic area, relevant legislation, schemes, lists, or other arrangements as they have effect from time to time.
Supervisory authority and enforcement
The Information Commissioner's Office (ICO), established under Part 5 of the Data Protection Act 2018 and continued under UK GDPR Article 51, is the supervisory authority responsible for monitoring application of the UK GDPR. Under UK GDPR Article 57, the ICO has tasks including monitoring and enforcing application of Chapter V. Article 58 confers investigative, corrective, and authorization powers, including the power to order suspension of data flows to a third country or international organisation and to impose administrative fines under Article 83 for infringement of Chapter V transfer restrictions.
Divergence from EU GDPR post-Brexit
The UK is a "third country" for purposes of the EU GDPR. Schedule 7 to the Data (Use and Access) Act 2025 introduced material divergence between the UK and EU transfer regimes: the EU retains the essential-equivalence standard under EU GDPR Article 45, as interpreted by the Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Case C-311/18, judgment of 16 July 2020, "Schrems II"), whereas the UK now applies the "not materially lower" threshold under Article 45B. Controllers and processors transferring personal data from both the UK and the EU to the same third country must maintain dual assessments and may need to rely on distinct legal mechanisms for each export.
Source: UK General Data Protection Regulation (Regulation (EU) 2016/679 as retained in UK law) Source: Data (Use and Access) Act 2025 (c. 18), Schedule 7 Source: Data Protection Act 2018 (c. 12)
UK adequacy regulations — approved third countries and the "not materially lower" assessment
The United Kingdom's framework for approving third countries for the free flow of personal data has been substantively amended by the Data (Use and Access) Act 2025 and related commencement regulations effective 5 February 2026. As of July 2026, the governing statutory provisions are Articles 45A–45C of the UK GDPR (as inserted by the 2025 Act) and the new adequacy test under Article 45B.
Legal authority and "not materially lower" test (2026)
The Secretary of State's power to make adequacy regulations – designating a country, territory, sector, or international organisation as providing adequate protection for UK data exports – is now set out in Article 45A UK GDPR, as amended by Schedule 7 to the 2025 Act and brought into force by SI 2026/82. A transfer covered by adequacy regulations may proceed without requiring further Article 46 safeguards or recourse to an Article 49 derogation.
Crucially, adequacy regulations may be adopted only if "the standard of the protection provided for data subjects with regard to general processing of personal data in the country or by the organisation is not materially lower than the standard of the protection provided for data subjects" by the UK GDPR and Parts 5–7 of the Data Protection Act 2018 (Article 45B(1)). This “not materially lower” threshold replaces the former “essential equivalence” requirement applied under EU law and is a key policy divergence post-Brexit. Article 45B(2) enumerates the criteria the Secretary of State must consider in making such a determination (rule of law, enforceable rights, oversight mechanisms, onward transfers, etc.).
Publication and monitoring of adequacy lists (2026 updates)
Article 45C creates a standing duty to keep developments under review and mandates the Information Commissioner to publish and update a list of jurisdictions currently approved by adequacy regulations, as well as those previously approved but now revoked. This list is available via the ICO's website and is kept continuously updated following regulatory changes.
Current approved countries (status as of July 2026)
- The principal adequacy list continues to include the EEA, Gibraltar, and the non-European countries and territories that were either subject to retained EU adequacy decisions (valid as at 31 December 2020) or have since been the subject of UK-specific adequacy regulations. These include: Andorra, Argentina, Faroe Islands, Guernsey, Isle of Man, Israel, Jersey, New Zealand, Switzerland, and Uruguay (full adequacy); and Canada (PIPEDA-covered data only), Japan (private sector under APPI), and the United States (organisations participating in the UK Extension to the Data Privacy Framework) as partial adequacy cases.
- The Data Protection (Adequacy) (United States of America) Regulations 2023 remain in force, enabling transfers to certified US organisations participating in the UK Extension to the EU-US Data Privacy Framework.
Material update
This section has been materially updated to reflect the coming into force of the Data (Use and Access) Act 2025 and its statutory amendments to the adequacy regime under the UK GDPR, including the move to a “not materially lower” assessment threshold, introduction of Articles 45A–45C, ongoing list publication, and the effective commencement of these reforms as of February 2026.
Source: UK General Data Protection Regulation, Articles 45A–45C (as amended by the Data (Use and Access) Act 2025, Schedule 7) Source: Data Protection (Adequacy) (United States of America) Regulations 2023 Source: ICO, Adequacy regulations — list of countries and territories Source: Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026
UK International Data Transfer Agreement and UK Addendum — Article 46 appropriate safeguards
Controllers and processors making restricted transfers to third countries or international organisations that do not benefit from UK adequacy regulations may rely on one of the "appropriate safeguards" listed in Article 46 of the UK GDPR. The two principal contractual safeguards issued by the Information Commissioner's Office (ICO) under section 119A of the Data Protection Act 2018 are the UK International Data Transfer Agreement (IDTA) and the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses (UK Addendum). Both came into force on 21 March 2022 and serve as alternatives to each other; organisations select one or the other depending on their operational footprint and existing contractual arrangements.
Statutory authority — section 119A DPA 2018
Section 119A(1) of the Data Protection Act 2018 empowers the Information Commissioner to issue a document specifying standard data protection clauses which the Commissioner considers are capable of securing that the data protection test set out in Article 46 of the UK GDPR is met in relation to transfers of personal data. The IDTA and the UK Addendum were laid before Parliament on 2 February 2022 and, following the 40-day parliamentary approval period prescribed by section 119A(6), entered into force on 21 March 2022. Article 46(2)(d) UK GDPR recognises "standard data protection clauses specified in a document issued (and not withdrawn) by the Commissioner under section 119A … of the 2018 Act and for the time being in force" as an approved appropriate safeguard.
The UK International Data Transfer Agreement (IDTA)
The IDTA is a standalone contractual agreement designed for transfers from the UK to non-adequate countries. It is structured in four parts:
- Part 1 — Tables (mandatory): the parties complete case-specific details including the exporter and importer identity, transfer details (categories of data subjects, categories of personal data, purposes, and onward-transfer provisions), and the role relationship (controller-to-controller, controller-to-processor, processor-to-processor, or processor-to-controller).
- Part 2 — Extra Protection Clauses (optional): allows the parties to add supplementary technical or organisational measures where a transfer risk assessment identifies residual risks not fully mitigated by the IDTA's mandatory clauses.
- Part 3 — Commercial Clauses (optional): permits inclusion of commercial terms. The ICO guidance notes that if making a restricted transfer to a processor, parties may add in the clauses required by Article 28 of the UK GDPR, though the IDTA itself does not provide a data processing agreement. Controllers transferring to processors must incorporate Article 28 clauses in a linked agreement.
- Part 4 — Mandatory Clauses: contains the binding data-protection obligations for exporter and importer, including purpose limitation, data security measures, onward-transfer controls, data-subject rights (access, rectification, erasure, restriction, portability, objection), breach notification, and cooperation with the ICO.
Section 9 of the IDTA's Mandatory Clauses requires the importer to provide the exporter with information about local laws and practices that may affect the transfer ("Importer Information"), enabling the exporter to conduct the transfer risk assessment. The IDTA also contains suspension and termination provisions in Sections 27–28 and 30 where a "significant harmful impact" on data subjects arises.
The UK Addendum to the EU SCCs
The UK Addendum is a modular add-on to the European Commission's standard contractual clauses adopted on 4 June 2021 (Commission Implementing Decision (EU) 2021/914). Organisations that have entered into the 2021 EU SCCs for transfers from the EEA may use the UK Addendum to cover parallel transfers from the UK, avoiding the need to negotiate a second standalone agreement. The UK Addendum comprises:
- Part 1 — Tables: mirrors the IDTA structure, requiring the parties to specify which modules of the EU SCCs (Module 1: controller to controller; Module 2: controller to processor; Module 3: processor to processor; Module 4: processor to controller) are in use, the effective date, and the UK-specific adaptations.
- Part 2 — Mandatory Clauses: sets out the UK-specific obligations that supplement the EU SCCs, including the requirement that the data protection test under UK law is met and the parties' cooperation with the ICO.
The ICO guidance states that organisations may incorporate the Part 2 Mandatory Clauses by reference only (so they do not need to set them out in full), provided they include the text set out in the "Alternative Part 2 Mandatory Clauses."
Choosing between the IDTA and the UK Addendum
Controllers and processors transferring personal data from the UK only will typically find the IDTA simpler, as it is a single standalone document. Organisations transferring personal data from both the UK and the EEA to the same recipient will usually prefer the UK Addendum layered onto the 2021 EU SCCs, because the same underlying modular clauses cover both UK and EU transfers with minimal duplication. Both mechanisms are legally equivalent for UK GDPR compliance; the choice is operational.
Transfer risk assessment (TRA) — mandatory for all Article 46 safeguards
The ICO guidance states that if relying on an Article 46 transfer mechanism (including the IDTA or the UK Addendum), the exporter must carry out a transfer risk assessment before making the restricted transfer. The TRA helps the exporter consider whether, in the circumstances of the transfer and with the chosen Article 46 transfer mechanism in place, the relevant protections for people under the UK data protection regime will be undermined. The ICO guidance identifies two broad types of risk the exporter must consider:
- Risks to people's rights arising in the destination country from third parties accessing the information that are not bound by the Article 46 transfer mechanism, in particular government and public bodies (for example, surveillance laws, national-security access, law-enforcement data requests that conflict with the IDTA or Addendum obligations).
- Risks arising from the receiver's own actions or practices, including whether the receiver's legal system provides effective and enforceable data-subject rights and effective administrative and judicial redress.
The ICO notes that the TRA is a requirement under UK data protection laws, confirmed by the Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Case C-311/18, judgment of 16 July 2020, "Schrems II"), which established the role of risk assessments in the rules on restricted transfers.
If the TRA identifies conflicts between local law and the IDTA or Addendum obligations, the ICO guidance instructs the exporter to implement supplementary technical or organisational measures (for example, encryption, pseudonymisation, or contractual commitments to challenge government requests) where feasible, or to suspend or refrain from making the transfer where the IDTA or Addendum can no longer deliver appropriate safeguards. Both the IDTA and the UK Addendum contain built-in suspension and termination mechanisms for such circumstances.
Ongoing monitoring and review
The ICO guidance requires that for ongoing or repeated transfers, the exporter must regularly reassess the level of protection the Article 46 transfer mechanism provides (and any extra steps and extra protections taken alongside it), to ensure that the level of protection does not decrease over time. The exporter must consider whether the level of protection may be undermined by changes in the law or practices of the destination country, changes in the receiver's practices or ownership, or changes in UK law or ICO guidance. The IDTA and UK Addendum both permit the parties to elect automatic updating when the ICO issues a new version of the standard clauses, pursuant to section 119A(2) DPA 2018.
Source: Data Protection Act 2018 (c. 12), section 119A Source: ICO, What are standard data protection clauses (the UK IDTA and the Addendum)? Source: ICO, International Data Transfer Agreement (IDTA)
Article 49 derogations — specific situations permitting transfers without adequacy or safeguards
As of July 2026, the Article 49 derogations permitting international personal data transfers from the UK without adequacy regulations or Article 46 safeguards remain available but are now expressly framed under the amended structure of the UK GDPR, as revised by the Data (Use and Access) Act 2025 and brought fully into force through the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026 (SI 2026/82) and further modifications (SI 2026/386).
Statutory amendments — material changes (2026):
- Article 49 of the UK GDPR was substantively amended by Schedule 7, paragraphs 9–10 of the 2025 Act, effective 5 February 2026 and clarified by SI 2026/386. The updated statute now refers to "adequacy regulations under Article 45A" in place of the former references to adequacy decisions or s.17A DPA 2018.
- A new Article 49A empowers the Secretary of State to make further regulations restricting or prescribing reliance on certain Article 49 grounds (notably the public interest derogation under Article 49(1)(d)), though as of July 2026, no such regulations have been enacted.
Current legal structure and practical effect:
- The core list of derogations in Article 49(1) — including explicit consent, contract performance, legal claims, public interest, vital interests, and data from public registers — has not seen new grounds or removals, but the statutory prerequisites, cross-references, and formal documentation duties are reinforced.
- Controllers and processors must demonstrate that the transfer is genuinely exceptional: derogations remain narrow exceptions to be interpreted restrictively, consistent with ICO guidance and EDPB standards. Routine or large-scale transfers are not permitted on derogation grounds.
2026 ICO guidance and clarifications:
- The ICO confirmed in its January and July 2026 guidance updates that, while the legal claims derogation (Article 49(1)(e)) may still be relied upon in proceedings before courts, administrative authorities, or in out-of-court dispute contexts, the updated statutory framing requires fresh documentation that no other lawful transfer mechanism is available and that reliance is strictly necessary and proportionate.
- For recurring or systematic transfers, the ICO now requires an explicit justification of why no adequacy or appropriate safeguard could be used and why the derogation is indispensable.
No active regulations restricting derogation use as of July 2026:
- The anticipated regulatory powers to further restrict the public interest derogation under new Article 49A have not been exercised to date and there are no additional prohibitions in force. Controllers should, however, monitor for further regulatory activity in this space.
Summary of required steps when relying on a derogation:
- Document why no adequacy or appropriate safeguard applies;
- Record the specific derogation ground and ensure it is interpreted narrowly;
- For public interest or legal claims, check for any future regulations under Article 49A;
- Comply with all revised record-keeping and proportionality requirements per the July 2026 ICO guidance, including enhanced justification where special category data or repetitive transfers are in scope.
This section reflects all statutory amendments and ICO interpretive changes effective as of July 2026.
Source: UK General Data Protection Regulation, Article 49 (as amended by Data (Use and Access) Act 2025, Schedule 7 paragraph 9, SI 2026/386) Source: Data (Use and Access) Act 2025, Schedule 7 Source: Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026 (SI 2026/82) Source: ICO, derogations guidance July 2026
Binding corporate rules (BCRs) — Article 46(2)(b) approval mechanism for intra-group transfers
Multinational corporate groups and groups of undertakings engaged in joint economic activity may rely on binding corporate rules (BCRs) approved by the Information Commissioner's Office (ICO) under Article 46(2)(b) of the UK GDPR to transfer personal data to third countries or international organisations within the group without the need for UK adequacy regulations or a contract-based safeguard such as the IDTA or UK Addendum. BCRs are particularly suited to organisations that make repeated intra-group transfers to group entities located in non-adequate countries, because once the ICO approves the BCR, the group may make restricted transfers between BCR Members under a single approved governance framework rather than executing bilateral contracts for each transfer.
Statutory basis — Article 46(2)(b) and Article 47 UK GDPR
Article 46(2)(b) UK GDPR recognises "binding corporate rules approved in accordance with Article 47" as an appropriate safeguard for restricted transfers. Article 47(1) provides that the competent supervisory authority (the ICO) shall approve BCRs provided they satisfy the conditions laid down in Article 47(2). Article 47(2) requires that BCRs be legally binding and enforced by every member of the group, that they expressly confer enforceable rights on data subjects with regard to the processing of their personal data, and that they fulfil the requirements set out in Article 47(2)(a) to (m). Those requirements include specification of the structure and contact details of the group, a description of the data flows, the general data protection principles (especially purpose limitation, data minimisation, and limited storage periods), the rights of data subjects (access, rectification, erasure, and objection under Articles 15 to 22), mechanisms for ensuring compliance (including data-protection training for personnel and audit procedures), liability for breaches, procedures for handling complaints by data subjects, and arrangements for cooperation with the ICO.
ICO approval process — Article 58(3)(j) UK GDPR and application requirements
The ICO approves UK BCRs under the power conferred by Article 58(3)(j) UK GDPR (authorising and advisory powers). The ICO has published detailed guidance, application forms, and a referential table for both controller BCRs (UK BCR-C) and processor BCRs (UK BCR-P). The updated guidance (published August 2023) reflects the Court of Justice of the European Union's Schrems II judgment (Case C-311/18, 16 July 2020), which the ICO treats as applicable to the UK regime. The ICO guidance states that "a fundamental change to the approval process is the revision of the referential table" and that applicants "must understand and demonstrate your understanding of the spirit and intent behind Article 47 in your policies and procedures."
A UK BCR application pack consists of:
- Application form — the ICO provides a standardised form for UK BCR-C or UK BCR-P; separate applications are required for controller and processor BCRs even if the same group is applying for both.
- Binding instrument (also known as the intra-group agreement or IGA) — a legally binding contract between all BCR Members. The ICO guidance (updated August 2023) states that the ICO expects the binding instrument to ensure "effective and enforceable rights" and that nominated UK legal entities "either has or can individually call on sufficient assets to remedy any breach of the UK BCRs."
- BCR Policy — a published document setting out the key Article 47 information for data subjects. The ICO guidance states that "this is the document we expect you to publish in full" and that it "provides people with the key Article 47 information they need about their data and its transfers under the UK BCRs."
- Referential table — a completed ICO UK BCR Referential Table (version 2.0 or later) indicating where in the application form, BCR Policy, and binding instrument each Article 47 requirement is met.
- Supporting documentation — copy policies and procedures that demonstrate compliance with the commitments made in the BCR.
The ICO will review the application and, if satisfied that the Article 47 requirements are met, will decide whether to approve the rules and notify the controller or processor of that decision under Schedule 21, paragraph 9(5) DPA 2018.
Transfer risk assessment (TRA) requirement
Even where a group has ICO-approved BCRs, the ICO guidance states that "you can make a restricted transfer within your group if: both you and the receiver are part of your group's approved UK BCR; and you've completed a TRA to make sure the standard of protection for people's information is not materially lower after you transfer it." This aligns with the post-Schrems II requirement that exporters relying on any Article 46 safeguard must assess whether the legal or practical environment in the destination country undermines the effectiveness of the safeguard. The ICO's updated Controller and Processor guidance both list "the impact of Schrems II and the importance of undertaking a transfer risk assessment" as an overarching principle.
UK BCR Addendum — simplified approval for groups with existing EU BCRs
Multinational groups that already hold an approved EU BCR (approved by a European Data Protection Authority under EU GDPR Article 47) may apply for approval of a UK BCR using the UK BCR Addendum, a modular template published by the ICO. The ICO guidance states that "the UK BCR Addendum will become the UK binding instrument, ensuring that the UK BCR is enforceable in the UK. It contains all relevant provisions of Article 47 UK GDPR, meaning that your EU BCR will work in the UK."
The UK BCR Addendum comprises three parts: Part 1 confirms the existence of an approved EU BCR and explains how the Addendum forms a UK BCR meeting Article 47 requirements; Part 2 comprises four tables (start date and Lead UK BCR Member, documents forming the approved EU BCR, selection of options such as type of BCR and applicable UK laws, and dispute resolution); and Part 3 contains the substantive mandatory clauses.
The group must submit the UK BCR Addendum, the approved EU BCR documents (including the EU BCR policy and binding instrument), and a new UK BCR Summary aimed at data subjects. The ICO guidance states "you must create a new UK BCR Summary document" and "we expect you to make your UK BCR Summary concise and easy to read." The ICO will review the content of the UK BCR Summary as part of the approval process. The group must publish the UK BCR Summary alongside the EU BCR summary after ICO approval.
Groups using the UK BCR Addendum do not need to complete a full application form or referential table. The ICO guidance notes that "we expect all BCR Members to sign the Addendum as this is structured as an intragroup agreement" and that "you can only use the UK BCR Addendum as an international transfer mechanism from the date that the last BCR Member signs it."
Transitional provisions for legacy EU BCRs — Schedule 21, paragraph 9, DPA 2018
Schedule 21, Part 3, paragraph 9 of the Data Protection Act 2018 provides that any binding corporate rules authorised by the ICO which, immediately before IP completion day (31 December 2020), provided appropriate safeguards under EU GDPR Article 46(1), continue to provide appropriate safeguards under UK GDPR Article 46 on and after IP completion day. Paragraph 9(3) permits the group to incorporate Brexit-related changes without triggering a fresh approval, provided (a) all of the changes are made in consequence of the withdrawal of the United Kingdom from the EU and (b) none of the changes alters the effect of the rules. Paragraph 9(4) provides that the following changes are to be treated as falling within subparagraph (3)(a) and (b): changing references to adequacy decisions made by the European Commission into references to equivalent UK provision, and changing references to transferring personal data outside the European Union or the European Economic Area into references to transferring personal data outside the United Kingdom. Paragraph 9(5) provides that the transitional arrangements cease to apply in relation to binding corporate rules if, on or after IP completion day, the Commissioner withdraws the authorisation of the rules.
Groups relying on paragraph 9 transitional arrangements may at any time submit a fresh UK BCR application or adopt the UK BCR Addendum to align their UK BCR with their current EU BCR.
Operational comparison — BCRs, IDTA, and UK Addendum
BCRs, the IDTA, and the UK Addendum are all Article 46 appropriate safeguards and are legally equivalent for UK GDPR compliance. The choice between them is operational. BCRs are designed for intra-group transfers within a multinational corporate group; they are not suitable for transfers to third-party processors or controllers outside the group. The IDTA and UK Addendum work for transfers to any third party, whether intra-group or external. For an organisation that makes frequent intra-group transfers to non-adequate countries, BCRs offer administrative simplicity; for transfers to external service providers or business partners, the IDTA or UK Addendum is the appropriate mechanism. All three require a transfer risk assessment and, where necessary, supplementary measures.
Source: UK General Data Protection Regulation, Article 46(2)(b) Source: Data Protection Act 2018 (c. 12), Schedule 21, Part 3, paragraph 9 Source: ICO, Guide to Binding Corporate Rules — (B) Controller - Traditional UK BCR application process Source: ICO, What are binding corporate rules? Source: ICO, (A) UK BCR Addendum
Binding corporate rules (BCRs) — Article 47 approval for multinational group transfers
Multinational corporate groups making intra-group restricted transfers of personal data from the UK to non-adequate countries may rely on binding corporate rules (BCRs) as an appropriate safeguard under Article 46(2)(b) of the UK GDPR. BCRs are an alternative to the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, designed specifically for transfers within a group of undertakings or a group of enterprises engaged in a joint economic activity (such as franchises or joint ventures). BCRs require approval by the Information Commissioner, which the Commissioner grants under Article 58(3)(j) UK GDPR where the BCRs meet the requirements set out in Article 47.
Statutory authority — Article 46(2)(b) and Article 47 UK GDPR
Article 46(2)(b) UK GDPR recognises "binding corporate rules" as an appropriate safeguard that permits a controller or processor to make a restricted transfer to a third country or international organisation. Article 47(1) provides that the Commissioner shall approve binding corporate rules, provided they:
- are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees;
- expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and
- fulfil the requirements laid down in Article 47(2).
Schedule 7 paragraph 7 of the Data (Use and Access) Act 2025 inserted the words "Transfers subject to appropriate safeguards:" at the beginning of the Article 47 heading; that amendment came into force on 5 February 2026.
Article 47(2) minimum requirements
Article 47(2) UK GDPR requires BCRs to specify at least the following:
- Structure and contact details — the structure and contact details of the group and of each of its members (Article 47(2)(a));
- Scope of transfers — the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected, and the identification of the third country or countries in question (Article 47(2)(b));
- Legally binding nature — their legally binding nature, both internally and externally (Article 47(2)(c));
- Data protection principles — the application of the general data protection principles, in particular purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis for processing, processing of special categories of personal data, measures to ensure data security, and the requirements in respect of onward transfers to bodies not bound by the binding corporate rules (Article 47(2)(d));
- Data subject rights — the rights of data subjects in regard to processing and the means to exercise those rights, including the right to protection in connection with decisions based solely on automated processing (including profiling), the right to lodge a complaint with the Commissioner and before the UK courts, and to obtain redress and, where appropriate, compensation for a breach of the binding corporate rules (Article 47(2)(e));
- Acceptance of responsibility by UK member — the acceptance by the controller or processor established on the territory of the United Kingdom of liability for any breaches of the binding corporate rules by any member concerned not established in the United Kingdom; the controller or the processor shall be exempt from that liability, in whole or in part, only if it proves that that member is not responsible for the event giving rise to the damage (Article 47(2)(f));
- Information for data subjects — how the information on the binding corporate rules, in particular on the provisions referred to in Article 47(2)(d), (e), and (f), is provided to the data subjects in addition to Articles 13 and 14 (Article 47(2)(g));
- Responsibility for data protection compliance — the tasks of any data protection officer designated in accordance with Article 37 or any other person or entity in charge of the monitoring compliance with the binding corporate rules within the group, as well as monitoring training and complaint handling (Article 47(2)(h));
- Complaint procedures (Article 47(2)(i));
- Compliance verification mechanisms — the mechanisms within the group for ensuring the verification of compliance with the binding corporate rules. Such mechanisms shall include data protection audits and methods for ensuring corrective actions to protect the rights of the data subject (Article 47(2)(j));
- Reporting to ICO on local law conflicts — the mechanisms for reporting to the Commissioner any legal requirements to which a member of the group is subject in a third country which are likely to have a substantial adverse effect on the guarantees provided by the binding corporate rules (Article 47(2)(m)); and
- Data protection training — the appropriate data protection training to personnel having permanent or regular access to personal data (Article 47(2)(n)).
ICO approval process
The ICO approves UK BCRs under Article 58(3)(j) UK GDPR. The ICO has published detailed guidance for controller BCRs (UK BCR-C) and processor BCRs (UK BCR-P), together with application forms and a UK BCR Referential Table that applicants must complete. The ICO guidance states that the application package comprises a completed application form, an intra-group agreement (IGA) or other legally binding instrument, a BCR Policy document that must be published in full after approval (providing data subjects with the key Article 47 information about their data and its transfers), and supporting documents including the completed ICO UK BCR Referential Table demonstrating where each Article 47 requirement is met.
The ICO guidance emphasises that applicants must demonstrate an understanding of the spirit and intent behind Article 47 in their policies and procedures, and their compliance with Article 47 and the UK GDPR more broadly. The ICO guidance notes that organisations with multiple UK legal entities within a single BCR may use an "exporting entity model," where each UK exporter has a separate liability model, provided the structure does not undermine effective and enforceable rights. The ICO requires the nominated UK entity (or entities) to demonstrate sufficient assets to remedy any breach of the UK BCRs.
UK BCR Addendum for organisations with existing EU BCRs
The ICO recognises that BCR applicants may seek both EU and UK BCRs and that Article 47 requirements in both jurisdictions currently overlap. For organisations that have already obtained approval of EU BCRs from an EU supervisory authority, the ICO offers a streamlined route: the UK BCR Addendum. The UK BCR Addendum is a standard-form or template document that layers UK-specific obligations onto the approved EU BCR, enabling the organisation to obtain a UK BCR approval without completing a full UK BCR application form or referential table.
The ICO guidance describes the UK BCR Addendum as comprising three parts: Part 1 confirms that the applicant has an approved EU BCR and explains how the UK BCR Addendum forms a UK BCR meeting the requirements of Article 47 UK GDPR; Part 2 comprises four tables for the applicant to complete specifying key information including the start date (inserted after ICO approval), the Lead UK BCR Member responsible for breaches by non-UK BCR members, the documents forming the approved EU BCR, and selections for type of UK BCR (controller or processor), BCR Members' decision process, which UK laws apply, and whether future updates to the Addendum will apply automatically; and Part 3 is a UK BCR Summary — a concise, data-subject-facing document setting out how personal data is processed under the UK BCR, the rights data subjects have, and how to enforce them.
The ICO guidance states that applicants using the UK BCR Addendum email the completed Addendum and requested documents to the ICO at [email protected]. The ICO guidance notes that all BCR Members must sign the Addendum, as it is structured as an intra-group agreement, and that the UK BCR Summary must be published alongside the EU BCR (or EU BCR summary) after approval. Organisations with existing UK BCR approval may also use the UK BCR Addendum if they wish to amend their UK BCR to align with an EU BCR.
Transitional BCRs approved under Directive 95/46/EC
Holders of EU BCRs for which the Information Commissioner issued an authorisation under Directive 95/46/EC before 25 May 2018 were automatically eligible for a UK BCR under paragraph 9, Part 3, Schedule 21 to the Data Protection Act 2018 (as amended from 1 January 2021). The ICO maintains a list of such BCRs on its website.
Transfer risk assessment requirement
The ICO guidance states that an exporter relying on BCRs must complete a transfer risk assessment (TRA) before making the restricted transfer. The ICO guidance notes that the TRA is a requirement under UK data protection laws, confirmed by the Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Case C-311/18, "Schrems II"), which established the role of risk assessments in the rules on restricted transfers. The ICO guidance instructs the exporter to consider whether, in the circumstances of the transfer and with the BCR in place, the relevant protections for people under the UK data protection regime will be undermined.
The ICO guidance identifies two broad types of risk the exporter must consider: risks arising in the destination country from third parties (in particular government and public bodies) accessing the information where they are not bound by the BCR — for example, surveillance laws, national-security access, or law-enforcement data requests that conflict with the BCR obligations; and risks arising from the receiver's own actions or practices, including whether the receiver's legal system provides effective and enforceable data-subject rights and effective administrative and judicial redress.
Where the TRA identifies conflicts between local law and the BCR obligations, the ICO guidance instructs the exporter to implement supplementary technical or organisational measures (for example, encryption, pseudonymisation, or contractual commitments to challenge government requests) where feasible, or to suspend or refrain from making the transfer where the BCR can no longer deliver appropriate safeguards. Article 47(2)(m) obliges the group to establish mechanisms for reporting to the ICO any legal requirements to which a member is subject in a third country that are likely to have a substantial adverse effect on the guarantees provided by the BCRs.
When to choose BCRs over IDTA or UK Addendum
BCRs are the preferred Article 46 safeguard for multinational groups making high-volume, repeated intra-group transfers where the group has a significant number of affiliates in non-adequate countries; the group wishes to centralise the transfer mechanism and compliance obligations in a single, group-wide policy rather than negotiating bilateral IDTAs or UK Addenda with each affiliate; or the group operates shared IT systems, centralised HR processing, or global customer-relationship-management platforms that involve continuous flows of personal data among group members.
Controllers and processors making ad hoc or one-off transfers to third-party recipients outside the group, or making transfers to a small number of group affiliates, will usually find the IDTA or UK Addendum faster and simpler to implement, as those mechanisms do not require ICO approval and can be executed immediately.
Interaction with adequacy regulations and other safeguards
Where a restricted transfer from the UK is destined for a third country covered by UK adequacy regulations under Article 45A, the exporter does not need to rely on BCRs (or any other Article 46 safeguard) for that transfer. BCRs are relevant only for transfers to countries or sectors not covered by adequacy. If an organisation holds approved UK BCRs but also makes transfers to third-party recipients outside the group, those third-party transfers require a separate Article 46 safeguard (typically an IDTA or UK Addendum with the third-party recipient) or reliance on an Article 49 derogation.
Source: UK General Data Protection Regulation, Article 46(2)(b) Source: UK General Data Protection Regulation, Article 47 (as amended by Data (Use and Access) Act 2025, Schedule 7 paragraph 7) Source: Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026 (S.I. 2026/82) Source: ICO, Guide to Binding Corporate Rules Source: ICO, What are binding corporate rules?
Binding corporate rules — Article 47 UK GDPR intra-group transfer mechanism
Binding corporate rules (BCRs) are an Article 46(2)(b) appropriate safeguard that multinational groups may use to authorise transfers of personal data from the UK to third countries within the same corporate group or group of enterprises engaged in a joint economic activity. Article 47 of the UK GDPR, as amended by the Data (Use and Access) Act 2025, provides the statutory framework for BCRs. The Information Commissioner's Office (ICO) describes BCRs as the "gold standard" transfer mechanism because they demonstrate the group's commitment to implementing comprehensive data-protection safeguards across its global operations. Unlike the UK International Data Transfer Agreement (IDTA) or the UK Addendum, which are bilateral contracts between two entities, a BCR is a single binding instrument that governs all intra-group transfers from the UK to third countries, reducing the administrative burden for groups that make many such transfers.
Statutory definition and scope — Article 4(20) and Article 47(1)
Article 4(20) UK GDPR defines "binding corporate rules" as personal data protection policies which are adhered to by a controller or processor established in the UK for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity. The scope covers both controller BCRs (UK BCR-C) for intra-group controller-to-controller transfers and processor BCRs (UK BCR-P) for intra-group processor-to-processor transfers or processor-to-controller transfers.
Article 47(1) UK GDPR provides that the Information Commissioner shall approve binding corporate rules, provided that they meet three conditions: (a) they are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees; (b) they expressly confer enforceable rights on data subjects with regard to the processing of their personal data; and (c) they fulfil the requirements laid down in Article 47(2).
Article 47(2) mandatory content requirements
Article 47(2) UK GDPR sets out thirteen mandatory elements that BCRs must contain. Controllers and processors preparing BCRs for ICO approval must address each element in the BCR policy, the binding instrument, or the application form. The mandatory requirements are:
- (a) Structure and contact details — the structure and contact details of the group of undertakings, or group of enterprises engaged in a joint economic activity, and of each of its members;
- (b) Data transfers — the data transfers or set of transfers, including the categories of personal data, the type of processing and its purposes, the type of data subjects affected, and the identification of the third country or third countries in question;
- (c) Legally binding nature — their legally binding nature, both internally and externally;
- (d) Data protection principles — the application of the general data protection principles, in particular purpose limitation, data minimisation, limited storage periods, data quality, data protection by design and by default, legal basis for processing, processing of special categories of personal data, measures to ensure data security, and the requirements in respect of onward transfers to bodies not bound by the binding corporate rules;
- (e) Data subject rights — the rights of data subjects in regard to processing and the means to exercise those rights, including the right to protection in accordance with Articles 22A to 22D (automated decision-making, as amended by the Data (Use and Access) Act 2025), the right to make a complaint to the controller under section 164A of the Data Protection Act 2018, the right to make a complaint to the Commissioner under section 165 of the 2018 Act, the right to lodge a complaint with a court in accordance with Article 79, and to obtain redress and, where appropriate, compensation for a breach of the binding corporate rules;
- (f) Liability and third-party beneficiary rights — the acceptance by the controller or processor established in the United Kingdom of liability for any breaches of the binding corporate rules by any member concerned not established in the United Kingdom; the controller or processor shall be exempt from that liability, in whole or in part, only if it proves that that member is not responsible for the event giving rise to the damage;
- (g) Data protection responsibilities — how the information on the binding corporate rules, in particular on the provisions referred to in points (d), (e) and (f) of Article 47(2) is provided to the data subjects in addition to Articles 13 and 14;
- (h) DPO or compliance function — the tasks of any data protection officer designated in accordance with Article 37 or of any other person or entity in charge of the monitoring compliance with the binding corporate rules within the group of undertakings, or group of enterprises engaged in a joint economic activity, as well as monitoring training and complaint handling;
- (i) Complaint procedures — the complaint procedures;
- (j) Change and update mechanisms — the mechanisms within the group of undertakings, or group of enterprises engaged in a joint economic activity for ensuring the verification of compliance with the binding corporate rules. Such mechanisms shall include data protection audits and methods for ensuring corrective actions to protect the rights of the data subject. Results of such verification should be communicated to the person or entity referred to in point (h) and to the board of the controlling undertaking of a group of undertakings, or of the group of enterprises engaged in a joint economic activity, and should be available upon request to the Commissioner;
- (k) Data subject information and cooperation — the mechanisms for reporting and recording changes to the rules and reporting those changes to the Commissioner;
- (l) Cooperation with supervisory authority — the cooperation mechanism with the Commissioner to ensure compliance by any member of the group of undertakings, or group of enterprises engaged in a joint economic activity, in particular by making available to data subjects the results of verifications of the measures referred to in point (j);
- (m) Reporting conflicting legal requirements — the mechanisms for reporting to the Commissioner any legal requirements to which a member of the group of undertakings, or group of enterprises engaged in a joint economic activity is subject in a third country which are likely to have a substantial adverse effect on the guarantees provided by the binding corporate rules; and
- (n) Data protection training — the appropriate data protection training to personnel having permanent or regular access to personal data.
ICO approval pathways — traditional UK BCR application or UK BCR Addendum
The ICO offers two distinct pathways for obtaining a UK BCR approval, depending on whether the group already holds an approved EU BCR:
Traditional UK BCR application Groups without an existing EU BCR, or groups that prefer a standalone UK BCR, must submit a comprehensive application pack to the ICO comprising (i) a completed application form; (ii) a BCR Policy document (which the ICO expects the group to publish in full to provide data subjects with key Article 47 information about their data and its transfers); (iii) a binding instrument (such as an intra-group agreement or IGA) that is legally binding on all group members and confers enforceable third-party beneficiary rights on data subjects; (iv) a completed ICO UK BCR Referential Table indicating where in the documentation each Article 47(2) requirement is met; and (v) any supporting policies, procedures, or audit reports. The ICO's detailed controller guidance and processor guidance, each comprising 11 and 13 sections respectively, set out the ICO's expectations for each element. The ICO states that it will seek assurances during the approval process that the UK entity (or entities, in an exporting entity model where multiple UK legal entities transfer under the same BCR with separate liability models) has or can call on sufficient assets to meet liabilities under the BCR.
UK BCR Addendum Groups that already hold an approved EU BCR may apply for a UK BCR by adding the UK BCR Addendum (version C.1.0, issued 19 December 2023) onto the approved EU BCR, together with a UK BCR Summary providing information to data subjects (and, for processor BCRs, to third-party exporters). The UK BCR Addendum incorporates and extends the scope of the EU BCR to include UK restricted transfers, and becomes the UK binding instrument enforceable in the UK. The ICO states that the Addendum "contains all relevant provisions of Article 47 UK GDPR, meaning that your EU BCR will work in the UK." This pathway avoids unnecessary duplication for groups that seek both EU and UK BCR approvals.
Transfer risk assessment — mandatory even with approved BCRs
The ICO guidance confirms that relying on a UK BCR does not eliminate the requirement to conduct a transfer risk assessment (TRA) for each restricted transfer or type of transfer. A group may make a restricted transfer within its approved UK BCR only if (i) both the exporter and the receiver are part of the group's approved UK BCR, and (ii) the exporter (or the group on behalf of its members) has completed a TRA to ensure that the standard of protection for people's information is not materially lower after the transfer. The ICO recognises that in practice the group may have completed a single overarching TRA that covers multiple restricted transfers of the same type, rather than conducting a fresh TRA for each individual transfer.
The TRA requirement for BCRs flows from the Court of Justice of the European Union's judgment in Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Case C-311/18, judgment of 16 July 2020, known as "Schrems II"), which the ICO confirms remains applicable to the UK. The ICO controller guidance and processor guidance both emphasise the importance of Schrems II and the necessity of undertaking a TRA as one of the overarching principles of Article 47 UK GDPR. Where the TRA identifies conflicting legal requirements in the third country — for example, government surveillance laws or law-enforcement data requests that would override the BCR's data-subject-rights protections — the group must implement supplementary technical or organisational measures (such as encryption, pseudonymisation, or contractual commitments to challenge requests), or suspend or refrain from making the transfer if the BCR can no longer deliver appropriate safeguards. Article 47(2)(m) obliges the group to establish mechanisms for reporting such conflicting legal requirements to the ICO.
Post-approval obligations and ongoing monitoring
Once the ICO approves a UK BCR, the group must maintain ongoing compliance with the BCR's terms and Article 47(2) requirements. The BCR must include mechanisms for data protection audits, corrective actions, and verification of compliance (Article 47(2)(j)), and the group must report changes to the BCR to the ICO (Article 47(2)(k)). The ICO expects the group to cooperate with the ICO to ensure compliance by all group members and to make audit results available to data subjects upon request (Article 47(2)(l)). The ICO guidance notes that approved BCRs remain subject to ongoing ICO oversight and review, and the Commissioner retains the power under Article 58 UK GDPR to order suspension of data flows or to impose administrative fines under Article 83 if the BCR is breached or if the group fails to maintain the required standard of protection.
BCRs approved under UK GDPR
The ICO maintains a public list of BCRs approved under UK GDPR. As of June 2026, the list includes multinational groups across sectors including technology, telecommunications, and financial services. Organisations holding EU BCRs that were authorised under Directive 95/46/EC (the predecessor to the EU GDPR) were automatically eligible for a UK BCR under paragraph 9, Part 3, Schedule 21 to the Data Protection Act 2018 (as amended from 1 January 2021), subject to producing a UK version of their BCRs incorporating the changes required by Brexit and providing the amended documentation to the ICO.
Source: UK General Data Protection Regulation, Article 47 (as amended by Data (Use and Access) Act 2025, Schedule 7 paragraph 7) Source: UK General Data Protection Regulation, Article 4(20) (definition of binding corporate rules) Source: ICO, Guide to Binding Corporate Rules Source: ICO, UK BCR Addendum Source: Data Protection Act 2018, Schedule 21 paragraph 9 (transitional provision for EU BCRs)
Transfer risk assessment (TRA) — UK requirement for restricted transfers under Article 46 safeguards
For restricted transfers of personal data from the UK to third countries using Article 46 appropriate safeguards—such as the UK International Data Transfer Agreement (IDTA), UK Addendum to the EU SCCs, or binding corporate rules (BCRs)—the Information Commissioner's Office (ICO) requires exporters to conduct a transfer risk assessment (TRA). This expectation is grounded in regulatory guidance and reflects the principles set out by the Court of Justice of the European Union (CJEU) in Schrems II (Case C-311/18), although neither UK GDPR Article 46 nor the Data Protection Act 2018 expressly mandates a TRA by name.
Origin and authority chain The obligation to carry out a TRA in the UK arises from the ICO's "Transfer Risk Assessments" guidance, last updated March 2022, now found at the current ICO international transfers guidance portal. This guidance interprets the requirement for appropriate safeguards in Article 46 UK GDPR in light of external legal developments, notably Schrems II, which held that exporters relying on SCCs (and, by extension, similar mechanisms) must ensure the transferred data receives protections essentially equivalent to those in the originating jurisdiction. The ICO, while departing from the EU's “essential equivalence” test, makes clear that a TRA is a regulatory expectation underpinning any decision to transfer under Article 46.
TRA process under UK law The ICO's approach is risk- and outcomes-focused, and companies may use the ICO's model TRA tool or adopt a methodology inspired by the EU Data Protection Board's TIA recommendations. The ICO’s model is structured to:
- Identify parties, data types, and transfer context,
- Assess whether people may be harmed by the transfer,
- Examine destination-country laws and practices (including government or state access rights), and
- Evaluate contractual, technical, and organisational measures (such as encryption or minimisation) to mitigate risks.
Unlike the EU TIA, the UK’s TRA does not require an "essential equivalence" standard but asks whether the protection is not materially lower than the UK standard. Where risks are unmitigable or the necessary protections cannot be achieved, the exporter is expected not to proceed with the transfer using Article 46 safeguards.
Documentation and review The ICO explicitly requires organisations to record the outcome of their TRA and explain the rationale for their decision. Maintaining evidence of regular reviews is expected for ongoing or repetitive transfers. Persistent failure to conduct and document a TRA may result in regulatory intervention under the ICO’s investigative and corrective powers; however, the legal foundation for fines and formal action comes from the enforcement framework in Article 58 and penalty provisions in Article 83 of the UK GDPR.
Practitioners exporting personal data from both the UK and EU must perform both a UK TRA and an EU TIA—each regime has specific expectations and standards, and the results may differ even if the underlying risks are similar.
Source: ICO, Completing a transfer risk assessment Source: UK GDPR Article 46 Source: ICO International transfers — Appropriate safeguards
Onward transfers by importers — requirements for further exports under UK Article 46 safeguards (IDTA, Addendum, BCRs)
When a UK controller or processor transfers personal data to a non-adequate country using an Article 46 safeguard, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or approved Binding Corporate Rules (BCRs), legal obligations attach to how the importer in the destination country may further disclose (onward transfer) that data to other parties or jurisdictions. UK law and ICO guidance provide that onward transfers are only permitted if certain requirements are met—designed to maintain a consistent level of protection along the full chain of data recipients.
IDTA and UK Addendum: onward transfer constraints
- The IDTA (Section 16) and the UK Addendum require that an importer (recipient in the initial restricted transfer) must not onward transfer UK personal data to a new third-country controller or processor unless one of the following applies:
- The onward recipient enters into an agreement imposing data protection terms at least equivalent to those in the IDTA or Addendum;
- The onward transfer is covered by an alternative Article 46 safeguard (for example, Binding Corporate Rules covering both importer and onward recipient);
- The transfer qualifies for a specific Article 49 derogation (such as explicit consent or vital interests), as outlined in the UK GDPR and confirmed by ICO guidance; these are strictly limited exceptions.
- Section 16.2 IDTA prohibits onward transfers where these conditions are not met. The obligation falls contractually on the importer, but ICO guidance states the UK-based exporter should verify these provisions are present in the transfer agreement.
- Both the IDTA and Addendum emphasize that onward transfers must not undermine the original level of data protection and must be covered by an appropriate legal mechanism whenever data leaves the importer or is further exported.
Binding Corporate Rules: intra-group onward transfers
- UK BCRs (Article 47(2)(d) UK GDPR) must contain clear rules on onward transfers to entities outside the BCR group. A BCR member can onward transfer personal data to a non-member only if the onward recipient is bound by BCRs, a contract providing equivalent safeguards (such as the IDTA), or if a derogation under Article 49 applies.
- The ICO's BCR Referential Table and guidance confirm that such mechanisms for onward transfer must be included in the BCR approval package, and assurance of comparable protection is required before data is further disclosed outside the approved group.
Practical responsibilities and documentation
While the initial UK exporter is responsible for ensuring the Article 46 safeguard is in place, the onward transfer duties attach to the importer under the terms of the UK-approved contract or policy. The ICO recommends, and the IDTA formalizes, routine documentation of all transfers and the safeguards used for any further export. Routine re-assessments (such as a transfer risk assessment) may be required if the legal environment for onward transfers changes or a new recipient is added.
Breaches of onward transfer clauses or failure to use a required safeguard may result in enforcement under Article 58 and penalty provisions under Article 83 UK GDPR.
Source: UK International Data Transfer Agreement (IDTA) Source: ICO, What are standard data protection clauses (the UK IDTA and the Addendum)? Source: ICO, Guide to Binding Corporate Rules Source: UK General Data Protection Regulation, Article 47(2)(d)
Enforcement and penalties for breach of UK international transfer restrictions — Article 83 UK GDPR and DPA 2018
The United Kingdom enforces its international transfer rules under Chapter V of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) with a full suite of investigative, corrective, and punitive powers. Controllers and processors that make restricted transfers without a valid legal mechanism—such as adequacy regulations, Article 46 safeguards, or enumerated Article 49 derogations—face both administrative fines and corrective orders from the Information Commissioner’s Office (ICO).
Investigatory and corrective enforcement by the ICO The ICO, as the UK supervisory authority, has explicit authority under Article 58 UK GDPR to investigate, audit, order suspensions, and issue warnings, reprimands, and bans on processing—including the power to suspend international data flows (Art. 58(2)(f)). The enforcement toolkit is extended by DPA 2018 sections 149–152 (enforcement notices), 146–148 (assessment notices, including audits), and 155–156 (penalty notices). It is a criminal offence not to comply with certain ICO notices (s.156 DPA 2018).
Fine structure — Article 83(5) and DPA 2018 Breaches of Chapter V transfer restrictions fall in the upper fine tier: the ICO may impose an administrative fine of up to the greater of £17.5 million or 4% of annual worldwide turnover (Art. 83(5)(c) UK GDPR, as incorporated by s.155 DPA 2018). The ICO must consider detailed aggravating and mitigating factors listed in Article 83(2), such as the nature and gravity of breach, intent, precedent, cooperation, and remedial steps. For less fundamental violations, lower-tier fines (up to £8.7 million or 2% turnover under Article 83(4)) may apply.
Practical enforcement posture The ICO routinely publishes enforcement notices, reprimands, and penalties for breaches, including for unlawful or insufficiently protected international transfers. Publicly available actions and full notices are published on the ICO enforcement actions register. Practitioners should check for case-specific guidance on scope and aggravating factors in recent ICO actions: see ICO – action we’ve taken. (Where a specific notice or fine is referenced in compliance documentation, ensure it is directly accessible from this register.)
Private remedies and representative actions Individuals whose rights are infringed may seek compensation through UK courts under Article 82 UK GDPR and ss.168–169 DPA 2018. Representative actions (s.187 DPA 2018) are possible if authorized by the court, typically for claims about damage or distress, though UK law limits such collective actions to proceedings receiving explicit court approval—these remain rare in practice.
Regulatory guidance and evolving standards While the legal text of the UK GDPR and DPA 2018 does not expressly require a “transfer risk assessment” (TRA), the ICO expects exporters relying on Article 46 safeguards to complete a TRA as set out in official guidance—this expectation is not black-letter law but is treated as best practice and may impact regulatory decision-making (see ICO guidance linked below). The ICO continues to reference CJEU decisions like Schrems II when determining UK post-Brexit standards for risk assessment and safeguards, but such rulings are formally persuasive, not binding.
Update: Broken Link Repaired (July 2026) The previous citation for the ICO's transfer risk assessment guidance was dead; it has now been updated to the current official location.
Source: UK General Data Protection Regulation, Article 83 Source: Data Protection Act 2018, s.149–152, s.155–156, s.168–169 Source: ICO – Regulatory action policy and enforcement notices Source: ICO, Transfer risk assessments Source: UK GDPR Article 46
UK–US Data Bridge — scope, certification, and compliance under the UK Extension to the EU-US Data Privacy Framework
The UK–US Data Bridge (formally, the "UK Extension to the EU-US Data Privacy Framework") enables UK organisations to transfer personal data to certified US organisations without needing further contractual safeguards, provided the transfer falls within the Extension’s scope. This mechanism became operative on 12 October 2023, following the entry into force of the Data Protection (Adequacy) (United States of America) Regulations 2023 (SI 2023/1028), made under Article 45A of the UK GDPR.
Scope and eligible recipients Only US organisations that are (a) self-certified to the EU-US Data Privacy Framework and (b) appear on the UK Extension list (as maintained by the US Department of Commerce – DPF List) are eligible for adequacy under the UK regime. UK exporters must confirm that the intended data recipient is listed for the UK Extension prior to transfer. Certification to the EU DPF is not sufficient—participation in the UK Extension is a separate, affirmative step. US public sector entities are not eligible, and some categories of data (e.g., HR data when used outside the employment context) are excluded.
Distinctions from EU DPF and sectoral limitations Although the UK Extension closely mirrors the requirements and principles of the EU-US DPF, the UK adequacy regulations are a separate legal instrument, and only organisations on the UK Extension list qualify for frictionless UK transfers. The extension does not cover data that is outside the scope of the UK GDPR (such as certain financial services data covered by parallel regimes). If the data includes special categories (Art 9 UK GDPR), exporters must verify that US recipients provide the supplemental protections required under DPF and UK rules.
Practical verification and compliance steps The Information Commissioner’s Office (ICO) mandates that UK exporters: (1) verify current certification (using the DPF List), (2) confirm the data is within the coverage of both the UK GDPR and DPF Principles, (3) document the basis for the adequacy reliance in the organisation’s transfer records, and (4) monitor the recipient’s certification status for the duration of the transfer. If certification lapses or is revoked, continued transfers require an appropriate safeguard under Article 46 or, if applicable, a derogation under Article 49 UK GDPR.
Monitoring, redress, and complaints The Department for Science, Innovation and Technology (DSIT) monitors adequacy-related developments. Complaints concerning a recipient under the UK Extension should be routed through the mechanisms published by the US Department of Commerce, with oversight by the ICO and relevant US authorities (FTC, DoT). If persistent issues arise regarding US law or enforcement, the Secretary of State/DSIT retains the power to review or suspend the adequacy determination.
Source: Data Protection (Adequacy) (United States of America) Regulations 2023 Source: ICO, How does the UK Extension to the EU-US Data Privacy Framework work? Source: ICO, Adequacy regulations — list of countries and territories
Supplementary measures for international transfers — ICO expectations post-Schrems II (encryption, pseudonymisation, legal remedies)
Controllers and processors transferring personal data from the UK to third countries using Article 46 appropriate safeguards—such as the International Data Transfer Agreement (IDTA), Addendum to the EU SCCs, or binding corporate rules (BCRs)—must assess whether those safeguards alone are sufficient to protect data to the UK standard.
The Information Commissioner's Office (ICO) guidance, citing the CJEU’s Schrems II decision (Case C-311/18, 16 July 2020), requires exporters to consider "supplementary measures" where the legal or practical environment in the destination country could undermine the chosen safeguard. The ICO's standard differs from the EU's "essential equivalence" test: UK law applies a "not materially lower" threshold, and the transfer risk assessment (TRA) must determine if the Article 46 safeguard alone provides adequate protection. If risks remain, exporters should work with importers to implement supplementary technical, contractual, or organisational measures.
ICO examples of supplementary measures Per ICO guidance, such measures may include:
- Technical: End-to-end encryption (with keys retained by the UK exporter or a trusted UK party), strong pseudonymisation, minimisation of data categories, and access controls. Encryption is most effective where it prevents the importer or third parties (such as state authorities) from accessing the data in intelligible form.
- Contractual: Clauses obliging importers to notify the exporter of government access requests, to legally challenge such requests, to enable audits, and to require express approval for onward transfers. These are recommended to supplement, not replace, baseline IDTA or Addendum clauses where the TRA identifies risks.
- Organisational: Policies and training for staff, documented procedures for handling access requests, internal compliance reviews, and regular reassessment of the legal environment in the destination country.
The ICO notes that for some recipient countries—especially where surveillance or lack of effective legal redress for data subjects exists—technical measures (such as robust encryption) may be the only effective safeguards. If supplementary measures cannot sufficiently address the risk, the ICO guidance states the exporter should not proceed with the transfer under Article 46.
Documentation and ongoing review Exporters must document any supplementary measures in the TRA, be able to justify their effectiveness, and keep this under review for ongoing or repeated transfers. Where legal or practical risks change, the ICO expects re-evaluation of the safeguards and supplementary measures. Enforcement is risk-based, and failure to assess or apply suitable supplementary measures may trigger corrective powers or fines under Article 58 or 83 UK GDPR.
EDPB Recommendations 01/2020 remain persuasive in shaping the UK approach, but are not binding UK law. ICO guidance reflects the UK regime as of 2026, informed by recent regulatory and judicial decisions.
Source: ICO, Completing a transfer risk assessment — Supplementary measures Source: ICO, Appropriate safeguards — Supplementary measures section
What counts as a 'restricted transfer' under UK GDPR? Definition, scope, and edge cases (remote access, processors, cloud)
A 'restricted transfer' under the UK General Data Protection Regulation (UK GDPR) takes place whenever personal data is sent, disclosed, or otherwise made available to a recipient outside the UK (a “third country”) or to an international organisation, and the transfer meets the requirements of Chapter V. The latest Information Commissioner’s Office (ICO) guidance (January 2026) and legislative updates provide an authoritative three-step test and clarify several long-standing edge cases, particularly around remote access and the definition of a separate legal entity.
Three-step legal test (ICO 2026 guidance and statutory basis) As of the January 2026 ICO guidance, a transfer is 'restricted' only if all three conditions apply:
- The UK GDPR applies to the processing of the personal data.
- The personal data is sent, disclosed, or made accessible to a receiver outside the UK (in a third country or to an international organisation).
- The receiver is a separate legal entity from the sender (for example: a non-UK processor, controller, cloud provider, affiliate, or contractor). If the recipient is not a separate legal entity—such as an overseas employee of the same UK company—this step is not met and the transfer is not 'restricted'.
Statutory context: Data (Use and Access) Act 2025 & 'data protection test' The Data (Use and Access) Act 2025, Schedule 7, reformed Chapter V of the UK GDPR. The key statutory addition is the 'data protection test': under Article 45B(1), the Secretary of State may only approve overseas data transfers via adequacy regulations where "the standard of the protection provided for data subjects with regard to general processing of personal data in the country or by the organisation is not materially lower than the standard of the protection provided for data subjects" by UK GDPR and relevant Parts of the Data Protection Act 2018. In practice, the ICO guidance continues to reference the 'transfer risk assessment' (TRA) model, but notes that the statutory term is now the 'data protection test'.
Edge case clarifications and current ICO position
- Remote access by employees or branch staff of the same UK legal entity, even where those staff are overseas, does NOT trigger a restricted transfer—this is a new explicit point per ICO's January 2026 update, reflecting a change from earlier common interpretations.
- Sharing with an overseas contractor, partner, processor, affiliate or any other separate legal entity abroad remains a restricted transfer, triggering Chapter V compliance (via adequacy, appropriate safeguard, or a derogation).
- Physical server location is not determinative: the decisive factor is whether a separate legal entity outside the UK can access or process the data. As per the ICO: "It is about making data accessible to someone outside the UK, not just where your servers are physically located."
- Transfers from a UK-based processor to a non-UK subprocessor, as well as onward transfers by a non-UK importer to other third country entities, are restricted transfers under both statutory rules and ICO guidance.
Cautious approach for ambiguous scenarios The ICO explicitly states: "If you are unsure whether your data flow is a restricted transfer, we recommend you treat it as one and document your reasoning." This remains good practice for risk management and compliance documentation.
Exclusions and scope notes
- Transfers of data solely within the UK (including England, Scotland, Wales, Northern Ireland) are not restricted transfers.
- Transfers from the EEA to the UK are subject to the EU GDPR, not the UK GDPR.
- For entities relying on guidance published before January 2026, the new express clarification regarding remote overseas employee access may affect your previous analysis.
Material change: This section incorporates statutory and guidance-based updates effective January 2026, especially the expanded legal entity distinction for remote access. Previous guidance was silent or ambiguous on this point.
Source: ICO, What is a restricted transfer? (January 2026 update) Source: UK General Data Protection Regulation, Chapter V Source: Data (Use and Access) Act 2025, Schedule 7
Record-keeping for international transfers — Article 30 UK GDPR and ICO documentation expectations
Controllers and processors subject to the UK General Data Protection Regulation (UK GDPR) must keep detailed records of international transfers of personal data—these duties are set out in Article 30 (Records of Processing Activities, “ROPA”), reinforced by the Information Commissioner’s Office (ICO) guidance. Article 30(1) requires controllers (and, with limitations, processors) to document not only what data is processed, but also the fact of any “transfers of personal data to a third country or an international organisation,” the identification of those destinations, and “the documentation of suitable safeguards” relied upon under Article 46 or Article 49.
What must be recorded?
- Name the third country or international organisation to which data is transferred (Art 30(1)(e)).
- Identify which legal basis or safeguard applies to each restricted transfer (e.g., adequacy under Article 45A, UK IDTA, BCRs, or a derogation under Article 49 as amended).
- Where appropriate, include a description of the safeguards (copies of IDTAs/Addenda/BCRs, summary of derogation, or—if used—documented supplementary measures).
- For processors, Article 30(2) requires substantially the same transfer recording for processing carried out on behalf of another controller.
- The ICO’s guidance expects that any supporting documentation—such as transfer risk assessments, legal analysis, or correspondence about supplementary measures—is retained and linked to the record of processing for that transfer category.
Practical overlays
- The obligation applies even if only one-off or occasional restricted transfers take place, and regardless of volume. The ICO interprets the “fact of transfer” to include remote access from abroad and cloud-based disclosures (see ICO’s official examples).
- For organisations employing Article 46 appropriate safeguards, the ROPA must specify which safeguard applies to each transfer or transfer category and include a reference (contract name/number, location, and parties) and—where applicable—the outcome of the required transfer risk assessment (TRA).
- Where an Article 49 derogation is relied upon, the controller must record the justification and details explaining why no other transfer mechanism could be used, consistent with ICO guidance.
- Transfers covered by adequacy regulations require recording the destination and that the basis is adequacy. It is best practice to reference the adequacy regulation number or the ICO’s up-to-date adequacy register.
Retention and access The ROPA and all supporting transfer documentation must be retained, kept accurate and current, and be available to the ICO upon request (UK GDPR Art 30(4)). Failure to maintain these records can result in regulatory investigation and, for substantive or persistent breaches, attract the full penalty and enforcement powers outlined elsewhere in this guide.
Source: UK GDPR, Article 30 (Records of processing activities) Source: ICO, Documentation – international transfers and restricted transfers
Transfers to non-UK processors — mandatory Article 28 clauses and ICO expectations for processor contracts
When a UK-based controller transfers personal data to a processor located outside the UK (“third country”), this is a ‘restricted transfer’ under Chapter V of the UK General Data Protection Regulation (UK GDPR). Two legal requirements are triggered: a valid transfer mechanism under Article 46 (such as the UK International Data Transfer Agreement (IDTA) or Addendum) and a contract meeting Article 28 UK GDPR (processor contract) requirements.
Article 28 processor contract requirements Under Article 28(3) UK GDPR, controllers must have a binding contract with any processor processing personal data on their behalf, whether that processor is inside or outside the UK. For non-UK processors, Article 28 applies in addition to any international transfer mechanism such as the IDTA. The contract must specify:
- The subject-matter, duration, nature, and purpose of processing, types of personal data and categories of data subjects, and the controller’s obligations and rights (Art 28(3)).
- That the processor shall only process personal data on documented instructions from the controller, including in relation to further transfers (“onward transfers”) to a third country (Art 28(3)(a) combined with Art 46(2)).
- Confidentiality, security, data-subject rights assistance, subprocessor approval and flow-down, return/erasure at contract end, and audit/cooperation (Art 28(3)(b)-(h)).
Overlay of Article 46 transfer mechanism In addition, when transferring to a non-UK processor, the controller must execute the IDTA or UK Addendum to the EU SCCs (Article 46(2)(d)), or use another UK-approved safeguard. The ICO’s guidance confirms that the existence of an IDTA alone does not substitute for the separate obligation to have an Article 28-compliant contract. Controllers must therefore ensure that the necessary Article 28 clauses are included in, or operate alongside, the Article 46 agreement, and that subprocessor arrangements (onward transfers) also meet these standards.
ICO guidance and practical expectations The Information Commissioner’s Office (ICO) guidance instructs controllers to:
- Include the Article 28 clause set in the contract used for international transfers, alongside the IDTA or Addendum. If two documents are used, they must not contradict each other;
- Ensure explicit written authorisation for subprocessors and flow-down of obligations (see ICO guidance, section "Sub-processors and restricted transfers");
- Maintain records of all such restricted transfers and contracts as part of their Article 30 documentation.
The ICO also states that failure to satisfy Article 28 and Article 46 may result in corrective or enforcement action under the powers in UK GDPR Articles 58 and 83, if the Commissioner considers a controller has failed in its obligations.
Source: UK GDPR, Article 28 (Processor requirements) Source: UK GDPR, Article 46 (Transfer mechanisms) Source: ICO, What must you include in the contract with the processor?