Cross-Border Data Transfer
UK GDPR — restricted transfers of personal data
United Kingdom · January 1, 2021; IDTA and UK Addendum from March 21, 2022; DUAA data protection test from February 5, 2026
The UK's structure mirrors Chapter V, but the instruments and the risk test are its own. Transfers rely on UK adequacy regulations, or on the ICO's International Data Transfer Agreement (or the UK Addendum bolted onto the EU SCCs), backed by a transfer risk assessment. The Data (Use and Access) Act 2025 changed the test rather than the mechanism: from February 5, 2026, new transfers must be assessed against a statutory 'data protection test' — whether the standard of protection in the destination is not materially lower than under UK law — which the exporter applies acting reasonably and proportionately. That is a deliberately less absolute standard than the EU's essential-equivalence test, and it is the clearest current point of divergence between the two regimes. Transfer mechanisms validly entered into before commencement remain effective; the ICO has signalled refreshed IDTA and Addendum templates during 2026, so template suites will need revisiting.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.