WorldPrivacyAtlas
Laws by country

Cross-Border Data Transfer

UK GDPR — restricted transfers of personal data

UK GDPR Chapter V / IDTA

United Kingdom · January 1, 2021; IDTA and UK Addendum from March 21, 2022; DUAA data protection test from February 5, 2026

The UK's structure mirrors Chapter V, but the instruments and the risk test are its own. Transfers rely on UK adequacy regulations, or on the ICO's International Data Transfer Agreement (or the UK Addendum bolted onto the EU SCCs), backed by a transfer risk assessment. The Data (Use and Access) Act 2025 changed the test rather than the mechanism: from February 5, 2026, new transfers must be assessed against a statutory 'data protection test' — whether the standard of protection in the destination is not materially lower than under UK law — which the exporter applies acting reasonably and proportionately. That is a deliberately less absolute standard than the EU's essential-equivalence test, and it is the clearest current point of divergence between the two regimes. Transfer mechanisms validly entered into before commencement remain effective; the ICO has signalled refreshed IDTA and Addendum templates during 2026, so template suites will need revisiting.

UK GDPR, Arts. 44-49; International Data Transfer Agreement and UK Addendum to the EU SCCs (in force March 21, 2022); Data (Use and Access) Act 2025Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.