Artifact GuideUKAdequacy

UK GDPR Adequacy

A UK transfer approval is usable only when regulations in force cover the exact destination and transfer. Record the scope check before treating Article 45A as the transfer route.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

Since 5 February 2026, Article 45A calls this route a . The familiar term 'adequacy' is still useful, but the binding test is now in Article 45B: protection for people must not be materially lower than UK protection when considered as a whole. Check the exact destination, recipient, data and sector covered by the regulations before relying on them.

Section 1

What is a UK GDPR adequacy decision, and why does it matter for international transfers?

Under Articles 45A-45C, the Secretary of State may approve transfers to a third country or international organisation by regulations after applying the Article 45B data protection test. Approval may cover all transfers or only specified transfers, including a sector, geographic area, recipient, data type, exporter or transfer method.

If approval regulations cover the transfer, Article 44A does not require an Article 46 safeguard or Article 49 derogation for that transfer. The exporter and recipient still have to meet all other applicable UK GDPR duties, including lawful processing, transparency, security, processor terms, and accountability.

  • Confirm that personal data is being transferred to a third country or international organisation; remote access or onward disclosure can matter even when storage remains in the UK.
  • Identify the approval regulations in force, not only a policy announcement or adequacy assessment.
  • Match the country or organisation, recipient class, sector, geographic area, data type, exporter, and transfer method to any limits in the regulations.
  • Keep the regulations, official published-list check, scope analysis, destination and recipient, date checked, owner, and review trigger.
  • If approval does not cover the transfer, assess Article 46 safeguards or a fact-specific Article 49 derogation and check any Article 49A restriction.
Section 2

Who should own an adequacy decision, and what evidence should prove the decision?

The exporter remains responsible for choosing and documenting the route. Privacy or legal should verify the regulations and their current scope; the business owner should identify the recipient, destination, purpose and onward-transfer path; procurement should confirm the contracting entity; and security should confirm the actual access and hosting arrangement.

Evidence should identify the transfer, exporter, importer, destination, approval regulations, effective status, every applicable scope condition, date checked, reviewer and change trigger. Keep a copy or stable link to the regulations and the Article 45C published-list result, not only a vendor statement that the destination is 'adequate.'

  • Identify the legal recipient, because approval for one scheme, sector or certified organisation does not automatically cover another recipient in the same country.
  • Record whether the transfer includes special-category or criminal-offence data and whether the approval regulations impose a data-type limit.
  • Record remote access, support access, subprocessors and onward transfers rather than checking only the primary storage country.
  • Recheck before a new recipient, country, sector, data type, transfer method or onward transfer is added, and when the approval regulations or Article 45C list changes.
Section 3

What should teams check before relying on an adequacy decision?

Before using this route, confirm that the approval regulations are in force, that the destination appears on the current list published under Article 45C, and that the transfer matches every scope limit. Article 45C requires ongoing government monitoring and amendment or revocation where the data protection test is no longer met.

If the destination is only partly covered, or if the approval has been amended or revoked, the uncovered transfer needs another Article 44A route before it proceeds. A government review alone does not change the legal route unless the regulations or their status change, but it is a reason to monitor the record closely.

  • Check whether the approval is country-wide, sector-specific, territory-specific, recipient-specific, data-specific, exporter-specific, scheme-based, or limited by transfer method.
  • For example, the UK-US data bridge described by the government covers transfers to US organisations participating in the UK Extension to the Data Privacy Framework; a US location alone is not enough.
  • Separate approval regulations from Article 46 safeguards such as the IDTA, UK Addendum, binding corporate rules, approved codes, or certification, and from Article 49 derogations.
  • Do not rely on an older approval if the destination, scope, or review status has changed.
  • Do not treat a data bridge as reciprocal: approval for UK exports says nothing by itself about transfers into the UK or exports from another jurisdiction.
  • Do not use a narrow Article 49 derogation as the default route for regular transfers; document its specific conditions and any Article 49A restriction.
Section 4

How should teams use adequacy in day-to-day transfer planning?

Use Article 44A as the route map: a transfer needs approval under Article 45A, appropriate safeguards under Article 46, or a specific Article 49 derogation, and it must not breach a restriction under Article 49A. Approval under Article 45A removes the need for an Article 46 safeguard for the covered transfer, but not the rest of UK GDPR.

Approve the route only after matching the real transfer to the regulations. If approval does not cover it, stop that branch and assess Article 46 safeguards or a fact-specific Article 49 derogation. Keep the transfer record linked to the Article 30 entry, contract, privacy information, security assessment and onward-transfer controls.

  • Input: exporter, importer, countries, access locations, personal-data categories, people, purpose, systems, transfer method, subprocessors and onward recipients.
  • Approval branch: cite the Article 45A regulations, match every scope condition, record the Article 45C list check, and retain the dated decision.
  • Safeguards branch: identify the Article 46 instrument and document the reasonable and proportionate data-protection-test assessment required by the current Article 46.
  • Derogation branch: identify the exact Article 49 condition, explain why it applies to this transfer, and check whether Article 49A restricts reliance on it.
  • Review branch: reopen the decision when the transfer facts, recipient participation or certification, regulations, published list, or onward-transfer chain changes.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding route map requiring approval regulations, Article 46 safeguards, or an Article 49 derogation and compliance with any Article 49A restriction.
legislation.gov.uk
Referenced sections
  • Binding current source for approval regulations, Article 46 safeguards, Article 49 derogations, Article 49A restrictions, and Article 45C monitoring.
legislation.gov.uk
Referenced sections
  • Articles 44A-49A are the binding current transfer provisions, including approvals by regulations and the data protection test.
"the standard of the protection provided for data subjects"
edpb.europa.eu
Referenced sections
  • EU operational background only; UK exporters must apply the current UK statutory route and approval regulations.
assets.publishing.service.gov.uk
Referenced sections
  • UK government guidance for Adequacy assessments and international data transfer context.
"This Guidance is intended to assist with this process"
gov.uk
Referenced sections
  • Official example of a scheme-limited approval: the UK-US bridge applies to participating certified US organisations, not every US recipient.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.