How do we decide whether adequacy covers a transfer?
First apply the ICO's restricted-transfer test: UK GDPR applies to the processing, your organisation initiates a transfer to an organisation outside the UK, and the recipient is a separate legal entity. If all three conditions are met, check the current ICO adequacy list and the underlying regulation.
Match the destination, territory, sector, recipient, data type, and any eligibility conditions. Record the regulation and date checked. If adequacy covers the transfer, no Article 46 safeguard or TRA is required, but the lawful basis, transparency, security, processor, rights, minimisation, and accountability duties still apply.
- Map the sender, recipient, locations, roles, data, purpose, access method, and onward transfers.
- Record why the movement is a before selecting adequacy or another Chapter V route.
- Check whether the regulation gives full or and whether every scope condition is met.
- For Canada, confirm the transferred information is subject to PIPEDA; for Japan, confirm the recipient and information fall within the APPI scope described by the decision.
- For the United States, confirm the recipient participates in and is eligible for the to the EU-US Data Privacy Framework.
Provides the current UK adequacy list, distinguishes full and partial adequacy, and explains the Canada, Japan, South Korea, and US scope conditions.
Sets out the current three-step test for deciding whether the UK GDPR transfer rules apply.