Artifact GuideUKIDTA addendum and transfer risk assessment

UK GDPR IDTA addendum and transfer risk assessment

Use the UK Addendum with qualifying EU standard contractual clauses or use the standalone IDTA, then document the Article 46 data protection test and any additional measures.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

For a that needs an Article 46 safeguard, use the when the European Commission's 2021 standard contractual clauses are already part of the contract, or use the standalone when that structure fits better. Since 5 February 2026, Article 46 calls the required transfer risk assessment the . The sender must decide, acting reasonably and proportionately, that the safeguard and any other measures leave protection after transfer not materially lower than UK protection.

Section 1

How should an IDTA addendum and transfer risk assessment workflow run under the UK GDPR?

First confirm that the data flow is a and is not covered by current Article 45A approval regulations. Check whether a specific Article 49 exception applies; these exceptions are fact-dependent and are not a routine substitute for Article 46 safeguards. Then select the standalone International Data Transfer Agreement () or the International Data Transfer to the EU Commission's standard contractual clauses (UK Addendum).

Use the only when the European Commission's 4 June 2021 EU standard contractual clauses are part of the arrangement and their modules match the parties' roles. EU SCCs alone are not a UK safeguard. Use the when a standalone UK instrument fits the transfer. The choice is contractual, not a hierarchy: the Addendum often reduces duplication where the parties already use the EU SCCs, while either approved tool can support a UK if completed correctly.

The current A1.0 has Part 1 tables, optional extra-protection clauses, optional commercial clauses, and mandatory Part 4 clauses. The current B1.0 has Part 1 tables and mandatory Part 2 clauses. Complete the required party, transfer, data, module, appendix, security, and termination information. Incorporation by reference works only through the approved alternative wording and a legally binding arrangement; prohibited changes to mandatory clauses or missing required information can cause the instrument to stop operating as the approved safeguard.

For example, the ICO describes a UK travel company sending booking details to a separate Australian hotel where no approval regulation or Article 49 exception applies. The parties could use the or , but the UK company must also complete the transfer risk assessment and add any measures needed to meet the . The same pack may cover genuinely similar recurring transfers if its scope and evidence remain accurate.

  • Map exporter, importer, roles, destinations, transfer purposes, data and people, volume, frequency, systems, remote access, retention, subprocessors, and onward transfers.
  • Choose and execute the or ; confirm that referenced agreements, security requirements, party details, and signatures cover the actual transfer.
  • Apply Article 46's . Acting reasonably and proportionately, decide whether the safeguard and any other measures leave protection after transfer not materially lower than UK protection.
  • Assess reliable information about destination law and practice, enforceability, access by public authorities, redress, importer capability, onward transfers, and the effectiveness of contractual, technical, and organisational measures.
  • Approve only when the test is met, every required additional protection is operating, and the safeguard legally binds the parties. If adequate protection cannot be achieved for some or all of the data, use a valid Article 49 exception for that data if one applies or do not transfer it. Then update Article 30 records, privacy information, processor authorisations, operating controls, and monitoring triggers.
  • Record an inapplicable outcome where the flow is not a , current approval regulations fully cover it, or a fact-specific Article 49 derogation lawfully applies; do not execute the or merely to avoid deciding the correct Chapter V route.
Section 2

What fields should the IDTA addendum and transfer risk assessment template capture?

The transfer pack should let a reviewer connect the signed instrument and assessment to the live data flow. Record the evidence, assumptions, gaps, and conclusion. The clauses do not by themselves eliminate destination-law, public-authority-access, enforceability, or redress risks.

  • Transfer details: parties, roles, destinations, purposes, data and people, volume, frequency, systems, access, retention, subprocessors, and onward transfers.
  • Instrument: or version, linked agreement and EU clauses and modules where relevant, required tables and annexes, mandatory-clause incorporation wording, security requirements, commercial clauses, effective date, signatures, permitted amendments, and termination terms.
  • Assessment: applicable law and practice, public-authority access, redress, enforceability, reliable importer experience, data sensitivity, volume, exposure, likelihood and consequences of access or non-compliance, and the Article 46 conclusion.
  • Measures: record why each contractual, technical, or organisational measure addresses the identified gap. Examples can include encryption with suitable key control, pseudonymisation, minimisation, access controls, transparency, challenge commitments, audits, deletion, and onward-transfer restrictions.
  • Governance: assumptions, evidence sources, owners, approver, unresolved issues, change triggers, next review, and suspension or exit plan.
Section 3

How should teams review and improve the IDTA addendum and transfer risk assessment workflow?

Review when the data flow, parties, roles, destination, subprocessor chain, law or practice, instrument, security, purpose, data, volume, or importer evidence changes. Monitor the actual controls and suspend, narrow, or redesign the transfer if the Article 46 test is no longer met. Do not wait for a renewal date when an earlier event changes the protection.

The ICO states that it plans to update the and during 2026 and that organisations should continue using the current versions until then. Check the ICO page before signing or renewing an instrument and apply its change provisions when a replacement version is issued.

  • Verify that the signed instrument and referenced security requirements still cover the live service and onward transfers.
  • Retest additional measures when access architecture, encryption, key custody, or importer operations change.
  • Track relevant legal and regulator developments for the destination and transfer tool.
  • Record remediation, suspension, replacement, or termination decisions and update the Article 30 record and notices.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Article 46 states the current data protection test and reasonable-and-proportionate assessment for safeguarded transfers.
ico.org.uk
Referenced sections
  • Supports the three conditions for a safeguard to become appropriate and the requirement not to transfer data that remains insufficiently protected.
assets.publishing.service.gov.uk
Referenced sections
  • UK government manual guidance used for adequacy-assessment context when assessing international transfer risk.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.