Artifact GuideUKIDTA addendum and transfer risk assessment
UK GDPR IDTA addendum and transfer risk assessment
Use the UK Addendum with qualifying EU standard contractual clauses or use the standalone IDTA, then document the Article 46 data protection test and any additional measures.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
For a that needs an Article 46 safeguard, use the when the European Commission's 2021 standard contractual clauses are already part of the contract, or use the standalone when that structure fits better. Since 5 February 2026, Article 46 calls the required transfer risk assessment the . The sender must decide, acting reasonably and proportionately, that the safeguard and any other measures leave protection after transfer not materially lower than UK protection.
1
Section 1
How should an IDTA addendum and transfer risk assessment workflow run under the UK GDPR?
First confirm that the data flow is a and is not covered by current Article 45A approval regulations. Check whether a specific Article 49 exception applies; these exceptions are fact-dependent and are not a routine substitute for Article 46 safeguards. Then select the standalone International Data Transfer Agreement () or the International Data Transfer to the EU Commission's standard contractual clauses (UK Addendum).
Use the only when the European Commission's 4 June 2021 EU standard contractual clauses are part of the arrangement and their modules match the parties' roles. EU SCCs alone are not a UK safeguard. Use the when a standalone UK instrument fits the transfer. The choice is contractual, not a hierarchy: the Addendum often reduces duplication where the parties already use the EU SCCs, while either approved tool can support a UK if completed correctly.
The current A1.0 has Part 1 tables, optional extra-protection clauses, optional commercial clauses, and mandatory Part 4 clauses. The current B1.0 has Part 1 tables and mandatory Part 2 clauses. Complete the required party, transfer, data, module, appendix, security, and termination information. Incorporation by reference works only through the approved alternative wording and a legally binding arrangement; prohibited changes to mandatory clauses or missing required information can cause the instrument to stop operating as the approved safeguard.
For example, the ICO describes a UK travel company sending booking details to a separate Australian hotel where no approval regulation or Article 49 exception applies. The parties could use the or , but the UK company must also complete the transfer risk assessment and add any measures needed to meet the . The same pack may cover genuinely similar recurring transfers if its scope and evidence remain accurate.
Map exporter, importer, roles, destinations, transfer purposes, data and people, volume, frequency, systems, remote access, retention, subprocessors, and onward transfers.
Choose and execute the or ; confirm that referenced agreements, security requirements, party details, and signatures cover the actual transfer.
Apply Article 46's . Acting reasonably and proportionately, decide whether the safeguard and any other measures leave protection after transfer not materially lower than UK protection.
Assess reliable information about destination law and practice, enforceability, access by public authorities, redress, importer capability, onward transfers, and the effectiveness of contractual, technical, and organisational measures.
Approve only when the test is met, every required additional protection is operating, and the safeguard legally binds the parties. If adequate protection cannot be achieved for some or all of the data, use a valid Article 49 exception for that data if one applies or do not transfer it. Then update Article 30 records, privacy information, processor authorisations, operating controls, and monitoring triggers.
Record an inapplicable outcome where the flow is not a , current approval regulations fully cover it, or a fact-specific Article 49 derogation lawfully applies; do not execute the or merely to avoid deciding the correct Chapter V route.
What fields should the IDTA addendum and transfer risk assessment template capture?
The transfer pack should let a reviewer connect the signed instrument and assessment to the live data flow. Record the evidence, assumptions, gaps, and conclusion. The clauses do not by themselves eliminate destination-law, public-authority-access, enforceability, or redress risks.
Transfer details: parties, roles, destinations, purposes, data and people, volume, frequency, systems, access, retention, subprocessors, and onward transfers.
Instrument: or version, linked agreement and EU clauses and modules where relevant, required tables and annexes, mandatory-clause incorporation wording, security requirements, commercial clauses, effective date, signatures, permitted amendments, and termination terms.
Assessment: applicable law and practice, public-authority access, redress, enforceability, reliable importer experience, data sensitivity, volume, exposure, likelihood and consequences of access or non-compliance, and the Article 46 conclusion.
Measures: record why each contractual, technical, or organisational measure addresses the identified gap. Examples can include encryption with suitable key control, pseudonymisation, minimisation, access controls, transparency, challenge commitments, audits, deletion, and onward-transfer restrictions.
Governance: assumptions, evidence sources, owners, approver, unresolved issues, change triggers, next review, and suspension or exit plan.
How should teams review and improve the IDTA addendum and transfer risk assessment workflow?
Review when the data flow, parties, roles, destination, subprocessor chain, law or practice, instrument, security, purpose, data, volume, or importer evidence changes. Monitor the actual controls and suspend, narrow, or redesign the transfer if the Article 46 test is no longer met. Do not wait for a renewal date when an earlier event changes the protection.
The ICO states that it plans to update the and during 2026 and that organisations should continue using the current versions until then. Check the ICO page before signing or renewing an instrument and apply its change provisions when a replacement version is issued.
Verify that the signed instrument and referenced security requirements still cover the live service and onward transfers.
Retest additional measures when access architecture, encryption, key custody, or importer operations change.
Track relevant legal and regulator developments for the destination and transfer tool.
Record remediation, suspension, replacement, or termination decisions and update the Article 30 record and notices.