Artifact GuideUKIDTA vs EU SCCs

UK GDPR IDTA vs EU SCCs

Use the standalone IDTA for a UK-only transfer contract, or attach the UK Addendum to the European Commission's 2021 SCCs when that contract structure fits the deal.

The contract is only one part of the decision. Confirm that the transfer is restricted, check for UK approval regulations or an exception, and apply the Article 46 data protection test through a documented transfer risk assessment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

For a under the UK GDPR, the exporter may choose either the standalone International Data Transfer Agreement (IDTA) or the UK Addendum attached to the approved 2021 EU Standard Contractual Clauses (EU SCCs). EU SCCs alone are not a UK safeguard. The Addendum is often easier when the parties already use EU SCCs, but it is also available for UK-only transfers. In either case, the parties must complete the contract correctly and the UK exporter must complete a transfer risk assessment to apply the and show that protection after transfer is not materially lower.

Side-by-side comparison

IDTA vs EU SCCs with the UK Addendum

Compare the two UK contractual routes by purpose, parties, structure, assessment, evidence, and use alongside EU GDPR.

Review all sources
First framework
IDTA

A standalone UK contract for restricted transfers using standard data protection clauses.

Second framework
EU SCCs + UK Addendum

The Commission's approved 2021 EU SCCs modified by the UK Addendum for UK restricted transfers.

Comparison row 1

What it does

IDTA

The IDTA supplies the complete approved UK contractual safeguard in one instrument.

EU SCCs + UK Addendum

The Addendum modifies approved 2021 EU SCCs so they can supply the UK contractual safeguard. EU SCCs without the Addendum do not do this.

Operational implication

Choose a UK route only after confirming that the transfer is restricted and is not already covered by approval regulations.

Comparison row 2

Contract structure

IDTA

Complete the IDTA Part 1 tables and include Part 4 mandatory clauses. Parts 2 and 3 are optional areas for extra protection and commercial clauses.

EU SCCs + UK Addendum

Complete the Addendum tables, identify the approved EU SCCs and module, and complete the incorporated SCC annexes and selections.

Operational implication

The shorter Addendum is not a standalone form; its operation depends on the identified EU SCC contract.

Comparison row 3

When it usually fits

IDTA

The IDTA can fit a UK-focused contract where the parties do not need an EU SCC package.

EU SCCs + UK Addendum

The Addendum can reduce duplication when the parties already use EU SCCs for EEA transfers. It may also be used when only UK GDPR applies.

Operational implication

Contract convenience does not change the transfer test or remove the assessment.

Comparison row 4

Transfer assessment

IDTA

The UK exporter must assess the transfer and identify any extra protections needed to meet the Article 46 .

EU SCCs + UK Addendum

The same UK assessment is required when the Addendum is used. If EU GDPR also applies, the EU SCC assessment remains a separate conclusion under EU law.

Operational implication

Do not label one undifferentiated document as both the UK and EU assessment without showing how each legal test is met.

Comparison row 5

Parties and responsibility

IDTA

The sender and receiver must ensure that the IDTA details are correct and comply with its obligations.

EU SCCs + UK Addendum

The parties must correctly identify the Addendum parties, EU SCC roles and module, and the UK-specific selections.

Operational implication

Match legal entities and transfer roles to the actual data flow; a group name or vendor brand is not enough.

Comparison row 6

Evidence to retain

IDTA

Keep the signed IDTA, completed tables, transfer map, assessment, extra protections, approvals, and review triggers.

EU SCCs + UK Addendum

Keep the signed EU SCCs and Addendum, completed annexes and selections, UK assessment, any EU assessment, supplementary measures, approvals, and review triggers.

Operational implication

Review the package when the data flow, destination, parties, law, onward transfers, or ability to comply changes.

Practical decision rule

Which route should the exporter choose?

  • Choose the IDTA when a standalone UK transfer agreement fits the contract.
  • Choose the 2021 EU SCCs with the UK Addendum when the parties want one SCC-based package for UK and EEA data flows, or already use the EU SCCs.
  • Before signing either route, confirm the restricted-transfer analysis, complete all required contract fields, perform the UK assessment, add necessary protections, and identify review triggers.
Section 1

Decide whether a transfer contract is needed

Start with the ICO's three-step restricted-transfer test: the UK GDPR must apply to the sender's processing, the sender must initiate and agree to send or make personal information accessible to a separate organisation, and the receiver must be located outside the UK or covered by an applicable exception to the location rule. Remote access can be a transfer; sending data within the same legal entity is not a .

If the transfer is restricted, first check whether UK approval regulations cover the destination and transfer type. If they do not, consider an Article 46 safeguard such as the IDTA or Addendum. Article 49 exceptions are limited routes for specific situations, not a routine substitute for a safeguard.

  • Map the sender, receiver, locations, legal entities, data, purposes, frequency, onward transfers, and remote-access paths.
  • Record why the transfer is or is not restricted and why any approval regulation or exception covers the actual transfer.
  • If Article 46 is used, identify the safeguard and complete the reasonable and proportionate assessment required by the current UK text.
  • Do not assume that a processor contract under Article 28, an EU SCC contract, or a vendor's security certificate supplies the UK transfer safeguard by itself.
Section 2

Complete the chosen contract and assessment

The IDTA has four parts. Part 1 identifies the parties, transfer details, personal information, and security requirements; Part 4 contains the mandatory clauses. Parts 2 and 3 can add extra protection and commercial terms. The Addendum identifies the parties and the approved EU SCCs, modules, selections, and appendix information that it modifies for UK law.

Both parties must ensure that the contract details are accurate and comply with the contractual obligations. The exporter should also retain the transfer facts, destination analysis, assessment conclusion, any supplementary technical or organisational measures, approvals, and review triggers. Reassess when the parties, purposes, data, destination law, government-access risk, onward transfers, or safeguards materially change.

  • Do not omit required IDTA Part 1 information or make changes to Part 4 beyond the changes the instrument permits.
  • For the Addendum, identify the correct 2021 EU SCC module and complete the incorporated SCC annexes as well as the Addendum tables.
  • Keep the Article 28 processor terms distinct where needed; the transfer instrument does not automatically replace every processor-contract requirement.
  • Document which evidence supports the UK assessment and, if EU GDPR also applies, keep the EU SCC transfer-impact assessment as a separate legal conclusion.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding current text for UK restricted transfers and the Article 46 data protection test.
legislation.gov.uk
Referenced sections
  • Sets the binding UK rules for approval regulations, appropriate safeguards, the data protection test, and exceptions.
ico.org.uk
Referenced sections
  • Explains how to choose, complete, and amend the IDTA or Addendum and confirms that EU SCCs alone are not valid for UK restricted transfers.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.