Artifact GuideUKTransfer Workflow

UK GDPR Transfer Workflow

Map the restricted transfer first, then use Article 45A approval regulations, an Article 46 safeguard with the required data protection test, or a specific Article 49 derogation.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use this workflow for a where a UK GDPR controller or processor makes personal data accessible to a separate organisation outside the UK. Map exporter, importer, roles, destination, onward access and transfer direction; then apply Article 44A in order: approval regulations under Article 45A, an Article 46 safeguard, or a specific Article 49 derogation, subject to any Article 49A restriction.

Section 1

How should a Transfer Workflow run under the UK GDPR?

Confirm that UK GDPR-covered processing sends or makes personal data accessible to a separate recipient in a third country or international organisation. Map remote access, cloud hosting, support, group-company disclosure, processor and subprocessor chains, and onward transfers. A transfer within the same legal entity may fall outside this definition, but the overseas processing still needs UK GDPR security and accountability controls.

Do not classify a flow from geography alone. A UK employee remotely viewing data on the same UK controller's overseas system may remain an internal movement, while support access by a separate overseas vendor can be a even when no file is downloaded. A disclosure to another company in the same group is still between separate legal persons and can be restricted.

Apply Article 44A in order. First check whether current Article 45A approval regulations cover the destination, recipient, data, and transfer. An approval can be limited: for example, the UK-US data bridge covers eligible US organisations participating in the UK Extension to the EU-US Data Privacy Framework, not every US recipient. Keep evidence of current participation and that the data falls within scope.

If approval regulations do not cover the flow, use an Article 46 safeguard and complete the required . If neither route applies, use Article 49 only where the facts meet a listed specific situation and no Article 49A restriction blocks the transfer. Consent must be explicit and informed of transfer risks; contract and public-interest routes have necessity tests; and the compelling-legitimate-interests route has additional limits and notification requirements. A derogation is not a standing vendor-transfer mechanism merely because the transfer is convenient.

  • Map exporter, importer, controller and processor roles, destination, data and people, purpose, frequency, access method, retention, security, and onward recipients.
  • For Article 45A, keep the applicable regulations and evidence that the transfer stays within their scope and any conditions.
  • For Article 46, select a valid safeguard, such as the UK IDTA, UK Addendum to the European Commission's 4 June 2021 SCCs, approved binding corporate rules, an approved code or certification with binding commitments, or another safeguard listed in Article 46.
  • Acting reasonably and proportionately, assess whether the safeguard and any other measures leave protection after transfer no more than materially lower than UK protection.
  • For Article 49, record the exact derogation and necessity facts. Do not use consent, contract necessity, legal claims, or compelling legitimate interests as a standing substitute for an available safeguard.
  • Update notices, processor authorisations, Article 30 records, contracts, security controls, and review triggers before the transfer begins.
  • Set one of four explicit outcomes: not a ; covered by identified Article 45A regulations; approved under a named Article 46 safeguard after the ; or permitted for the recorded event under a specific Article 49 derogation. Escalate or stop where no route is established.
Section 2

What fields should the Transfer Workflow template capture?

The record must connect the actual data flow to one lawful Chapter V route. A contract name alone is not enough: show the parties and signatures, covered transfers, assessment, measures, operating evidence, assumptions, and review owner.

  • Flow: exporter, importer, roles, destinations, systems, remote access, purposes, data categories and volume, people, frequency, retention, subprocessors, and onward transfers.
  • Route: applicable Article 45A regulations and scope evidence, Article 46 safeguard and execution details, or exact Article 49 derogation, necessity analysis, limits, and required notifications.
  • Assessment: relevant destination laws and practices, contractual enforceability, importer capabilities, access risks, past requests where reliable, technical and organisational measures, and the Article 46 conclusion.
  • Controls: encryption and key control, minimisation, access restrictions, transparency, challenge and notice commitments, audit rights, incident response, deletion, and onward-transfer conditions.
  • Governance: owner, reviewer, approvals, Article 30 and notice updates, assumptions, evidence location, change triggers, and next review.
Section 3

How should teams review and improve the Transfer Workflow?

Review when approval regulations, recipient eligibility, the chosen safeguard, destination law or practice, importer ownership, subprocessor chain, data categories, volume, purpose, access method, security, or evidence changes. A fixed review date does not replace event-driven monitoring.

  • Verify that the live data flow and onward-transfer chain match the approved record.
  • Confirm signed instruments, referenced security measures, and approval evidence remain in force.
  • Reapply the Article 46 after a material change and suspend or redesign the transfer if the test is no longer met.
  • Record the decision and remedial action when monitoring identifies government-access, importer, security, or enforceability changes.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for checking whether the approved route and Article 46 data protection test remain satisfied after a material change.
legislation.gov.uk
Referenced sections
  • Articles 44A-49A provide the current route order, transfer safeguards, derogations and restrictions.
assets.publishing.service.gov.uk
Referenced sections
  • GOV.UK manual guidance for recording adequacy-assessment information that can inform international-transfer governance records.
gov.uk
Referenced sections
  • GOV.UK explainer for documenting UK-US data bridge eligibility and protection-level assumptions in transfer workflows.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.