First decide whether the disclosure is a restricted transfer. Then test adequacy, appropriate safeguards, and only then a relevant derogation.
Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.
The IDTA and UK Addendum are alternative Article 46 safeguards for restricted transfers from the UK when adequacy does not cover the transfer. Use the IDTA as the standalone UK contract, or the Addendum with the approved EU Standard Contractual Clauses. Since 5 February 2026, the exporter must act reasonably and proportionately in deciding that protection provided after transfer will not be materially lower than UK protection. Signing a contract does not by itself pass that or satisfy the rest of the UK GDPR.
1
Section 1
Is the disclosure a restricted transfer?
A restricted transfer generally occurs when a controller or processor subject to the UK GDPR sends or makes personal data accessible to a separate controller or processor outside the UK. Remote access from another country can be a transfer. Sending data directly to the person it is about is not a restricted transfer merely because that person is abroad.
Map the actual transfer chain, including onward transfers and remote support. A UK processor sending data to an overseas subprocessor must address the restricted transfer even if its UK controller selected the vendor. An internal movement within the same legal entity is not a transfer to a separate recipient, although security and other UK GDPR duties still apply.
Apply Article 44A in order: check whether UK adequacy regulations cover the country, territory, sector, or framework; if not, select an Article 46 safeguard and pass the ; if neither applies, determine whether a specific Article 49 derogation fits. Derogations cover defined situations such as explicit informed consent, contractual necessity, important public interest, legal claims, vital interests, or a qualifying public register. Necessity and the condition's limits must be shown for the particular transfer; a derogation is not a routine substitute for safeguards.
Identify the UK exporter, overseas importer, controller or processor roles, countries, data, people, purposes, access methods, and onward recipients.
Check the precise scope and conditions of an adequacy regulation, including any required certification or sector limitation.
Document why the transfer rules do or do not apply instead of signing clauses by default.
Check Article 49A regulations and sector-specific restrictions before relying on a derogation.
Use the IDTA when the parties want a standalone UK transfer contract. Use the UK Addendum when they already use the European Commission's approved 2021 Standard Contractual Clauses and need those clauses to support UK restricted transfers too. Select the EU SCC module that matches the parties' roles, then complete the Addendum tables and mandatory clauses.
The instruments are standard data protection clauses, not complete service agreements. Add Article 28 processor terms, commercial obligations, security schedules, audit arrangements, and operational responsibilities elsewhere where needed. Do not amend protected mandatory clauses in a way that reduces the safeguards.
The published standalone IDTA is version A1.0 and the Addendum is version B1.0, both in force from 21 March 2022. Verify the official instrument version before signing. The ICO currently says to keep using these versions while it plans an update during 2026, so a saved template or vendor schedule may cease to be current.
Record why the IDTA or Addendum was selected and how exporter, importer, and processor roles map to the contract.
Complete the parties, transfer details, special-category or criminal-offence data, security, onward-transfer, review, governing-law, and termination information rather than relying on placeholders.
Use optional commercial clauses only where they do not contradict or reduce the mandatory clauses.
Keep the signed instrument, referenced security measures, linked service contract, and version evidence together.
For an Article 46 transfer, act reasonably and proportionately in deciding whether the safeguard and any additional measures provide protection that is not materially lower than the UK GDPR and Data Protection Act 2018. The legislation calls this the ; the ICO still calls the documented assessment a transfer risk assessment or TRA.
Assess the people, data, purpose, transfer method, importer, onward transfers, destination laws and practices, enforceability of contractual rights, access by public authorities, redress, and the practical operation of the safeguards. Consider technical, contractual, and organisational measures such as strong encryption with controlled keys, data minimisation, split processing, access controls, transparency, challenge duties, and deletion.
If the test does not pass, change the transfer or add effective measures and reassess. If protection still remains materially lower, do not rely on the IDTA or Addendum for that transfer. Use another lawful mechanism or stop the transfer.
Use evidence about the actual destination, importer, service, access model, and onward transfers; do not rely only on a country label.
Record assumptions, evidence gaps, importer answers, supplementary measures, residual risks, approver, and review events.
Reassess when destination law or practice, parties, processing, data, transfer method, subprocessors, security, or government-access risk changes.
Do not confuse the UK's adequacy assessment for regulations with the exporter's transfer-level .
The controller owns the transfer decision for its processing; a processor is responsible for its own compliance when it makes a restricted transfer and must also assist, follow instructions, and obtain required authorisation for subprocessors. Procurement, security, privacy, legal, and service owners supply evidence, but one named owner should maintain the transfer map and review schedule.
The transfer pack should contain the transfer map, roles, destinations, adequacy analysis or safeguard, executed IDTA or Addendum and referenced EU SCCs, , supplementary measures, Article 28 terms, subprocessor approvals, lawful basis, transparency wording, DPIA link where relevant, security evidence, rights-request route, incident route, deletion or return terms, owner, approval, and review triggers.
Verify that the signed instrument's tables, annexes, modules, security measures, and commercial agreement describe the same transfer.
Track onward transfers and remote access rather than recording only the first importer.
Set review triggers for legal changes, new subprocessors, security incidents, access requests, service changes, and new countries.
Suspend or modify transfers when the importer cannot comply with the clauses or supplementary measures no longer make the test pass.
Turn UK GDPR transfers, IDTA, and UK Addendum into assigned work
Record the transfer chain, roles, destinations, adequacy or safeguard, signed instrument version, data protection test, supplementary measures, approval, and change triggers before access begins.