---
title: "UK GDPR Transfers, IDTA, and UK Addendum Guide"
canonical_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/transfers-idta-and-uk-addendum"
source_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/transfers-idta-and-uk-addendum"
author: "Sorena AI"
description: "Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test."
published_at: "2026-05-09"
updated_at: "2026-07-25"
keywords:
  - "UK GDPR"
  - "transfers"
  - "IDTA"
  - "and UK Addendum"
  - "UK GDPR transfers"
  - "compliance checklist"
  - "practical guidance"
  - "transfers, IDTA, and UK Addendum"
  - "Compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# UK GDPR Transfers, IDTA, and UK Addendum Guide

Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.

*Artifact Guide* *UK* *transfers, IDTA, and UK Addendum*

## UK GDPR transfers, IDTA, and UK Addendum

First decide whether the disclosure is a restricted transfer. Then test adequacy, appropriate safeguards, and only then a relevant derogation.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

The IDTA and UK Addendum are alternative Article 46 safeguards for restricted transfers from the UK when adequacy does not cover the transfer. Use the IDTA as the standalone UK contract, or the Addendum with the approved EU Standard Contractual Clauses. Since 5 February 2026, the exporter must act reasonably and proportionately in deciding that protection provided after transfer will not be materially lower than UK protection. Signing a contract does not by itself pass that data protection test or satisfy the rest of the UK GDPR.

## Definitions

### Article 46 data protection test

**Term:** data protection test

For an Article 46 transfer, the data protection test asks whether the safeguards and any other relevant measures will leave the transferred personal data with protection that is not materially lower than UK protection. To use the safeguard, the controller or processor must act reasonably and proportionately in considering that the test is met. The assessment covers the actual or likely circumstances, including the nature and volume of the data.

**Why it matters here:** The ICO still uses transfer risk assessment or TRA for the documented assessment that applies this statutory test. Signing the IDTA or Addendum is not enough: the exporter must complete the TRA, implement any necessary extra measures and keep the conclusion under review.

Sources:

- [Consolidated UK GDPR, Article 46](https://www.legislation.gov.uk/eur/2016/679/article/46?ref=sorena.io)
- [ICO - Completing a transfer risk assessment](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/completing-a-transfer-risk-assessment/?ref=sorena.io)

## Is the disclosure a restricted transfer?

A restricted transfer generally occurs when a controller or processor subject to the UK GDPR sends or makes personal data accessible to a separate controller or processor outside the UK. Remote access from another country can be a transfer. Sending data directly to the person it is about is not a restricted transfer merely because that person is abroad.

Map the actual transfer chain, including onward transfers and remote support. A UK processor sending data to an overseas subprocessor must address the restricted transfer even if its UK controller selected the vendor. An internal movement within the same legal entity is not a transfer to a separate recipient, although security and other UK GDPR duties still apply.

Apply Article 44A in order: check whether UK adequacy regulations cover the country, territory, sector, or framework; if not, select an Article 46 safeguard and pass the data protection test; if neither applies, determine whether a specific Article 49 derogation fits. Derogations cover defined situations such as explicit informed consent, contractual necessity, important public interest, legal claims, vital interests, or a qualifying public register. Necessity and the condition's limits must be shown for the particular transfer; a derogation is not a routine substitute for safeguards.

- Identify the UK exporter, overseas importer, controller or processor roles, countries, data, people, purposes, access methods, and onward recipients.
- Check the precise scope and conditions of an adequacy regulation, including any required certification or sector limitation.
- Document why the transfer rules do or do not apply instead of signing clauses by default.
- Check Article 49A regulations and sector-specific restrictions before relying on a derogation.

Sources for this answer:

- [ICO - Are we making a restricted transfer?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/are-we-making-a-restricted-transfer/?ref=sorena.io) - ICO scope guidance on exporters, separate recipients, remote access, processors, and transfers made directly to an individual.
- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding Articles 44A to 49A governing the order of UK transfer mechanisms.
- [ICO - Adequacy regulations](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/?ref=sorena.io) - Current ICO guidance for checking the scope and conditions of UK adequacy regulations.

## When should you use the IDTA or UK Addendum?

Use the IDTA when the parties want a standalone UK transfer contract. Use the UK Addendum when they already use the European Commission's approved 2021 Standard Contractual Clauses and need those clauses to support UK restricted transfers too. Select the EU SCC module that matches the parties' roles, then complete the Addendum tables and mandatory clauses.

The instruments are standard data protection clauses, not complete service agreements. Add Article 28 processor terms, commercial obligations, security schedules, audit arrangements, and operational responsibilities elsewhere where needed. Do not amend protected mandatory clauses in a way that reduces the safeguards.

The published standalone IDTA is version A1.0 and the Addendum is version B1.0, both in force from 21 March 2022. Verify the official instrument version before signing. The ICO currently says to keep using these versions while it plans an update during 2026, so a saved template or vendor schedule may cease to be current.

- Record why the IDTA or Addendum was selected and how exporter, importer, and processor roles map to the contract.
- Complete the parties, transfer details, special-category or criminal-offence data, security, onward-transfer, review, governing-law, and termination information rather than relying on placeholders.
- Use optional commercial clauses only where they do not contradict or reduce the mandatory clauses.
- Keep the signed instrument, referenced security measures, linked service contract, and version evidence together.

Sources for this answer:

- [ICO - The UK IDTA and Addendum](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/?ref=sorena.io) - ICO guidance on choosing, completing, changing, and combining the approved UK instruments with other contract terms.
- [ICO - International Data Transfer Agreement](https://ico.org.uk/media2/migrated/4019538/international-data-transfer-agreement.pdf?ref=sorena.io) - Official published IDTA text; confirm the current ICO version before execution.
- [ICO - International Data Transfer Addendum](https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf?ref=sorena.io) - Official published UK Addendum text; confirm the current ICO version and approved EU SCCs before execution.

## How do you complete the data protection test?

For an Article 46 transfer, act reasonably and proportionately in deciding whether the safeguard and any additional measures provide protection that is not materially lower than the UK GDPR and Data Protection Act 2018. The legislation calls this the data protection test; the ICO still calls the documented assessment a transfer risk assessment or TRA.

Assess the people, data, purpose, transfer method, importer, onward transfers, destination laws and practices, enforceability of contractual rights, access by public authorities, redress, and the practical operation of the safeguards. Consider technical, contractual, and organisational measures such as strong encryption with controlled keys, data minimisation, split processing, access controls, transparency, challenge duties, and deletion.

If the test does not pass, change the transfer or add effective measures and reassess. If protection still remains materially lower, do not rely on the IDTA or Addendum for that transfer. Use another lawful mechanism or stop the transfer.

- Use evidence about the actual destination, importer, service, access model, and onward transfers; do not rely only on a country label.
- Record assumptions, evidence gaps, importer answers, supplementary measures, residual risks, approver, and review events.
- Reassess when destination law or practice, parties, processing, data, transfer method, subprocessors, security, or government-access risk changes.
- Do not confuse the UK's adequacy assessment for regulations with the exporter's transfer-level data protection test.

Sources for this answer:

- [ICO - Completing a transfer risk assessment](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/completing-a-transfer-risk-assessment/?ref=sorena.io) - Current ICO guidance on the data protection test, reasonable and proportionate assessment, risk factors, supplementary measures, outcomes, and review.
- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding Article 46 data protection test and appropriate-safeguards requirements.
- [ICO - Appropriate safeguards](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/?ref=sorena.io) - ICO guidance on safeguards, enforceable rights, remedies, and when a data protection test is required.

## What should the transfer pack contain?

The controller owns the transfer decision for its processing; a processor is responsible for its own compliance when it makes a restricted transfer and must also assist, follow instructions, and obtain required authorisation for subprocessors. Procurement, security, privacy, legal, and service owners supply evidence, but one named owner should maintain the transfer map and review schedule.

The transfer pack should contain the transfer map, roles, destinations, adequacy analysis or safeguard, executed IDTA or Addendum and referenced EU SCCs, data protection test, supplementary measures, Article 28 terms, subprocessor approvals, lawful basis, transparency wording, DPIA link where relevant, security evidence, rights-request route, incident route, deletion or return terms, owner, approval, and review triggers.

- Verify that the signed instrument's tables, annexes, modules, security measures, and commercial agreement describe the same transfer.
- Track onward transfers and remote access rather than recording only the first importer.
- Set review triggers for legal changes, new subprocessors, security incidents, access requests, service changes, and new countries.
- Suspend or modify transfers when the importer cannot comply with the clauses or supplementary measures no longer make the test pass.

Sources for this answer:

- [ICO - International transfers](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/?ref=sorena.io) - ICO overview linking the current scope, adequacy, safeguards, data protection test, derogations, and records guidance.
- [ICO - The UK IDTA and Addendum](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/?ref=sorena.io) - ICO completion and contract-management guidance for the UK instruments.
- [ICO - Completing a transfer risk assessment](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/completing-a-transfer-risk-assessment/?ref=sorena.io) - ICO guidance for documenting, approving, and reviewing the transfer-level data protection test.

*Recommended next step*

*Placement: after the practical guidance*

## Turn UK GDPR transfers, IDTA, and UK Addendum into assigned work

Record the transfer chain, roles, destinations, adequacy or safeguard, signed instrument version, data protection test, supplementary measures, approval, and change triggers before access begins.

- [Open Assessment Autopilot for UK GDPR](/solutions/assessment.md): Turn transfers, IDTA, and UK Addendum into scoped questions, evidence fields, and review tasks.
- [Review UK GDPR source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.

## Primary sources

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding Articles 44A to 49A, including adequacy, safeguards, the data protection test, and derogations.
- [ICO - International transfers](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/?ref=sorena.io) - Current ICO international-transfer guidance and decision route.
- [ICO - The UK IDTA and Addendum](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/?ref=sorena.io) - ICO guidance on choosing, completing, and changing the approved clauses, including the planned 2026 update.
- [ICO - Completing a transfer risk assessment](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/completing-a-transfer-risk-assessment/?ref=sorena.io) - Current ICO guidance on the transfer-level data protection test and supplementary measures.

## Related Topic Guides

- [How do you choose a lawful basis under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/lawful-bases.md): Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
- [UK Children's Code: Scope and 15 Standards](/artifacts/uk/general-data-protection-regulation/faq/children-s-code.md): Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
- [UK GDPR 72-hour Breach Reporting Guide](/artifacts/uk/general-data-protection-regulation/72-hour-breach-reporting.md): Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
- [UK GDPR 72-Hour Breach Reporting: Decision Guide](/artifacts/uk/general-data-protection-regulation/faq/72-hour-breach-reporting.md): Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
- [UK GDPR Adequacy Guide](/artifacts/uk/general-data-protection-regulation/adequacy.md): Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
- [UK GDPR Adequacy: When Can You Rely on It?](/artifacts/uk/general-data-protection-regulation/faq/adequacy.md): Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
- [UK GDPR AI and Automated Decisions Guide](/artifacts/uk/general-data-protection-regulation/ai-and-automated-decisions.md): Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
- [UK GDPR AI and Automated Decisions: Articles 22A-22D](/artifacts/uk/general-data-protection-regulation/faq/ai-and-automated-decisions.md): Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
- [UK GDPR Applicability Test Guide](/artifacts/uk/general-data-protection-regulation/applicability-test.md): Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
- [UK GDPR Article 30 Records Guide](/artifacts/uk/general-data-protection-regulation/article-30-records.md): Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
- [UK GDPR Article 30 Records: What to Document](/artifacts/uk/general-data-protection-regulation/faq/article-30-records.md): See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
- [UK GDPR Breach Notification Guide](/artifacts/uk/general-data-protection-regulation/breach-notification.md): Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
- [UK GDPR Breach Workflow Guide](/artifacts/uk/general-data-protection-regulation/breach-workflow.md): Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
- [UK GDPR Children and Age Appropriate Design Guide](/artifacts/uk/general-data-protection-regulation/children-and-age-appropriate-design.md): Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
- [UK GDPR Children's Code Guide](/artifacts/uk/general-data-protection-regulation/children-s-code.md): A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
- [UK GDPR Compliance Checklist](/artifacts/uk/general-data-protection-regulation/checklist.md): A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
- [UK GDPR Compliance FAQ: Duties, Rights, and Decisions](/artifacts/uk/general-data-protection-regulation/faq.md): Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
- [UK GDPR Compliance Guide](/artifacts/uk/general-data-protection-regulation/compliance.md): Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
- [UK GDPR Controller and Processor Status Guide](/artifacts/uk/general-data-protection-regulation/controller-and-processor-status.md): Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
- [UK GDPR Controller or Processor: How to Decide](/artifacts/uk/general-data-protection-regulation/faq/controller-and-processor-status.md): Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
- [UK GDPR Data Subject Rights Guide](/artifacts/uk/general-data-protection-regulation/data-subject-rights.md): Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
- [UK GDPR Deadlines and Compliance Calendar Guide](/artifacts/uk/general-data-protection-regulation/deadlines-and-compliance-calendar.md): Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
- [UK GDPR DPIA Workflow Guide](/artifacts/uk/general-data-protection-regulation/dpia-workflow.md): Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
- [UK GDPR DPIA: When It Is Required and What to Record](/artifacts/uk/general-data-protection-regulation/faq/dpias.md): Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
- [UK GDPR DPIAs and DPOs Guide](/artifacts/uk/general-data-protection-regulation/dpias-and-dpos.md): Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
- [UK GDPR DPO: When Appointment Is Mandatory](/artifacts/uk/general-data-protection-regulation/faq/dpos.md): Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
- [UK GDPR DSAR Workflow Guide](/artifacts/uk/general-data-protection-regulation/dsar-workflow.md): Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
- [UK GDPR IDTA Addendum and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/idta-addendum-and-transfer-risk-assessment.md): Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
- [UK GDPR Lawful Bases Guide](/artifacts/uk/general-data-protection-regulation/lawful-bases.md): Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
- [UK GDPR PECR Cookies Guide](/artifacts/uk/general-data-protection-regulation/pecr-cookies.md): UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
- [UK GDPR Penalties and Fines: Maximums and ICO Factors](/artifacts/uk/general-data-protection-regulation/penalties-and-fines.md): Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
- [UK GDPR Requirements Guide](/artifacts/uk/general-data-protection-regulation/requirements.md): Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
- [UK GDPR Transfer Workflow Guide](/artifacts/uk/general-data-protection-regulation/transfer-workflow.md): Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
- [UK GDPR vs Data Protection Act 2018: How They Work Together](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-data-protection-act-2018.md): See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
- [UK GDPR vs EU GDPR: Scope, Regulators and Transfers](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-eu-gdpr.md): Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
- [UK IDTA vs EU SCCs: Which Transfer Contract to Use](/artifacts/uk/general-data-protection-regulation/idta-vs-eu-sccs.md): Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
- [UK IDTA, Addendum, and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/faq/idta-addendum-and-transfer-risk-assessment.md): Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
- [UK vs EU GDPR Differences After the 2025 UK Reforms](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-gdpr-differences.md): Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
- [UK vs EU GDPR Operations: Regulators, Breaches and Transfers](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-differences.md): Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
- [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md): Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/uk/general-data-protection-regulation/transfers-idta-and-uk-addendum.md
