Since Brexit, the UK runs its own version of GDPR Chapter V: transfers of personal data out of the UK to countries without UK adequacy regulations are “restricted transfers” and need an ICO-approved safeguard. The instruments are the ICO’s International Data Transfer Agreement and the UK Addendum to the EU SCCs, both in force since 21 March 2022, and both requiring a transfer risk assessment before use. The transition is over: the old EU SCCs ceased to be valid for UK transfers on 21 March 2024.
| Regulation | UK GDPR Chapter V; IDTA/Addendum |
|---|---|
| In force | 21 March 2022 (old EU SCCs invalid from 21 March 2024) |
| Max penalty | GBP 17.5M or 4% of global annual turnover |
| Official guidance | ICO international transfers guidance |
The decision tree
First: is the destination adequate? The UK recognises the EEA, the pre-Brexit EU adequacy list, and its own additions, notably the UK-US data bridge (the UK extension to the EU-US Data Privacy Framework, in force 12 October 2023) and South Korea. Adequate destination, no paperwork.
Second: if not adequate, choose the safeguard. The standalone IDTA is a self-contained contract; the UK Addendum converts the EU 2021 SCCs into a UK-valid instrument, which is why groups already papered on SCCs almost always choose it. Binding corporate rules remain an option for intragroup transfers at enterprise scale.
Third: run the transfer risk assessment. The ICO’s TRA tool takes a risk-based approach: would this transfer, given the destination’s legal regime and the data involved, meaningfully increase the risk to individuals? Document the conclusion; the assessment is what the ICO asks for first.
Only then consider the Article 49-style exceptions (explicit consent, contract necessity), which the ICO, like the EDPB, treats as narrow and occasional, not as a transfer program.
Practical points teams miss
The Addendum must actually be executed, not just referenced; check module selection matches the real controller/processor roles. Onward transfers by your processors count, so vendor DPAs need the chain covered. The data bridge only helps if the US recipient’s certification is active and covers the data types, verifiable on the DPF program’s public list. And UK and EU transfers are separate legal events: a US vendor serving your UK and EU entities needs the SCCs for the EU leg and the Addendum (or bridge) for the UK leg, as covered in the EU transfers guide and the UK vs. EU GDPR comparison.
A practical first step is knowing where your site sends data at all: a free scan maps the third-party endpoints your pages actually contact.