UK Privacy Law United Kingdom

UK IDTA and Addendum: Restricted Transfers Explained

How to lawfully transfer personal data out of the UK: the IDTA, the UK Addendum to EU SCCs, transfer risk assessments, and the UK-US data bridge.

Regulation

UK GDPR, Chapter V; ICO IDTA and Addendum (in force 21 March 2022)

Max Penalty

GBP 17.5 million or 4% of global annual turnover

Enforcing Authority

Information Commissioner's Office (ICO)

Official Source

ico.org.uk

Executive Summary

  • A restricted transfer is any transfer of personal data from the UK to a country without UK adequacy regulations; it needs an appropriate safeguard or an exception.
  • The ICO's two instruments have been in force since 21 March 2022: the standalone International Data Transfer Agreement (IDTA) and the UK Addendum bolted onto the EU 2021 SCCs.
  • Old EU SCCs stopped being valid for UK transfers on 21 March 2024; contracts still relying on them are non-compliant.
  • A transfer risk assessment (TRA) is required before relying on the IDTA or Addendum; the ICO publishes its own TRA tool as an alternative to the EU-style approach.
  • The UK-US data bridge, the UK extension to the EU-US Data Privacy Framework, has covered transfers to certified US organizations since 12 October 2023.

Since Brexit, the UK runs its own version of GDPR Chapter V: transfers of personal data out of the UK to countries without UK adequacy regulations are “restricted transfers” and need an ICO-approved safeguard. The instruments are the ICO’s International Data Transfer Agreement and the UK Addendum to the EU SCCs, both in force since 21 March 2022, and both requiring a transfer risk assessment before use. The transition is over: the old EU SCCs ceased to be valid for UK transfers on 21 March 2024.

RegulationUK GDPR Chapter V; IDTA/Addendum
In force21 March 2022 (old EU SCCs invalid from 21 March 2024)
Max penaltyGBP 17.5M or 4% of global annual turnover
Official guidanceICO international transfers guidance

The decision tree

First: is the destination adequate? The UK recognises the EEA, the pre-Brexit EU adequacy list, and its own additions, notably the UK-US data bridge (the UK extension to the EU-US Data Privacy Framework, in force 12 October 2023) and South Korea. Adequate destination, no paperwork.

Second: if not adequate, choose the safeguard. The standalone IDTA is a self-contained contract; the UK Addendum converts the EU 2021 SCCs into a UK-valid instrument, which is why groups already papered on SCCs almost always choose it. Binding corporate rules remain an option for intragroup transfers at enterprise scale.

Third: run the transfer risk assessment. The ICO’s TRA tool takes a risk-based approach: would this transfer, given the destination’s legal regime and the data involved, meaningfully increase the risk to individuals? Document the conclusion; the assessment is what the ICO asks for first.

Only then consider the Article 49-style exceptions (explicit consent, contract necessity), which the ICO, like the EDPB, treats as narrow and occasional, not as a transfer program.

Practical points teams miss

The Addendum must actually be executed, not just referenced; check module selection matches the real controller/processor roles. Onward transfers by your processors count, so vendor DPAs need the chain covered. The data bridge only helps if the US recipient’s certification is active and covers the data types, verifiable on the DPF program’s public list. And UK and EU transfers are separate legal events: a US vendor serving your UK and EU entities needs the SCCs for the EU leg and the Addendum (or bridge) for the UK leg, as covered in the EU transfers guide and the UK vs. EU GDPR comparison.

A practical first step is knowing where your site sends data at all: a free scan maps the third-party endpoints your pages actually contact.

Frequently Asked Questions

IDTA or UK Addendum: which should I use?

If your group already uses the EU 2021 SCCs, the UK Addendum is the efficient choice: one document extends the SCCs to UK transfers. The standalone IDTA suits UK-only relationships with no EU dimension. Legally both work; the Addendum dominates in practice among multinationals.

Are old EU SCCs still valid for UK transfers?

No. Contracts concluded on the old EU SCCs before 21 September 2022 kept working only until 21 March 2024. Anything still on the old clauses for UK restricted transfers needs to be repapered onto the IDTA or the Addendum.

Do I need a transfer risk assessment?

Yes, when relying on the IDTA or Addendum. Following Schrems II logic, you must assess whether the destination country's laws and practices undermine the safeguards. The ICO's TRA tool offers a more risk-based route than the EU's essentially-equivalent test, asking whether the transfer meaningfully increases risk for the people concerned.

Can I send data to the US without an IDTA?

Yes, if the recipient is certified under the UK extension to the EU-US Data Privacy Framework (the UK-US data bridge), active since 12 October 2023. Check the recipient's certification covers UK data and HR data if relevant; otherwise fall back to the Addendum plus TRA.

Which countries does the UK treat as adequate?

The EEA and the countries inherited from EU adequacy decisions (including Japan, New Zealand, Switzerland, Israel, and others), plus the UK's own findings such as South Korea and the US data bridge. Transfers to these destinations need no further safeguard.

Regulatory Crosswalk

EU SCCsEU-US DPFAPEC CBPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.