Transferring Personal Data out of the UK
Data is the lifeblood of most businesses. As someone whose business relies on the integrity and protection of your data its security is a must. As far as personal data is concerned, you must comply with the Data Protection Act 2018 and the UK General Data Protection Regulation.
Data is at the heart of almost every business. It helps you to track sales, understand customer behaviour, market and deliver your products and services, and – ultimately – win and deliver new business.
So, it’s important to follow the requirements around processing personal data in the UK and transferring data out of the UK.
Here’s what you need to know if you are transferring personal data outside of the UK.
The General Data Protection Regulation – a quick recap
EU GDPR
When the EU’s General Data Protection Regulation (EU GDPR) came into force in 2018, we were part of the EU. As such, all UK companies had to ensure they complied with the EU GDPR.
UK GDPR
Also in 2018, the UK government passed the Data Protection Act, which brought into UK law all the provisions of the EU GDPR and added to it with some extras around national security. Around the same time, the UK population voted to leave the EU. With Brexit looming, and having just brought the EU GDPR into law in the UK, the privacy of data landscape was set to change yet again. Or was it?
BREXIT
Fast-forward two years to the UK’s departure from the EU on 31 January 2020, and we had to change to our own version of the regulation, called, with stunning originality: UK GDPR. Right now, the UK GDPR is, for all practical purposes, the same as the EU GDPR – but it’s possible that the two will diverge in the future. Now in 2024 we are still waiting for that change to take place. The EU has several pieces of new data related legislation in the wings, although they are more about digital resilience, cyber security and online safety than personal data. We’ll wait and see whether the UK decides to implement similar legislation, and if not, what impact that has.
Why does adequacy matter in international data flows?
To ensure that data can continue to flow freely between the UK and EU, in June 2021 the EU approved an adequacy decision covering data being transferred to the UK from the EU. Similarly, the UK granted adequacy to the EU member states and countries in the European Economic Area (EEA).
This means the EU agrees that the UK data protection rules are as good as theirs, and allows us to process the personal data of EU citizens under our laws, without needing to put extra provisions (like the ‘Standard Contractual Clauses’) in place. The ‘adequacy’ ruling also allows organisations in the UK to make transfers to the EU and other countries where there is an adequacy decision in place, without having to adopt additional safeguarding measures for the personal data transferred.
Transfers of personal data outside of the country of origin are called Restricted Transfers. Below you will find a step-by-step guide to making restricted transfers into, or out of, your business.
Can organisations in the EU and EEA send personal data to my UK business?
Simply put, yes.
Now that the EU has approved the adequacy of the UK as a safe place to share personal data with, this allows businesses that process data in the EU and EEA to send personal data to organisations in the UK, without any restrictions. For businesses operating in the UK, the adequacy decision made by the ICO regarding the EU and EEA means that UK businesses can send personal data to controllers in the EU and EEA, also without restrictions.
What about transferring personal data to and from other countries?
Transfers of personal data between the UK and jurisdictions outside the EEA need to comply with both UK GDPR and the DPA 2018.
As part of the UK GDPR, the UK has opted to accept all other countries which the EU has determined to be ‘adequate’, as being ‘good enough to safely process our personal data’. It’s quite a list!
If you need to transfer personal data from the UK to a country which doesn’t have an EU adequacy decision, the UK has approved what the ICO has called the ‘International Data Transfer Agreement’ (IDTA). Organisations must use this document when making a restricted transfer to third countries not covered by an adequacy decision and where other safeguards are not in place. In short, ITDAs are only needed:
- Where there is a Restricted Transfer, and
- Where there are no alternative adequate safeguards or exceptions.
It’s likely to be quicker and easier to use the IDTA, which has already been given the ICO’s seal of approval and evidences your compliance with the rules around international transfers, rather than coming up with your own safeguard.
Step by step guide to international transfers of personal data (‘Restricted Transfers’)
Ask yourself the following questions:
- Am I planning to transfer personal data outside of the UK? If the answer is “no” you can stop reading and get on with your day. If “yes”, go to the next question.
- Does the transfer have to include personal data to meet the objective of the transfer? If yes, it’s a restricted transfer. If you can anonymise the personal data or make the transfer having removed all the personal data beforehand then it’s not a restricted transfer and you can crack on and make the transfer.
- Is the transfer being made to any country covered by an adequacy decision? If yes, make the transfer. If no, go to the next question.
- Are you putting in place appropriate safeguards? What are they?
An appropriate safeguard would be:
- Legally binding contractual clauses with enforceability rights for the benefit of the data subject
- UK Binding Corporate Rules for intra-group and intra-country transfers
- International Data Transfer Agreement (issued by the ICO)
- Approved Code of Conduct
- Contractual Clauses submitted by you and approved by the ICO
- Administration arrangements between public authorities
- Certification – ICO has various certification schemes depending on the nature of your business and industry in which you operate
Most private organisations will tend to use legally binding contractual clauses or the IDTA.
5. OK, yes, I’ll use an appropriate safeguard.What’s next?
You need to do what is called a Transfer Risk Assessment (there’s a template on the ICO website) to satisfy yourself that the safeguard that you plan to put in place adequately protects the personal data of the data subjects whose data is being transferred and that the requirements of the UK GDPR and DPA 2018 will be upheld by the recipient and the safeguard includes enforceable rights by the data subject. Many businesses will use the IDTA because it comes with ICO approval. When you are happy with your safeguard you can make the transfer.
- Do I have to use an appropriate safeguard?
No, but you can only make a restricted transfer if there is an exception to the need for an appropriate safeguard under article 49 of the UK GDPR. If you make the transfer either without an appropriate safeguard or exception, the transfer will not be compliant and you could face censure from the ICO.
- I have no appropriate safeguard. Is the transfer covered by an exception?
You can make a restricted transfer if you need to send personal data to a third country where:
- There is an emergency happening
- Someone’s life, physical or mental health or wellbeing is at serious risk, and
- You cannot get the data subject’s consent because they are unable to give their consent, or
- You have the data subject’s explicit and freely given consent to the restricted transfer having provided them with a raft of specific information in your privacy notice.
There are, actually, 8 specific exceptions, the above is just a summary, and in short, the transfer has to be necessary. However, if you have gotten to this point having not put an appropriate safeguard in place, you should probably speak to us before you elect to use an exception.
Still unclear about international data transfer?
It sounds complicated but don’t worry – we can help guide you through the international data transfer maze. If you’d like more information about UK GDPR, EU GDPR, and what they mean for your business, please give us a call on 0118 353 6001 or email hello@devant.co.uk
Postscript for the technically inclined – a quick summary of the different bits of legislation
EU GDPR – the original beast that started this whole mess!
DPA 2018 – introduces EU GDPR into UK law and adds some derogations, clarifications and additional areas like national security. If there is further divergence between UK and EU, it will be made to this legislation.
UK GDPR – one of the EU withdrawal acts converts EU GDPR into UK GDPR – it’s the same as EU GDPR with terms updated so EU and EU institutions are removed and UK equivalents substituted.
Restricted Transfer – a transfer of personal data to a recipient outside of the UK.
As always, do not hesitate to get in touch for a no obligation call if you have any questions about this subject.