International data transfer agreement for a UK business

The transfer agreement or addendum a UK business needs to send personal data abroad, with the transfer risk assessment, drafted for the business with the privacy notice, £795 in five working days.

Share

International data transfer agreement for a UK business

The documents a UK business needs to send personal data abroad, drafted for the business, covering when a transfer is a restricted transfer and when it is not, adequacy, the data bridge and the countries that need nothing more, the international data transfer agreement and the addendum and which to use, the transfer risk assessment the regulator expects, the exceptions for occasional transfers and when they apply, and the processor abroad, the group company abroad and the documents for each. £795 with the privacy notice, delivered in five working days.

Buy now, £795

A UK business sends personal data abroad whenever it uses a cloud service hosted elsewhere, a supplier in another country, an overseas group company or a freelancer working from a beach, and the law allows it only where the destination has been found adequate or the business has put a safeguard in place, usually the international data transfer agreement or the addendum to the EU clauses, with a risk assessment behind it. The documents have to be the right ones for the transfer, completed properly rather than attached as a template, and backed by an assessment the business has recorded. I draft the transfer documents and the privacy notice for the business for a fixed fee of £795, delivered in five working days, with a note on the operational steps the documents assume.

Who this is for

Businesses in England and Wales using suppliers, hosting, group companies, freelancers or partners outside the United Kingdom, and businesses whose customers have asked what safeguard covers the transfer.

What matters in an international transfer

When a transfer is a restricted transfer and when it is not

A restricted transfer under Chapter V of the UK GDPR is the sending of personal data to a receiver outside the United Kingdom who is a separate controller or processor (not the sender's own employee travelling abroad with a laptop, which is a security question rather than a transfer), and it includes giving a receiver abroad remote access to data held in the United Kingdom, so that a cloud service hosted abroad, a supplier abroad, a group company abroad and a freelancer abroad are all restricted transfers needing a lawful route; the business should list its transfers (which the records of processing should already show) before choosing the documents, because the right instrument depends on who the receiver is and where.

Adequacy, the data bridge and the countries that need nothing more

Transfers to countries covered by adequacy regulations under Article 45 of the UK GDPR need no further safeguard: the European Economic Area, the countries the EU had found adequate at the end of 2020 and the United Kingdom has retained, and the United States for organisations certified under the UK extension to the EU-US data privacy framework (the data bridge), with the business checking the receiver's certification on the framework list before relying on it; the Data (Use and Access) Act 2025 restates the test for adequacy and for the business's own assessment as whether the standard of protection is not materially lower than the United Kingdom's, on commencement, which the note explains; for everywhere else, a safeguard is needed.

The international data transfer agreement and the addendum and which to use

The safeguards under Article 46 of the UK GDPR for most businesses are the Information Commissioner's international data transfer agreement (a standalone contract between the sender and the receiver, in force since 2022) or the UK addendum to the EU standard contractual clauses (which adapts the EU clauses for transfers from the United Kingdom and suits a receiver that already uses the EU clauses, such as a supplier with EU customers); the business uses the IDTA where the relationship is UK-only and the addendum where the receiver's paperwork is built on the EU clauses, completes the tables (the parties, the transfer, the data, the security, the governing law) rather than attaching the template blank, and signs it as a contract, with the receiver's obligations flowing down to any onward transfer; binding corporate rules suit large groups and are outside this service.

The transfer risk assessment the regulator expects

Before relying on the IDTA or the addendum the business must assess whether the safeguard will be effective in the destination (whether the receiver can comply, whether the destination's laws on government access and the rule of law undermine the protection, whether the data's sensitivity raises the risk), record the assessment, and keep it under review, which the Information Commissioner's transfer risk assessment tool structures as a comparison of the risk to the individuals in the destination against the risk in the United Kingdom; the note that comes with the documents sets out the assessment for the business's transfers so that it exists, because a safeguard without an assessment is the gap the regulator finds, and the 2025 Act's reframing of the test is reflected in it.

The exceptions for occasional transfers and when they apply

Article 49 of the UK GDPR permits a transfer without adequacy or a safeguard in limited cases (the individual's explicit consent after being told of the risks, a transfer necessary for a contract with the individual or in their interest, legal claims, vital interests, and a compelling legitimate interest for a one-off transfer with conditions), which suit a single transfer (sending a customer's details to a hotel abroad they have booked) and not a continuing arrangement with a supplier; the note says which of the business's transfers fall within an exception and which need a safeguard, because a business that relies on consent for its cloud hosting has chosen a route the regulator will not accept.

The processor abroad, the group company abroad and the documents for each

A processor abroad (a hosting provider, a software supplier, a freelancer) needs the Article 28 data processing agreement and the transfer safeguard (the IDTA or the addendum in its processor form, or the supplier's own adequate paperwork checked), a controller abroad (a partner, a customer) needs the data sharing terms and the safeguard in its controller form, and a group company abroad needs an intra-group agreement containing both, with the privacy notice telling the individuals about the transfers and the safeguards; the documents are drafted for the business's actual transfers, the business keeps the completed agreements and the assessment with its records of processing, and electronic marketing to individuals abroad remains subject to regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 where the recipient is in the United Kingdom and to local rules where not.

What it costs

DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.

Review of a customer's DPA, £495. They sent theirs and you need to know what you are accepting. Returned marked up with the changes to ask for and an explanation. Three working days.

Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
  • A privacy notice written for people to read rather than to be scrolled past
  • Clear allocation of controller and processor roles, which is where most confusion starts
  • International transfer provisions where you use overseas suppliers
  • Sub-processor and security provisions proportionate to what you do
  • A note on the operational steps the documents assume you are taking

What is not included

  • Full compliance audits and data mapping exercises
  • ICO registration, which you do yourself
  • Breach response and regulatory correspondence
  • Cyber security certification such as Cyber Essentials
  • Advice on data protection law outside the UK and EU

Questions I am often asked

We use a US cloud provider. Do we need a transfer agreement?

Where the provider is certified under the UK extension to the data privacy framework, adequacy covers it and no further safeguard is needed, though the DPA still is. If not, the provider's addendum or the IDTA, with a transfer risk assessment recorded.

Which should we use, the IDTA or the addendum?

The IDTA for a UK-only relationship; the addendum where the receiver's paperwork is built on the EU standard contractual clauses, which most international suppliers' is. Either is completed for the actual transfer, not attached blank.

Do we really need a risk assessment as well as the agreement?

A safeguard works only if it is effective in the destination, and the business must have assessed and recorded that. The note sets out the assessment for the business's transfers.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.