If your business sends personal data outside the UK (using overseas cloud services, an offshore support team, or an international group) you are making a restricted transfer, and the UK GDPR sets rules you must follow. Many small businesses do this without realising it. Here is how SMEs in England and Wales can transfer personal data abroad lawfully.
What is a "restricted transfer"?
A restricted transfer happens when you send personal data to a receiver (a different organisation or sometimes a different part of your group) located outside the UK. Using a US-based SaaS tool, hosting data overseas, or sharing data with an overseas supplier can all count.
Three main routes to transfer lawfully
The UK GDPR allows restricted transfers in broadly three ways:
1. Adequacy
The UK government can decide that a country (or international organisation) provides adequate protection, in which case you can transfer there much like a domestic transfer. The EU/EEA and a number of other countries benefit from UK adequacy arrangements. Check whether your destination is covered.
2. Appropriate safeguards
If there is no adequacy cover, you can put appropriate safeguards in place. For most SMEs this means using:
- the UK's International Data Transfer Agreement (IDTA); or
- the UK Addendum to the EU Standard Contractual Clauses (useful if you already use the EU SCCs).
These are standard contract terms that bind the receiver to protect the data.
3. Exceptions (derogations)
In limited situations you can rely on specific exceptions, for example, the individual's explicit consent to the transfer, or that the transfer is necessary for a contract with them. These are meant for occasional, not routine, transfers.
Don't forget the transfer risk assessment
When relying on safeguards like the IDTA, you should also carry out a Transfer Risk Assessment (TRA), checking whether the protections will be effective in the destination country (considering local laws and practices). The ICO provides a TRA tool to help.
Practical steps for SMEs
- Map your transfers: identify where your data actually goes (including via cloud providers and sub-processors).
- Check for adequacy first, it is the simplest route.
- Where there is no adequacy, use the IDTA or the UK Addendum to the SCCs, and complete a TRA.
- Make sure your processor contracts flow these protections down to sub-processors.
- Keep records and review them as services and laws change.
Key takeaways
- Sending personal data outside the UK is a restricted transfer, common via overseas cloud and suppliers.
- Use one of three routes: adequacy, appropriate safeguards (IDTA or UK Addendum to the SCCs), or limited exceptions.
- Carry out a Transfer Risk Assessment when relying on safeguards.
- Map your transfers and flow protections down to sub-processors.
Sources
- UK GDPR (Chapter on international transfers); Data Protection Act 2018
- ICO International Data Transfer Agreement (IDTA), UK Addendum to the EU SCCs, and Transfer Risk Assessment tool
- UK adequacy regulations
--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.