A new CRM, payroll platform or support tool stores UK customer or staff data on US servers. Check three things in order: whether this is a restricted transfer at all, whether the supplier is on the UK-US Data Bridge, and if not, whether you have an IDTA in place.
A supplier onboarding form asks where data is processed, and the answer comes back “United States”. UK GDPR calls this a restricted transfer, and it needs a lawful basis for the transfer itself, separate from the lawful basis for collecting the data in the first place. Most businesses that use a US-based email platform, helpdesk, payroll bureau or cloud backup are making one every day without having checked which basis applies.
The check runs in a fixed order, and it usually takes less time than the onboarding call that raised the question.
A restricted transfer happens when personal data is sent to, or made accessible to, a person or system outside the UK. “Made accessible” matters as much as “sent”: a UK-hosted database that a US support team can log into is a restricted transfer the moment that access exists, even though no file ever moved. The test looks at where the data can be reached from, not where the server sits.
This covers more ground than most owners expect. A UK consultancy emailing a staff spreadsheet to its own US office is making a restricted transfer. A UK retailer whose US-owned payment processor has engineers who can view UK transaction records is making one. A UK charity whose volunteer database sits on a server in London, with no overseas access to it at all, is not.
Three questions, each one closing off the need to ask the next.
Business terms and conditions from £695 +VAT, fixed in writing before work starts. See what is included.
The Data Bridge extends the EU-US Data Privacy Framework to the UK, so a US organisation that has self-certified under the UK Extension can receive UK personal data on the same footing as if it were in an adequate country. It is not a blanket US exemption. Certification is per legal entity, filed voluntarily with the US Department of Commerce, and searchable by name on the official Data Privacy Framework List. The entity that needs to appear is the one named in your contract or order form — a well-known parent brand can be certified while the specific subsidiary processing your data is not, and the list is the only place that distinction shows up.
Check the listing itself, not a supplier's marketing page that says “DPF compliant.” Some organisations certify for the EU framework and skip the UK Extension, which looks identical from the outside until the listing is opened.
Where the importer is not on the Data Bridge and the destination is not otherwise adequate, UK GDPR requires an “appropriate safeguard” around the transfer. The Information Commissioner's Office publishes two: the International Data Transfer Agreement, a standalone document, and the UK Addendum, which attaches to the EU's Standard Contractual Clauses for a business already using those for its EU transfers. Both have been in force since 21 March 2022, and any arrangement still running on the old EU-only clauses had to move onto one of them by 21 March 2024 — that transition period is closed.
Both documents are completed rather than drafted. The clauses that create the safeguard are fixed by the regulator; what you and the supplier fill in are the schedules naming the parties, describing the categories of data and the people it concerns, and setting out the security measures the importer applies. It sits beside the data processing agreement that already governs the supplier relationship, not instead of it — a processing agreement without a transfer safeguard behind it still leaves the transfer itself unauthorised.
A made-up scenario, to show how the check runs rather than a promise about any real business. A 14-person UK recruitment firm moves its candidate database onto a new applicant-tracking platform. The supplier's data processing agreement names the processing entity as a Delaware-registered company and confirms data is held on US servers with support staff access from the US. Step one: data clearly reaches outside the UK, since support staff can view it. Step two: the US is not covered by a UK adequacy regulation. Step three: the firm searches the exact entity name on the Data Privacy Framework List and finds it listed with the UK Extension included. No IDTA is needed, and the firm keeps a dated copy of the listing with the supplier file. A second supplier, a smaller US payroll bureau processing data for the firm's 14 staff, is not on the list at all — for that one, the firm puts the IDTA in place before the first payroll file is sent, alongside the data processing agreement it already had.
The Data (Use and Access) Act 2025 replaced the test an exporter applies when relying on a safeguard. The previous standard asked whether protection in the destination country was “essentially equivalent” to the UK's. From 5 February 2026 the question is whether it is “not materially lower”, judged reasonably and proportionately against the nature and volume of the data moving. The Information Commissioner's Office republished its international transfers guidance on 15 January 2026 to match, and now calls this the data protection test rather than the older “transfer risk assessment” label. The IDTA and UK Addendum themselves have not been replaced; what moved is the bar for deciding whether one on its own is enough or whether extra measures need adding on top.
For most small businesses sending ordinary customer or staff data to a mainstream US supplier, a lower volume and a routine purpose point toward a lighter-touch assessment under the new test. That is a judgement to record in writing at the time, not one to make informally and forget.
For the rest of what UK GDPR expects of a small business, read GDPR for small business, minus the jargon. For the privacy notice and processor agreements that sit around this, see our guide to website terms and privacy, and the data processing agreement template if you need the underlying document rather than the transfer safeguard. Prices for getting it done are on fixed-fee work.
Leave your email and we’ll send the supplier data-mapping checklist — the questions that show which of your platforms are making a restricted transfer and which are not.
No. First check whether the supplier is self-certified under the UK Extension to the EU-US Data Privacy Framework, in force since 12 October 2023 — the UK calls this the UK-US Data Bridge. A supplier on that list can receive the data without an IDTA or any other safeguard. The check is on the exact legal entity named in your contract, not the brand name, using the Data Privacy Framework List search tool. Only where the specific importer is not on that list, and the transfer is not otherwise covered by a UK adequacy regulation, do you need an IDTA or the UK Addendum to the EU Standard Contractual Clauses.
Sending personal data to, or giving a person or system outside the UK access to, data that identifies a living person. It covers more than uploading a file: letting a US colleague or a US-based support team log in and view UK customer or staff records is a transfer, even if the data never physically leaves a UK server. The test in UK GDPR Chapter 5 applies to the receiving party's location, not the server's. A UK company emailing a spreadsheet to its own US office is a restricted transfer in exactly the same way as emailing it to an external supplier.
Search the exact company name at the Data Privacy Framework List, the official US-run register, and open the listing to confirm the UK Extension is included alongside the EU one — some organisations certify for the EU framework only. Match the entity named in your contract or order form, since a US parent can be certified while a processing subsidiary is not, or the reverse. Save a dated screenshot or PDF of the listing with your supplier file, because the position can change if the certification lapses or is removed, and you need to show what the position was when you relied on it.
The International Data Transfer Agreement is a template published free by the Information Commissioner's Office, in force since 21 March 2022, that a UK exporter and an overseas importer sign to put an approved safeguard around a restricted transfer. The alternative is the UK Addendum attached to the EU's Standard Contractual Clauses. Both are completed, not rewritten: the operative wording is fixed, and what you fill in are the tables describing the parties, the data and the security measures. It sits alongside your data processing agreement with the supplier rather than replacing it.
From 5 February 2026, the test an exporter applies before relying on a safeguard changed from asking whether protection in the destination country is “essentially equivalent” to the UK's to asking whether it is “not materially lower”, applied reasonably and proportionately to the nature and volume of the data involved. The Information Commissioner's Office republished its international transfers guidance on 15 January 2026 to reflect this, introducing the term “data protection test” for what was previously called a transfer risk assessment. The IDTA and the UK Addendum continue to be used; what changed is the standard applied when deciding whether they are enough on their own or need extra measures added.
Not on location alone. If the data stays on servers physically in the UK and no person or system outside the UK can access it, it is not a restricted transfer, whoever owns the company running the data centre. It becomes one the moment the US parent's support staff, billing team or engineers can log in to that UK-held data from outside the UK, which is common with global cloud and SaaS platforms. Check the supplier's own data processing agreement and sub-processor list, since the answer usually sits in a schedule rather than the marketing page, and ask directly if it is not clear.
The transfer itself becomes a breach of UK GDPR, separate from anything going wrong with the data once it arrives. The Information Commissioner's Office can investigate, require the transfer to stop, and fine for the breach on its own facts. In practice the more common trigger is a customer's own due diligence or a subject access request that asks where their data goes, and finding no paper trail at that point is worse than finding one that needs updating. It is also one of the easier gaps to close, usually a Data Privacy Framework check and one signed form rather than a rebuild of how the business operates.
Yes, as non-reserved legal work: mapping which suppliers and offices receive UK personal data, checking Data Privacy Framework status for the US ones, and putting an IDTA or UK Addendum in place with a data processing agreement where one is needed, at a fixed price agreed in writing before anything starts. Book a legal review and say which suppliers hold personal data outside the UK. What is not included is acting as your appointed Data Protection Officer or defending an Information Commissioner's Office investigation, which goes to a regulated firm.
Tell us what has happened and what you want to happen about it. We will come back with what the job involves, who carries it out and what it costs, in writing, before you commit to anything.