It is no secret that Data Protection legislation in the UK is a little tricky. When you think you finally have everything you need to become compliant, a new law or agreement comes into play. On 21 March 2022, the Parliament approved the UK International Data Transfer Agreement (IDTA) and also introduced an international data transfer addendum to the New EU SCCs (UK Addendum).
This means that all organisations that need to transfer people’s personal data from the UK to third countries following Brexit should start using the IDTA to legally protect their organisation. Here we discuss what you need to know and do about the new UK International Data Transfer Agreement.
What is the International Data Transfer Agreement?
Under the UK GDPR, personal data exporters are prohibited from transferring that data outside of the UK and EU unless:
- That country is covered by UK adequacy regulations;
- There is an exception, permitting the restricted transfer (such as occasional transfers, a number of limited purposes or where the data subject has given explicit, informed consent; and
- The data transfer is executed using appropriate safeguards.
The new UK International Data Transfer Agreement replaces the EU Standard Contractual Clauses (SCCs) in the UK. It is a set of requirements that can be used by data exporters to comply with UK GDPR when making restricted transfers outside of the UK.
What is the UK Addendum?
The UK Addendum is an “add-on” to be used alongside the New EU SCCs. This alternative safeguard to the IDTA ensures that the New EU SCCs meet UK data protection legislation in a nutshell. However, it only works if the parties are using the New EU SCCs in their agreement.
What steps do I need to take?
In light of the new changes, there are a few things to consider. From now on, when making any international transfers of personal data outside the UK, you should:
- Identify and understand the transfers you are carrying out;
- Identify the contracts and transfers that are still relying on the Old EU SCCs for UK transfers;
- Get to know the roles of the different parties (e.g., processor, subprocessor, controller); and
- Keep information related to contracts and transfers updated.
Do I need to do a Transfer Risk Assessment?
Organisations transferring personal data using the IDTA or Addendum must carry out a transfer risk assessment (TRA). This is to assess whether the IDTA or Addendum contains sufficient safeguards to make the restricted transfer. Or if there is a need for additional protection.
To make it easier for companies dealing with such transfers, the ICO has published a draft international transfer risk assessment and tool.
What are the deadlines for implementation of the IDTA?
It is important to get the IDTA in place sooner rather than later. The deadlines to bear in mind are:
You can keep using the old SCCs up to 21 March 2024, provided they are in place by 21 September 2022. The longstop date to switch over from any remaining SCCs to IDTAs is 21 March 2024.
All contracts and transfers you make after 21 September 2022, where personal data is transferred outside the UK, must include either the IDTA or the UK Addendum.
Final thoughts
If you still find this a bit confusing, you can always visit the official ICO website where you will find lots of useful information to support your business in your data protection obligations.
Since the documents and obligations to become GDPR compliant differ from business to business. It is important to get the right legal advice from the outset.
To make it easier for startups and other companies to remain compliant, we have created a GDPR toolkit that contains policies relating to Data Handling, Data Protection, Data Retention and a handy checklist. We can also draft an IDTA and associated risk assessment for any companies that are currently using the EU SCCs with an addendum for these types of transfers of data.
If you have any questions about GDPR/Data Protection, please contact us and we would be more than happy to help.
