Guidance on International Data Transfers – Updates from the ICO
12th January 2026
Following the passing of the Data (Use and Access) Act 2025, the ICO has updated its guidance for organisations on international data transfers. While the law on international data transfers has not changed that much from regulations set out in the Data Protection Act 2018, the DUAA’s changes aim to make it simpler for organisations, reducing paperwork and time costs. The new ICO guidance introduces a three-step test to determine whether a data transfer is restricted, plus an updated Glossary section and FAQs to simplify jargon and reduce complexity.
Changes to International Transfers Under the DUAA
The DUAA makes it simpler for organisations to transfer personal data outside of the UK, but it does not remove the requirement for Transfer Risk Assessments (now known as Data Protection Test as per the DUAA) or other mechanisms to protect personal data. The new data protection test requires the data protection regulations in a third country to ‘not be materially lower’ than the UK, whereas the original UK GDPR required the data protection laws in a third country to be ‘essentially equivalent’ to the UK’s data protection regulations. A ‘third country’ in this case is considered to be any country outside the UK’s jurisdiction for data protection purposes, which includes EU countries now that the UK is no longer a member of the EU.

The ICO’s guidance has provided clarity on the difference between data protection laws that are ‘essentially equivalent’ and ‘not materially lower’ than the UK’s data protection regulations (Source: ICO). These might seem very similar, but showing that a third country’s data protection laws are ‘not lower’ than our own is simpler and easier than proving they are ‘essentially equivalent’. The focus has shifted to real-world risk rather than unlikely hypothetical situations, and whether or not personal data in that third country is sufficiently protected.
Key Changes to the ICO’s Guidance
The ICO has introduced a new three-step data protection test to help organisations identify if they are making a restricted transfer. If you answer ‘yes’ to all three steps, then you are making a restricted transfer, and you must still rely on a legitimate transfer mechanism to legally transfer the data – more on these later. This test is not a legal requirement, but following these steps and documenting the results would help to provide evidence of compliance with the GDPR. The three steps are:
Step 1: Does the UK GDPR apply to the personal information being transferred?
This involves checking if the data processing is subject to UK GDPR rules, i.e. it must be defined as personal data as per the UK GDPR. For example, if a UK-based organisation sends data on customer browsing habits to a marketing firm in Australia, this data would be subject to the UK GDPR. whereas if the same file was sent in which all personal identifiers had been permanently removed so no individual could be identified, then this would not be subject to the UK GDPR.
Step 2: Are you “initiating” the transfer to an organisation outside the UK?
This step looks at whether your organisation is responsible for setting up or choosing the recipient of the transfer. If you have legal or operational control over the decision to send data overseas, you are the initiator (controller). For example, a UK law firm signs a contract with a US-based cloud storage provider (like Dropbox or a legal-tech platform) and uploads client files to their servers. Even though the “cloud” feels automatic, the UK firm chose that specific provider and directed the data to be stored on their non-UK infrastructure. The ICO clarifies that you aren’t “initiating” a transfer if you are simply the passive recipient or if the data moves because of someone else’s independent action.
To determine if you are the one initiating, ask:
- Did I choose the recipient located outside the UK?
- Did I instruct the data to be sent or made available to them?
- Is the transfer a planned part of my business or organisational process?
Step 3: Is the receiver a separate legal entity?
A separate legal entity is any person or organisation that has its own legal personality. This includes different companies, subsidiaries and parent companies, joint ventures and individual professionals, e.g. self-employed consultants. If a UK company has a branch office in New York (not a separate US-incorporated company, just a physical office of the UK firm), sending data there is not a restricted transfer. Also, a UK employee accessing their own company’s database while working remotely from an overseas hotel is not considered to be a transfer to a separate entity.
What Organisations Need To Do
You should update any internal data protection impact assessments (DPIAs) and transfer policies to reflect the new “not materially lower” standard, and train all relevant team members on the changes detailed above. You should also ensure that procurement and IT teams understand that “initiating” a transfer includes making data available via remote access (e.g., overseas support staff viewing UK databases), not just physically sending files.
Organisations should also document all decisions regarding international data transfers, even if they know that the transfer meets the new data protection test. The law may be more pragmatic, but it doesn’t remove the need for accountability.
If your organisation already has a compliant Transfer Risk Assessment from prior to the DUAA coming into law that concluded that the protection was sufficient, you don’t need to do anything further – it will automatically meet the new standards of the DUAA. If a previous data transfer was rejected because the third country involved did not have ‘essential equivalence’ to UK data protection laws, you could now revisit this if the third country meets the requirement of their legal protections for personal data being ‘not materially lower’ than the UK’s.
Note: The UK still has adequacy decisions for many other countries that mean a data protection test is not required to transfer personal data to these countries. You can see more details about adequacy regulations and the full list of countries that have an adequacy agreement in place here on the ICO website.
The ICO is also hosting a webinar on March 10th 2026, regarding their updated guidance on international data transfers – you can sign up here.
If you want some more help or advice on international data transfers that is tailored to your organisation, get in touch with us here at Griffin House Consultancy by using the form below, or call us on 01673 885533.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.