Last updated: 8 October 2026
Quick answer: The UK International Data Transfer Agreement (IDTA) is a standard contract approved under the Data Protection Act 2018 that lets organisations make restricted transfers of personal data out of the UK. It has applied since 21 March 2022. You must still complete a transfer risk assessment, now called the data protection test.
If your organisation sends personal data from the UK to a supplier, group company or customer in a country without UK adequacy regulations, you need an appropriate safeguard. For most organisations that means the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses (SCCs).
The rules around both changed in 2026. The international transfer changes in the Data (Use and Access) Act 2025 took effect on 5 February 2026, after the ICO refreshed its transfer guidance in January 2026. This guide explains what the IDTA is, when to use it instead of the Addendum, how to complete it and what the new data protection test means for DPOs.
What is the UK International Data Transfer Agreement (IDTA)?
The IDTA is a set of standard data protection clauses for restricted transfers under the UK GDPR. It was laid before Parliament on 2 February 2022 under section 119A of the Data Protection Act 2018 and came into force on 21 March 2022, alongside the International Data Transfer Addendum to the EU SCCs.
The ICO describes both documents as contract clauses pre-approved for use as a safeguard under the UK GDPR. They impose obligations on the exporter and importer and give enforceable rights to the people whose data is transferred.
The UK needed its own documents because it left the EU before the European Commission adopted the current EU SCCs in 2021. Old-style SCCs could still be used for a while, but only as a transition:
- Contracts concluded on or before 21 September 2022 on the old SCCs could continue to be relied on.
- From 21 March 2024, the old SCCs stopped providing appropriate safeguards for UK transfers, so every UK transfer contract now needs the IDTA, the Addendum or another valid mechanism.
Common mistake: finding a legacy supplier contract that still relies on the pre-2021 SCCs. Those clauses have not protected UK transfers since March 2024. A contract review against your record of processing activities is the quickest way to find them.
When do you need the IDTA?
You need an IDTA (or another safeguard) when you make a restricted transfer to a country not covered by UK adequacy regulations and no exception applies.
The ICO’s updated guidance uses a three-step test. A transfer is restricted when all three are true:
- The UK GDPR applies to your processing of the personal information.
- You, as a UK sender, initiate the transfer to a receiver located outside the UK.
- The receiver is a separate legal person, such as another company, even if it is in your group.
If the destination is covered by UK adequacy regulations, you do not need the IDTA. For example, the Data Protection (Adequacy) (United States of America) Regulations 2023, in force since 12 October 2023, cover transfers to US organisations that participate in the UK Extension to the EU-US Data Privacy Framework. Transfers to US recipients that are not on the list still need a safeguard such as the IDTA.
IDTA or UK Addendum: which should you use?
Use the Addendum if you already rely on the EU SCCs for the same data flow; use the IDTA if the transfer is UK-only or you want a single UK-specific contract. The ICO notes that the Addendum suits organisations operating in both the UK and the EEA.
| Factor | UK IDTA | UK Addendum to EU SCCs |
|---|---|---|
| Best fit | Transfers from the UK only | Flows already covered by EU SCCs (EEA and UK exporters) |
| Structure | Four parts: tables, extra protection clauses, commercial clauses, mandatory clauses | Two parts: tables and mandatory clauses, bolted onto the EU SCCs |
| Changes allowed | Minor amendments to the mandatory clauses only as permitted in Part 4 Section 5 | Minor amendments only as set out in Sections 16 and 17 of Part 2 |
| Incorporation by reference | Yes, referencing IDTA A.1.0 issued by the ICO | Yes, referencing Addendum B.1.0 issued by the ICO |
| Transfer risk assessment | Required | Required |
In practice: multinational groups usually pick the Addendum so one set of SCCs covers both EEA and UK exports, while UK-only businesses often find the IDTA’s plain tables easier to explain to suppliers.
What does the IDTA contain?
The IDTA has four parts, two of which are mandatory:
- Part 1: Tables (mandatory). Table 1 covers the parties and signatures, Table 2 the transfer details, Table 3 the transferred data and Table 4 the security requirements.
- Part 2: Extra protection clauses (optional). Additional technical, organisational or contractual protections, often driven by your transfer risk assessment.
- Part 3: Commercial clauses (optional). For example, the processor terms required by Article 28 UK GDPR, or other business terms.
- Part 4: Mandatory clauses (mandatory). The core protections, which you cannot change except as the clauses themselves permit.
Parts 1 to 3 do not have to follow the ICO’s exact layout, as long as they contain the required information. That flexibility lets you put the tables into an existing data processing agreement rather than attaching a separate document.
How do you complete the UK International Data Transfer Agreement?
Treat the IDTA as a project, not a signature. These seven steps work for most DPOs:
- Map the transfer. Confirm the parties, their roles (controller or processor), the data categories, special category data, purposes and onward transfers.
- Confirm it is restricted. Apply the ICO’s three-step test and check whether adequacy regulations or an exception apply.
- Choose the mechanism. Decide between the IDTA and the Addendum, based on whether EU SCCs already cover the flow.
- Complete the transfer risk assessment. Assess the destination and the specific transfer against the data protection test (see below).
- Fill in the tables. Complete Tables 1 to 4, including realistic security requirements, and add any extra protection clauses the assessment identifies.
- Link to the commercial terms. Make sure Article 28 processor terms are covered in Part 3 or in your existing agreement.
- Record and review. Log the agreement, the assessment and review dates in your transfer register, and review when the transfer, the importer or the destination law changes.
Keeping transfers, contracts and assessments linked to each supplier record avoids the usual scramble at audit time. If you want to test that approach, you can start your 14-day free trial and load your current transfer inventory.
What is the data protection test for international transfers?
The data protection test is the new legal name for what the ICO still calls a transfer risk assessment (TRA). It asks whether the protection for the data after transfer will be not materially lower than under UK data protection law.
Schedule 7 of the Data (Use and Access) Act 2025 rewrote the UK GDPR transfer chapter around this test. The ICO’s guidance confirms that when you use the IDTA or the Addendum, you must also complete a TRA and put in place any extra protections needed to meet the data protection test.
The ICO’s guidance on completing a transfer risk assessment takes a risk-based approach. A proportionate assessment usually looks at:
- the nature, volume and sensitivity of the personal data
- how the data will be accessed and stored in the destination country
- the laws and practices on public authority access that could affect it
- whether the contractual protections can be enforced in practice
- the extra technical measures, such as encryption or pseudonymisation, that reduce remaining risk
In practice: the new test is more flexible than the old “essentially equivalent” standard, but it does not remove the need for documented reasoning. Record why you concluded the test is met, especially for special category data.
How do the UK, EU and US compare?
The mechanisms differ by jurisdiction, so check which rules apply to each data flow before choosing a contract.
| Jurisdiction | Standard contract | Assessment |
|---|---|---|
| UK | IDTA or UK Addendum to EU SCCs | TRA meeting the “not materially lower” data protection test |
| EU/EEA | EU SCCs (2021 version, modular) | Transfer impact assessment under the “essentially equivalent” standard |
| US | No general federal transfer contract; state privacy laws set processor contract requirements | No general equivalent; sector rules may apply |
For UK exporters, the practical effect is that one supplier contract may need the EU SCCs, the UK Addendum and a separate processing agreement. The GDPR and UK GDPR framework pages show how those requirements overlap.
What are the most common IDTA mistakes?
- Signing the IDTA but never completing or recording the transfer risk assessment.
- Leaving Table 4 (security requirements) vague, so it cannot be tested or audited.
- Forgetting onward transfers by the importer to its own sub-processors.
- Assuming every US transfer is covered by the UK-US data bridge without checking the importer’s certification.
- Not reviewing agreements when the ICO issues a new version of the IDTA or Addendum.
Supplier due diligence is where most of these gaps are caught. A structured vendor and third-party risk management process can ask the right transfer questions at onboarding, while a DPIA covers high-risk transfers in more depth. See also our list of common GDPR compliance mistakes.
Key takeaways
- The IDTA and UK Addendum have been the standard UK transfer contracts since 21 March 2022; old SCCs stopped working for UK transfers on 21 March 2024.
- Use the Addendum where EU SCCs already cover the flow, and the IDTA for UK-only transfers.
- Only minor, permitted changes to the mandatory clauses are allowed.
- Since 5 February 2026, transfers are assessed against the “not materially lower” data protection test.
- Keep the agreement, the TRA and review dates together in your transfer register.
Frequently asked questions
Is the IDTA mandatory for all international transfers?
No. The IDTA is one of several options for restricted transfers. You do not need it if the destination is covered by UK adequacy regulations, if you rely on binding corporate rules, or if a genuine exception applies. You can also use the UK Addendum to the EU SCCs instead. What is mandatory is having a valid mechanism for each restricted transfer.
Can I edit the IDTA?
Only within limits. Parts 1 to 3 can be laid out in your own format as long as they contain the required information, and you can add extra protection and commercial clauses. The Part 4 mandatory clauses can only be changed in the minor ways permitted by Part 4 Section 5. Larger changes mean the document is no longer the approved IDTA.
Do I still need a transfer risk assessment with the IDTA?
Yes. The ICO confirms that when you use the IDTA or the Addendum you must also complete a transfer risk assessment and add any extra protections needed. Since the Data (Use and Access) Act changes took effect, UK law calls this the data protection test and asks whether protection will be not materially lower than in the UK.
Are old EU SCCs still valid for UK transfers?
No. Contracts signed on or before 21 September 2022 using the old SCCs could be relied on only until 21 March 2024. Since then, UK exporters must use the IDTA, the UK Addendum to the 2021 EU SCCs, or another valid transfer mechanism. Review legacy supplier contracts to make sure none still rely on the old clauses.
Do the DUAA changes mean I must re-sign my IDTAs?
Not automatically. Existing IDTAs and Addenda remain valid safeguards after the international transfer changes took effect on 5 February 2026. What changes is the assessment standard you apply. Parties can choose to have their IDTA or Addendum update automatically when the ICO issues a new version, so check which option your contracts selected.
Keeping UK transfers defensible
The UK International Data Transfer Agreement remains the core tool for restricted transfers from the UK, and the Data (Use and Access) Act changes make the assessment behind it more flexible rather than optional. Map your transfers, choose the IDTA or the Addendum deliberately, document the data protection test and review both whenever the transfer changes.
Enactia’s AI-powered GRC platform keeps transfer records, supplier assessments and DPIAs connected across UK GDPR and EU GDPR. To discuss your transfer programme, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
