UKGI Compliance Manual

The rules and principles which apply

The UK GDPR recognises the global nature of data processing but prioritises ensuring that the high standards of data protection afforded to individuals within the UK are not undermined when their personal data is transferred abroad. To achieve this, the UK GDPR establishes a framework of rules and conditions that must be met for such transfers to be lawful.

All international transfers of personal data must be conducted lawfully, securely and in accordance with UK General Data Protection Regulation, The Data Protection Act 2018, ICO Guidance and any applicable contractual obligations that the firm may have, for example with insurers, clients, or business partners.

Firms must be able to demonstrate that every international transfer has a lawful basis (see Section XXXX) and appropriate safeguards.

An international data transfer occurs where personal data is:

  • Sent to a recipient outside the UK
  • Stored on Systems located outside the UK
  • Accessed remotely by an individual or organisation outside the UK
  • Processed by an overseas supplier acting on the firm’s behalf

It is important to recognise that a transfer can occur even where the data remains physically stored in the UK but can be accessed overseas.

Personal data may only be transferred internationally where one of the following applies:

  • Adequacy Regulations – where the destination country has been recognised by the UK Government as providing an adequate level of protection for personal data (usually where this is at least equivalent to those standards set out in the UK GDPR. Where adequacy arrangements are in place no additional safeguards are usually required.
  • Appropriate Safeguards – Where no adequacy arrangements apply, a firm must ensure appropriate safeguards are in place, these may include:
    • A UK International Data Transfer Agreement (IDTA)
    • UK Addendum to the EU Standard contractual clauses
    • Approved binding corporate rules
    • Approved codes of conduct or certification mechanisms

Firms are required to document their international transfer arrangements and safeguards in a Transfer Risk Assessment (TRA), this should typically be undertaken before the transfer commences.

How this may affect firms

Firms will typically transfer data outside the UK where for example they share data with overseas insurers, reinsurers, loss adjusters, and claims handlers. They may also transfer data to technology suppliers or other suppliers based outside the UK or use cloud services where data is stored or accessed internationally. The requirements for international data transfers also apply if the firm shares data with other group companies who are located outside of the UK and it is important to note that international transfers can include both routine and one-off arrangements.

The appropriate contractual mechanisms should be agreed before any transfer begins, if firms are however unsure as to whether any of their current data sharing arrangements involve international transfers,  we recommend that they complete a review of their data sharing arrangements by checking their agreements with third parties, and where there is any doubt, requesting confirmation from the parties with whom data is shared as to whether this involves the storing or processing of data outside the UK. Firms should record these arrangements on their data asset register (see Section K.6.1) which should include:

  • Destination countries
  • Categories of personal data transferred
  • Purpose of the transfer
  • Legal basis and safeguards used
  • Transfer risk assessments
  • Supporting contracts
  • Review dates

Adequacy Arrangements

Personal data may be transferred outside the UK where the UK Government has confirmed that the destination country, territory, sector, or international organisation provides an adequate level of protection for personal data.

Where an adequacy decision applies, personal data can flow to that recipient as though it remains within the UK, because the Government has assessed the legal framework as providing comparable protection. In these circumstances, no further transfer safeguards are usually required.

Because the UK GDPR closely reflects EU data protection principles and requirements, personal data can currently continue to flow freely between the UK and EEA member states under an adequacy decision. This means the UK and EU recognise their respective data protection frameworks as broadly equivalent.

GOV.UK publishes information on the UK’s adequacy arrangements including a list of existing Adequate Countries, Jurisdictions and Territories.

It is important to note that Adequacy Decisions do remain under review and can be withdrawn, therefore firms relying on these to transfer data outside of the UK should regularly check that these remain in place.

Appropriate Safeguards

In situations where a recipient country or organisation has not been deemed adequate by the UK government, personal data can still be transferred if the exporting organisation implements appropriate safeguards. These safeguards aim to provide a level of protection essentially equivalent to the guaranteed by the UK GDPR. Crucially, the UK GDPR emphasises that alongside these safeguards, individuals’ rights must be enforceable, and effective legal remedies must be available to them in the recipient country should any issues arise after the transfer.

The UK GDPR provides a non-exhaustive list of mechanisms that can serve as appropriate safeguards in Article 46 of the UK GDPR – known as Article 46 transfer mechanisms which are:

  • Legally binding agreements between public authorities or bodies: These are formal agreements that establish data protection standard for the transfer.
  • Binding Corporate Rules (BCRs): These are internal data protection policies adopted by multinational corporate groups that govern the transfer of personal data between entities within the same group located inside and outside the UK. BCRs need to be approved by the UK’s Information Commissioner’s Office (ICO).
  • International Data Transfer Agreement (IDTA): This is a standard form of contract, issued by the ICO, the organisations can use to provide appropriate safeguards for international transfers.
  • Addendum to the EU Standard Contractual Clauses (SCCs): Organisations can also use the EU SCCs with a specific addendum approved by the ICO to make them work for transfers from the UK.
  • Compliance with an approved code of conduct: These are sets of rules developed by associations or other bodies and approved by the ICO, outlining how personal data should be processed in specific sectors.
  • Certification under an approved certification mechanism: These are schemes that allow organisations to demonstrate their compliance with the UK GDPR’s requirements for international transfers.
  • Contractual clauses authorised by the competent supervisory authority (the ICO): Organisations can also draft their own contractual clauses for data transfers, but these need to be reviewed and authorised by the ICO.
  • Provisions inserted into administrative arrangements between public authorities or bodies authorised by the competent supervisory authority (the ICO): Similar to legally binding agreements, these are specific arrangements between public entities with embedded data protection obligations.

Before a firm may rely on an Article 46 transfer mechanism to make a restricted transfer, it must be satisfied that the relevant protections in the UK GDPR are not undermined for people whose data is transferred.

A TRA must be completed, documented, and retained. It should assess both the protections provided by the chosen Article 46 transfer mechanism and the level of protection available to data subjects in the destination country, including:

  • Surveillance and government access laws
  • Availability of legal remedies
  • Nature and sensitivity of the data
  • Volume of data transferred
  • Security controls in place
  • Technical protections (e.g. encryption)

If the outcome of the assessment is that the Article 46 transfer mechanism does not provide the required level of protection, extra steps must be taken before the transfer is made so that it does provide the right level of protection.

Limited Exceptions

While the UK GDPR sets a general framework requiring adequacy decisions or appropriate safeguards, it also provides specific exceptions that allow for data transfers in particular situations. These are set out in Article 49 of the UK GDPR and are intended to address specific needs; they should therefore be interpreted narrowly and include cases where:

  • The individual has explicitly consented to the transfer
  • The transfer is necessary for the performance of a contract  with the person the information is about or with a third party, and doing so benefits the person the information is about
  • The transfer is required for legal proceedings
  • The transfer is necessary for important public interest reasons
  • Necessary to protect the vital interests of the data subject (this is a very limited exception for situations where someone’s life or health is at risk).

You will need to justify and document your reasons for relying on an exception in your TRA and before relying on an Article 49 exception, you must be sure that it is both necessary and proportionate to do so which means that you must ask yourself:

  • Is it possible to achieve the purpose set out in the exception , without making the restricted transfer?
  • Would it be more proportionate to use an Article 46 transfer mechanism rather than rely on an exception?

This means that firms should exercise caution before relying wholly on an exception and you must first consider if you can reasonably achieve the same purpose by other means, this is because when you transfer personal information on the basis of an exception there is a danger that the information (and the person concerned) will lose all protection once you’ve transferred it.

In practice therefore, you should aim to reduce the risk by putting other protections in place where possible, which will help to make relying on the exception more proportionate, for example:

  • a safeguard with a TRA which identifies the information which is not sufficiently protected;
  • professional rules (e.g. legal privilege);
  • contractual protections (e.g. a confidentiality agreement or binding obligations to delete the information soon after transfer); or
  • technical and organisational measures to protect the information (e.g. pseudonymisation and restrictions on accessing or using the information).

ICO guidance states that it is not enough to argue that the transfer is necessary because you have chosen to operate your business in a particular way. The question is whether the transfer is objectively necessary and proportionate for the stated purpose, not whether it is a necessary part of your chosen methods.

You may also wish to rely on an exception in situations where you have an Article 46 transfer mechanism in place but your transfer risk assessment, decided that appropriate safeguards were in place for some, but not all, of the risks to data.

The ICO website provides further information on Article 49 exceptions in its Guide to International Transfers including examples of what might be considered when assessing whether reliance on an exception is necessary and proportionate in the circumstances.

Where international transfers occur, these must be explained in the firms Privacy Notice which should include:

  • That international transfers may take place
  • Relevant destination countries (where appropriate)
  • Safeguards in place
  • How individuals can obtain further information

One-Off or Infrequent Transfers

In very specific circumstances involving one-off or infrequent transfers of personal data concerning only a relatively few individuals, and where no adequacy decision, appropriate safeguards, or exception applies, the UK GDPR still permits the transfer under strict conditions, including:

  • The transfer not being made by a public authority in the exercise of its public powers.
  • The transfer being non-repetitive (not part of an ongoing pattern).
  • The transfer involving data related to only a limited number of individuals.
  • The transfer being necessary for the compelling legitimate interests of the organisation making the transfer, provided these interests are not overridden by the interests or rights and freedoms of the individual.
  • The organisation implementing suitable safeguards to protect the personal data, based on an assessment of all the circumstances surrounding the transfer.

In these exceptional cases, organisations are obliged to inform the Information Commissioner’s Office (ICO) of the transfer and provide additional information to the individuals whose data is being transferred.

Responsibilities

Senior Management is responsible for ensuring that appropriate governance arrangements are in place regarding international data transfers and that adequate resources are available to ensure that compliance is monitored and that significant transfers are appropriate authorised with appropriate technical organisational measures to protect data security (more information on Accountability and Governance can be found in Section K.6 and data security measures can in Section K.6.2)

It is also important that appropriate due diligence is undertaken before engaging any overseas suppliers which is covered in more detail in Section K.6.3.