Description

UK International Data Transfer Agreement implemented

On 21 March 2022, the UK International Data Transfer Agreement (IDTA) proposed by the Information Commissioner's Office is implemented, replacing the EU Standard Contractual Clauses (SCCs) for international data transfers. Similarly to the EU SCCs, the IDTA contains clauses detailing the obligations of data exporters and importers, including duties in the event of a data breach and in dealing with data access requests. The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Addendum), for use by businesses already using the EU SCCs to carry out data transfers from the EU, has also been implemented.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2021-08-11
in consultation

On 11 August 2021, the United Kingdom (UK) Information Commissioner (ICO) issued the draft UK Inter…

2021-10-11
processing consultation

On 11 October 2021, the consultation on the United Kingdom International Data Transfer Agreement (I…

2022-02-02
adopted

On 2 February 2022, the UK Information Commissioner (ICO) issued the UK International Data Transfer…

2022-03-21
in force

On 21 March 2022, the UK International Data Transfer Agreement (IDTA) proposed by the Information C…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): transfer (any destination)
Regulatory tool
Risk or other impact assessment requirement
Standard contractual clauses requirement
Adequacy decision requirement
Sanctions
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): transfer (any destination)