International Data Transfer Agreement
The International Data Transfer Agreement (IDTA) is a standard contract created for use under the UK data protection regime that organisations can put in place when they send personal data to a country outside the UK that does not have a UK adequacy decision. It sets out legally binding commitments intended to protect that personal data once it leaves the UK. It is a UK-specific tool and should not be assumed to apply to transfers governed by the EU GDPR or other regimes.
The IDTA is a form of standard data protection clauses that UK data exporters may use as an appropriate safeguard for a restricted transfer of personal data under the UK GDPR when no relevant adequacy decision applies, provided it is entered into as a legally binding contract. As reflected in ICO guidance, the IDTA (or the UK Addendum to the EU standard contractual clauses) is typically used alongside a transfer risk assessment (TRA), and per the sources organisations entering into new arrangements involving UK personal data after 21 September 2022 are expected to rely on the IDTA or the Addendum. This entry describes the IDTA's role as a transfer mechanism only; it does not cover the detailed mechanics of completing a TRA, the substantive terms of the IDTA, retention obligations, the separate EU GDPR transfer regime, or enforcement consequences. Whether reliance on the IDTA is adequate depends on the specific transfer, jurisdictions, and implementation, and its use alone does not guarantee compliance.
Why it matters
For organisations operating under the UK data protection regime, moving personal data outside the UK to a country without a UK adequacy decision is a restricted transfer that generally requires an appropriate safeguard. The IDTA provides a standard, legally binding contractual mechanism to supply that safeguard, giving exporters a recognised route to demonstrate that personal data remains protected after it leaves the UK. Without such a mechanism in place, a restricted transfer may lack a lawful basis for the transfer itself, which is a distinct requirement from having a lawful basis for the underlying processing.
The IDTA also matters because it is UK-specific and should not be treated as interchangeable with the EU GDPR transfer regime or other frameworks. According to the sources, organisations entering into new arrangements involving UK personal data after 21 September 2022 are expected to rely on the IDTA or the UK Addendum to the EU standard contractual clauses. Selecting the correct instrument for the correct regime is therefore a practical compliance decision, and using an EU-facing mechanism alone will not necessarily satisfy UK requirements.
It is important to keep expectations realistic: entering into the IDTA does not by itself guarantee compliance. Per ICO guidance, the IDTA is typically used alongside a transfer risk assessment (TRA), and whether reliance on the IDTA is adequate depends on the specific transfer, the jurisdictions involved, and how it is implemented. Accountability generally requires demonstrable evidence that the safeguard and any accompanying assessment were actually carried out, not merely that a contract was signed.
Who it's relevant to
Inside IDTA
Common questions
Answers to the questions practitioners most commonly ask about IDTA.