Skip to main content
Category: International Data Transfers

International Data Transfer Agreement

Also known as: IDTA, UK IDTA, International data transfer agreement
Simply put

The International Data Transfer Agreement (IDTA) is a standard contract created for use under the UK data protection regime that organisations can put in place when they send personal data to a country outside the UK that does not have a UK adequacy decision. It sets out legally binding commitments intended to protect that personal data once it leaves the UK. It is a UK-specific tool and should not be assumed to apply to transfers governed by the EU GDPR or other regimes.

Formal definition

The IDTA is a form of standard data protection clauses that UK data exporters may use as an appropriate safeguard for a restricted transfer of personal data under the UK GDPR when no relevant adequacy decision applies, provided it is entered into as a legally binding contract. As reflected in ICO guidance, the IDTA (or the UK Addendum to the EU standard contractual clauses) is typically used alongside a transfer risk assessment (TRA), and per the sources organisations entering into new arrangements involving UK personal data after 21 September 2022 are expected to rely on the IDTA or the Addendum. This entry describes the IDTA's role as a transfer mechanism only; it does not cover the detailed mechanics of completing a TRA, the substantive terms of the IDTA, retention obligations, the separate EU GDPR transfer regime, or enforcement consequences. Whether reliance on the IDTA is adequate depends on the specific transfer, jurisdictions, and implementation, and its use alone does not guarantee compliance.

Why it matters

For organisations operating under the UK data protection regime, moving personal data outside the UK to a country without a UK adequacy decision is a restricted transfer that generally requires an appropriate safeguard. The IDTA provides a standard, legally binding contractual mechanism to supply that safeguard, giving exporters a recognised route to demonstrate that personal data remains protected after it leaves the UK. Without such a mechanism in place, a restricted transfer may lack a lawful basis for the transfer itself, which is a distinct requirement from having a lawful basis for the underlying processing.

The IDTA also matters because it is UK-specific and should not be treated as interchangeable with the EU GDPR transfer regime or other frameworks. According to the sources, organisations entering into new arrangements involving UK personal data after 21 September 2022 are expected to rely on the IDTA or the UK Addendum to the EU standard contractual clauses. Selecting the correct instrument for the correct regime is therefore a practical compliance decision, and using an EU-facing mechanism alone will not necessarily satisfy UK requirements.

It is important to keep expectations realistic: entering into the IDTA does not by itself guarantee compliance. Per ICO guidance, the IDTA is typically used alongside a transfer risk assessment (TRA), and whether reliance on the IDTA is adequate depends on the specific transfer, the jurisdictions involved, and how it is implemented. Accountability generally requires demonstrable evidence that the safeguard and any accompanying assessment were actually carried out, not merely that a contract was signed.

Who it's relevant to

Data protection officers and privacy leads
Those responsible for UK data protection compliance need to identify restricted transfers and determine whether the IDTA or the UK Addendum is the appropriate mechanism, and to ensure it is used alongside a transfer risk assessment where applicable. This entry does not cover the detailed mechanics of completing a TRA.
UK data exporters
Organisations acting as UK data exporters can use the IDTA as an appropriate safeguard for restricted transfers of personal data outside the UK where no relevant adequacy decision applies, provided it is entered into as a legally binding contract.
Legal and contracting teams
Teams drafting and negotiating data transfer arrangements need to put the IDTA or the UK Addendum in place for new arrangements involving UK personal data, and to confirm the instrument is legally binding. The substantive terms of the IDTA are outside the scope of this entry.
Compliance and governance functions
Those maintaining evidence of accountability should note that using the IDTA alone does not guarantee compliance; its adequacy depends on the specific transfer, jurisdictions, and implementation, and demonstrable evidence of the safeguard and any accompanying assessment is generally expected. This entry does not address retention obligations, the separate EU GDPR transfer regime, or enforcement consequences.

Inside IDTA

UK-Specific Transfer Instrument
The IDTA is a transfer mechanism issued by the UK Information Commissioner's Office for use under the UK GDPR to legitimise transfers of personal data from the UK to third countries lacking a UK adequacy determination. It is distinct from the EU Standard Contractual Clauses, which serve the equivalent function under the EU GDPR; the two instruments are not interchangeable, though they address a comparable problem.
Addendum to the EU SCCs
Alongside the standalone IDTA, the ICO published an addendum that can be appended to the EU Standard Contractual Clauses, allowing organisations already relying on the EU SCCs to extend those clauses to cover UK-originating transfers rather than executing a separate standalone document.
Party Roles and Obligations
The instrument allocates obligations according to the roles of the parties, typically the data exporter and the data importer, and reflects whether each acts as a controller or processor. The distribution of obligations differs depending on these roles, and the parties should identify their capacity accurately before completing the document.
Relationship to Transfer Risk Assessment
Reliance on the IDTA is generally understood to be accompanied by an assessment of the risks arising in the destination jurisdiction, considering local laws and practices that may affect the protection afforded to the transferred data. The IDTA itself is the contractual instrument and does not by itself substitute for that assessment.

Common questions

Answers to the questions practitioners most commonly ask about IDTA.

Does using the IDTA on its own guarantee that our international transfer is compliant?
No. The IDTA is a transfer mechanism recognised under the UK GDPR for transferring personal data to a jurisdiction not covered by UK adequacy regulations, but executing it does not by itself make a transfer lawful. Generally, you also need a valid lawful basis for the underlying processing, must satisfy the wider UK GDPR obligations, and, in most cases, are expected to assess the risks associated with the destination jurisdiction. Putting the IDTA in place addresses the transfer safeguard question but is not a substitute for the rest of your compliance obligations. This answer does not cover the detailed content of any such assessment.
Is the IDTA the same thing as the EU Standard Contractual Clauses (SCCs)?
No, they are distinct instruments tied to different regimes. The IDTA is a UK instrument used for transfers subject to the UK GDPR, whereas the EU SCCs are used for transfers subject to the EU GDPR. They should not be treated as interchangeable. The UK also recognises an approach that layers a UK addendum onto the EU SCCs as an alternative to the standalone IDTA. Because the underlying regimes differ, you should scope which instrument applies to a given transfer rather than assuming one document satisfies both. This answer does not address the specific drafting differences between the documents.
When would we choose the IDTA versus the UK addendum to the EU SCCs?
Both are recognised routes for transfers subject to the UK GDPR. Organisations that operate only under the UK regime, or that want a self-contained UK-specific document, may prefer the standalone IDTA. Organisations already using the EU SCCs for EU-scoped transfers sometimes prefer to add the UK addendum so that a single underlying set of clauses covers both regimes with less duplication. The choice is generally driven by which regimes apply to your transfers and how you prefer to manage contract maintenance. This answer does not cover the specific formatting or completion steps for either option.
Who is responsible for completing and maintaining the IDTA, the controller or the processor?
Responsibility depends on which parties are the exporter and importer and their roles in the transfer. Generally the exporting party has a strong interest in ensuring the correct mechanism is in place, but both parties enter into the agreement and take on the obligations it assigns to them. Accountability under the UK GDPR requires demonstrable evidence, so both sides should typically retain records showing the IDTA was executed, kept current, and mapped to the specific transfers it covers. This answer does not specify the individual obligations allocated within the IDTA text.
Do we need to reassess an IDTA once it is signed, or is it a one-time step?
It should generally be treated as an ongoing obligation rather than a one-time formality. Circumstances that can affect a transfer, such as changes in the nature of the data, the parties involved, the destination jurisdiction, or the surrounding legal environment, may require you to revisit whether the safeguard remains appropriate. Maintaining evidence of periodic review supports the accountability principle. This answer does not prescribe a review frequency or the criteria for triggering reassessment.
Does the IDTA cover retention, deletion, and security requirements for the transferred data?
The IDTA functions as a transfer safeguard and addresses the protections that travel with the data between exporter and importer, but it is not a complete substitute for your broader obligations. Retention and deletion rules, and the specific technical and organisational security controls you apply, are typically governed by the wider UK GDPR framework and your internal policies rather than resolved solely by the existence of a transfer instrument. You should treat the IDTA as one component within your overall governance and security programme. This answer does not detail retention periods or specific security controls.

Common misconceptions

The IDTA and the EU Standard Contractual Clauses are the same thing and can be used interchangeably.
The IDTA is a UK instrument tied to the UK GDPR, while the EU SCCs are issued under the EU GDPR. They are separate mechanisms with distinct legal footing. Where an organisation relies on the EU SCCs and also needs to cover UK transfers, the ICO's addendum is the intended bridge rather than treating one document as automatically covering both regimes.
Executing an IDTA on its own guarantees that a cross-border transfer is compliant.
The IDTA provides a contractual basis for a transfer, but compliance depends on context, including the roles of the parties, an assessment of the destination jurisdiction, and the overall lawfulness of the underlying processing. No single instrument guarantees compliance in isolation.
An IDTA is only relevant once and does not need revisiting after signature.
The appropriateness of relying on the IDTA can change if circumstances in the destination jurisdiction, the nature of the data, or the roles of the parties change. Practitioners generally treat it as something to review over time rather than a one-time formality.

Best practices

Confirm whether a UK adequacy determination already covers the destination before defaulting to the IDTA, since a transfer mechanism is generally only needed where adequacy is absent.
Identify the capacity of each party (exporter or importer, controller or processor) accurately before completing the document, because the allocation of obligations depends on these roles.
Decide deliberately between the standalone IDTA and the ICO addendum to the EU SCCs based on which instrument your existing contractual arrangements already rely on.
Carry out and document an assessment of the risks in the destination jurisdiction rather than treating execution of the IDTA as sufficient on its own.
Maintain demonstrable evidence of the completed instrument, the role determinations, and any supporting assessment, since accountability requires evidence rather than stated intent.
Review reliance on the IDTA periodically and when circumstances change, rather than treating signature as a permanent conclusion.
Note that this entry addresses the IDTA as a transfer instrument and does not cover retention rules, the mechanics of every alternative transfer route, or enforcement penalties, which should be assessed separately.