Restricted Transfer
A restricted transfer is when an organisation makes personal information available to a separate organisation located outside the UK, either by sending it there or by letting them access it. Because the receiving organisation is in another country, extra safeguards are generally needed before the transfer can lawfully go ahead. This concept comes from UK data protection guidance and is not about restrictions on transferring company shares.
Under UK GDPR as described in ICO guidance, a restricted transfer generally arises where a UK-based organisation sends, or makes accessible, personal data to a separate legal entity (a distinct controller or processor) located outside the UK. Per the ICO, the transfer is treated as occurring at the point the information is made accessible to a person or entity outside the UK, which includes remote access by an overseas organisation rather than only physical or electronic sending. This definition addresses only when a restricted transfer is deemed to take place and the separate-entity element; it does not cover the transfer mechanisms that may be required to lawfully make such a transfer (such as adequacy determinations or standard contractual clauses), retention obligations, or enforcement consequences, which are addressed separately. Treatment differs under other regimes, including the EU GDPR, and the term should not be conflated with unrelated 'transfer restriction' concepts in corporate or securities contexts, such as provisions blocking a stockholder from transferring shares.
Why it matters
Determining whether a data flow constitutes a restricted transfer is the trigger that decides whether additional safeguards are needed before personal data can lawfully leave the UK's protective framework. If an organisation misclassifies an arrangement, for example, treating routine overseas access to a UK database as an internal matter rather than a restricted transfer, it may proceed without the transfer mechanism that would otherwise be required, exposing the organisation to compliance risk. Getting the threshold question right is therefore a prerequisite to any downstream analysis of adequacy, contractual safeguards, or supplementary measures.
The concept is particularly important because, under ICO guidance, the transfer is treated as occurring at the point personal data is made accessible to a separate organisation outside the UK. This means the trigger is not limited to physically or electronically sending a dataset abroad; granting an overseas entity remote access to data that remains hosted in the UK can also constitute a restricted transfer. Common cloud, support, and outsourcing arrangements can therefore fall within scope even where the data itself never appears to move, which is a frequent source of expert-level oversight.
A further reason precision matters is the separate-entity element: a restricted transfer generally arises where data is made available to a distinct legal entity, a separate controller or processor, located outside the UK. Confusing this concept with the unrelated corporate or securities meaning of 'transfer restriction' (a provision blocking a stockholder from transferring shares) can lead to serious analytical errors. This entry addresses only when a restricted transfer is deemed to take place; it does not cover the mechanisms required to make such a transfer lawful, retention obligations, or enforcement consequences, which are treated separately.
Who it's relevant to
Inside Restricted Transfer
Common questions
Answers to the questions practitioners most commonly ask about Restricted Transfer.