Skip to main content
Category: International Data Transfers

Restricted Transfer

Also known as: Transfer Restriction
Simply put

A restricted transfer is when an organisation makes personal information available to a separate organisation located outside the UK, either by sending it there or by letting them access it. Because the receiving organisation is in another country, extra safeguards are generally needed before the transfer can lawfully go ahead. This concept comes from UK data protection guidance and is not about restrictions on transferring company shares.

Formal definition

Under UK GDPR as described in ICO guidance, a restricted transfer generally arises where a UK-based organisation sends, or makes accessible, personal data to a separate legal entity (a distinct controller or processor) located outside the UK. Per the ICO, the transfer is treated as occurring at the point the information is made accessible to a person or entity outside the UK, which includes remote access by an overseas organisation rather than only physical or electronic sending. This definition addresses only when a restricted transfer is deemed to take place and the separate-entity element; it does not cover the transfer mechanisms that may be required to lawfully make such a transfer (such as adequacy determinations or standard contractual clauses), retention obligations, or enforcement consequences, which are addressed separately. Treatment differs under other regimes, including the EU GDPR, and the term should not be conflated with unrelated 'transfer restriction' concepts in corporate or securities contexts, such as provisions blocking a stockholder from transferring shares.

Why it matters

Determining whether a data flow constitutes a restricted transfer is the trigger that decides whether additional safeguards are needed before personal data can lawfully leave the UK's protective framework. If an organisation misclassifies an arrangement, for example, treating routine overseas access to a UK database as an internal matter rather than a restricted transfer, it may proceed without the transfer mechanism that would otherwise be required, exposing the organisation to compliance risk. Getting the threshold question right is therefore a prerequisite to any downstream analysis of adequacy, contractual safeguards, or supplementary measures.

The concept is particularly important because, under ICO guidance, the transfer is treated as occurring at the point personal data is made accessible to a separate organisation outside the UK. This means the trigger is not limited to physically or electronically sending a dataset abroad; granting an overseas entity remote access to data that remains hosted in the UK can also constitute a restricted transfer. Common cloud, support, and outsourcing arrangements can therefore fall within scope even where the data itself never appears to move, which is a frequent source of expert-level oversight.

A further reason precision matters is the separate-entity element: a restricted transfer generally arises where data is made available to a distinct legal entity, a separate controller or processor, located outside the UK. Confusing this concept with the unrelated corporate or securities meaning of 'transfer restriction' (a provision blocking a stockholder from transferring shares) can lead to serious analytical errors. This entry addresses only when a restricted transfer is deemed to take place; it does not cover the mechanisms required to make such a transfer lawful, retention obligations, or enforcement consequences, which are treated separately.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads use the restricted transfer test to identify which data flows require further scrutiny before proceeding. Correctly recognising that overseas remote access can trigger the concept, and not only the physical or electronic sending of data, helps ensure that safeguards are considered at the right point. Note that identifying a restricted transfer does not itself establish a lawful mechanism for it; that is a separate analysis.
Legal and Compliance Teams
Legal and compliance professionals rely on the separate-entity and overseas-location criteria when advising on outsourcing, group arrangements, and vendor relationships under UK GDPR. They should be careful to distinguish this ICO concept from the unrelated corporate or securities meaning of 'transfer restriction,' and to remember that treatment differs under the EU GDPR and other regimes.
Cloud, IT, and Data Governance Teams
Teams responsible for data architecture, cloud services, and support arrangements need to understand that granting an overseas entity access to UK-hosted personal data can constitute a restricted transfer even where the data does not appear to move. Accurate data flow and entity mapping supports demonstrable accountability and helps the organisation surface arrangements that may need additional review.

Inside Restricted Transfer

Cross-Border Data Flow
A restricted transfer generally refers to the movement of personal data from a jurisdiction with data protection rules to a recipient in another country or international organisation that is not covered by those same rules. The concept originates in EU GDPR and is mirrored in UK GDPR, though the precise scope and terminology differ between the two regimes and other frameworks.
Transfer Mechanism
For a restricted transfer to proceed lawfully, an appropriate safeguard or legal basis for the transfer typically needs to be in place. In the EU and UK regimes these commonly include adequacy decisions, standard contractual clauses, binding corporate rules, or specified derogations. The availability and form of these mechanisms differ by jurisdiction and are subject to change.
Exporter and Importer Roles
A restricted transfer typically involves a data exporter (the party disclosing or making the data available, which may be a controller or processor) and a data importer (the recipient). Obligations attach differently depending on whether each party acts as a controller or a processor; this entry does not resolve those role-specific duties in full.
Adequacy Consideration
Some destinations may be recognised by a regulator or competent authority as offering an adequate level of protection, which can remove the need for an additional transfer mechanism. Adequacy determinations are jurisdiction-specific, are made by particular authorities, and can be granted, limited, or withdrawn over time.
Onward Transfer
Personal data received through a restricted transfer may be subject to further, or onward, transfers to additional recipients. Such onward flows generally require their own consideration of whether an appropriate mechanism or basis applies.

Common questions

Answers to the questions practitioners most commonly ask about Restricted Transfer.

Does encrypting personal data before sending it abroad mean the transfer is no longer restricted?
No. Encryption is a security control that protects confidentiality in transit and at rest, but it does not remove data from the scope of a restricted transfer. Encrypted personal data generally remains personal data, because the transfer still involves making that data accessible to a recipient in a third country, and the encryption may be reversible by parties holding the keys. Under the EU GDPR and UK GDPR, encryption may serve as a supplementary technical measure supporting a transfer mechanism, but it does not by itself constitute a lawful basis for the transfer or make the transfer unrestricted. This answer does not address which specific transfer mechanism applies in a given case.
If our cloud provider stores the data within the same region, does that automatically mean no restricted transfer occurs?
Not necessarily. A restricted transfer generally turns on whether personal data becomes accessible to, or is processed by, a recipient located in or subject to the jurisdiction of a third country, not solely on where data is physically stored. Remote access to data from a third country by support staff, administrators, or sub-processors can itself constitute a restricted transfer under the EU GDPR and UK GDPR. Storage location and access location are distinct considerations, and both should be assessed. This answer does not cover the specific mechanics of any individual provider arrangement.
How should we identify whether a given data flow qualifies as a restricted transfer?
Typically this involves mapping the personal data flows in scope of the relevant regime, identifying the exporting party and its role, and determining whether a recipient is located in or subject to a third country as defined by that regime. Because the EU GDPR and UK GDPR treat their respective lists of adequate jurisdictions differently, the same flow may be assessed differently under each. Documenting the source, recipients, categories of data, and access arrangements supports this analysis. This answer does not prescribe which transfer mechanism to select once a restricted transfer is identified.
What role does a transfer risk or impact assessment play when relying on a transfer mechanism?
Where a transfer relies on a mechanism such as standard contractual clauses, controllers and processors are generally expected under the EU GDPR and UK GDPR to assess whether the mechanism, combined with any supplementary measures, provides protection that is essentially equivalent in the destination jurisdiction. This assessment considers the legal context of the recipient country and the practical circumstances of the transfer. The outcome should be documented as evidence, since accountability requires demonstrable records rather than stated intent. This answer does not specify the exact form or template such an assessment must take.
Who bears responsibility for putting a valid transfer mechanism in place?
Responsibility depends on the roles of the parties in the specific flow. A data controller that acts as the exporter generally bears primary accountability for ensuring a lawful transfer mechanism and appropriate safeguards are in place, while a processor exporting data on a controller's instructions has its own obligations under its processing arrangement. Where onward transfers to sub-processors occur, the contractual chain should reflect corresponding obligations. This answer does not address the internal allocation of these duties within any particular organization or contract.
How should organizations maintain evidence of their restricted transfer arrangements?
Because accountability under these frameworks requires demonstrable evidence, organizations typically retain the executed transfer mechanism, records of the flows it covers, any transfer risk assessment, and documentation of supplementary measures applied. These records may connect to broader governance artefacts such as records of processing activities, though a records of processing obligation is a legal requirement and not the same as any particular inventory tool. Evidence should be kept current as flows, recipients, and jurisdictional adequacy positions change. This answer does not address retention periods or enforcement consequences.

Common misconceptions

Encrypting or tokenizing personal data before sending it abroad means the transfer is no longer a restricted transfer.
Encryption and tokenization are security measures that may support the case that a transfer has appropriate safeguards, but they do not, by themselves, render data non-personal or remove it from the scope of transfer rules. Where the data can still be linked back to individuals, it generally remains personal data and the transfer remains restricted.
Putting a standard contractual clause in place automatically guarantees the transfer is compliant.
A transfer mechanism such as standard contractual clauses is typically necessary but not automatically sufficient. In most cases the exporter is expected to assess whether the mechanism provides effective protection in the specific circumstances, including the legal environment of the destination, and to implement supplementary measures where needed. Compliance depends on context and implementation.
Restricted transfer rules under EU GDPR, UK GDPR, and other regimes are interchangeable.
These regimes address cross-border transfers separately, with distinct terminology, mechanisms, and adequacy determinations. A safeguard recognised under one regime is not automatically valid under another, and frameworks such as CCPA/CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework treat data movement differently or not through the same lens.

Best practices

Map data flows to identify where personal data leaves the originating jurisdiction, recording the exporter, the importer, and each party's role as controller or processor.
Determine whether the destination benefits from an adequacy determination by the relevant authority before relying on a contractual or other transfer mechanism, and re-check periodically as such determinations can change.
Where a transfer mechanism such as standard contractual clauses or binding corporate rules is used, assess whether it provides effective protection in context and document any supplementary measures rather than treating the mechanism as self-sufficient.
Treat security controls like encryption and tokenization as supporting safeguards, not as a means of removing data from the scope of transfer rules.
Account for onward transfers by ensuring recipients are contractually and operationally bound to apply an appropriate basis before disclosing data further.
Maintain demonstrable, evidenced records of transfer assessments and decisions, since accountability under these frameworks generally requires documentation rather than stated intent, and confirm the analysis against the specific regime that applies.