UK Addendum
The UK Addendum is a document issued by the UK's Information Commissioner's Office that attaches to the EU's standard contractual clauses so those EU clauses can be used to legitimise transfers of personal data out of the UK. It is one of two tools the ICO provides for this purpose, alongside the standalone UK International Data Transfer Agreement (IDTA). It is used only to provide safeguards for restricted international transfers and does not, on its own, set out broader terms such as the general roles of the parties.
The UK Addendum (also referred to as the International Data Transfer Addendum) is an ICO-issued instrument that modifies the European Commission's standard contractual clauses adopted under the EU GDPR on 4 June 2021 (the EU SCCs) so that they operate as appropriate safeguards for restricted transfers of personal data from the UK under the UK GDPR, as defined in section 3 of the Data Protection Act 2018. It functions as an alternative to the standalone UK IDTA, allowing parties already relying on the EU SCCs to extend that mechanism to UK-originating restricted transfers. Per the ICO, the Addendum must always be interpreted consistently with the UK GDPR. Scope limitation: the Addendum (like the IDTA) is intended only to legitimise restricted international transfers and does not itself supply the full commercial or controller-to-processor arrangement between the parties; this entry does not cover the substantive processing terms, retention rules, transfer risk assessment obligations, or enforcement consequences, and treatment differs from the EU regime, where the EU SCCs apply directly under the EU GDPR.
Why it matters
For organisations transferring personal data out of the UK, a restricted transfer generally requires an appropriate safeguard under the UK GDPR (as given effect in UK law and referencing definitions in the Data Protection Act 2018). Following the UK's departure from the EU, the EU's standard contractual clauses adopted by the European Commission on 4 June 2021 do not, on their own, cover transfers originating from the UK. The UK Addendum, issued by the Information Commissioner's Office, addresses this gap by modifying the EU SCCs so they can operate as an appropriate safeguard for UK-originating restricted transfers.
The practical significance is efficiency and consistency. Many organisations already rely on the EU SCCs for transfers governed by the EU GDPR. Rather than negotiating and executing an entirely separate standalone UK International Data Transfer Agreement (IDTA), parties can attach the Addendum to their existing EU SCCs to extend that mechanism to UK transfers. This allows a single contractual approach to cover both EU and UK data flows, which can reduce duplication in multi-jurisdictional data-sharing arrangements.
It is important not to overstate what the Addendum accomplishes. It is intended only to provide the safeguards required to legitimise a restricted international transfer; it does not itself supply the broader commercial arrangement, the controller-to-processor terms, or the wider allocation of roles between the parties. Organisations should also be aware that reliance on the Addendum typically does not, on its own, discharge related obligations such as any transfer risk assessment. Treatment differs from the EU regime, where the EU SCCs apply directly under the EU GDPR without an addendum. This entry does not cover the substantive processing terms, retention rules, transfer risk assessment obligations, or enforcement consequences.
Who it's relevant to
Inside UK Addendum
Common questions
Answers to the questions practitioners most commonly ask about UK Addendum.