Skip to main content
Category: International Data Transfers

UK Addendum

Also known as: International Data Transfer Addendum, UK Addendum to the EU SCCs, Addendum to the EU Standard Contractual Clauses
Simply put

The UK Addendum is a document issued by the UK's Information Commissioner's Office that attaches to the EU's standard contractual clauses so those EU clauses can be used to legitimise transfers of personal data out of the UK. It is one of two tools the ICO provides for this purpose, alongside the standalone UK International Data Transfer Agreement (IDTA). It is used only to provide safeguards for restricted international transfers and does not, on its own, set out broader terms such as the general roles of the parties.

Formal definition

The UK Addendum (also referred to as the International Data Transfer Addendum) is an ICO-issued instrument that modifies the European Commission's standard contractual clauses adopted under the EU GDPR on 4 June 2021 (the EU SCCs) so that they operate as appropriate safeguards for restricted transfers of personal data from the UK under the UK GDPR, as defined in section 3 of the Data Protection Act 2018. It functions as an alternative to the standalone UK IDTA, allowing parties already relying on the EU SCCs to extend that mechanism to UK-originating restricted transfers. Per the ICO, the Addendum must always be interpreted consistently with the UK GDPR. Scope limitation: the Addendum (like the IDTA) is intended only to legitimise restricted international transfers and does not itself supply the full commercial or controller-to-processor arrangement between the parties; this entry does not cover the substantive processing terms, retention rules, transfer risk assessment obligations, or enforcement consequences, and treatment differs from the EU regime, where the EU SCCs apply directly under the EU GDPR.

Why it matters

For organisations transferring personal data out of the UK, a restricted transfer generally requires an appropriate safeguard under the UK GDPR (as given effect in UK law and referencing definitions in the Data Protection Act 2018). Following the UK's departure from the EU, the EU's standard contractual clauses adopted by the European Commission on 4 June 2021 do not, on their own, cover transfers originating from the UK. The UK Addendum, issued by the Information Commissioner's Office, addresses this gap by modifying the EU SCCs so they can operate as an appropriate safeguard for UK-originating restricted transfers.

The practical significance is efficiency and consistency. Many organisations already rely on the EU SCCs for transfers governed by the EU GDPR. Rather than negotiating and executing an entirely separate standalone UK International Data Transfer Agreement (IDTA), parties can attach the Addendum to their existing EU SCCs to extend that mechanism to UK transfers. This allows a single contractual approach to cover both EU and UK data flows, which can reduce duplication in multi-jurisdictional data-sharing arrangements.

It is important not to overstate what the Addendum accomplishes. It is intended only to provide the safeguards required to legitimise a restricted international transfer; it does not itself supply the broader commercial arrangement, the controller-to-processor terms, or the wider allocation of roles between the parties. Organisations should also be aware that reliance on the Addendum typically does not, on its own, discharge related obligations such as any transfer risk assessment. Treatment differs from the EU regime, where the EU SCCs apply directly under the EU GDPR without an addendum. This entry does not cover the substantive processing terms, retention rules, transfer risk assessment obligations, or enforcement consequences.

Who it's relevant to

Data protection officers and privacy leads
Those responsible for lawful international data flows need to determine whether the UK Addendum, the standalone UK IDTA, or another mechanism is the appropriate safeguard for a given restricted transfer out of the UK. Where an organisation already relies on the EU SCCs, the Addendum is typically the more efficient route, but it does not by itself discharge related obligations such as transfer risk assessments.
Legal and contracting teams
Teams negotiating data-sharing and outsourcing agreements should understand that the Addendum attaches to and modifies the EU SCCs and must be interpreted consistently with the UK GDPR. They should not treat it as a complete arrangement, since it does not supply the broader commercial or controller-to-processor terms, which must be addressed separately.
Compliance and governance functions in multi-jurisdictional organisations
Organisations transferring personal data under both the EU GDPR and UK GDPR can use the Addendum to extend an existing EU SCC-based mechanism to UK transfers, supporting a consistent contractual approach. Governance teams should retain demonstrable evidence of the safeguards relied upon, recognising that accountability requires documented implementation rather than stated intent.
Vendors and processors receiving UK personal data
Recipients of restricted transfers from the UK, including processors, may be asked to be bound by the Addendum alongside the EU SCCs. They should confirm which module and safeguards apply to their arrangement and recognise that the Addendum addresses transfer safeguards only, not the full processing terms.

Inside UK Addendum

International Data Transfer Addendum to the EU SCCs
The UK Addendum is a mechanism, issued by the UK's data protection authority, that adapts the European Commission's Standard Contractual Clauses (EU SCCs) for use as a valid transfer tool under the UK GDPR. Rather than replicating the EU SCCs in full, it attaches to and modifies them so they operate for restricted transfers of personal data out of the UK.
Relationship to the UK GDPR
The Addendum exists because, following the UK's departure from the EU legal framework, the EU SCCs adopted under EU GDPR are not by themselves a lawful transfer mechanism for transfers governed by the UK GDPR. The Addendum bridges that gap so organisations can rely on the EU SCCs framework in a UK-facing form.
Alternative to the UK IDTA
The UK offers two contractual transfer tools: the International Data Transfer Agreement (IDTA), a standalone document, and this Addendum, which layers onto the EU SCCs. Organisations already using EU SCCs for EU transfers can generally use the Addendum to extend coverage to UK transfers without adopting an entirely separate standalone agreement.
Tables and party details
The Addendum typically requires the parties to complete information identifying the parties, the selected EU SCCs (including module and options chosen), and the specifics of the transfer. It records which version and configuration of the EU SCCs it modifies.
Modifications to the underlying clauses
The Addendum sets out the changes needed so that references, governing law, supervisory authority, and jurisdiction in the EU SCCs are read as UK-appropriate for transfers subject to the UK GDPR.

Common questions

Answers to the questions practitioners most commonly ask about UK Addendum.

Is the UK Addendum just the UK version of the EU Standard Contractual Clauses?
No. The UK Addendum is not a standalone replacement for the EU SCCs; it is a mechanism that attaches to and amends the EU SCCs so they operate for restricted transfers under the UK GDPR rather than the EU GDPR. The two instruments are distinct: the EU SCCs are issued under the EU regime, while the UK's transfer tools sit under the UK data protection framework. Treating them as interchangeable is a common error, and organisations should confirm which instrument governs a given transfer based on which regime applies to the exporter.
Does putting the UK Addendum in place by itself guarantee that a restricted transfer is lawful?
Generally, no. Executing the UK Addendum provides an appropriate safeguard for the transfer mechanism, but lawfulness of a restricted transfer typically also depends on other factors, such as assessing the circumstances of the transfer and the destination and implementing any supplementary measures that may be necessary. No single contractual instrument, on its own, can be said to guarantee compliance; the outcome depends on context, jurisdiction, and implementation. This entry does not cover the detailed mechanics of transfer risk assessments or supplementary measures.
When would we use the UK Addendum instead of the UK's other transfer tool?
The UK Addendum is typically used where parties already rely on the EU SCCs and want to extend or adapt them to cover restricted transfers under the UK GDPR, avoiding the need to negotiate an entirely separate standalone agreement. The UK also recognises a separate standalone contractual instrument for UK transfers. Which to choose generally depends on whether the transfer already involves the EU SCCs and on the parties' commercial and drafting preferences. This entry does not advise on which option is preferable in any specific arrangement.
How does the UK Addendum interact with an existing EU SCC agreement between the same parties?
The UK Addendum is designed to be appended to the EU SCCs and to modify their terms so they function under the UK GDPR. In practice this means the parties complete the relevant tables or information the Addendum requires and read the EU SCCs together with the Addendum as amended. Where a single arrangement covers both EU and UK restricted transfers, parties commonly use the EU SCCs for the EU leg and the Addendum for the UK leg. This entry does not address the completion of specific fields or the underlying EU SCC modules.
Which party is responsible for putting the UK Addendum in place?
Responsibility for ensuring an appropriate transfer mechanism is in place generally rests with the party making the restricted transfer, whether acting as controller or processor, though both parties to the arrangement enter into the contractual terms. Accountability under the UK framework typically requires that the exporter be able to demonstrate the safeguard is in place and appropriate, not merely assert it. Allocation of specific obligations between the parties depends on their respective roles and the terms agreed. This entry does not resolve controller-versus-processor obligations for any particular transfer.
Does the UK Addendum tell us how long we can retain the transferred data or what happens if we breach it?
No. The UK Addendum's function is to provide contractual safeguards for restricted transfers under the UK GDPR; retention periods, enforcement outcomes, and penalty amounts are outside its core purpose and outside the scope of this entry. Retention obligations arise from the broader UK data protection principles and any applicable sector rules, and enforcement is a matter for the relevant supervisory authority. Organisations should address retention and breach handling through their wider governance and compliance arrangements rather than relying on the Addendum alone.

Common misconceptions

The EU SCCs on their own are sufficient to cover restricted transfers out of the UK.
The EU SCCs were adopted under the EU legal framework and are generally not, by themselves, a valid transfer mechanism for transfers governed by the UK GDPR. The UK Addendum (or the standalone UK IDTA) is typically needed to make a contractual transfer tool valid for UK-governed transfers.
Executing the UK Addendum by itself makes an international transfer lawful and complete.
The Addendum is a transfer mechanism, not a complete compliance solution. A lawful transfer generally still depends on having a lawful basis for the underlying processing, meeting broader UK GDPR obligations, and, where relevant, assessing the circumstances of the transfer. The Addendum does not address retention, lawful basis selection, or enforcement matters, and its adequacy in any given case depends on context and implementation.
The UK Addendum and the UK IDTA are interchangeable or the same document.
They are distinct tools. The IDTA is a standalone contract, while the Addendum attaches to and modifies the EU SCCs. Organisations choose between them based on their existing contractual arrangements; the Addendum is generally convenient where EU SCCs are already in place.

Best practices

Confirm which UK GDPR transfer mechanism fits your arrangement: use the Addendum where you already rely on EU SCCs, or consider the standalone UK IDTA where no EU SCCs are in place.
Accurately complete the Addendum's tables, recording the specific EU SCCs version, module, and options it modifies, and keep this documentation as demonstrable evidence of your transfer arrangements.
Do not treat the Addendum as standalone assurance of compliance; verify you also have a lawful basis for the underlying processing and meet other applicable UK GDPR obligations, which fall outside the Addendum's scope.
Where you transfer personal data out of both the EU and the UK, keep the EU SCCs and the UK Addendum aligned so that changes to the underlying clauses are reflected consistently across both regimes.
Maintain version control over the executed EU SCCs and Addendum, and review them when the underlying clauses, parties, or nature of the transfer change.
Engage legal counsel or your data protection function to assess the specific transfer circumstances, since the adequacy of any contractual mechanism depends on jurisdiction, context, and implementation rather than execution alone.