The ICO has opened 2026 with a significant update to its guidance on international data transfers, aiming to finally simplify one of the most tangled areas of the UK GDPR.
Published on 15 January, the new guidance promises to reduce complexity and give organisations a clearer, more practical framework for determining when a transfer is considered “restricted”[1].
At the heart of the update is a new three step test. Instead of navigating pages of technical definitions, organisations now only need to consider three straightforward questions:
Deciding if it’s a restricted transfer
- Does UK GDPR apply to the processing of the personal information you are transferring?
- Is your organisation initiating the transfer of personal information to an organisation which is located outside the UK?
- Are you transferring the personal information to a separate legal entity?
If the answer to all three questions is yes, the transfer is restricted.
Who must comply with restricted‑transfer rules?
If your organisation initiates a restricted transfer, you are responsible for meeting the transfer requirements.
This applies whether or not you’re based in the UK, as long as the UK GDPR applies to your processing, and it applies regardless of your role in the chain as a controller, processor or sub‑processor.
How to make a restricted transfer?
When you’re responsible, the transfer must be covered by one of the following:
– UK adequacy regulations
– Appropriate safeguards
– A specific exception (“derogation”)
These requirements apply in addition to your other UK GDPR obligations.
The ICO also clarifies when the UK GDPR applies in the first place, including where UK-based organisations carry out real activities in the UK, where a non-UK group company processes data that is inextricably linked to a UK establishment, or where an overseas company is offering goods or services to UK individuals. These explanations, while technical, offer welcome clarity to international businesses and groups operating across borders.
A key practical update concerns what it means to “initiate” a transfer. The ICO confirms that an organisation initiates a transfer if is:
- sending personal information to a separate organisation outside the UK; or
- making it accessible to a separate organisation outside the UK.
The rules apply to all restricted transfers, even small, infrequent ones and all organisations that handle personal information (including sole traders and self-employed individuals).
Importantly, the location of the recipient organisation, not the physical location of the servers, determines whether the transfer is restricted. This clarification goes a long way toward settling longstanding uncertainty around cloud hosting, multi-region data storage and remote support teams[2].
Recognising the complexity of modern digital eco-systems, the ICO has expanded its guidance on roles and responsibilities within multi-layered supply chains. Whether data passes through cloud platforms, overseas affiliates or intricate outsourcing arrangements, the updated materials are designed to help organisations understand their obligations. To support smaller organisations in particular, the ICO has also released a short guide, FAQs and a glossary that break down key concepts in accessible language[3].
One of the most notable clarifications is likely to have real operational impact, the ICO’s view that transfers from UK-based processors to overseas controllers are not restricted transfers. Because a processor in this scenario is acting solely on behalf of the controller, and not making an independent decision to transfer data, the ICO concludes that the three-step test is not met. This position differs from that in parts of the EU and could significantly reduce the need for mechanisms such as Standard Contractual Clauses (“SCCs”), the International Data Transfer Agreement (“IDTA”) or Transfer Risk Assessments (“TRAs”) in common outsourcing scenarios.
The ICO has emphasised that this guidance is part of a broader modernisation programme. More tools are on the way, including an interactive assistant to help organisations determine whether a transfer is restricted, as well as further guidance on TRAs and the IDTA. Additional real-world examples are also planned to reflect the realities of increasingly global data flows.
Overall, the updated guidance aims to bring clarity, predictability and a more user-friendly structure to a complex regulatory area. It reflects the ICO’s wider push to streamline compliance while supporting innovation and economic growth, a welcomed combination by many organisations.
Preparing for compliance
The ICO’s refreshed approach to international data transfers marks a meaningful shift toward clarity and practicality. By distilling the assessment into a simple three‑step test and offering more nuanced explanations of roles, responsibilities and real‑world data flows, the guidance gives organisations a far more workable framework for navigating global transfers. Yet with these clarifications come new considerations, particularly for groups with complex supply chains, cloud‑based infrastructures or cross‑border operational models.
As with any regulatory update, the challenge lies not only in understanding the rules but in embedding them into day‑to‑day governance, contracts and technical processes.
UK‑based and international organisations should accordingly:
- Assess whether data flows constitute restricted transfers under the ICO’s new three‑step test.
- Map and document global data movements, including cloud, SaaS and multi‑layered supply chain arrangements.
- Select and implement the appropriate transfer mechanism, whether adequacy, safeguards or derogations.
- Review and update contracts, including SCCs, the IDTA and data processing agreements, in light of the ICO’s clarified position on processor‑to‑controller transfers.
- Conduct TRAs aligned with the ICO’s forthcoming updated guidance.
- Develop governance frameworks that ensure ongoing compliance as they scale or expand internationally.
Whilst the regulatory landscape for international data flows is moving toward greater simplicity, the operational implications remain significant. With the right preparation, organisations can therefore mitigate risk, streamline compliance and maintain the agility needed to operate across borders.
Please contact Jose Saras and Xavier Prida for detailed advice on the above.
The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.
This article is written in the English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.
[1] Updated guidance on international transfers published | ICO
[2] Are we making a restricted transfer | ICO
[3] Glossary | ICO, Quick reference FAQs | ICO, A brief guide to international transfers | ICO