International Data Transfers Under UK GDPR, Explained
If you use US-hosted software (and almost every UK business does), you are transferring personal data internationally. That is perfectly lawful — as long as you use a recognised transfer mechanism and can show it. This guide explains the UK-US data bridge, the ICO's IDTA, transfer risk assessments and the DUAA 2025 test, in language you can actually act on.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
Why this affects nearly every UK business
If your business uses cloud software, you are almost certainly transferring personal data internationally — even if you have never left Yorkshire. Email, file storage, accounting, CRM, booking systems, marketing tools: many of these are hosted on servers in the United States, or run by companies based there. The moment personal data (a customer’s name, an employee’s payroll record, a supplier contact) is sent to or accessed from outside the UK, UK GDPR’s rules on international transfers apply.
The good news, and the single most important point in this guide: this is lawful. Sending UK personal data to the United States is not illegal. It becomes a problem only when you cannot point to a lawful mechanism and cannot say where the data lives. This guide explains, in plain English, what those mechanisms are and how a small business can stay on the right side of them without a legal department.
If you are new to the basics, start with our GDPR basics for UK small business and come back — this guide assumes you already know what personal data is.
What counts as an international transfer
A “restricted transfer” happens when you make personal data available to a receiver based outside the UK. That includes:
- Storing files or emails on servers physically located abroad.
- Using a SaaS tool run by an overseas company, even if the data centre is in the UK.
- Letting an overseas support team access UK data to help you.
- A parent company or contractor abroad viewing UK records.
Some destinations are covered by UK “adequacy” — the government has decided they protect data to a similar standard, so no extra mechanism is needed. The EEA countries and Switzerland are examples. Transfers to those places are treated much like keeping data in the UK.
The United States is the one that trips businesses up, because it is only partly covered — and that partial cover depends on the specific company you are dealing with.
Mechanism 1: the UK-US data bridge
The UK-US “data bridge” is the UK Extension to the EU-US Data Privacy Framework (DPF). In plain terms, certain US companies can sign up to a scheme, promise to protect data to an agreed standard, and be officially recognised. If your US supplier is on that list, you can send them UK personal data without needing extra contracts.
The catch that most guides skate over: the bridge is valid per recipient, not for the whole country. It only covers a US organisation that is actively certified under the Data Privacy Framework and has specifically opted into the UK Extension. Two things must both be true:
- The supplier appears on the official Data Privacy Framework list.
- Their certification explicitly includes the UK Extension.
If your supplier is not certified, or is certified for the EU but not the UK Extension, the bridge does not help you for that supplier — and you fall back to Mechanism 2.
What to do: for each US tool holding personal data, check the DPF list by the company’s name. Many large providers are covered; plenty of smaller ones are not.
Mechanism 2: the IDTA (or the UK Addendum) plus a TRA
Where the data bridge does not apply, the standard route is a contract-based one:
- The International Data Transfer Agreement (IDTA) — the ICO’s own template contract — or
- The UK Addendum to the EU Standard Contractual Clauses (SCCs), which bolts UK terms onto the EU’s clauses.
Most reputable suppliers already include one of these in their data processing terms, so in practice you are agreeing to it rather than drafting it. Your job is to make sure it is actually in place.
Using the IDTA or Addendum is not quite the whole job. You also need a Transfer Risk Assessment (TRA): a short, written check that the data will get essentially equivalent protection in the destination country. You consider the type of data, how sensitive it is, the laws of the destination, and any extra safeguards — encryption in transit and at rest being the obvious one. The ICO publishes a free TRA tool and template, so you are not starting from a blank page.
Sending UK personal data to the United States is not illegal. It becomes a problem only when you cannot point to a lawful mechanism and cannot say where the data lives.
The DUAA 2025 test: “not materially lower”
The rules were updated by the Data (Use and Access) Act 2025 (DUAA). Since 5 February 2026, the test for transfers is whether the protection in the destination country is “not materially lower” than the standard under UK law. This is a slightly more proportionate, risk-based wording than the old “essentially equivalent” phrasing, and it is designed to be workable for smaller organisations. It does not lower the bar to nothing — you still assess and document — but it recognises that sensible, well-protected transfers should not be blocked by theoretical risks.
In practice, for a typical small business using mainstream, well-secured tools with encryption, a TRA will usually conclude the transfer is fine. The point is to have done and recorded the thinking.
A practical checklist for small businesses
You do not need to become a data-transfer expert. You need a short, honest inventory. Work through this:
- List your tools. Every system that holds personal data: email, file storage, accounting, CRM, payroll, marketing, backups, booking.
- Find out where the data lives. Check each supplier’s documentation for data location and residency options. Many now offer UK or EU data residency you can simply switch on.
- Identify the mechanism for each. Data bridge (check the DPF list), IDTA/Addendum, or UK/EEA hosting with no transfer at all.
- Do a light-touch TRA where you rely on the IDTA/Addendum, using the ICO’s tool.
- Write it down. Add transfers to your Record of Processing Activities (ROPA) and make sure your privacy notice honestly tells people their data may be processed outside the UK and how it is protected.
- Review annually, and whenever you add a new tool or a supplier changes its terms.
That record is what turns “we think we’re fine” into “we can show we’re fine” — which is the whole game if the ICO ever asks.
Reducing the problem: keep more data closer to home
Every transfer you avoid is one less assessment to do and document. That is a legitimate reason many small businesses now choose UK, EEA or Swiss-hosted tools for the sensitive parts of their stack — email, passwords, file storage and backups. Switzerland, for example, benefits from UK adequacy, so Swiss-hosted services do not require a transfer mechanism at all. Privacy-focused providers such as Proton, which hosts email, VPN, password and storage services in Switzerland and the EU, are a straightforward way to shrink your transfer footprint for the data that matters most. It will not replace every tool you use, but it can take the most sensitive data out of the transfer question entirely.
This is not about avoiding US software — that would be impractical and unnecessary. It is about being deliberate: use the data bridge and IDTAs where they fit, and reduce complexity where you easily can.
Where DACROS fits
Most small businesses do not have a clear picture of where their data actually lives — and that is the hardest part of this to fix alone. As a managed IT and cyber-security provider in Leeds and Yorkshire, we can build your data inventory, check each supplier’s transfer mechanism, help you complete TRAs with the ICO’s tools, and make sure your privacy notice and ROPA reflect reality. It is usually a short, one-off exercise that gives you a document you can rely on.
If you would like a hand mapping where your data goes, take a look at our services or get in touch — we will keep it in plain English.
Frequently asked questions
Is it illegal to store UK customer data in the United States?
No. Storing or processing UK personal data in the US is lawful as long as you rely on a valid transfer mechanism — either the UK-US data bridge (where your specific US supplier is certified under the Data Privacy Framework with the UK Extension), or the ICO's IDTA (or the UK Addendum to the EU Standard Contractual Clauses) backed by a documented transfer risk assessment. Anyone who tells you US hosting is banned outright is mistaken.
How do I know if my US supplier is covered by the UK-US data bridge?
The bridge only covers a US recipient that is actively certified under the EU-US Data Privacy Framework AND has opted into the UK Extension. You can check the official Data Privacy Framework list for the organisation's name and its certification status. If your supplier is not on the list with the UK Extension, you cannot rely on the bridge for that supplier and will usually need an IDTA plus a transfer risk assessment instead.
What is a Transfer Risk Assessment (TRA)?
A TRA is a short written assessment you complete before relying on the IDTA (or SCCs). It records whether the personal data will get essentially the same protection in the destination country as it would in the UK, considering the type of data, the laws of that country and any extra safeguards such as encryption. The ICO publishes a free TRA tool and template. Since 5 February 2026 the test under the DUAA 2025 is whether protection is 'not materially lower' than under UK law.
We only use Microsoft 365 and a couple of SaaS tools — do we really need to worry about this?
Yes, but it is manageable. Mainstream providers like Microsoft handle the heavy lifting with data bridge certification and standard clauses in their contracts, and many now offer UK or EU data residency. Your job is smaller: list which tools hold personal data, note where that data is stored, check the mechanism each supplier relies on, and record it. A managed IT provider can produce that list for you quickly.
Does using a UK or European provider remove the problem entirely?
It removes the transfer question for that supplier, which is one less thing to assess and document. Keeping data in the UK, the EEA or an adequate country (such as Switzerland) means no international transfer mechanism is needed for it. That is a legitimate reason many small businesses choose UK or EU-hosted email, storage and backup tools — it simplifies your compliance rather than eliminating your other obligations.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.