The UK IDTA and Addendum are the two contractual tools the Information Commissioner’s Office provides for sending personal data out of the United Kingdom, and choosing the wrong one is a common cause of rework in vendor contracts. Both came into force on 21 March 2022 and both serve as an appropriate safeguard under Article 46 of the UK GDPR.
This guide explains which tool fits which situation, what a restricted transfer is, why a transfer risk assessment sits alongside the contract, and how to avoid the drafting errors that reviewers keep finding. For the wider picture, see our international data transfers guide.
What the UK IDTA and Addendum are for
UK GDPR restricts transfers of personal data to organisations outside the UK unless a valid mechanism applies. The ICO’s transfer guidance describes three routes: UK adequacy regulations, appropriate safeguards such as the International Data Transfer Agreement or UK binding corporate rules, and, as a last resort, the exceptions in Article 49. The IDTA and the Addendum belong to the middle route.
The ICO’s test for a restricted transfer has three questions: does the UK GDPR apply to the processing, are you sending the data to an organisation outside the UK, and is the recipient a separate legal entity. If all three answers are yes, you need a mechanism. Transfers within one company, or to your own employee working abroad, generally fail the third question, so check before you sign anything.
| Tool | What it is | Typical use |
|---|---|---|
| International Data Transfer Agreement (IDTA) | A standalone UK contract with its own tables and mandatory clauses | A UK-only transfer to a supplier abroad |
| UK Addendum | A short document that amends the EU standard contractual clauses for UK use | Transfers already covered by EU SCCs |
| Adequacy regulations | A UK government finding that a country’s protection is adequate | Transfers to covered countries, with no contract needed |
Choosing between the UK IDTA and Addendum
The simplest rule is to follow the contract you already have. If your supplier is signing the EU standard contractual clauses for European data, attach the Addendum so the same clauses also work for UK data. One signed set then serves both regimes. If the transfer is purely from the UK, or the counterparty has no EU clauses in place, the IDTA is the natural standalone choice.
The ICO says exporters can use either tool as a transfer mechanism to comply with Article 46, so the decision is practical rather than legal. Consider who holds negotiating power. A large cloud provider may only offer the Addendum on top of its EU terms, while a small supplier with no EU paperwork may prefer a single IDTA. Our UK GDPR vs EU GDPR comparison explains why the two regimes still need separate references.
Filling in the tables
Both instruments rely on tables where the parties record details. Fill these in with care. The tables should name the parties and their roles, describe the data and the categories of individuals, state the purpose, list the security measures, and identify any onward recipients. A common failure is leaving generic text such as “all personal data” in the description field. That undermines the whole contract, because a reviewer cannot tell what is being protected.
The transfer risk assessment alongside the UK IDTA and Addendum
The contract does not finish the job. The ICO’s guidance states that when you rely on appropriate safeguards you must complete a transfer risk assessment, to confirm that the standard of protection for people’s information is not materially lower after the transfer. In practice, you look at the destination country’s laws on government access, how well the recipient’s practices match the contract, and whether technical measures such as encryption can close any gap.
Free transfer impact assessment
Can this transfer of personal data go ahead?
Check whether the transfer needs a TIA, map it, assess the laws and practice of the destination, rate the risks from 27 transfer scenarios and choose supplementary measures. Covers the EU SCCs and the UK IDTA and Addendum, free.
Record the reasoning, not just the conclusion. A one-line statement that the risk is low will not satisfy a reviewer. Our guides to the transfer impact assessment example and the difference between a transfer risk assessment and a TIA show how to structure the record.
What has changed with the Data (Use and Access) Act
The Data (Use and Access) Act 2025 amends the UK’s transfer rules, and you should read our Data (Use and Access) Act 2025 guide for the wider reform. The ICO’s international transfers guide, as updated in January 2026, did not cover the Act’s new approach in the text we reviewed, so confirm the current position on the ICO site before relying on it in a live transfer decision. Existing IDTAs and Addenda remain the tools in use today.
A hypothetical example of choosing a tool
A London retailer uses a customer support platform hosted by a supplier in a country without UK adequacy regulations. The supplier already signs the EU standard contractual clauses with its European customers and offers the retailer the same paper plus the UK Addendum. The retailer accepts, fills in the Addendum tables with the categories of customer data, the support purpose and the supplier’s security measures, and completes a transfer risk assessment covering local access laws and the supplier’s encryption. It then records the transfer in its register and its privacy notice. The example is illustrative only.
Had the supplier offered no EU paperwork, the retailer would have proposed the IDTA instead and asked the supplier to complete its tables. Either path gives the same result: a documented, defensible mechanism.
Group companies and intra-group transfers
Multinational groups often assume that a shared parent removes the need for a mechanism. It does not: two group companies are separate legal entities, so a UK company sending data to an affiliate overseas is making a restricted transfer. Groups typically use an intra-group agreement based on the IDTA or the Addendum, or UK binding corporate rules where they have them. Keep one signed agreement covering all group entities and update the schedule of parties whenever the group structure changes, otherwise a newly acquired subsidiary receives data with no cover.
Roles and responsibilities
The data protection lead usually owns the transfer register and the assessment, procurement makes sure the right clauses appear in supplier contracts, legal reviews any changes to the mandatory text, and IT confirms that the technical measures described actually exist. Suppliers should also be told to notify you before adding sub-processors or moving data to a new country, since either change can invalidate your assessment. Put that obligation in the contract and diarise a review at least once a year.
Evidence a reviewer will ask for
Expect requests for the signed IDTA or Addendum, the completed tables, the transfer risk assessment with its date and author, the decision record showing why adequacy or an exception did not apply, the list of sub-processors and their locations, and the entry in your record of processing. Keeping these together in one folder per supplier makes an audit or an ICO enquiry much easier to handle, and it shows that the UK IDTA and Addendum are managed as living controls, not as one-off paperwork.
Common mistakes with the UK IDTA and Addendum
- Using EU SCCs alone for UK data. The EU clauses do not cover UK transfers unless the Addendum is attached.
- Ignoring the risk assessment. The contract is signed, but no assessment exists.
- Vague tables. Data categories, purposes and security measures are left generic.
- No owner. Nobody tracks expiry, changes in the supplier’s location or new sub-processors.
- Forgetting onward transfers. The supplier passes data to a sub-processor in a third country with no matching safeguard.
- Missing from the record. Transfers are not listed in the records of processing or the privacy notice.
A practical workflow for the UK IDTA and Addendum
- Map your transfers. Start from suppliers, group companies and support arrangements that touch personal data.
- Test for a restricted transfer. Apply the three ICO questions to each.
- Check for adequacy. If the destination is covered, record the basis and move on.
- Select the tool. Choose the IDTA or the Addendum, following existing contracts where possible.
- Complete a transfer risk assessment. Document laws, practices and supplementary measures.
- Update your records. Reflect the transfer in your record of processing and privacy notice.
- Review annually. Revisit when suppliers, locations or laws change.
Documents that speed up UK transfer compliance
Most of the effort goes into consistent paperwork: a transfer register, a decision record for each mechanism, a risk assessment template and clause checklists. The UK GDPR Toolkit includes templates for these records, which you can adapt to your suppliers. The ICO’s own page on the IDTA and Addendum is the primary reference for the documents themselves.
UK IDTA and Addendum FAQ
When did the UK IDTA and Addendum come into force?
Both came into force on 21 March 2022 as tools for restricted transfers under Article 46 of the UK GDPR.
Should I use the IDTA or the Addendum?
Use the Addendum where you already have EU standard contractual clauses in place, and the IDTA for a standalone UK transfer. Either is acceptable to the ICO.
Do I still need a risk assessment?
Yes. The ICO expects a transfer risk assessment when you rely on appropriate safeguards.
Do I need a contract for a transfer to an adequate country?
Not for the transfer mechanism, because UK adequacy regulations provide the basis, but you still need a processing agreement where the recipient is a processor.