A UK transfer risk assessment, often shortened to TRA, is the analysis a UK exporter carries out before sending personal data to a country without an adequacy arrangement, using the International Data Transfer Agreement or the UK Addendum to the EU standard clauses. It is the UK counterpart of the transfer impact assessment used under the EU GDPR, and it has the same purpose: to check that the protection promised by the transfer tool will hold up in practice.
This guide explains when a UK transfer risk assessment is needed, how the ICO expects it to be approached, what to record, how it differs from an EU assessment and how to keep it up to date. It is general information, not legal advice, and UK rules have been changing, so check the current position with the ICO and your counsel.
What a UK transfer risk assessment is
Under UK data protection law, personal data can leave the UK freely to countries with adequacy regulations. For other countries, exporters need an appropriate safeguard, most commonly the IDTA or the UK Addendum to the EU standard contractual clauses. Before relying on either, the exporter must consider whether the tool will be effective in the destination country, given its laws and practices.
The ICO calls this a transfer risk assessment and publishes guidance and a tool to help. The purpose is to check that people’s data will be protected to a standard that is not materially lower than in the UK, in practice as well as on paper. See the ICO guidance on international transfers for the current text. Our guide to transfer risk assessments compared with TIAs explains how the terms relate.
Free transfer impact assessment
Can this transfer of personal data go ahead?
Check whether the transfer needs a TIA, map it, assess the laws and practice of the destination, rate the risks from 27 transfer scenarios and choose supplementary measures. Covers the EU SCCs and the UK IDTA and Addendum, free.
When you need a UK transfer risk assessment
You need a UK transfer risk assessment when you rely on the IDTA or the UK Addendum for a restricted transfer, and the destination is not covered by adequacy regulations. It applies to transfers to processors, to affiliates and to other controllers, including transfers within a corporate group.
You do not need one where adequacy applies, though you should confirm the scope, and where a genuine exception applies, although exceptions are narrow. Note that UK rules on transfers have been amended by recent legislation, so confirm which version of the test applies to your transfer and when the changes take effect.
Step one: describe the transfer
Record what you send, why, who receives it, where they are, how it is sent and stored, how often and for how long. Note sensitivity, volume and the categories of people. A precise description shapes every later step, because risk depends on the data and the context.
Include onward transfers and sub-processors. If the importer passes the data to another entity in another country, that flow needs its own assessment. Our TIA for sub-processors page lists what to ask.
| Step | Question | Output |
|---|---|---|
| 1. Describe the transfer | What data, to whom, where and why? | Transfer description |
| 2. Choose the tool | Adequacy, IDTA, Addendum or exception? | Tool and reasoning |
| 3. Assess the risk | Would the destination’s laws or practice undermine the protection? | Risk rating with reasons |
| 4. Add measures | Do we need technical, contractual or organizational safeguards? | Measures list |
| 5. Decide and record | Proceed, adjust or stop? | Signed record and review date |
Step two: confirm the tool
Decide which transfer mechanism you will use and why. The IDTA is the UK’s standalone agreement. The UK Addendum lets you adapt EU standard clauses for UK use. Check that the tool fits the roles: controller to processor, controller to controller and so on.
Check the details, such as required fields, annexes and the description of security measures, so that the agreement is complete and consistent with your assessment.
- Confirm that adequacy regulations do not already cover the destination
- Choose the IDTA or the Addendum and record why
- Complete the required tables and annexes accurately
- Align the description with the actual data flows
Step three: assess the destination
Consider the laws and practices of the destination that might affect the data, especially rules on public authority access. Ask whether those powers are limited to what is necessary and proportionate, whether there is independent oversight and whether individuals have redress. The ICO tool guides you through a series of questions and lets you rate the level of risk.
Use reliable sources, such as government publications, reports from independent bodies and your own supplier’s information. Record the sources and the date. Where the analysis is complex, take legal advice. Our guide to third-country laws in a TIA explains a similar method.
Step four: measures and decision
If the assessment finds a risk that the tool alone does not address, consider additional safeguards. Technical measures such as strong encryption with keys kept in the UK, pseudonymisation or splitting data can be very effective; see encryption as a supplementary measure. Contractual and organizational measures help but rarely fix a legal problem on their own.
Then decide: proceed, proceed with additional measures, change the design or do not proceed. The ICO expects you to reach a reasoned conclusion, and to record it. A decision that the risk is low should still show why.
How it differs from an EU TIA
The steps are similar, but the legal tests and tools differ. The EU assessment asks whether the destination provides essentially equivalent protection, following the case law of the Court of Justice. The UK approach uses its own test and guidance from the ICO, and the tools are the IDTA and Addendum rather than only the EU standard clauses.
If you transfer from both the UK and the EU, you may be able to reuse the factual work and much of the legal analysis, but you must check that each conclusion meets the right test. Keep one core assessment with a UK and EU annex, if that suits your structure. See our transfer impact assessment example for a format.
Keep your UK transfer risk assessment up to date
A UK transfer risk assessment is not a one-off. Review it when the destination law changes, when adequacy regulations are adopted or revised, when the supplier or its sub-processors change and at least once a year. Record each review with a date, findings and a sign-off.
Add the transfers to your record of processing, as explained in international transfers in the ROPA, so the documents stay aligned. See TIA review and monitoring for a full review approach.
Common mistakes
Frequent errors include treating the IDTA as sufficient without any assessment, using a generic assessment for all countries, ignoring onward transfers, relying on supplier assurances without evidence, failing to record the reasoning and not revisiting the assessment when the law changes. Another is failing to notice that UK transfer rules have moved on since the assessment was first written.
Avoid these by working through the ICO steps for each transfer, keeping evidence and setting review dates.
Governance and evidence for a UK transfer risk assessment
Keep the assessment with the transfer agreement, the supplier due diligence and the record of processing. Note who prepared it, who approved it and the sources relied on. If the ICO or a customer asks how you decided that a transfer was safe, you can produce a single, dated file. Assign an owner for each transfer and include overdue reviews in your regular governance reporting.
Train the people who start new supplier relationships. Most gaps occur because a team signs up to a foreign service before anyone from privacy has seen it. A simple intake form that asks where data will go, and triggers an assessment, catches most of them.
A short worked example
A UK marketing agency sends campaign data to an analytics processor in a country without adequacy regulations. It uses the UK Addendum, describes the transfer in detail and reviews the destination’s access laws using the ICO tool. Finding a moderate risk, it adds encryption with keys held in the UK and pseudonymises identifiers before sending.
It records the reasoning, obtains approval from the DPO and sets a review for twelve months. When the supplier later adds a sub-processor in another country, the agency updates the assessment and adjusts the measures.
Structuring the assessment
If you want the transfer description, tool, legal analysis, measures and sign-off in one place, the Transfer Impact Assessment Report and Workbook provides a structured report and workbook for transfer assessments. Whatever the format, a good UK transfer risk assessment describes the data flow accurately, tests the tool against real conditions and records the decision.
UK transfer risk assessment FAQ
Is a UK transfer risk assessment the same as a TIA?
They serve the same purpose. The UK term is transfer risk assessment, used with the IDTA and UK Addendum, while the EU term is transfer impact assessment, used with EU standard clauses.
Do we need one if we use the UK Addendum?
Yes, for restricted transfers to countries without adequacy regulations. You must assess whether the safeguard will be effective in practice.
Can we reuse an EU TIA?
You can reuse the factual work and much of the analysis, but you must check that the conclusion meets the UK test and record it separately or in a UK section.
Do we need one for transfers to countries with adequacy regulations?
Generally no, but confirm that the transfer is within the scope of the adequacy regulations and monitor their status.
How often should we review it?
At least annually and whenever the destination law, supplier or transfer changes.