Don’t do SECURITY. Do business SECURELY.

Deadline passes for old EU SCCs in UK transfers

UK organisations can no longer rely on the pre-2021 EU Standard Contractual Clauses for restricted transfers.

From today, UK organisations can no longer rely on contracts using the old EU Standard Contractual Clauses (from before 2021) for restricted transfers of personal data out of the UK.

Restricted transfers must now be covered by one of:

  • UK adequacy regulations (for example transfers to the EEA, or to US organisations under the UK–US data bridge).
  • The UK International Data Transfer Agreement (IDTA).
  • The UK Addendum to the 2021 EU SCCs.
  • Binding Corporate Rules or another Article 46 safeguard, or an Article 49 exception.

If you have not yet replaced old clauses in supplier, customer or intra-group contracts, treat this as a priority, and make sure a transfer risk assessment is on file.

Source: UK IDTA and Addendum guidance (ICO)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights