Any arrangement where client data is processed outside the UK raises a specific compliance question that has nothing to do with the quality of the work: how the transfer itself is governed under UK data protection law.
What mechanism actually covers this?
The UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a documented transfer risk assessment specific to the arrangement, set out in guidance from the Information Commissioner’s Office.
Why does this sit in the contract, not the marketing copy?
The mechanism is a legal instrument between the parties, not a claim to make on a website. A firm should expect to see it addressed properly in the data processing agreement, detailed in our article on what a DPA actually needs to say.
What should a firm ask for?
Sight of the actual transfer mechanism and risk assessment, in writing, before any client data moves under the arrangement, part of the checklist in our article on what to ask before instructing a provider.
What actually triggers the international transfer rules?
Any personal data leaving the UK to be processed elsewhere, including data sent to a delivery team working on a firm’s matters, falls under Chapter V of the UK GDPR. It doesn’t matter that the underlying work is legal support rather than a typical outsourced service; the transfer rules apply the same way regardless of what the data is being used for.
Firms sometimes assume this only applies to large-scale data processing. It doesn’t. A single client file transferred for review triggers the same obligation as a bulk data transfer would.
What does a transfer risk assessment actually need to cover?
The ICO’s transfer risk assessment guidance expects an evaluation of the destination country’s data protection landscape, the specific safeguards in place under the transfer mechanism, and whether those safeguards are genuinely effective given the nature of the data being transferred. This isn’t a box-ticking form; it’s a documented judgement specific to the arrangement.
A properly drafted engagement builds this assessment into the data processing agreement itself, rather than treating it as a separate, easily forgotten compliance step.
UK IDTA or the UK Addendum: does it matter which is used?
Either is acceptable under current ICO guidance; what matters is that one is actually in place and properly completed, not left as a template with blanks. The UK Addendum works alongside the EU Standard Contractual Clauses where a firm’s arrangement already touches EU mechanisms; the standalone UK IDTA is often simpler where it doesn’t.
A firm doesn’t need to have a preference between the two. It needs to confirm whichever one is used has actually been completed for the specific engagement, not just referenced generically.
Who within a firm is responsible for checking this?
Typically the firm’s Compliance Officer for Legal Practice or equivalent, working alongside whoever holds data protection responsibility. The SRA Code of Conduct for Firms expects proper systems and controls around confidentiality and data handling, and international transfers sit squarely inside that expectation.
This isn’t a task to leave entirely to an external provider to self-certify. A firm should expect to review the actual documents, not just take assurance on trust.
What should be in place before any data moves under the arrangement?
The signed transfer mechanism, the risk assessment specific to the engagement, and the access-control and deletion terms sitting inside the same contract. Our provider selection guide covers exactly what to ask for before instructing anyone, and our AML and compliance article touches on how this interacts with a firm’s wider regulatory obligations.
None of this should be presented as marketing reassurance. It should be a specific document a firm can read, question, and keep on file.
Where can a firm get this set up properly?
Through the engagement’s contract terms directly. Our Pricing page sets out the fixed packages, and our contact page is the place to ask to see the transfer mechanism and risk assessment in writing before committing to anything.
Does an adequacy decision change any of this?
The jurisdiction a delivery team is based in may not currently have a UK adequacy decision, which is precisely why a transfer mechanism like the IDTA or Addendum is required rather than optional. If a destination country had UK adequacy status, the additional mechanism wouldn’t be necessary; without one, it is, and there’s no shortcut around it.
This is worth confirming directly with any provider, since it’s a simple factual check rather than a matter of interpretation.
What happens if a breach occurs on the offshore side?
A properly drafted engagement requires breach notification to the firm within hours, giving the firm enough time to assess whether it needs to report to the ICO within the 72-hour window UK GDPR requires for notifiable breaches. That speed of internal reporting is what makes the firm’s own compliance obligations achievable at all.
Firms should confirm this reporting timeline explicitly in writing rather than assume it’s implied by a general confidentiality clause.
Does this apply differently depending on how much data is transferred?
The legal mechanism applies regardless of volume, but the risk assessment itself should reflect the actual nature and sensitivity of what’s being transferred. A firm sending private client financial and estate data warrants closer scrutiny in the risk assessment than routine filing paperwork, even though the underlying legal mechanism is the same either way.
That’s a judgement worth making explicitly rather than applying a one-size-fits-all assessment to every type of matter.
How does this interact with the firm’s own client-facing transparency obligations?
A firm’s own privacy notice to clients should reflect that some processing happens outside the UK, if that’s genuinely the case, consistent with the general transparency principle running through UK GDPR. This doesn’t need to name the specific offshore team, but it shouldn’t misrepresent where processing actually happens either.
Getting the international transfer mechanism right internally is only half the picture; being straightforward with clients about it, at a proportionate level of detail, closes the loop.
Does this add cost or delay to setting up an outsourced arrangement?
Very little, once the templates exist. Drafting a transfer risk assessment from scratch each time would be slow, but a provider working with UK firms regularly should already have the mechanism drafted and simply need the specific engagement details filled in. The compliance step shouldn’t be the bottleneck in getting a firm’s outsourced arrangement up and running.
What takes real time is a firm reviewing the documents properly before signing, which is time well spent rather than a delay to resent.
What’s the single most useful question a firm can ask a provider?
“Can I see the transfer mechanism and risk assessment for this specific engagement before we start?” A provider that can produce this immediately, rather than needing to draft it after the fact, has clearly already built compliance into how it operates rather than treating it as an afterthought.
Does this differ for a sole practitioner compared to a larger firm?
The legal requirement is identical regardless of firm size, but a sole practitioner often has less internal capacity to scrutinise a provider’s data protection paperwork closely. That makes it more important, not less, to work with a provider that has the mechanism already drafted and ready to review, rather than one that treats it as something to sort out later.
Our embedded support article covers how a dedicated arrangement, complete with its data protection terms, tends to work best for smaller practices precisely because it removes the need for in-house compliance expertise the firm may not have.
Is this a one-off check or an ongoing obligation?
Ongoing. A transfer risk assessment reflects circumstances at a point in time, and firms should expect it to be reviewed periodically, not signed once and forgotten for the life of the engagement. A properly run arrangement builds a review point into the relationship rather than leaving compliance paperwork to go stale.
Ask when the last review happened and when the next one is due. A vague answer to that question is itself useful information.
Compliance here isn’t complicated once it’s built into the contract properly. It’s simply a set of specific documents a firm is entitled to see before any file crosses the border.
Want to see how the transfer mechanism is actually documented?
We’ll assign a dedicated paralegal to your matter for 7 days, no charge, so you can see the standard of work before deciding anything.
Confidential · No obligation · Typically a 20-minute call
Frequently Asked Questions
Is it lawful to have client data processed outside the UK at all?
Yes, provided a proper transfer mechanism such as the UK IDTA is in place, supported by a documented transfer risk assessment.
Who is responsible for ensuring the transfer mechanism is correct?
The instructing firm, as data controller, should verify the mechanism is properly documented within its data processing agreement with the provider.
Does a transfer risk assessment need to be provider-specific?
Yes, it should reflect the actual arrangement in place, not a generic template, and should be available for the firm to review.


