Skip to content

UK-US Data Transfer and Agreements: What Businesses Need to Know 

Table of Contents

In Short

  • The UK GDPR allows data transfers to the US only if specific safeguards are in place.
  • The UK-US Data Bridge simplifies transfers to certified US companies but isn’t always available.
  • If your US supplier is not certified, other options like SCCs or anonymisation may apply, but require careful handling.

Tips for Businesses

Check whether your US partners are certified under the UK-US Data Bridge. If not, consider alternatives like SCCs with a Transfer Risk Assessment or anonymisation. Don’t rely on exceptions unless absolutely necessary. Given the complexity and legal risk, speak to a data protection lawyer before transferring any personal data to the US.

Transferring personal data to the US may be necessary if your business works with US-based companies, such as key suppliers. However, UK data protection law imposes strict requirements to ensure that personal data remains protected, even when sent outside the UK. The UK GDPR permits international data transfers only where specific legal rules are followed. This article explores what your business needs to know about data transfers to the US, which agreements and safeguards you could rely on and their importance for compliance with UK GDPR.

Why are International Data Transfers Considered High Risk?

Transferring personal data across borders can challenge compliance because data protection laws differ between jurisdictions. The UK GDPR requires that personal data leaving the UK receive an adequate level of protection to ensure that individuals’ rights and personal information remain safeguarded.

Some jurisdictions (including the US) have different legal frameworks for data privacy. These variations can create uncertainty about how personal data will be handled when transferred internationally. Therefore, businesses transferring data abroad must carefully assess and comply with applicable data transfer rules in line with UK GDPR requirements.

How Can the UK-US Data Bridge Help Address Compliance?

The UK government introduced the UK-US Data Bridge as a partial adequacy decision to facilitate personal data transfers to the US. Businesses can transfer personal data to US organisations if those organisations have obtained certification under the Data Privacy Framework (DPF) and the UK Extension to this framework. Certified US companies must, however, comply with strict data protection principles, e.g., those relating to transparency, accountability, and data minimisation.

Front page of publication
GDPR Essentials Factsheet

This factsheet sets out how your business can become GDPR compliant.

Download Now

For your business, the UK-US Data Bridge can help simplify compliance by removing the need for additional safeguards when transferring personal data to a certified US organisation. However, various criteria apply to rely on the UK-US Data Bridge mechanism. Unfortunately, it may not always be appropriate for data transfers, so it is essential to take legal advice if you are unsure. 

Continue reading this article below the form
By submitting this form, you agree to receive emails from LegalVision and can unsubscribe at any time. View our Privacy Policy.
This field is for validation purposes and should be left unchanged.

What if Your US Supplier is Not Certified Under the UK-US Data Bridge?

Not all organisations will be certified under the UK-US Data Bridge mechanism, and it is not mandatory to rely on it. 

Suppose your US supplier has not obtained certification under the UK-US Data Bridge (or you cannot rely on this mechanism). In that case, your business can look to use an alternative legal mechanism to transfer personal data lawfully to the US. 

Alternative Mechanisms

Other options to consider include the following:

  • your business may seek to rely on European Union Standard Contractual Clauses (EU SCCs) with the UK Addendum or the UK’s standalone International Data Transfer Agreement. These mechanisms (commonly called ‘SCCs‘) serve as legally approved contractual contracts that protect personal data transferred to a country without an adequacy decision. Before relying on SCCs, your business must conduct a Transfer Risk Assessment (TRA) to determine whether the recipient can provide adequate protection for personal data. The TRA helps companies to identify risks associated with differing legal frameworks and ensures appropriate safeguards are in place;
  • if the SCCs are unsuitable, your business may rely on a specific exception under the UK GDPR. These exceptions allow transfers in limited circumstances, e.g. when the individual has explicitly consented. Companies should use exceptions only as a last resort, as they are subject to strict conditions; and
  • another option may be anonymisation. If your business anonymises personal data before transferring it to the US, UK GDPR does not restrict the transfer because anonymised data no longer qualifies as personal data. However, your business must ensure that the anonymisation process is entirely irreversible and workable. If there is any risk that the data could be re-identified, UK GDPR transfer rules will still apply.

How Can a Lawyer Help Ensure Data Transfers to the US Are Compliant?

Navigating the legal complexities of international data transfers to the USA (and deciding which agreements to use) requires careful consideration of legal risks and compliance requirements. A data protection lawyer can help your business assess the risks of transferring personal data to the US and determine the most appropriate legal mechanism for your circumstances. 

A data protection lawyer can also help you correctly implement necessary steps, such as appropriately completing international data transfer documents (such as SCCs) or carrying out a transfer risk assessment. Given the high risk of getting this wrong, legal advice is crucial if you are unsure how to lawfully transfer personal data to the USA.

Key Takeaways

Many businesses commonly transfer data to the US as part of everyday business. However, your business must ensure data transfers to the US comply with UK GDPR. You may be able to rely on various mechanisms, depending on the nature of your transfers and the recipient parties in the US. Seeking legal advice from a data protection solicitor can help you ensure compliance and mitigate risks when transferring personal data to the US.

If you need advice on transferring personal data to the US, our experienced data,privacy and IT lawyers can help as part of our LegalVision membership. For a low monthly fee, you’ll have unlimited access to lawyers who can answer your questions, review your data protection policies, and guide you through complex compliance issues. Call us today on 0808 196 8584 or visit our membership page.

Frequently Asked Questions 

What is the UK-US Data Bridge?

The UK-US Data Bridge provides a framework allowing UK businesses to transfer personal data to US-based organisations that have obtained certification under the Data Privacy Framework and the UK extension to it without additional safeguards.

What if my US supplier is not part of the UK-US Data Bridge?

For example, your business may still be able to transfer data by using an appropriate safeguard permitted under law, such as the UK’s International Data Transfer Agreement. 

Register for our free webinars

Startup 101: Raising Capital for Later Stage Companies

Online
Learn how to secure investment for your growing startup. Register for our free webinar.
Register Now

Employee vs Contractor: Protect Your Business from Costly Status Mistakes

Online
Avoid legal and financial risks by correctly classifying employees, workers and contractors. Register for our free webinar.
Register Now

Unfair Contract Terms Explained: Ensuring Compliance and Avoiding Pitfalls

Online
Protect your business from unfair contract terms. Register for our free webinar.
Register Now

Navigating Common Employment Disputes: Legal Insights for Employers

Online
Learn how to handle workplace disputes and avoid costly legal challenges. Register for our free webinar.
Register Now
See more webinars >
Sej Lamba

Sej Lamba

Sej is an Expert Legal Contributor at LegalVision. She is an experienced legal content writer who enjoys writing legal guides, blogs, and know-how tools for businesses. She studied History at University College London and then developed a passion for law, which inspired her to become a qualified lawyer.

Qualifications: Legal Practice Course, Kaplan Law School; Graduate Diploma in Law, Kaplan Law School; BA, History, University College.

Read all articles by Sej

About LegalVision

LegalVision is an innovative commercial law firm that provides businesses with affordable, unlimited and ongoing legal assistance through our membership. We operate in Australia, the United Kingdom and New Zealand.

Learn more

We’re an award-winning law firm

  • Award

    2024 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2024 Law Firm of the Year Finalist - Modern Law Private Client Awards

  • Award

    2023 Economic Innovator of the Year Finalist - The Spectator

  • Award

    2023 Law Company of the Year Finalist - The Lawyer Awards

  • Award

    2023 Future of Legal Services Innovation - Legal Innovation Awards