Law note · United Kingdom

UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom

cite UK GDPR, Arts. 44A-50, as amended by the Data (Use and Access) Act 2025 stage In effect since 2026-02-05 reviewed 2026-08-24

The European Commission's own adequacy decisions for the UK were reaffirmed 19 December 2025 and now run to 27 December 2031. For UK-outbound transfers, the ICO administers its own International Data Transfer Agreement (IDTA, in force since 21 March 2022) and IDTA Addendum as the appropriate-safeguards mechanism where no UK adequacy regulation covers the destination.

The DUA Act restructured UK General Data Protection Regulation (GDPR)'s transfer chapter: the original Article 44 was omitted and replaced from 5 February 2026 by a new Article 44A, which requires that a transfer either be approved by regulations, made subject to appropriate safeguards, or made in reliance on a derogation for specific situations, the same three-track adequacy, safeguards, or derogation structure as EU GDPR Chapter V, run through the UK's own instruments rather than the EU's. This is a real, structured condition on outbound transfer, not an absence of restriction.

What it asks of an app

  • Before moving personal data of a person in the United Kingdom outside the UK, either rely on a UK adequacy regulation, put appropriate safeguards in place such as the ICO's International Data Transfer Agreement or Addendum, or rely on a narrow Article 49 derogation, under UK General Data Protection Regulation (GDPR) Article 44A.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_voice, processes_biometrics

Primary source: legislation.gov.uk, official consolidated text, verified by direct crawler fetch
European Commission UK adequacy decisions

← Back to the example  ·  Lint your app →