Law note · United Kingdom
UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom
The European Commission's own adequacy decisions for the UK were reaffirmed 19 December 2025 and now run to 27 December 2031. For UK-outbound transfers, the ICO administers its own International Data Transfer Agreement (IDTA, in force since 21 March 2022) and IDTA Addendum as the appropriate-safeguards mechanism where no UK adequacy regulation covers the destination.
The DUA Act restructured UK General Data Protection Regulation (GDPR)'s transfer chapter: the original Article 44 was omitted and replaced from 5 February 2026 by a new Article 44A, which requires that a transfer either be approved by regulations, made subject to appropriate safeguards, or made in reliance on a derogation for specific situations, the same three-track adequacy, safeguards, or derogation structure as EU GDPR Chapter V, run through the UK's own instruments rather than the EU's. This is a real, structured condition on outbound transfer, not an absence of restriction.
What it asks of an app
- Before moving personal data of a person in the United Kingdom outside the UK, either rely on a UK adequacy regulation, put appropriate safeguards in place such as the ICO's International Data Transfer Agreement or Addendum, or rely on a narrow Article 49 derogation, under UK General Data Protection Regulation (GDPR) Article 44A.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_voice, processes_biometrics
Primary source: legislation.gov.uk, official consolidated text, verified by direct crawler fetch
European Commission UK adequacy decisions