The International Data Transfer Agreement and the UK Addendum to EU standard contractual clauses are the two mechanisms UK GDPR provides for sending personal data to non-adequate countries. UK deal teams need one or both whenever an overseas buyer, their advisers or their data room gains access to personal data held by a UK controller.

This article explains what each mechanism is, how the IDTA differs from the UK Addendum, what a transfer risk assessment requires, and how the UK-US Data Bridge affects the analysis. It also covers how to configure a data room so that the restricted transfer controls are built into the access sequence rather than managed alongside it. For the broader picture of UK data residency and where deal data is allowed to sit, see the hub page. For the UK GDPR rules that create the restricted transfer obligation in the first place, see UK GDPR and where your deal data is allowed to sit.

What the IDTA is, and when it applies

The International Data Transfer Agreement is the UK-specific mechanism for lawfully transferring personal data from a UK controller or processor to a recipient in a country that does not have UK adequacy recognition, under Article 46 of UK GDPR. It was published by the Information Commissioner's Office and came into force on 21 March 2022, which is the date from which UK controllers needed to use it rather than the EU-derived standard contractual clauses that had governed transfers before the Brexit transition period ended.

The IDTA is a contract, not a registration or a self-assessment. It is signed by two parties: the data exporter, who is typically the UK controller or processor whose data is being transferred, and the data importer, who is the recipient entity in the non-adequate country. The mandatory terms cannot be altered. They cover obligations on the importer around data subject rights, security standards, sub-processing arrangements and the transfer risk assessment that the exporter must carry out before the contract takes effect. Parties can add a commercial schedule setting out the details of the specific transfer, including the categories of data, the purpose and the duration, without affecting the mandatory clauses.

In the M&A context, the typical data exporter is the sell-side entity or its advisers running the data room process. The data importer is the overseas buyer or, where the access is structured through its advisers, the overseas firm whose legal team will review the documents. The transfer occurs, on the ICO's test, at the point when personal data becomes accessible to a separate legal entity in a non-adequate country, not when a document is actively downloaded or reviewed. An IDTA must therefore be in place before the access grant is made, not merely before diligence begins in a broader sense. A data room gate that opens on NDA signature without a separate check on IDTA status is a compliance gap in the sequencing.

Non-adequate countries for UK GDPR purposes include the United States (except for transfers to self-certified Data Privacy Framework participants), China, India and most countries in South-East Asia, the Middle East and sub-Saharan Africa. The UK government publishes an adequacy table. Deal teams should check the table against the actual legal entities receiving access, not against countries generally: a US parent and its UK subsidiary are separate legal entities with different adequacy profiles.

The UK Addendum to EU standard contractual clauses

The UK Addendum is a separate document published by the ICO. Rather than replacing EU standard contractual clauses in the way the standalone IDTA does, it adapts the EU SCCs for use by UK controllers and processors. It sits on top of an existing set of EU SCCs and modifies their terms for UK GDPR purposes: the ICO is substituted for the EU supervisory authority, UK GDPR replaces EU GDPR in the operative provisions, and certain redress mechanisms are adjusted to reflect the UK regulatory landscape.

The UK Addendum came into force on 21 March 2022, the same date as the standalone IDTA. Either mechanism satisfies Article 46 UK GDPR for a restricted transfer to a non-adequate country. The choice between them is primarily practical. Where a deal already involves European parties using EU SCCs for their own transfers, adding the UK Addendum allows the UK elements to sit alongside the existing documentation without a separate IDTA negotiation cycle. Where the non-adequate counterparty is a US entity with no pre-existing EU SCCs in place, a standalone IDTA is typically cleaner.

Neither the IDTA nor the UK Addendum is a consent mechanism for the data subjects whose personal data is being transferred. Both are controller-to-controller or controller-to-processor contracts. They authorise the transfer as a matter of UK GDPR compliance, but they do not override the lawfulness requirement for the underlying processing or suspend data subject rights during the diligence period. The Schedule 2 paragraph 5(2) exemption under the Data Protection Act 2018 provides limited relief from certain data subject rights in the context of legal proceedings, but it does not alter the transfer mechanism requirement.

A UK deal scenario

Belford Manufacturing Holdings Limited is a fictional Midlands-based precision engineering business with 180 employees and revenue of approximately twenty-two million pounds. In July 2026 its private equity shareholders instructed an M&A adviser to run a dual-track process targeting UK and European trade buyers alongside two US strategic acquirers identified during a prior market-sounding exercise.

The adviser raised the restricted transfer question at the process design stage. The data room would contain TUPE employee liability information under Regulation 11 of the Transfer of Undertakings (Protection of Employment) Regulations 2006, salary data, disciplinary records and personal pension details for all 180 employees. That information is personal data under UK GDPR. The UK and EEA trade buyers could receive access under UK adequacy without any additional mechanism. The two US parties could not, because neither had self-certified to the UK-US Data Bridge, and most US M&A teams have not.

The sell-side solicitors prepared an IDTA naming Belford Manufacturing Holdings as the data exporter and each US bidder entity as a separate data importer. A transfer risk assessment was prepared in parallel, covering the categories of data in the room and the specific US legal environment, including the Foreign Intelligence Surveillance Act provisions relevant to commercial employee data. Both documents were included in the NDA bundle sent to the US parties. The data room platform was configured so that the access gate required countersignature of the IDTA before any document link resolved. The UK and EEA buyers received the standard NDA package without an IDTA, and the two access regimes ran from the same data room without either party being aware of the distinction.

Transfer risk assessments: what they require

A transfer risk assessment is the analysis that a data exporter must carry out before relying on the IDTA or the UK Addendum for a restricted transfer. The IDTA itself contains the requirement in mandatory Clause 11: the exporter must complete Part 2 of the IDTA, which includes the TRA analysis. The ICO's guidance adds further detail on what the assessment must cover.

The core question is whether the laws and practices of the destination country undermine the protections that the IDTA provides in practice, not just in theory. For transfers to the United States, the relevant factors include Section 702 of the Foreign Intelligence Surveillance Act, Executive Order 14086 on enhancing safeguards for signals intelligence activities, and any other US government access powers that might reach the specific data being transferred. The Schrems II judgment in the EU, and its UK equivalent, established that standard clauses alone are insufficient where the destination country's legal environment prevents their effective implementation. A TRA must address this question for the specific data involved, not for data room transfers in the abstract.

In practice, for a standard M&A restricted transfer to a US buyer involving employee personal data, the TRA will typically be a standard-form document adapted by the sell-side solicitors for the specific nature of the data and the identity of the importer. It does not require bespoke legal advice in most cases, provided the data categories and the importer profile are accurately described. The ICO has published a template TRA framework that can be adapted for deal use. The important discipline is timing: the TRA must be documented before the access grant is made, not assembled retrospectively if the ICO makes an inquiry.

For a fuller treatment of how transfer risk assessments interact with the data room documentation checklist, see the data room due diligence checklist for UK deals.

The UK-US Data Bridge, and its limits in deal practice

The UK-US Data Bridge is the UK Extension to the EU-US Data Privacy Framework, which provides an adequacy route for transfers to US organisations that have self-certified to the Framework's principles under the US Department of Commerce scheme. Where a US recipient has self-certified, the transfer is covered by UK adequacy and no IDTA or UK Addendum is required. That is a useful simplification when it applies.

The limitation in M&A deal practice is that most US counterparties have not self-certified. Self-certification under the Data Privacy Framework is a voluntary US scheme, and the participants tend to be US tech and cloud companies that routinely handle EU and UK personal data at scale. US law firms, investment banks, private equity funds and their portfolio companies rarely appear on the Data Privacy Framework list, because they have not needed to. Before assuming the Data Bridge applies, a deal team should check the active participant list on the Department of Commerce website against the specific legal entity that will access the data room. Checking a parent company without verifying that the operating entity is separately certified can produce a false answer.

Where the Data Bridge does apply, the transfer risk assessment is replaced by a lighter adequacy reliance. The ICO guidance on the UK Extension confirms that a TRA is not required for transfers to certified participants. That said, a diligence file should still record the adequacy basis relied on and confirm that the recipient's certification was verified and current at the time of the access grant.

Configuring a data room for restricted transfers

The legal framework sets out what is required; the data room platform determines how reliably it is enforced. The gap that most compliance failures fall through is the sequencing between NDA signature and IDTA countersignature. If the data room gate opens on NDA receipt and the IDTA is circulated separately, the access happens before the mechanism is in place.

For UK deal teams running a process that includes non-adequate counterparties, Papermark is the data room that most directly addresses this at the platform level. Its NDA gate is a hard technical gate: no document loads until the gate condition is met. The IDTA can be embedded in the gate terms or sent as a separate countersignature requirement that must resolve before the link activates. The access sequence is then part of the audit trail rather than a separate paper trail managed by the legal team alongside the platform. Papermark hosts by default in Frankfurt on AWS eu-central-1, which covers the storage layer under UK adequacy without a separate IDTA for the storage decision itself. It holds SOC 2 Type II and ISO/IEC 27001 certification, with a signable data processing agreement that forms part of the Article 28 documentation. The Data Rooms plan is $99 per month for three team members with unlimited data rooms.

For the full scored comparison of UK data room providers, including how each platform handles the IDTA documentation requirements, see the ranked guide to virtual data rooms for the UK market in 2026.

Common mistakes UK deal teams make on restricted transfers

Treating IDTA signature as optional once the NDA is signed. The NDA and the IDTA serve different purposes and neither substitutes for the other. The NDA is a confidentiality obligation. The IDTA is the statutory mechanism that authorises the restricted transfer under Article 46 UK GDPR. Where the two documents are circulated in the same bundle, the NDA is almost always returned promptly while the IDTA is treated as a secondary document. If the data room opens on NDA signature, the access that follows is a restricted transfer without a mechanism for the period before the IDTA is returned. That period can last days on a competitive process. The solution is either to gate the data room on IDTA receipt or to hold access until both documents are returned, whichever the platform supports.

Skipping the transfer risk assessment on the basis that the data is low-risk. The TRA is not a risk-level test that produces a pass or fail. It is a mandatory component of the IDTA under Clause 11. A deal team that completes and signs the IDTA but does not document a TRA has not fully executed the mechanism. Low-risk transfers still require a TRA; the outcome of the analysis may be brief, but the analysis must be done and the conclusion recorded before the access is granted.

Assuming UK hosting removes the need for an IDTA. By the ICO's test, a restricted transfer occurs when personal data is sent or made accessible to a separate legal entity in a non-adequate country. Granting a US buyer access to a UK-hosted data room is a restricted transfer because the data becomes accessible to an entity in a non-adequate country, regardless of where the server sits. UK hosting resolves the storage question but does not affect the access analysis. This is the single most common misconception in UK deal practice, and it leads teams to spend money on UK hosting while omitting the IDTA that would actually address the compliance question.

Using the wrong legal entity as the data importer. US private equity funds, law firms and strategic acquirers typically operate through multiple legal entities. The data importer in the IDTA must be the specific entity that will access the data room, not the parent fund or the firm generally. Naming the wrong entity means the IDTA does not cover the actual access. Where a buy-side firm accesses the room through a data protection officer or a deal team at a named subsidiary, that subsidiary is the data importer. Checking the entity structure before drafting the IDTA is part of the process design work, not an afterthought.

Relying on the Article 49 derogations for standing data room access. The Article 49 derogations under UK GDPR allow a restricted transfer without standard clauses in narrow circumstances, including necessity for legal claims or contractual performance. The ICO has confirmed these are not a substitute for Article 46 mechanisms in repeated or systematic transfers. A buyer reviewing documents in a data room over several weeks is making systematic access. The derogations do not apply, and relying on them exposes the process to enforcement risk if the ICO were to examine the transfer documentation.

For the documents and configuration that a UK deal data room requires, including the TUPE workstream, Companies House register and NDA gate setup, see the data room due diligence checklist for UK deals. For the UK data residency picture, including which providers offer named UK hosting and how that interacts with the IDTA analysis, see the UK data residency guide.