UK GDPR imposes no data residency requirement. Deal documents stored in Frankfurt or Amsterdam are lawful under UK adequacy without any additional mechanism. What the law requires is a valid legal basis for each restricted transfer, and granting an overseas buyer access to the data room is itself a transfer that needs one.
For UK deal teams that need EU-hosted storage covering UK adequacy without a separate IDTA for the storage layer, Papermark is best for UK data residency. Its Data Rooms plan hosts by default on AWS eu-central-1 in Frankfurt, holds SOC 2 Type II and ISO/IEC 27001 certification, and includes a signable data processing agreement. Enterprise plans add managed UK-resident hosting through region selection for transactions that specify the United Kingdom. For the full scored comparison of UK data room providers, see the ranked guide to virtual data rooms for the UK market.
This guide covers what UK GDPR actually requires from a data room in an M&A or fundraising process, what the IDTA and UK Addendum are and when they are needed, and how EU hosting interacts with the restricted transfer analysis. For the broader picture of what UK data residency means for data room selection, see the hub page. For the documents a UK deal team needs in the room itself, see the UK M&A data room checklist.
What UK GDPR actually requires
UK GDPR is the EU General Data Protection Regulation as retained in UK law by section 3(10) of the Data Protection Act 2018 following the end of the Brexit transition period on 31 December 2020. In most respects it mirrors the EU text, but the two regimes have diverged in important ways since then, and they are now separate legal instruments administered by separate regulators: the Information Commissioner's Office in the UK and the European Data Protection Board for the EU.
The law contains no data residency requirement. Article 44 UK GDPR prohibits restricted transfers to countries without an adequacy decision or an appropriate safeguard, but it says nothing about where data must stay. A UK-registered company can lawfully store personal data of UK data subjects in Germany, Ireland, the Netherlands or any other country that the UK has recognised as adequate, with no further legal mechanism required. The constraint is on transfers, not on location.
Article 46 UK GDPR sets out the appropriate safeguards that authorise a restricted transfer in the absence of an adequacy decision. These include the International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, binding corporate rules, approved codes of conduct with enforceable commitments, and approved certification mechanisms. Of these, the IDTA and the UK Addendum are the mechanisms that deal teams encounter most often, because they are standardised, widely understood by counterparties, and can be incorporated into the data room's legal documentation without bespoke negotiation.
The Data Protection Act 2018 supplements UK GDPR in several ways relevant to deal work. Schedule 2 paragraph 5(2) provides a limited exemption from certain data subject rights during legal proceedings and for purposes of establishing, exercising or defending legal rights, which can be relevant when documents containing personal data are disclosed in a formal diligence process. The exemption does not suspend the lawfulness requirement for restricted transfers.
Adequacy and the EEA
The UK government has made adequacy regulations recognising a list of countries as having an adequate level of data protection for UK GDPR purposes. All EEA member states are on that list, as are countries including Switzerland, New Zealand, Israel, South Korea and Jersey. The United States is recognised as adequate only under the UK Extension to the EU-US Data Privacy Framework, known as the UK-US data bridge, which applies only to US organisations that have self-certified to the Framework. Most US law firms, investment banks and acquirers in an M&A process will not have done so, which means that granting them access to a data room is a restricted transfer requiring a mechanism.
For deal teams using EU-hosted data rooms, the EEA adequacy is the key practical point. Storing deal documents in Frankfurt, Dublin or Amsterdam is lawful under UK adequacy without an IDTA or UK Addendum for the storage layer itself. The data is not in the UK, but it is in an adequate country, and that satisfies Article 44. The transfer analysis then shifts to the question of who is accessing the data, not where it is stored.
This distinction matters in practice. A UK target company running a sale process through an EU-hosted data room is not committing a UK GDPR restricted transfer by storing its documents in Frankfurt. It is committing a restricted transfer when it grants a US acquirer access to those documents. The legal work required is an IDTA or UK Addendum covering the access decision, which is substantially less burdensome than a general residency analysis.
Restricted transfers and the IDTA
The ICO defines a restricted transfer as a transfer of personal data from a UK controller or processor to a recipient in a third country that is not adequate and where no other Article 46 safeguard or Article 49 derogation applies. The critical word is recipient. The transfer occurs when the data becomes accessible to a separate legal entity in that country, not only when data physically moves across a border. This is the central point that most discussions of data room residency miss.
A UK seller stores its TUPE employee liability information in a Frankfurt-hosted data room. It grants a US private equity firm access to the employment workstream. At the moment that access grant is made, a restricted transfer occurs. The data has not moved. The server has not changed. The transfer is constituted by the access. This is the ICO's position in its guidance on international transfers.
The International Data Transfer Agreement is the UK-specific mechanism for this situation. Published by the ICO and in force since 21 March 2022, it replaced EU standard contractual clauses for UK-originating transfers in the post-Brexit regime. An IDTA is a contract between the data exporter (the UK seller or its advisers operating the data room) and the data importer (the overseas buyer or its legal team) that imposes obligations on the importer equivalent to those UK GDPR would impose if it applied directly. Mandatory clauses covering data subject rights, security, sub-processing and transfer impact assessment cannot be altered or omitted.
In a formal M&A process, the IDTA is typically included in the non-disclosure agreement package or in the data room terms of access, so that it is in place before any personal data becomes accessible. The sell-side solicitors will usually prepare or review it. For a deal team relying on a data room with an NDA gate, the gate should not open until the IDTA is signed by the accessing party, not merely acknowledged. A platform that enforces the NDA gate at the technical level, preventing any document access until the agreement is countersigned, provides a cleaner record than one where the sequence is managed manually.
A UK deal scenario
Ashford Systems Limited is a fictional Hampshire-based software business with 48 employees and annual recurring revenue of just over four million pounds. In August 2026 its founders appointed a corporate finance adviser to run a controlled sale process targeting both UK trade buyers and two US strategic acquirers that had previously expressed interest.
The adviser raised the data residency question at the first process planning meeting. The target's documents included TUPE employee liability information under Regulation 11 of the Transfer of Undertakings (Protection of Employment) Regulations 2006, which contained each employee's salary, contract terms and disciplinary history. That information is personal data under UK GDPR, and granting the US acquirers access to it would constitute a restricted transfer. The adviser proposed a Frankfurt-hosted data room for the EU and UK trade buyers, covered by UK adequacy, combined with an IDTA incorporated into the data room access terms for the two US parties.
The sell-side solicitors drafted an IDTA covering the US acquirers as data importers and included it in the NDA package. The data room was configured so that the TUPE folder was accessible only to shortlisted parties, and the NDA gate required the IDTA to be countersigned by the authorised signatory of the importing entity before the link resolved to any document. The UK trade buyers received the standard NDA without an IDTA, as transfers to UK-resident entities required no additional mechanism. The two access regimes ran in parallel from the same data room platform. The distinction between them was invisible to the bidders but reflected in the audit log.
The UK Addendum to EU standard contractual clauses
The UK Addendum is a separate ICO document that adapts EU standard contractual clauses for use in UK-originating transfers. It is used when a party already has EU SCCs in place and wishes to extend their coverage to UK GDPR without negotiating a standalone IDTA. The Addendum sits on top of the EU SCCs and modifies their terms for UK purposes, substituting the ICO for the EU supervisory authority and adjusting the references to EU law to their UK equivalents.
The UK Addendum came into force on the same date as the IDTA, 21 March 2022. It is published by the ICO and is mandatory in form: the text cannot be altered. Either the IDTA or the UK Addendum satisfies Article 46 UK GDPR for a restricted transfer to a non-adequate country. For deals involving European parties already using EU SCCs, adding the UK Addendum is often the more practical route because it avoids a new negotiation cycle over a different document. For transactions where the US side has no pre-existing SCCs in place, a standalone IDTA is typically cleaner.
Deal teams should note that neither the IDTA nor the UK Addendum is a consent mechanism for the data subjects whose personal data is being transferred. Both operate as controller-to-controller or controller-to-processor contracts, not as consents from employees or customers. The Article 49 derogations allow a one-off transfer without standard clauses where, among other conditions, the transfer is necessary for the performance of a contract with the data subject or is necessary for the establishment, exercise or defence of legal claims. The derogations are narrow and the ICO has confirmed they are not a substitute for Article 46 mechanisms in repeated or systematic transfers such as ongoing data room access throughout a deal process.
Transfer Impact Assessments
A Transfer Impact Assessment is an analysis of whether the IDTA or standard clauses offer effective protection for personal data transferred to the destination country. The IDTA itself requires the exporter to carry out a TIA as part of completing the document. The ICO's guidance sets out what a TIA should cover: the laws and practices of the destination country, in particular any laws that allow public authorities to access personal data; the likelihood that those laws and practices will result in a level of protection that undermines the guarantees in the IDTA; and any supplementary measures available to address the shortfall.
For transfers to the United States, the key question is the extent to which US surveillance law, including the Foreign Intelligence Surveillance Act and Executive Order 14086, affects the effectiveness of the IDTA guarantees for the specific data at issue. Transfers of employee personal data in an M&A context, where the data subjects are UK-resident employees without a visible national security profile, are generally assessed as lower risk than transfers of communications or financial data, but the TIA still needs to be carried out and documented. The Schrems-equivalent UK analysis follows the same framework as the Schrems II judgment in the EU, because UK GDPR inherited the same underlying obligation from Article 46.
In practice, a TIA for a standard M&A restricted transfer to a US buyer will typically be a standard-form document prepared by the sell-side solicitors, adapted for the specific nature of the data in the room and the identity of the importer. It does not require bespoke legal advice in most cases. The ICO has published a template TIA framework that can be adapted for deal use. The important point is that the TIA must be documented before the access is granted, not reconstructed afterwards if the ICO asks.
For more on the full UK data residency picture, including which data room providers offer a named UK storage option and how UK hosting interacts with the restricted transfer analysis, see the UK data residency guide. For every confirmed data room price in the UK market, including which providers publish in sterling, see the data room costs guide.
Common mistakes about UK GDPR and deal data
Treating UK hosting as a complete compliance solution. Several deal teams believe that choosing a UK-hosted data room removes all UK GDPR complexity. It does not. UK hosting resolves the storage layer by keeping data in the UK, but it has no effect on the access question. Granting a US or non-adequate buyer access to a UK-hosted data room is a restricted transfer by the ICO's definition, because the data becomes accessible to a separate entity in a non-adequate country. The IDTA or UK Addendum is required regardless of where the server sits.
Assuming EU hosting is non-compliant for UK buyers. The opposite mistake is also common. Some deal teams reject EU-hosted data rooms on the basis that they are "not UK-compliant", which is wrong. The UK has granted adequacy to all EEA member states. Storing data in Frankfurt or Dublin is lawful under UK GDPR without any additional mechanism. The residency analysis is about adequacy, not about geography relative to the UK border.
Signing the NDA but not the IDTA. In deal practice, parties often circulate the NDA and the IDTA as separate documents in the same bundle. The NDA is typically signed promptly. The IDTA is sometimes treated as a secondary document and returned late, or not at all. If a non-adequate party accesses the data room before the IDTA is returned, the access is a restricted transfer without a mechanism. A data room that enforces the NDA gate at the platform level prevents access before countersignature, but only if the IDTA is embedded in the gate rather than sent separately.
Omitting a Transfer Impact Assessment from the documentation. The IDTA is not complete without a TIA. Many deal teams prepare and sign the IDTA but treat the TIA as an optional internal exercise rather than a mandatory component of the document. The ICO's guidance is clear that a TIA must be carried out before a restricted transfer is made. Preparing it after the data room has opened is not compliant with the obligation, even if the outcome of the analysis would have been the same.
Conflating GDPR compliance with data room security certification. SOC 2 Type II and ISO/IEC 27001 certifications confirm that the data room provider has appropriate technical and organisational security measures in place. They are relevant to the Article 5(1)(f) integrity and confidentiality requirement. They do not address the restricted transfer analysis. A fully certified data room still requires an IDTA when its documents are accessed by a party in a non-adequate country. The security and the transfer questions are separate compliance workstreams.
For a practical checklist covering the UK-specific documents and configuration that a data room for a UK deal requires, including the TUPE and Companies House workstreams, see the data room due diligence checklist. For the full scored ranking of UK data room providers, including how each handles UK GDPR and data residency, see the best virtual data rooms in the UK 2026. For a detailed walkthrough of the two mechanisms that authorise a restricted transfer, including how the IDTA and the UK Addendum differ and what a transfer risk assessment must cover, see the IDTA and the UK Addendum, explained for deal teams.