Library
International Data Transfers for AI & Cloud Tools
The common case is a UK or EU operator sending personal data to a US-hosted model or SaaS tool. Adequacy (including the EU-US Data Privacy Framework and the UK Extension) is the first gate; if it does not cover that vendor, you need 2021 SCCs and/or the UK IDTA or Addendum, plus a transfer risk assessment.
Last reviewed
MikeFounder & developer
- EU data & privacy
- AI governance
- Compliance
On this page
Who this is for
- UK or EEA operators whose AI or cloud vendor stores or processes personal data in the United States
- Teams who were told “the API is fine, they are on the Privacy Shield” (that instrument is gone)
- Procurement owners filling the vendor checklist
The real case
A support team pastes a customer ticket into a US-hosted model. A hotel's PMS sits on US servers. A recruiter's ATS is a US SaaS product with an “AI rank” layer. In each case personal data is leaving the UK or the EEA. That is a restricted transfer under Chapter V of the GDPR / UK GDPR unless a mechanism applies.
The AI Act does not replace this. Transfers are a data-protection problem. See GDPR and AI for basis and purpose. This page is the crossing.
Gate 1: Adequacy
If the destination is covered by an adequacy decision, you do not need SCCs or the IDTA for that transfer.
EU → US. The Commission's adequacy decision of 10 July 2023 for the EU-US Data Privacy Framework (DPF) remains in force as of 13 August 2026. It covers transfers to US organisations that are self-certified under the DPF for the relevant data. Check the Data Privacy Framework list, not the vendor's homepage claim. The General Court upheld the decision in Latombe (September 2025); an appeal to the CJEU has been filed (Case C-703/25 P). Status as of 13 August 2026: the DPF is in force; its long-term survival is before the Court. Keep a documented SCC fallback. Do not pretend the appeal has already struck it down.
UK → US. The UK Extension to the DPF (the “data bridge”), via the Data Protection (Adequacy) (United States of America) Regulations 2023, is a separate UK adequacy finding. The ICO restated that independence on 30 July 2026: the UK Extension would not automatically fall if the EU DPF were invalidated, though the UK government would still have to review the underlying US commitments. The US organisation must have certified for the UK Extension, not only the EU DPF.
EU ↔ UK. The EU has an adequacy decision for the UK; the UK has adequacy for the EEA. As of 13 August 2026 both remain in force. They are reviewed, not eternal.
If the vendor is not certified, or the data type is outside the certification, adequacy does not help. Go to Gate 2.
Gate 2: Appropriate safeguards
From the EEA: the Commission's 2021 Standard Contractual Clauses (Implementing Decision (EU) 2021/914). Pick the module that matches the relationship (controller-to-controller, controller-to-processor, processor-to-processor, processor-to-controller). Complete a transfer impact assessment. The 2010 SCCs are not valid for new transfers.
From the UK: the EU SCCs are not valid on their own. Use either:
- the ICO International Data Transfer Agreement (IDTA) (in force 21 March 2022); or
- the EU 2021 SCCs plus the UK Addendum.
The ICO has said it plans to update the IDTA and Addendum during 2026 to reflect the Data (Use and Access) Act 2025, and that you should keep using the current versions until then. As of 13 August 2026 those updates have not replaced the current texts.
Complete a transfer risk assessment (the ICO's TRA tool, or equivalent). Under the DUAA the statutory language around the “data protection test” is in force for some transfer provisions; the ICO's clause updates are the piece still coming. If you are unsure which DUAA transfer sections have commenced for your case, check the latest commencement SI rather than assuming the whole Act is live. Section 80 (ADM) commenced 5 February 2026; transfer-clause updates are a different commencement story.
Gate 3: What the AI vendor must still show you
A DPF badge or an SCC pack is necessary, not sufficient.
- Where is inference run? Where are prompts stored? For how long?
- Is your data used to train their models? If yes, that is a further purpose and often a further transfer.
- Sub-processors: named, location, same mechanism.
- Encryption in transit and at rest; who holds keys.
- A way to delete or export if you leave.
Those questions sit on the vendor checklist in full.
Questions
The vendor says they are “GDPR compliant”. Is that a transfer mechanism?
No. Compliance is a claim. Adequacy, SCCs, IDTA/Addendum, or a valid derogation are mechanisms. Ask which one, and for which legal entity.
Can we rely on the DPF and skip SCCs?
If, and only if, the US entity is currently certified for the data you actually send (EU DPF for EEA data; UK Extension for UK data). Keep SCCs or the IDTA as a fallback while Latombe is on appeal. That is judgement, not a legal requirement to double-key every contract.
We use a UK-hosted model. Are we done?
Hosting in the UK does not end the analysis if the vendor's sub-processor, support staff, or backup sits in the US. Read the sub-processor list.
What changed
- 13 August 2026: First publication. DPF in force; UK Extension independent (ICO, 30 July 2026); IDTA/Addendum still the current ICO texts, updates planned later in 2026. Cadence: medium (90–180 days). Next review due 9 January 2027. Off-cycle if the CJEU rules on the DPF or the ICO issues new IDTA text.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- GDPR and AI: Where the Two Actually OverlapThe GDPR is stable. What keeps moving is how the EDPB applies it to models. The overlap that matters in practice is three points: a legal basis for training and inference, purpose limitation when you reuse customer data for a new AI feature, and when an AI system triggers a DPIA.
- Automated Decision-Making Under GDPR Article 22In the EU, Article 22 GDPR still restricts solely automated decisions with legal or similarly significant effects, with a right to human intervention. ‘Meaningful’ involvement is a person who can change the outcome. A click is not enough. The UK has replaced Article 22 with Articles 22A–22D; that regime is a separate page.
- The AI Vendor Risk ChecklistA procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.