{"id":8244,"date":"2024-03-15T15:55:28","date_gmt":"2024-03-15T14:55:28","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=8244"},"modified":"2024-03-15T15:55:29","modified_gmt":"2024-03-15T14:55:29","slug":"uk-restricted-transfers-standard-data-protection-clauses","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/","title":{"rendered":"UK Restricted Transfers: Standard data protection clauses by the ICO"},"content":{"rendered":"\n<p>As organisations continue to navigate the complexities of <a href=\"https:\/\/techgdpr.com\/blog\/making-sense-of-new-eu-wide-data-regulations-the-red-thread-behind-the-digital-single-market\/\">data protection laws<\/a>, staying abreast of key deadlines is paramount. One such deadline relates to organisations&nbsp;involved in restricted transfers of personal data under UK data protection law. <a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/international-transfers\/international-transfers-a-guide\/#:~:text=3.%20Standard%20data,assessment%20(see%20above).\">The ICO set a critical deadline for organisations that transfer personal data outside the UK<\/a>. This article explains what you need to do to ensure compliance with the ICO&#8217;s directive and the UK GDPR.<\/p>\n\n\n\n<p>The deadline pertains to the validity of old EU standard contractual clauses (SCCs) issued by the European Commission under the previous Data Protection Directive (the old EU SCCs). Note that the EU has also replaced the old EU SCCs and the last month of their validity was December 2022. If your organisation relies on these clauses for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024. <a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/international-transfers\/international-data-transfer-agreement-and-guidance\/\">The ICO has issued 2 sets of standard data protection clauses<\/a> for restricted transfers under the UK GDPR. Organisations must either enter into a new contract based on the International Data Transfer Agreement (IDTA) or annex the Addendum provided by the Information Commissioner\u2019s Office (ICO).<\/p>\n\n\n\n<p>Standard data protection clauses are pre-approved contracts that organisations can use to ensure personal data transferred outside the UK receives adequate protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to determine if this deadline affects your organisation in the UK<\/h2>\n\n\n\n<p>If your organisation transfers personal data outside the UK (restricted transfers), you need to act now if you were previously relying on the old EU SCCs. These old SCCs are no longer valid for restricted transfers under UK GDPR after March 21, 2024.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Assess your current restricted data transfers<\/strong><\/h3>\n\n\n\n<p>Review your organisation&#8217;s current data transfer practices to ascertain whether they involve restricted transfers under the UK GDPR. Do you transfer personal data from the UK to countries outside the UK? If yes, were you previously relying on old EU SCCs approved under the Data Protection Directive for these transfers? Did you answer yes to both questions, then you need to switch to the International Data Transfer Agreement (IDTA) provided by the ICO. If you answered no to the second question, you may not need to take further action.<\/p>\n\n\n\n<p>Note that in the UK, if you currently rely on the new EU SCCs adopted in June 2021, it is not necessary to sign the IDTA; the ICO allows you to annex the Addendum to your existing EU SCCs. However, if the SCCs are old, you will have to stop relying on them completely.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Evaluate existing Agreements<\/strong><\/h3>\n\n\n\n<p>Determine when your organisation entered into the contracts. Contracts entered into under the Data Protection Directive are valid only until March 21, 2024, after which any transfer of personal data out of the UK under such Agreements will most likely constitute an illegal transfer of data.<\/p>\n\n\n\n<p>As an indication, the new EU SCCs were adopted in June 2021, therefore any EU SCC document dated before that would be the old version.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1280\" height=\"720\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg\" alt=\"\" class=\"wp-image-8252\" style=\"width:510px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg 1280w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-300x169.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-1024x576.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-768x432.jpg 768w\" sizes=\"(max-width: 1280px) 100vw, 1280px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The ICO restricted transfers deadline affects my organisation, what can I do?<\/h2>\n\n\n\n<p>The UK Information Commissioner&#8217;s Office (ICO) offers <strong>two options<\/strong> for compliant data transfers after March 21, 2024.<\/p>\n\n\n\n<p>Organisations in the UK can choose to do either of the following:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Use the UK International Data Transfer Agreement (IDTA)<\/strong><\/h3>\n\n\n\n<p>This Agreement is specifically designed for restricted transfers under the UK GDPR.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Use the UK Addendum with the new EU SCCs<\/strong><\/h3>\n\n\n\n<p>This option allows you to leverage the new EU SCCs (adopted in June 2021) but requires an additional agreement (the Addendum) to ensure compliance with UK GDPR. If your organisation relies on the new EU SCCs, it will need to annex the Addendum to comply. It will not need to enter into an entirely new agreement. Before annexing the UK Addendum to previously signed SCCs, ensure to check with the other contracting party or parties. This ensures that they are aligned on the additional obligations introduced by the UK Addendum.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Conduct a Transfer Risk Assessment:<\/strong><\/h3>\n\n\n\n<p><strong>Regardless of the option you choose<\/strong>, you must conduct a transfer risk assessment. This assessment evaluates the potential risks to personal data in the recipient country. This is a requirement by the ICO.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>It is essential for organisations to act proactively. Doing this prevents disruptions in data transfers and potential non-compliance with data protection laws. Not sure about how the required changes impact your organisation or need assistance in navigating the required changes? Get in touch with us. We can carry out a quick assessment and design custom-made solutions to align your organisation with the ICO\u2019s directive.<\/p>\n\n\n\n<p>Generally, we can help your organisation stay ahead of compliance requirements and safeguard the integrity of data transfers in accordance with UK data protection laws.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">In summary\u2026<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Review your data transfer practices. Identify all instances where you transfer personal data from the UK to countries outside the UK.<\/li>\n\n\n\n<li>Determine if you were using old EU SCCs for these transfers.<\/li>\n\n\n\n<li>If the deadline applies to you, explore the IDTA and Addendum options.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>As organisations continue to navigate the complexities of data protection laws, staying abreast of key deadlines is paramount. One such deadline relates to organisations&nbsp;involved in restricted transfers of personal data under UK data protection law. The ICO set a critical deadline for organisations that transfer personal data outside the UK. This article explains what you [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":8252,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[75,299],"tags":[35,58,79,300,302,303,248,168],"class_list":["post-8244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-international-transfers","category-uk-gdpr","tag-gdpr","tag-gdpr-compliance","tag-international-transfers","tag-restricted-transfers","tag-standard-data-protection-clauses","tag-uk-data-protection-law","tag-uk-gdpr","tag-uk-idta"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg",1280,720,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-300x169.jpg",300,169,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-768x432.jpg",640,360,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-1024x576.jpg",640,360,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg",1280,720,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg",1280,720,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>As organisations continue to navigate the complexities of data protection laws, staying abreast of key deadlines is paramount. One such deadline relates to organisations&nbsp;involved in restricted transfers of personal data under UK data protection law. The ICO set a critical deadline for organisations that transfer personal data outside the UK. This article explains what you need to do to ensure compliance with the ICO&#8217;s directive and the UK GDPR. The deadline pertains to the validity of old EU standard contractual clauses (SCCs) issued by the European Commission under the previous Data Protection Directive (the old EU SCCs). Note that the&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/international-transfers\/\" rel=\"category tag\">International Transfers<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/uk-gdpr\/\" rel=\"category tag\">UK GDPR<\/a>","author_info":{"name":"Kezia Vilawa","url":"https:\/\/techgdpr.com\/blog\/author\/kezia\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg",1280,720,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-300x169.jpg",300,169,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-768x432.jpg",640,360,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-1024x576.jpg",640,360,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg",1280,720,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg",1280,720,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>As organisations continue to navigate the complexities of data protection laws, staying abreast of key deadlines is paramount. One such deadline relates to organisations&nbsp;involved in restricted transfers of personal data under UK data protection law. The ICO set a critical deadline for organisations that transfer personal data outside the UK. This article explains what you need to do to ensure compliance with the ICO&#8217;s directive and the UK GDPR. The deadline pertains to the validity of old EU standard contractual clauses (SCCs) issued by the European Commission under the previous Data Protection Directive (the old EU SCCs). Note that the&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/international-transfers\/\" rel=\"category tag\">International Transfers<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/uk-gdpr\/\" rel=\"category tag\">UK GDPR<\/a>","author_info_v2":{"name":"Kezia Vilawa","url":"https:\/\/techgdpr.com\/blog\/author\/kezia\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>UK Restricted Transfers: Standard data protection clauses by the ICO - TechGDPR<\/title>\n<meta name=\"description\" content=\"If your organisation relies on these SCCs for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"UK Restricted Transfers: Standard data protection clauses by the ICO - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"If your organisation relies on these SCCs for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-15T14:55:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-03-15T14:55:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kezia Vilawa\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kezia Vilawa\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/\"},\"author\":{\"name\":\"Kezia Vilawa\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/b4bc038d21ed7d7b59d2fb361fe10454\"},\"headline\":\"UK Restricted Transfers: Standard data protection clauses by the ICO\",\"datePublished\":\"2024-03-15T14:55:28+00:00\",\"dateModified\":\"2024-03-15T14:55:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/\"},\"wordCount\":826,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/brexit-3579600_1280-edited.jpg\",\"keywords\":[\"GDPR\",\"GDPR Compliance\",\"International transfers\",\"Restricted Transfers\",\"Standard data protection clauses\",\"UK data protection law\",\"UK GDPR\",\"UK IDTA\"],\"articleSection\":[\"International Transfers\",\"UK GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/\",\"name\":\"UK Restricted Transfers: Standard data protection clauses by the ICO - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/brexit-3579600_1280-edited.jpg\",\"datePublished\":\"2024-03-15T14:55:28+00:00\",\"dateModified\":\"2024-03-15T14:55:29+00:00\",\"description\":\"If your organisation relies on these SCCs for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/brexit-3579600_1280-edited.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/brexit-3579600_1280-edited.jpg\",\"width\":1280,\"height\":720},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/uk-restricted-transfers-standard-data-protection-clauses\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"UK Restricted Transfers: Standard data protection clauses by the ICO\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/b4bc038d21ed7d7b59d2fb361fe10454\",\"name\":\"Kezia Vilawa\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Kezia_OF_2076_700-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Kezia_OF_2076_700-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2024\\\/03\\\/Kezia_OF_2076_700-150x150.jpg\",\"caption\":\"Kezia Vilawa\"},\"description\":\"Kezia Vilawa (LL.M) is a Nigerian-trained Lawyer with a proven history of working in data protection and interested in real estate, corporate governance and administration. She is currently an Associate Consultant, having obtained a master\u2019s degree in Intellectual Property Law in Germany where she developed interest in the EU GDPR and data protection. Her work description spans across privacy contract negotiation, legal drafting for privacy and property transactions, regulatory compliance, the creation and maintenance of ROPA (Records of Data Processing Activities), data subject requests (DSR) handling, DPAs, data sharing agreements, GDPR training, reporting on current state of GDPR compliance. litigation, customer service and real estate agency.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/kezia-v-830473a9\\\/\"],\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/kezia\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"UK Restricted Transfers: Standard data protection clauses by the ICO - TechGDPR","description":"If your organisation relies on these SCCs for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/","og_locale":"en_US","og_type":"article","og_title":"UK Restricted Transfers: Standard data protection clauses by the ICO - TechGDPR","og_description":"If your organisation relies on these SCCs for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024","og_url":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/","og_site_name":"TechGDPR","article_published_time":"2024-03-15T14:55:28+00:00","article_modified_time":"2024-03-15T14:55:29+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg","type":"image\/jpeg"}],"author":"Kezia Vilawa","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Kezia Vilawa","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/"},"author":{"name":"Kezia Vilawa","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/b4bc038d21ed7d7b59d2fb361fe10454"},"headline":"UK Restricted Transfers: Standard data protection clauses by the ICO","datePublished":"2024-03-15T14:55:28+00:00","dateModified":"2024-03-15T14:55:29+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/"},"wordCount":826,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg","keywords":["GDPR","GDPR Compliance","International transfers","Restricted Transfers","Standard data protection clauses","UK data protection law","UK GDPR","UK IDTA"],"articleSection":["International Transfers","UK GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/","url":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/","name":"UK Restricted Transfers: Standard data protection clauses by the ICO - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg","datePublished":"2024-03-15T14:55:28+00:00","dateModified":"2024-03-15T14:55:29+00:00","description":"If your organisation relies on these SCCs for restricted transfers in the UK, they are no longer valid for restricted transfers after March 21, 2024","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/brexit-3579600_1280-edited.jpg","width":1280,"height":720},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/uk-restricted-transfers-standard-data-protection-clauses\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"UK Restricted Transfers: Standard data protection clauses by the ICO"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/b4bc038d21ed7d7b59d2fb361fe10454","name":"Kezia Vilawa","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Kezia_OF_2076_700-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Kezia_OF_2076_700-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/03\/Kezia_OF_2076_700-150x150.jpg","caption":"Kezia Vilawa"},"description":"Kezia Vilawa (LL.M) is a Nigerian-trained Lawyer with a proven history of working in data protection and interested in real estate, corporate governance and administration. She is currently an Associate Consultant, having obtained a master\u2019s degree in Intellectual Property Law in Germany where she developed interest in the EU GDPR and data protection. Her work description spans across privacy contract negotiation, legal drafting for privacy and property transactions, regulatory compliance, the creation and maintenance of ROPA (Records of Data Processing Activities), data subject requests (DSR) handling, DPAs, data sharing agreements, GDPR training, reporting on current state of GDPR compliance. litigation, customer service and real estate agency.","sameAs":["https:\/\/www.linkedin.com\/in\/kezia-v-830473a9\/"],"url":"https:\/\/techgdpr.com\/blog\/author\/kezia\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=8244"}],"version-history":[{"count":7,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8244\/revisions"}],"predecessor-version":[{"id":8256,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/8244\/revisions\/8256"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/8252"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=8244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=8244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=8244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}