← Back to Regulatory Updates

Regulatory Update • January 2026

ICO International Transfers Guidance Refresh

Published: 15 January 2026Topic: International TransfersSource: ICO

In January 2026 the Information Commissioner’s Office updated and expanded its guidance on international transfers of personal information.

The update introduces clearer explanations of restricted transfers, safeguards and transfer compliance expectations under the UK data protection framework.

Reading time 2 minutes

What changed

The ICO updated and expanded its guidance on international transfers, introducing a clearer approach to identifying restricted transfers and adding supporting material including FAQs and glossary content.

The refreshed guidance is intended to make the rules easier to understand and apply in practice, particularly for organisations that rely on overseas vendors, cloud services or international software providers.

What is a restricted transfer?

In simple terms, a restricted transfer happens when UK GDPR applies, you are sending or making personal information accessible to an organisation outside the UK, and that organisation is a separate legal entity.

Why this matters

International transfers remain one of the most misunderstood areas of UK data protection law. Many organisations use tools or suppliers located outside the UK without fully mapping where personal information is going or which safeguards apply. For a fuller explanation of how these rules work in practice, see our guide International Data Transfers Under UK GDPR Explained.

Organisations may also need to rely on specific safeguards such as Standard Contractual Clauses (SCCs) Explained Under UK GDPR, and may need to understand the wider range of safeguards and legal routes available in our guide UK GDPR Transfer Mechanisms Explained.

The updated guidance does not create an entirely new transfer regime, but it does make the regulator’s expectations clearer and gives organisations a useful opportunity to review existing arrangements. Organisations can also monitor future changes through the Regulatory Updates page.

What organisations should do

Organisations should consider taking the following steps to review whether any existing arrangements involve restricted transfers.

  • Review whether any overseas vendors receive personal data from the organisation.
  • Check whether those arrangements amount to restricted transfers under the updated ICO guidance.
  • Confirm which transfer mechanism is being relied upon, such as adequacy regulations or Article 46 safeguards.
  • Review existing transfer documentation to make sure terminology and internal records remain up to date.

Practical takeaway

For organisations using overseas vendors, cloud infrastructure or global software platforms, this update is a useful prompt to revisit transfer arrangements and confirm that safeguards and internal documentation remain aligned with current ICO guidance.

Grounded in

UK GDPR Articles 44 to 49, and ICO guidance on international transfers, restricted transfers, safeguards and related support material, updated January 2026.

Sources

Future Implementation Support Waitlist