Guides

Sending data abroad: the 'data protection test' explained

If your business uses cloud tools or suppliers based abroad, your data is travelling. New guidance from January 2026 introduces a clearer 'data protection test'. Here is what it means without the jargon.

TheDutyDesk Editorial19 January 20263 min readReviewed 7 June 2026

Almost every business sends personal data abroad without thinking of it that way. If you use a US cloud provider, an overseas email tool, or a supplier with staff in another country, your customers' and staff's data is crossing borders.

UK law has always asked you to make sure that data stays protected when it leaves the country. On 15 January 2026 the regulator published updated, consolidated guidance on how to do this, reflecting a new approach introduced by the Data (Use and Access) Act.[19] [1]

What the test asks

The new approach is often called the "data protection test".[1] In plain terms, before you send personal data to another country, you need reasonable confidence that the protection for that data will not be materially lower than it is here.

This is meant to be a sensible, outcome-focused judgement rather than a box-ticking exercise.[19] The question is practical: will people's data still be looked after to a comparable standard once it arrives?

Some destinations are already covered by an "adequacy" arrangement, which means the UK has decided they offer suitable protection and you can send data there freely. The EU is one example. For everywhere else, you rely on safeguards such as approved contract terms, and the data protection test is the judgement that sits behind them.[3]

Why this matters to smaller businesses

You do not need an international legal team to be affected. The moment you sign up to a tool that stores data outside the UK, you are making a transfer.

The good news is that most reputable providers have done much of the groundwork and can tell you where your data is held and what protections apply. Your job is to ask the question and keep the answer.

What this means for you

Start with a simple list: which of your tools and suppliers hold personal data, and where. That single list answers most transfer questions.

For anything based outside the UK, check whether the destination is covered by an adequacy arrangement or whether your provider relies on contract-based safeguards. If you cannot tell, ask the provider directly. Keeping their answer on file is usually enough to show you took the question seriously.

Sources used in this article

  • [19]ICO updated international transfers guidance, January 2026
  • [1]Data (Use and Access) Act 2025
  • [3]UK GDPR (retained EU regulation)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 19 July 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.