Almost every business sends personal data abroad without thinking of it that way. If you use a US cloud provider, an overseas email tool, or a supplier with staff in another country, your customers' and staff's data is crossing borders.
UK law has always asked you to make sure that data stays protected when it leaves the country. On 15 January 2026 the regulator published updated, consolidated guidance on how to do this, reflecting a new approach introduced by the Data (Use and Access) Act.[19] [1]
What the test asks
The new approach is often called the "data protection test".[1] In plain terms, before you send personal data to another country, you need reasonable confidence that the protection for that data will not be materially lower than it is here.
This is meant to be a sensible, outcome-focused judgement rather than a box-ticking exercise.[19] The question is practical: will people's data still be looked after to a comparable standard once it arrives?
Some destinations are already covered by an "adequacy" arrangement, which means the UK has decided they offer suitable protection and you can send data there freely. The EU is one example. For everywhere else, you rely on safeguards such as approved contract terms, and the data protection test is the judgement that sits behind them.[3]
Why this matters to smaller businesses
You do not need an international legal team to be affected. The moment you sign up to a tool that stores data outside the UK, you are making a transfer.
The good news is that most reputable providers have done much of the groundwork and can tell you where your data is held and what protections apply. Your job is to ask the question and keep the answer.
What this means for you
Start with a simple list: which of your tools and suppliers hold personal data, and where. That single list answers most transfer questions.
For anything based outside the UK, check whether the destination is covered by an adequacy arrangement or whether your provider relies on contract-based safeguards. If you cannot tell, ask the provider directly. Keeping their answer on file is usually enough to show you took the question seriously.