Brexit & Personal Data Transfers, risk management starts today.

European comisson logo

I wrote last week, about the United Kingdom government wishing to leave the European Union & EEA (EU) with an arrangement that means the UK is deemed to have adequate data privacy safeguards in place that allow seamless EU cross border transfer.

I am happy to spell out in 2 blog postings the challenges and risks that UK & EU organisations face should Britain leave the EU and more worrying not been deemed as adequate.

An adequacy arrangement means that data can be transferred to Countries outside the EU & EEA without additional safeguards as laid down by article 46 of the GDPR. This currently works well in the case of 14 Countries who number include, Jersey, Isle of Man, Israel, New Zealand and the Faroe Islands.

The UK has recently introduced a Data Protection 2018 Act, which as a main plank of the legislations provides Data Protection safeguards such as the GDPR within it. So in essence done everything possible to go to the table with a strong set of laws.

However the EU have said that under current arrangements:

Personal data – Brexit preparedness:

Currently, personal data can flow freely between the Member States of the EU, when the GDPR (General Data Protection Regulation 2016/679) is respected. Once EU law ceases to apply to the United Kingdom, the transfer of personal data from the EU to the United Kingdom will still be possible, but it will be subject to specific conditions set in EU law.

Companies and Member States’ authorities that are currently transmitting personal data to the United Kingdom should therefore be aware that this will become a “transfer” of personal data to a third country, and explore if it could be permitted under relevant provisions of EU legislation.

If the United Kingdom’s level of personal data protection is essentially equivalent to that of the EU, the Commission would adopt an adequacy decision which allows for transfer of personal data to the United Kingdom without restrictions. However, this decision could only be taken once the United Kingdom becomes a third country.

Companies should therefore assess whether, in the absence of an adequacy decision, measures are necessary to ensure that these transfers remain possible. The Member States Data Protection Authorities should assist companies in this endeavour.

What the EU have not said that this also will apply to EU – U.K flows as well, so if you are Paris processing data in London start preparing.

The U.K have agreed a transition deal, subject to a deal being struck, which means that EU laws and trading arrangements will still be applicable up until 31.12.2020, so if the UK is deemed to be an adequate country then happy days, if not the work has only just begun.

So what happens if the UK is deemed an adequate country, is seen outside the GDPR/EU club for data protection law and UK based companies want to send data into the EU and vice versa?

In essence the UK will have the same status as 14 Countries soon to be 15 as Japan has been ratified in recent days. A 2- way transfer in and out of the EU requires additional safeguards and a lot of work, mainly for lawyers to ensure that we can trade data across these borders. Some already have these safeguards in place, however unlikely for most, as the UK is currently in the EU and there was no requirement to put these safeguards in place on the 25th May 2018.

Be warned in the EU paper there is a clear and present danger of the adequacy decision being made post BREXIT, that maybe a negotiating stance, but you would be foolish not to identify a period of transition from the UK status from member to, non member to adequate status as quite a risk.

There are 2 main requirements under GDPR that UK/EU organisations will have to undertake to ensure they can continue to trade.

  1. These being the putting in place additional safeguards subject to article 46 such as Binding Corporate Rules(Which take ages and there is a waiting list), New Contracts, New consent regimes or the development of an industry wide scheme or certification, if the latter is completed in time.
  2. In addition UK companies will have to appoint a representative within the EU to act on behalf of UK companies under article 27.

Therefore you should be identifying the potential risk of the UK leaving the EU and taking action now.

I shall cover the safeguards you need to put in place and the role of the EU representative in next week’s paper, however for now I trust you are already planning your next steps.

We at DPAS have both a UK & EU base and happy to support the preparing for transition that will be required to be able to transfer data across EU borders post BREXIT.

Nigel Gooding, Founder, Data Privacy Advisory Service

dpas.gsl.media

#gdpr #brexit #safegaurd #EU #EEA #dataprotection #dataprotectionact2018

related posts

Jack Penaligon

How to Respond to a Data Breach: A Practical Guide

This blog provides an overview of the practical steps organisations can take to reduce the impact of a data breach once it has been identified. It focuses on the actions that should be taken during the early stages of an incident to contain the breach, protect affected individuals, and meet regulatory requirements.

The article discusses a range of mitigation measures, including contacting unintended recipients of personal data, securing the deletion or recovery of exposed information, isolating compromised systems, and maintaining clear records of actions taken. It also explores the challenges posed by both digital and physical data breaches, highlighting the importance of balancing operational needs with data protection obligations.

Finally, the blog emphasises the value of preparation, explaining how established procedures, communication templates, and predefined response plans can help organisations respond more effectively and demonstrate accountability during a regulatory investigation.

Read More »
Noah de Wild

How to Assess a Data Breach: A Practical Guide

This blog explains how to assess a data breach by identifying its cause, determining what information was exposed, and evaluating the potential impact on affected individuals and the organisation. It outlines common causes of breaches, the importance of understanding the type and scale of compromised data, and how assessing the timeline of an incident can help businesses respond effectively, meet legal obligations, and reduce long-term risks.

Read More »
Noah de Wild

Don’t Panic: A Pragmatic Guide to the June 2026 Enforcement of the Data (Use and Access) Act Changes

With the June 19, 2026 enforcement of the Data (Use and Access) Act approaching, ensuring your business is compliant doesn’t have to be complicated or expensive. In our latest guide, we break down exactly what the new data protection complaint rules mean for you. Cut through the noise and discover our simple, free six-step checklist to update your protocols, designate handlers, and keep your business confidently compliant.

Read More »

Get a Free Consultation