Preiskel & CoPreiskel & Co
Preiskel & Co
A boutique law firm in London
  • Home
  • About Us
    • Diversity, Social Responsibility, and Pro Bono
  • Services
    • Corporate
    • Commercial
    • Regulatory
    • Competition & Antitrust
    • Data Protection, Privacy, and Retention
    • Intellectual Property
    • Dispute Resolution
    • Employment
  • Sectors
    • Telecommunications
    • IT, Technology, & Internet
    • Media and Broadcasting
    • Websites, Blogging, & Social Media
    • Film & Television
    • Gambling & Online Gaming
    • Leisure & Retail
    • Energy & Minerals
    • Cryptocurrency & Blockchain
    • Creative Industries
  • People
    • Daniel Preiskel
    • Ronnie Preiskel
    • Tim Cowen
    • Jose Saras
    • Robert Dougans
    • Karthyaeni Vittala
    • Tina Cowen
    • Xavier Prida
    • Martina Raciti
    • Ewelina James
    • Rachael Machado
    • Maria Constantin
    • Peter Dally
    • Richard Stewart
    • Joanna Coombs-Huang
    • Paul Stelges
    • Hannah Leader
    • Alison MacFarlane
    • Ilanit Appelfeld
    • Daniel Oakland
    • Sophia Yakhno
    • Sue Warwick
    • D A T Green
    • Antony Corel
    • Stewart White
    • Mor Swiel
    • Stephen Hornsby
    • Tony Curzon-Price
    • Robert Harvey
    • Shardi Shameli
  • International
  • Blog
  • News
    • Publications
  • Contact
Menu back  

ICO reveals new transfer risk assessment tool

November 25, 2022By Preiskel & Co

The Information Commissioner’s Office (“ICO”) has revealed a revised guidance on international data transfers, including a new section on transfer risk assessments (“TRA”) and a TRA tool.

The UK GDPR contains rules about transfers of personal data to importers located outside the UK, which are referred to as restricted transfers. One way to comply with the UK GDPR rules on restricted transfers is to implement an Article 46 transfer mechanism. These are the so-called appropriate safeguards and examples include the ICO’s International Data Transfer Agreement (“IDTA”), the Addendum to the EU SCCs (the “Addendum”) and Binding Corporate Rules (“UK BCRs”).

The implementation of a TRA helps organisations ensure that, in specific circumstances of restricted transfers, the Article 46 transfer mechanism will provide adequate protections as well as effective and enforceable rights for people.

Alternative EDBD framework for international data transfers

As a result of the ruling in Schrems II which confirmed the role of risk assessments in the regulations on restricted transfers, the ICO requires TRAs to be implemented by companies intending to make a restricted transfer of personal data from the UK and to assist UK data exporters to make reasonable and proportionate TRAs in order to guarantee that appropriate protection is afforded to data subjects.

For instance, carrying out a risk assessment to confirm whether the personal data established by the UK data protection regime will be upheld in the jurisdiction where the data importer is located. Such analysis being in addition to implementing a legally enforceable data transfer safeguarding mechanism for data subjects under Article 46 of the UK GDPR (which includes using IDTAs or UK BCRs).

New TRA tool

The newly announced TRA tool is a template document comprised of six questions and provides direction to assist UK data exporters reach a preliminary risk level valuation for the relevant categories of data, and to determine whether the circumstances of their data transfer significantly increases the risk of either a privacy or other human rights breach.

If by using the TRA tool, an organisation finds that its Article 46 transfer mechanism will not provide appropriate safeguards and effective and enforceable data subject rights for all the personal data, then it must not make the restricted transfer. The tool accordingly also helps identify any additional steps and extra protections that need to be implemented in order for the overall international transfer mechanism to be compliant.

Further guidance from the ICO on how to implement IDTAs and the Addendum to the SCCs is expected to be revealed in the coming months.

 

Please contact Jose Saras and Xavier Prida if you have any questions about international data transfer mechanisms and risk assessments.

The material in this article is only for general review of the topics covered and does not constitute legal advice. No legal or business decision should be based on its content.

Latest Preiskel & Co blog posts
  • CMA AI Report: The Foundation of the UK’s AI Response
    September 21, 2023
  • Navigating Health Data Compliance: A Roadmap for Employers
    September 21, 2023
  • Transatlantic convergence? Recent cases on advertising and privacy from the USA and UK
    September 15, 2023
  • Practical Guide – Net Neutrality in the UK
    September 14, 2023
  • Virgin succeeded in defending a claim by EE for loss of EE’s profits caused by Virgin’s breach of the MVNO Exclusivity Clause
    September 12, 2023
  • Getting out of a (data) scrape: global statement published for the protection of publicly accessible personal data online
    September 8, 2023
  • The dark side of design: the ICO and CMA call for businesses to rethink their website layouts
    August 18, 2023
  • Could the Supreme Court’s ruling on litigation funding agreements cause havoc for litigation funders?
    August 17, 2023
  • US Threats of a ‘Te(ch)xodus’ from the UK?
    August 17, 2023
  • Smoother Sailing for EU-US Data Transfers after GDPR Adequacy Decision
    August 4, 2023
  • Unlocking Data Flows: EU-US Data Privacy Framework Receives Adequacy Decision
    July 13, 2023
  • UK’s World Leading Approach on Artificial Intelligence – White Paper outlines 5 guideline principles for responsible use of AI
    July 5, 2023

The Preiskel Blog

  • CMA AI Report: The Foundation of the UK’s AI Response 21 Sep 2023
  • Navigating Health Data Compliance: A Roadmap for Employers 21 Sep 2023
  • Transatlantic convergence? Recent cases on advertising and privacy from the USA and UK 15 Sep 2023
  • Practical Guide – Net Neutrality in the UK 14 Sep 2023

Preiskel news

  • Practical Guide – Net Neutrality in the UK
  • Danny Preiskel featured in GCCM Magazine (June/July 2023 issue 55)  
  • Danny Preiskel moderating a panel at the MEF Connects – The Future of Fraud Prevention event (5th September 2023, hybrid)
  • Preiskel & Co advised TMT Analysis on the acquisition of Phronesis Technologies
Preiskel & Co LLP
4 King's Bench Walk,
Temple,
London
EC4Y 7DL
United Kingdom

Tel: +44 20 7332 5640
Email: info@preiskel.com

Find us on:

TwitterLinkedinMail
© Preiskel & Co LLP 2023 | Site map | Legal notices | Cookie Policy | Privacy