Data transfers outside the EU: EDPB vs ICO — essential equivalence or risk test?
On 15 Jan 2026, the ICO introduced a simplified three‑step test and TRA, diverging from the EDPB/CNPD’s ‘essential equivalence’ plus supplementary measures approach. Bottom line: distinct compliance tracks for EU vs UK transfers.
Executive summary. On 15 January 2026, the ICO overhauled its “International transfers” guidance with a three‑step test and a simplified TRA aligned to the Data (Use and Access) Act 2025. This diverges from the EDPB/CNPD’s ‘essential equivalence’ approach requiring supplementary measures (since 2021). Bottom line: dual compliance tracks depending on transfer origin (EU vs UK).
The case
On 15/01/2026, the UK Information Commissioner’s Office published a substantial update to “International transfers”, including a three‑step test to qualify a restricted transfer and a revamped Transfer Risk Assessment (TRA) aligned with the Act’s “data protection test”. The ICO emphasizes operational clarity, an interactive tool, and additional use cases. See “Updated guidance on international transfers” (ICO, 15/01/2026) and the sections “A guide to international transfers”, “Appropriate safeguards” and “Completing a transfer risk assessment”. Sources: ICO, 15/01/2026: A brief guide; A guide; Appropriate safeguards; Completing a TRA; News. (ico.org.uk)
In the EU, the EDPB has since 18/06/2021 maintained Recommendations 01/2020 on “measures that supplement transfer tools”, rooted in Schrems II, requiring verification that third‑country protection is “essentially equivalent” to the GDPR standard, with supplementary measures where needed (technical, contractual, organisational). Source: EDPB, Recommendations 01/2020. (edpb.europa.eu)
In Luxembourg, the CNPD updated its “International transfers” guidance on 18/04/2025, explicitly referring to Recommendations 01/2020 (six‑step approach, EU‑style TIA/TRA), the 2021/914 SCCs and BCR/certifications as Article 46 GDPR tools. Sources: CNPD, 18/04/2025; EUR‑Lex: Decision (EU) 2021/914. (cnpd.public.lu)
Legal reasoning
EU framework (EDPB/CNPD)
- GDPR Articles 44–49: third‑country transfers are lawful only with an adequacy decision (Art. 45), appropriate safeguards (Art. 46: 2021/914 SCCs, Art. 47 BCRs, Art. 46(2)(e)-(f) code/certification), or limited derogations (Art. 49). Accountability lies with the controller (Arts. 5(2), 24). (cnpd.public.lu). For a refresher on Chapter V, see the GDPR provisions.
- EDPB Recommendations 01/2020 (18/06/2021): a six‑step transfer impact assessment and “essential equivalence” requirement; where third‑country law/practice undermines SCCs/BCRs, exporters must add supplementary measures (e.g., strong encryption with EU‑based key management, importer‑side irreversible pseudonymisation). (edpb.europa.eu)
- 2021/914 SCCs (European Commission): modular clauses, exporter assessment duties, and obligations to notify/suspend where third‑country laws/practices prevent compliance. (eur-lex.europa.eu)
- CNPD (18/04/2025): endorses the EDPB six‑step grid, and stresses that exporters must demonstrate the chosen safeguard and its effectiveness; mentions BCRs and certification (see EDPB 07/2022; Europrivacy usable as an Art. 46 guarantee). (cnpd.public.lu)
UK framework (ICO)
- UK GDPR + Data (Use and Access) Act 2025: the ICO formalises a three‑step test to qualify a restricted transfer and a TRA assessing whether protection after transfer is not “materially lower” than the UK standard; tools include the IDTA/Addendum, UK BCRs, and exceptions. (ico.org.uk)
- Practical guide “Completing a TRA” (15/01/2026): the ICO accepts some government analyses (e.g., US) and offers interactive tools. (ico.org.uk)
The key divergence
- EDPB/CNPD: high bar of “essential equivalence” (Schrems II) and focus on the real‑world effects of third‑country law/practice on SCC/BCR performance — often requiring strong technical measures. (edpb.europa.eu)
- ICO: a more risk‑based, operational approach: if the protection is not “materially lower”, the IDTA/Addendum plus a documented TRA suffice — with checklists and use cases. (ico.org.uk)
What this changes in practice
- Luxembourg groups with UK/US/Asia affiliates:
- If exporting from the EEA/Luxembourg: apply the EDPB/CNPD approach. 2021/914 SCCs + six‑step TIA remain the norm absent adequacy, with supplementary measures where needed (e.g., exporter‑side encryption, key segregation, logical split, public access‑request logs). (eur-lex.europa.eu). To anchor CNPD compliance in Luxembourg, harmonise contract templates and TIA evidence.
- If exporting from the UK: the IDTA/Addendum + ICO TRA may suffice under the “not materially lower” standard. Caution: once the same data flow back to the EU or are co‑processed by an EU entity, “essential equivalence” applies. Anticipate dual‑track TIAs (EU/UK) for the same flow. (ico.org.uk)
- Global SaaS and support: For EU contracts, use the right SCC modules (C2P, P2P, etc.), assess hosting/support laws, and document feasibility of technical measures (E2EE, BYOK/HYOK, segregation). In the UK, add the UK Addendum to EU SCCs, but this does not displace the EDPB analysis for EU‑originating data. (eur-lex.europa.eu)
- BCRs and certification: For complex intra‑group flows, BCRs (Art. 47) remain robust in the EU; in Luxembourg, the CNPD details the procedure and fee (EUR 1,500). Certification can serve as an Art. 46 tool if approved (EDPB 07/2022; Europrivacy now usable). (cnpd.public.lu)
- Mapping and governance: Maintain a transfer register clearly separating “EU flows” and “UK flows”, the legal bases (EU Arts. 46/49 vs UK adequacy/safeguards), and the associated TIA/TRA documentation. In CNPD audits, you must justify “supplementary measures” for higher‑risk third countries per EDPB 01/2020. To structure this, consider an external DPO mandate to systematise governance and evidence.
Common pitfalls
- Confusing ICO TRA with EDPB TIA. A UK‑style TRA is not sufficient for transfers originating in the EU/LU: the CNPD expects the EDPB six‑step grid and a demonstration of “essential equivalence” plus supplementary measures where needed. (cnpd.public.lu)
- Overlooking onward transfers. The 2021/914 SCCs require suspension/adaptation where laws/practices impede compliance; anticipate downstream processors and support chains. (eur-lex.europa.eu)
- Relying on clauses alone. Without a serious assessment of third‑country law/practice, SCCs are insufficient. Add robust technical measures and verify effectiveness (keys, telemetry, hardening). (edpb.europa.eu)
- Mixing frameworks. The IDTA/Addendum and the “not materially lower” concept apply to UK exports; EU/LU exports remain under the EDPB line. Document dual tracks if you operate from both the EU and the UK. (ico.org.uk)
- Ignoring new tools. Certification (Arts. 42/46) is now practical: the Europrivacy seal can serve as a transfer guarantee; integrate it alongside SCCs/BCRs. (cnpd.public.lu)
Official sources
- ICO (15 January 2026) — Updated guidance on international transfers; A brief guide; A guide; Appropriate safeguards; Completing a TRA; What are standard data protection clauses (the UK IDTA and the Addendum?). https://ico.org.uk/…
- EDPB — Recommendations 01/2020 on measures that supplement transfer tools (final, 18/06/2021). https://www.edpb.europa.eu/…
- European Commission — Implementing Decision (EU) 2021/914 of 04/06/2021 (Standard Contractual Clauses). https://eur-lex.europa.eu/…
- CNPD Luxembourg — Dossiers and updates “International transfers” (18/04/2025, upd. 05/06/2025); April 2026 news on certification (Europrivacy). https://cnpd.public.lu/…
- EDPB — Guidelines 05/2021 on Article 3 and Chapter V (definition of ‘transfer’). https://www.edpb.europa.eu/…
Practical note (Aug 2026)
If your flows involve both the UK and the EU, build “dual‑compliance” matrices (EDPB/CNPD vs ICO) and set your internal standard at the higher bar (EDPB 01/2020 + 2021/914 SCCs + supplementary measures) to avoid CNPD audit blind spots. Need operational guidance? Reach us via contact.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →