Skip to main content
Open call for evidence

Data flows you can trust

Published 15 July 2026

This work will help us to shape how data is used so that we can maximise its potential, drive growth and improve lives across the UK. This Call for Evidence seeks practical, experience-based insight into whether the UK’s data regime is enabling data flows you can trust. We want to understand: does the UK’s approach to international data transfers achieve this as effectively as it can do? Where should we preserve the current system, and what parts of it are most suitable for reform? 

Introduction

How data is handled matters. It matters because data about you represents information that is often deeply personal, and how it is treated is important. For organisations, data is a critical operational and strategic asset. It underpins day-to-day business activity, enables firms to operate across borders, and supports innovation, investment, and growth. Trust in how data is handled is therefore essential to enabling organisations to use data confidently and responsibly. And taken across the UK, it matters because data represents a strategic national asset of significance to both our prosperity and security. The potential benefits are huge, with data flows now contributing more to economic growth globally than trade in goods.

We want to understand how we can most effectively manage international data transfers. Our commitment to high standards of data protection, and to maintaining trust in the UK’s data regime, remains fundamental. That trust depends not only on the existence of rules, but on whether those rules are meaningful in practice, and that they are understood, effective, enforceable, and targeted at the emerging risks that matter most. This Call for Evidence is intended to ensure we are hearing directly from those using the system in practice, so that it remains effective and fit for the future, including where new services powered by technologies like AI rely on data flowing securely across borders to deliver reliable, personalised experiences for people.  

For individuals, international data flows also bring clear benefits. They make it easier to access services, connect with others, and participate in a global digital economy. Most people rely on these flows every day, often without noticing them. Therefore, when data leaves the UK, it is right to ask whether the protections that travel with it are genuinely effective in practice and whether they are proportionate to the risks involved. It is also right to consider how international data transfers interact with the UK’s broader interests in security and resilience.

International data flows already deliver significant benefits for the UK economy and for people’s everyday lives. Moreover, the UK’s international data transfer regime is a strong foundation for trusted global data flows. It supports high standards of data protection while enabling the secure movement of data that underpins modern services, research, trade, innovation and public safety. The Government has chosen to examine these themes now to ensure this continues in a changing context, including a fast-evolving threat and technology landscape, as recently set out by the Director of GCHQ.

The pace and frequency of international data transfers have also grown over recent years, with organisations increasingly relying on global cloud services and distributed data infrastructures, often involving multiple jurisdictions simultaneously. At the same time, data is a critical input to the development and deployment of AI systems and other data intensive technologies, making international data flows central to the UK’s ambitions for innovation and growth. Recent reforms to the international transfers statutory framework through the Data (Use and Access) Act 2025 have also created an opportunity to examine how the current toolkit is functioning in practice, particularly as data use becomes more complex, global, and dynamic.

This includes examining whether existing tools for governing international data transfers support clear, effective, and trusted data flows in practice, and whether safeguards remain responsive and proportionate to an evolving threat and technology landscape. We are interested in how organisations make decisions and manage risk in real-world settings; how regulatory tools and mechanisms influence behaviour; and what more may be needed to instil trust and confidence in the use of data, while maintaining robust protections, a resilient UK data infrastructure and enabling economic opportunity.

This Call for Evidence should also be read alongside the Government’s Call for Evidence on Data regulation in the age of AI and Data-Intensive Technologies and the Marginal Cost Restriction on Public Sector Data Re-use in the domestic context, which relates to how personal and non-personal data regulation operates in practice, including: the UK GDPR and relevant provisions of the Data Protection Act 2018, including Part 3. Together, these exercises form part of a coordinated effort to understand how the UK GDPR and wider data framework operate across different use cases and sectors. Respondents may wish to consider both Calls for Evidence to reflect the full scope of the Government’s thinking on the future of data regulation in an AI-enabled economy.

You may also be aware of recent work by the Information Commissioner’s Office (ICO) on international data transfers, including updated guidance published in January 2026.2 This Call for Evidence is distinct in scope and purpose. It is not consulting on specific policy proposals or assessing the implementation of existing guidance. Instead, it is an open invitation to share evidence and real-world experience to inform future policy development. We will use the evidence gathered through this exercise to better understand how the current framework operates in practice and to inform consideration of any future policy options. 

Any future UK policy announcements will take into consideration the importance of maintaining frictionless data flows with all international partners, including UK-EU data flows. This Call for Evidence aims to build a clear evidence base on what works well, where organisations experience challenges or constraints, and where targeted improvements, guidance, or systematic adjustments may be needed.

References to international data transfers should be understood broadly. This includes not only situations where data is actively transferred to another country, but also “transfer by access”, where personal data remains in the UK but is accessed from overseas. For example, where data is hosted in the UK but accessed remotely by a user located abroad, this may still constitute an international transfer. In responding, you may therefore wish to consider all such scenarios, including where data is accessed rather than physically moved.

What we are asking for

We are seeking evidence from organisations and individuals with an interest or experience in international data transfers to understand how international data transfer rules operate in real world settings. We would welcome inputs both from those involved in the technical detail of data transfers, such as Data Protection Officers and lawyers involved in data transfers, as well as those involved in wider organisational decision making and how international data transfers impact their business models, such as founders, CEOs, CTOs, CFOs and strategy teams.

We would also welcome inputs from interested individuals, academics, think tanks, advocacy groups, and organisations in the third sector. At its heart, international data transfers affect both UK organisations and people. While some detailed aspects of the regulatory framework will be most relevant to specialists, everyone has a stake in how data is used and protected. We are therefore taking an approach to engagement that, alongside this Call for Evidence, aims to hear from a wide range of perspectives in ways that allow different audiences to respond meaningfully.

We are interested in how current tools and approaches influence decision making, whether the framework supports both usability and trust in practice, and how it interacts with evolving technologies, security considerations, and international data use. We are also interested in how international data flows influence the UK’s resilience and technological sovereignty. You may respond to as many or as few themes as are relevant to your experience. But we will particularly welcome:

  • short case studies or worked examples
  • descriptions of governance or decision-making processes (what you do in practice)
  • operational detail on implementation (technical, organisational, contractual, or otherwise); and
  • any existing analysis, data, research, or evaluations you can share (including unpublished material)

How this call for evidence is structured

This call for evidence is organised around four themes. Each theme includes:

  1. a short description of what we are seeking evidence on;
  2. prompt question(s) to help structure responses; and
  3. a list of areas where we are particularly interested in evidence (to help you decide what to include).

You are free to submit evidence in the way that works best for you. You can respond to as many or as few themes as are relevant to your experience. If you only have evidence on one theme, a focused response is welcome.

How to respond

This Call for Evidence is open from 15 July 2026 and will close at 11:59pm on 9 September 2026.

To help us analyse the responses, please use the online system wherever possible and ensure you have submitted your response before exiting the question.

Submit your online responses

If you are not able to submit responses using the online form, please contact dataflowscallforevidence@dsit.gov.uk for alternative ways to contribute.

In exceptional circumstances, if you need to submit a hard copy, please contact us at dataflowscallforevidence@dsit.gov.uk and we will advise how to do this. Should you require another format (e.g. braille or large font) please contact alt.formats@dsit.gov.uk.  

About you / your organisation (for context)

This section asks a small number of background questions to help us interpret evidence. You can skip any questions that are not relevant.

1. Are you responding as?

  • an individual
  • on behalf of an organisation

2. Name or organisation name (if responding on behalf of an organisation)

3. Organisation size (if applicable)

  • Sole trader (No employees)
  • Micro (1 to 9 employees)
  • Small (10 to 49 employees)
  • Medium (50 to 249 employees)
  • Large (250+ employees)
  • Don’t know/Prefer not to say

4. Sectors you operate in (if applicable)

  • Accommodation and food service activities
  • Administrative and support service activities
  • Agriculture, Forestry and Fishing
  • Arts, entertainment and recreation
  • Education
  • Financial and insurance activities
  • Human health and social work activities
  • Information and communication
  • Professional, scientific and technical activities
  • Public administration and defence
  • Wholesale and retail trade
  • Other (Please specify)
  • Don’t know/Prefer not to say

5. Are you content for your response to be attributed to you in any published summary?

  • yes, I’m happy for my content to be published, and attributed to my organisation or me
  • yes, I’m happy for my content to be published, but please anonymise it
  • no, do not include my content in published summaries

6. May we contact you to follow up on the points in your response in more detail?

  • yes
  • no

If yes, please provide a contact email:

Themes

Theme 1: awareness and behaviour around international transfers

We want to understand the various approaches to international data transfers in practice. This may include what drives decision‑making about why data is transferred internationally, what tools are used and how user friendly they are. We are also keen to understand how interested and aware individuals are in where data about them is transferred to, how this data is used, and how it might be used in a way that might cause harm.

Evidence suggests that UK organisations transfer data internationally most commonly to work with clients, consumers and third parties in the European Union (EU) and the United States.[footnote 1] For transfers involving personal data, adequacy decisions and standard contractual clauses are the most common legal safeguards. Among those that send personal data outside of the UK and said they have formal legal safeguards or policies in place, 31% reported using adequacy decisions and 43% reported using EU standard contractual clauses with the Addendum.

For Government to be able to make informed policy decisions, we would like to better understand how the full range of tools work, and whether behaviour matches the intention behind the development of these transfer tools.

The questions below are to help prompt thinking on this theme:

  • How well do you understand where data goes when it leaves the UK?
  • What tools do you use to transfer and protect personal data when it leaves the UK?

While you are free to submit any evidence pertaining to this theme, we are particularly interested in evidence relating to:

  • Whether protections for data subject rights are accessible and are effective in practice
  • Your awareness of which countries and international organisations personal data is transferred to (and the likelihood of onward transfers)
  • How you track which countries and international organisations you have shared data with and how you ensure this remains up to date
  • How well you understand which legal jurisdiction the data you hold is subject to once it is transferred internationally
  • How you maintain oversight of what happens to the data once it has been transferred
  • Which transfer tools you routinely use, and how easy they are to apply in practice[footnote 2]
  • What concerns you might have about how data transferred overseas is used
  • The frequency with which you rely upon derogations, and for what sort of transfers
  • Where international transfer requirements affect technical, commercial, or operational decisions, such as timing, location of processing or choice of supplier
  • How you navigate the framework of international data protection requirements across multi-jurisdictional supply chains
  • Whether AI systems and other data intensive technologies affect your choice of transfer mechanism or your approach to managing international data transfers
  • What factors or tools give you the most confidence that data transferred internationally is protected, including the onward transfer of personal data
  • How your approach to data sharing internationally varies across different categories of personal data, how differences in sensitivity, potential harm, or risk influence those approaches
  • How the use of distributed cloud infrastructure impacts your knowledge of where data is transferred to and the risks that might result
  • Measures you / your organisation takes to ensure the data you hold is secure when being transferred across borders

Theme 2: understanding and use of international transfer mechanisms

The UK’s international data transfer regime aims to make it possible for personal data to move across borders safely and responsibly. While international data flows support everyday services, innovation, and economic activity, the framework is designed to ensure that people’s data continues to be protected when it is transferred overseas. This means ensuring that appropriate safeguards are in place so that standards of protection are not materially reduced once data leaves the UK.

Adequacy decisions allow for personal data to be transferred from the UK to another country or international organisation without additional transfer mechanisms being set up by an organisation. Adequacy decisions involve the UK Government doing detailed assessments of a country’s laws, practices and culture, to establish how well protected personal data will be when sent to that country. We want to understand whether and how adequacy influences real‑world behaviour.

When data is transferred to countries without UK adequacy, alternative transfer mechanisms may be used, with a completed Transfer Risk Assessment to help ensure that the standard of protection for people’s information is “not materially lower” after it is transferred. These mechanisms include – but are not limited to - Standard Data Protection Clauses (UK IDTA/Addendum), Binding Corporate Rules, and instruments or arrangements between public bodies.

Evidence suggests that those familiar with data adequacy decisions value them for streamlining international data transfers, reducing due diligence requirements, and providing confidence in compliance when transferring data to UK adequate countries. [footnote 3] In 2025 to 2026, 79% of businesses that sent personal data outside of the UK said they were confident that they knew which legal safeguards (transfer mechanisms) to use when transferring personal data outside the UK.[footnote 4]

The questions below are to help prompt thinking on this theme:

  • How effective and proportionate are the compliance requirements for existing international data transfer mechanisms?

While you are free to submit any evidence pertaining to this theme, we are particularly interested in evidence relating to:

  • Awareness and use of UK adequacy decisions for specific countries.
  • Any challenges when understanding the scope of adequacy decisions/arrangements and whether Government or the ICO could provide greater clarity
  • How adequacy affects your approach to international transfers, including whether the absence of an adequacy decision affects whether, how or where you transfer personal data
  • How adequacy decisions affect costs, operational complexity, risk management, and confidence in compliance compared with other transfer tools (such as Standard Data Protection Clauses or Binding Corporate Rules, etc.)
  • Any barriers, concerns or risks associated with how the UK’s data transfers framework supports or does not support new and emerging technologies, such as cloud, AI, and future tech
  • Which countries you do business with, or would like to do business with, where you find current transfer rules a barrier
  • How adequacy decisions affect your confidence in the protections for data transferred internationally, compared to alternative transfer mechanisms
  • Whether “partial” adequacy would be helpful for more countries where “full” adequacy might not be possible, and whether there would be drawbacks. For example, the UK Government could consider adequacy decisions for specific sectors within a country, or adequacy with additional conditions for specific types of data
  • Any barriers, concerns or risks associated with how the UK’s data transfer framework supports or doesn’t support any international data flows to foreign governments or public sector organisations
  • Whether amendments to existing alternative transfer mechanisms, or new mechanisms, would be helpful, and what specific challenges they should address
  • What you see as the key opportunities and risks of using any kind of certification scheme as a mechanism to facilitate international data transfers[footnote 5]
  • Whether the use of any kind of certification scheme would increase individuals’ confidence in how an organisation handles personal data

Theme 3: balancing compliance with accountability

The current international transfers regime, as set out in the UK’s data protection framework, requires organisations transferring personal data to countries without an adequacy decision to assess risks and put in place appropriate safeguards before data is transferred. For international data transfers, UK organisations need to ensure the data protection test is met – in some cases they may need to complete a Transfer Risk Assessment (TRA), which covers elements of a third country’s legal and regulatory regime, as well as risks to people’s rights from third party access to the data. We want to understand how organisations manage risk in practice, including how they approach upfront compliance risks as part of their overall decision making.

Evidence suggests that UK organisations value TRAs for helping them identify risks when transferring data overseas and reviewing their own compliance procedures. Some use the ICO’s TRA tool directly, while others have developed their own assessments or adapted the ICO’s template.[footnote 6] We want to understand whether the requirement to undertake a data protection test – which is set out under data protection legislation – is still the most proportionate approach to supporting individuals’ right to privacy when data is transferred internationally.

Businesses have previously shared that the perceived advantages include enhanced data security, easier regulatory compliance, and potential local competitive benefits. However, disadvantages highlighted include increased operational costs, limitations on collaboration, and constraints on international business development.[footnote 7] Taking a broader look at international data flows, other countries around the world are beginning to consider restrictions on data flows, both personal and non-personal, for economic reasons as well as security and privacy concerns. These approaches bring trade-offs with them.

The questions below are to help prompt thinking on this theme:

  • How can UK organisations be better supported when making international data transfers?
  • Do current international data transfer requirements reflect the level of risk in practice, and how, if at all, do organisations apply them differently across transfers they consider to be lower or higher risk?
  • What factors do you consider when determining whether somewhere is high or low risk?
  • Does the current adequacy/data protection test help to distinguish between high and low risk destinations and if not, why not?

While you are free to submit any evidence pertaining to this theme, we are particularly interested in evidence relating to:

  • How you manage the differentiation between the contractual and physical location of data in international transfers
  • How your budget decisions and prioritisation of work are affected by enforcement of data protection standards, and the risk of non-compliance
  • How well current pre-transfer requirements (such as Transfer Risk Assessments) support the effective protection of individuals’ privacy in practice, and where they could be strengthened or streamlined
  • How you go about getting information for a Transfer Risk Assessment, what aspects of completing them are most challenging to get information on
  • How organisations currently assess and manage transfer related risks across different destination countries, particularly “non-adequate” countries, and how this shapes your approach to accountability and ongoing oversight once data is transferred
  • Whether you see any opportunities or risks associated with more tightly managed controls of UK data sets, including for security or wider UK benefit. If so, which types of data or datasets might be most relevant

Theme 4: ensuring trust in the face of a changing world

Keeping data protected as it moves across borders matters not only for organisations, but for people. Secure international data flows support public safety, reliable digital services, global health research, crisis response, and environmental monitoring, while helping maintain public confidence that data about them is handled responsibly.

As technology evolves, so do the threats and risks facing it. Whilst the current international transfers regime has strong safeguards and protections in place, we want to understand whether these remain responsive to an evolving threat and technology landscape, and to ensure that people continue to trust that their data is protected wherever in the world it is.

Evidence suggests that UK organisations perceive data to be at most risk when it is sensitive and could cause harm if mishandled. To mitigate these risks, some organisations use a range of security measures when transferring data internationally. Examples of this might include encryption, two-factor authentication, Virtual Private Networks (VPNs), and secure file transfer protocols, alongside contractual arrangements.[footnote 8]

Countries around the world are also being confronted with questions of economic security and supply chain resilience when it comes to international data flows. For sensitive data, there are questions around the legal, technical, contractual, governance, or infrastructure controls on that data.

The questions below are to help prompt thinking on this theme:

  • What security and privacy protections do you currently use to ensure your data is safe?
  • As technology and threats evolve, are existing data transfer mechanisms sufficient to uphold levels of protection when personal data is transferred overseas?
  • If not, what further protections do you think might be needed?

While you are free to submit any evidence pertaining to this theme, we are particularly interested in evidence relating to:

  • What level of confidence and trust do you or your organisation have in the security of your data flows? What is your rationale for this level of confidence, and what suggestions do you have for improvement?
  • How important is data security to you or your organisation compared with other considerations, such as cost, speed, innovation or service quality?
  • What level of understanding you have of potential risks to your data
  • What behaviours and actions you take to mitigate those risks. For example, local hosting solutions or greater use of encryption etc.
  • How important regulatory enforcement and compliance are in incentivising your organisation to comply with data protection requirements
  • How your organisation assesses and maintains awareness/knowledge over onward transfers of the data you hold to third countries, from a security perspective
  • Whether there would be merits or risks in a more explicit position from the Government on the ‘sovereignty’ of UK data. Whilst the term ‘data sovereignty’ can mean a range of things, it is generally understood as the level of control and access organisations and governments have over their data. This can include – but is not limited to – legal, technical, contractual, governance, or infrastructure
  • Any requests you encounter from public authorities in other countries to access data that you hold, either in the UK or when stored abroad
  • How much importance you put on security measures, such as encryption, in ensuring that personal data is protected, and what security measures you use most regularly

References

  1. UK Business Data Survey 2024 (DSIT). Research based on in-depth interviews with businesses on international data protection 

  2. Detail on alternative transfer mechanisms 

  3. UK Business Data Survey 2024 (DSIT): Research based on in-depth interviews with businesses covering international data protection - UKBDS 2024 International data transfer qualitative research findings 

  4. The UK Business Data Survey 2026 Official Statistics, DSIT - UK Business Data Survey 2026 

  5. Certification mechanisms may include CBPR or Europrivacy. 

  6. Phase 2 Evaluation of the implementation of International Data Transfer Agreements (2025) – research findings - Phase 2 Evaluation of the implementation of IDTAs - Research Findings 

  7. UK Business Data Survey 2024, (DSIT): Research based on in-depth interviews with businesses on international data protection - UKBDS 2024 International data transfer qualitative research findings - GOV.UK 

  8. UK Business Data Survey 2024, (DSIT): Research based on in-depth interviews with businesses covering international data protection - UKBDS 2024 International data transfer qualitative research findings - GOV.UK