Info Gov

The Information Commissioner’s Office has launched a new interactive self‑service tool designed to help organisations determine whether their cross-border data sharing arrangements constitute a restricted transfer under the UK GDPR.

The tool, now live on the ICO website, offers tailored guidance for organisations “short on time and need[ing] a helping hand”, providing an indication of how the legislation is likely to apply to a specific transfer scenario. According to the ICO, the tool is based on its established three‑part test, which assesses:

  • whether the UK GDPR applies to the information;
  • whether the data is being sent to an organisation outside the UK; and
  • whether that organisation is a separate legal entity.

Users are asked up to six questions, with the ICO stating that the process “only takes about ten minutes”. While the results are not definitive, the regulator says the tool provides “a reliable indication of how the legislation is likely to apply”, emphasising that controllers remain responsible for ensuring compliance with UK data protection law.

For public bodies, the tool is most likely to assist in procurement, contract management and digital transformation programmes where public sector organisations routinely engage with cloudbased HR and finance systems, international software vendors, global research partners, outsourced service providers or crossborder dataprocessing arrangements 

The tool’s structured questions can help information governance teams and procurement leads:

- identify when a transfer assessment is required 

- flag when a vendor relationship involves a restricted transfer 

- support earlystage risk assessments 

- reduce delays caused by uncertainty 

- provide consistent internal advice 

The ICO has clarified that the tool is not designed for processing carried out for law enforcement purposes under Part 3 of the Data Protection Act 2018, where different rules apply.

Also in this section

May 26, 2026

Key Data Protection Issues for Automated Recruitment in the Public Sector

The need to recruit faster in a competitive market, the need to minimise costs in the recruitment process, and the need to secure the best candidate quickly, makes the use of AI an appealing option for any employer including public bodies. But there are pitfalls for the unwary write David Leach and Charlotte Smith.
May 08, 2026

Schools warned over AI blackmail threat as guidance urges rethink on pupil images

Schools across the UK are being urged to review or remove identifiable photographs of pupils from their websites and social media accounts, following warnings that criminals are using artificial intelligence tools to manipulate those images into child sexual abuse material (CSAM) and then threaten to release it unless a ransom is paid.
Apr 28, 2026

AI in Education: Why Data Protection Must Come First

Artificial Intelligence promises a lot. It can undoubtedly do amazing things. But secretly (or maybe not so secretly), it also makes us slightly nervous. Adam Halsey looks at what this means for schools, and why data protection needs to sit at the centre of any decision to use AI.
Apr 22, 2026

Preparing for the new complaints regime

From 19 June 2026, all organisations acting as data controllers are required to have in place an effective process to enable individuals to raise complaints about how their personal data is handled. Ashleigh Dibb looks at what this will mean in practice.
Apr 17, 2026

When data protection doesn’t protect you

Recently, the Information Commissioner’s Office published the outcome of a criminal prosecution. The title? Just two names: Christopher Munro and William Chipoma. No explanation. No softening. No anonymity. And that, in itself, is a powerful lesson in how data protection law really works.

InfoGov Masthead Newsletter 800