Chapter V governs personal data leaving the UK or the EEA. Most transfers happen without anyone sending a file, which is why the first job is noticing them.
Chapter V restricts personal data going to a third country or international organisation. The structure is straightforward: a transfer needs either an adequacy decision, or an appropriate safeguard, or an exception. What makes it difficult in practice is noticing that a transfer is happening at all.
Recognising a restricted transfer
The intuition that a transfer means sending a file abroad is wrong and causes most of the gaps. Data can be hosted in the UK and still be transferred, because access from outside counts.
- A supplier's support team viewing your tenant from another country.
- An engineer with production access based abroad.
- Backups or disaster recovery in another region.
- A sub-processor further down the chain operating elsewhere.
- A group company abroad with access to a shared system.
The ICO updated its international transfers guidance in January 2026 and set out a three-step test for identifying a restricted transfer. If your position was assessed before that, it is worth re-running against the current guidance rather than assuming the analysis still holds.
The routes, in the order to consider them
Adequacy first. Where the destination is covered by adequacy regulations, the transfer can proceed without further safeguards. This is the cheapest route and it is a live list, so check it rather than remembering it.
Where there is no adequacy decision, Article 46(1) permits a transfer only where the controller or processor has provided appropriate safeguards. Article 46(2) lists what those can be:
- 1A legally binding and enforceable instrument between public authorities or bodies.
- 2Binding corporate rules under Article 47.
- 3Standard data protection clauses adopted by the Commission.
- 4Standard data protection clauses adopted by a supervisory authority and approved by the Commission.
- 5An approved code of conduct under Article 40, with binding and enforceable commitments.
- 6An approved certification mechanism under Article 42, with binding and enforceable commitments.
In the UK the instruments in practice are the IDTA, or the Addendum used alongside the EU standard contractual clauses. Which you use depends on the arrangement, and the ICO guidance covers the choice.
Exceptions under Article 49 exist and are genuinely narrow. They are for specific situations, not a fallback for a transfer you would rather not paper. Relying on one routinely is the pattern that attracts attention.
The transfer risk assessment
Using a safeguard is not the end of the analysis. Where you rely on an Article 46 safeguard rather than adequacy, you need to assess whether the protection it provides is undermined in the destination, in particular by local law on government access.
The ICO publishes guidance on completing one. Two practical points: it is per transfer rather than per supplier, since the same supplier may host different data in different places; and it needs revisiting when circumstances change, because the assessment is about the destination and the destination's law can move.
Where this connects to your record
Article 30(1)(e) asks you to record transfers, identifying the country or organisation and, in certain cases, the safeguards. That field is the register of what you have assessed, and a blank one usually means the transfers were never noticed rather than that none occur.
If you do one thing after reading this, work through your suppliers and ask where support is based. That single question surfaces more unrecorded transfers than reviewing hosting locations does.
How EmberHound fits
Transfers are a contractual and architectural question, and the answers come from your agreements rather than from a scan. Where discovery contributes is the reverse direction: data that came back and stayed, such as an export produced for an overseas partner and left on a laptop afterwards.
EmberHound reports personal data on enrolled company devices by category and location, which is the part of the picture your supplier contracts do not describe.
This article is general information, not legal advice. Transfer mechanisms and adequacy positions change; confirm the current position before relying on one.


