Safeguards for Transfers Abroad
Where the organisation transfers the person's personal data outside the UK, the response states the safeguards it relies on for the transfer.
Intent
Data sent abroad leaves the protection of UK law unless a safeguard carries that protection with it. Naming the safeguard is how the person knows one exists.
How to test it
An assessor scores the criterion against a single response:
- Score 2
- The response names the safeguards the organisation relies on for transfers outside the UK.
- Score 1
- The response states that data is transferred abroad and that safeguards are in place, without naming them.
- Score 0
- The response says nothing about safeguards for the transfer.
- Not applicable
- The organisation does not transfer the person's personal data outside the UK.
The law it reflects
This criterion reflects Article 15(2) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.
See E11 in context in the full standard.