Skip to main content

Safeguards for Transfers Abroad

Where the organisation transfers the person's personal data outside the UK, the response states the safeguards it relies on for the transfer.

Criterion
E11
Level
Level 1
Domain
Supplementary Information
Reflects
Article 15(2)

Intent

Data sent abroad leaves the protection of UK law unless a safeguard carries that protection with it. Naming the safeguard is how the person knows one exists.

How to test it

An assessor scores the criterion against a single response:

Score 2
The response names the safeguards the organisation relies on for transfers outside the UK.
Score 1
The response states that data is transferred abroad and that safeguards are in place, without naming them.
Score 0
The response says nothing about safeguards for the transfer.
Not applicable
The organisation does not transfer the person's personal data outside the UK.

The law it reflects

This criterion reflects Article 15(2) of the UK GDPR. That mapping is a guide, not a legal test: conformance is judged against the criterion, not the article.

See E11 in context in the full standard.