UK/US Data Bridge: What It Means for Transatlantic Transfers

The UK/US Data Bridge is the legal mechanism that makes transferring personal data from the UK to the United States significantly simpler. Before it existed, every UK-to-US data transfer required its own legal safeguard — a time-consuming, document-heavy process that frustrated businesses on both sides of the Atlantic.


“The UK/US Data Bridge gives UK organisations a lawful, straightforward route to share personal data with certified US businesses — without the paperwork burden of Standard Contractual Clauses every single time.”


Contents show

Key Takeaways

  • The UK/US Data Bridge (formally the UK Extension to the EU-US Data Privacy Framework) came into effect on 17 October 2023.
  • It allows UK organisations to transfer personal data to certified US businesses without needing additional transfer safeguards like the IDTA or SCCs.
  • US businesses must be actively certified under the Data Privacy Framework (DPF) and have specifically opted into the UK Extension.
  • The Bridge covers most personal data, but has specific rules for HR data, special category data, and sensitive information.
  • Banking and insurance sectors are excluded from participation due to gaps in US regulatory oversight.
  • If a US recipient is not certified, UK organisations must fall back on the IDTA, UK Addendum to SCCs, BCRs, or derogations.
  • A Transfer Risk Assessment (TRA) is not required when relying on the Data Bridge — but ongoing due diligence on your US partners still is.
  • The Bridge could face future legal challenge, so organisations should maintain contingency documentation.

Quick Answer

The UK/US Data Bridge is a UK government adequacy decision that allows personal data to flow freely from UK organisations to certified US businesses, without needing separate transfer safeguards. It mirrors the EU-US Data Privacy Framework but applies specifically to UK-to-US transfers under UK GDPR. To rely on it, the US recipient must hold active DPF certification that covers the UK Extension.


UK/US Data Bridge: What It Means for Transatlantic Transfers

What is the UK/US Data Bridge (UK Extension)?

The UK/US Data Bridge is the informal name for the UK Extension to the EU-US Data Privacy Framework. It is an adequacy regulation made under the UK GDPR and the Data Protection Act 2018. In plain English: the UK government has decided that certified US organisations provide an adequate level of data protection for UK personal data. That decision removes the need for additional transfer mechanisms when sending data to those certified businesses.

It came into force on 17 October 2023, following a formal adequacy assessment by the UK Secretary of State.

What is the EU-US Data Privacy Framework (DPF)?

The EU-US Data Privacy Framework is the parallel mechanism for EU-to-US personal data transfers, adopted by the European Commission in July 2023. US organisations self-certify their compliance with DPF principles through the US Department of Commerce. The UK Extension builds on this framework but is a separate, UK-specific adequacy decision — meaning EU and UK rules operate independently of each other. For a deeper look at how UK GDPR differs from EU GDPR, see our comprehensive comparison of EU GDPR vs UK GDPR.

The History of Transatlantic Data Transfers: From Safe Harbor and Privacy Shield to Schrems II

Transatlantic data transfers have had a turbulent legal history:

  • Safe Harbor (2000–2015): The original framework, struck down by the Court of Justice of the EU in the Schrems I ruling after Edward Snowden’s surveillance revelations.
  • Privacy Shield (2016–2020): Its replacement, invalidated by the Schrems II ruling in July 2020, which found US surveillance laws incompatible with EU fundamental rights.
  • EU-US Data Privacy Framework + UK Extension (2023): The current frameworks, designed with new US commitments on surveillance oversight and redress mechanisms.

The UK’s post-Brexit path meant it needed its own adequacy decision — hence the UK Extension, separate from the EU mechanism.


How the UK/US Data Bridge Works

The Bridge works by requiring US organisations to self-certify their compliance with a set of data protection principles through the US Department of Commerce. Once certified, they appear on a public list. UK organisations can then transfer personal data to those certified businesses without additional safeguards.

The Core Principles of the Data Privacy Framework

Certified US organisations must commit to principles including:

  • Notice — informing individuals about data collection and use
  • Choice — giving individuals opt-out rights for certain uses
  • Accountability for onward transfer — ensuring third parties they share data with also protect it
  • Security — implementing appropriate technical and organisational measures
  • Data integrity and purpose limitation — only using data for its stated purpose
  • Access — allowing individuals to access and correct their data
  • Recourse, enforcement, and liability — providing dispute resolution mechanisms

Who Can Use the UK/US Data Bridge?

UK organisations subject to UK GDPR can rely on the Data Bridge when transferring personal data to a US recipient that:

  1. Is certified under the EU-US Data Privacy Framework, and
  2. Has specifically opted into the UK Extension of that framework.

Both conditions must be met. A US business certified under the DPF but without the UK Extension cannot be relied upon for UK-to-US transfers under the Bridge.

Eligible US Organisations: FTC and DoT Regulation Requirements

Participation in the DPF (and therefore the UK Extension) is limited to US organisations subject to the jurisdiction of either the Federal Trade Commission (FTC) or the US Department of Transportation (DoT). These are the bodies that can enforce DPF commitments against US businesses.

Excluded Sectors: Why Banking and Insurance Cannot Participate

Banks and insurance companies in the US fall under different regulatory bodies — the Federal Reserve, OCC, and state insurance regulators — which are not covered by the FTC/DoT enforcement umbrella. Because the DPF relies on FTC/DoT jurisdiction to make commitments enforceable, these sectors cannot participate. UK organisations transferring data to US banks or insurers must use alternative safeguards instead.


Types of Data Covered Under the UK/US Data Bridge

Transferring Standard Personal Data

Most standard personal data — names, contact details, transaction records, customer information — can be transferred under the Bridge, provided the US recipient is certified and the UK Extension applies.

Rules for Transferring Human Resources (HR) Data

HR data (employee personal data) requires separate, explicit certification. A US business must specifically certify that its DPF registration covers HR data. UK employers sending employee data to a US parent company or HR platform must verify this separately. It’s a common oversight — and a costly one.

Special Category Data and Sensitive Information Requirements

Special category data (health, ethnicity, religion, sexual orientation, trade union membership, etc.) can be transferred, but the US recipient must apply heightened protections. Under the UK Extension principles, recipients must treat this data as sensitive and apply additional safeguards, including explicit consent requirements for certain uses.

Specific Safeguards for Criminal Offence, Genetic, and Biometric Data

Criminal offence data, genetic data, and biometric data used for identification purposes are treated as sensitive information under the UK Extension. US recipients must provide specific protections and cannot use this data in ways that would be incompatible with the purpose for which it was originally collected.

Data Types Excluded: The Journalistic Exception

Data processed solely for journalistic, literary, or artistic purposes falls outside the scope of the UK Extension. If your organisation transfers data for these purposes, you’ll need to rely on a different lawful transfer mechanism.


Benefits of the UK/US Data Bridge for UK Businesses

Photorealistic, high-resolution photography, Scandinavian minimalist design, neutral tones, Detailed () professional

Reduced Compliance Costs and Administrative Burden

Before the Bridge, every UK-to-US transfer needed its own legal safeguard — usually an IDTA or SCCs, plus a Transfer Risk Assessment. That’s significant time and legal cost, especially for organisations with multiple US vendors. The Bridge removes that requirement where the US recipient is certified. For guidance on your broader compliance costs, our GDPR compliance cost guide breaks this down clearly.

Enhanced Legal Clarity and Transatlantic Data Security

The Bridge provides a clear, documented legal basis for UK-to-US transfers. That clarity matters when demonstrating compliance to the ICO, responding to subject access requests, or managing vendor contracts. It also signals to US partners that the UK takes data protection seriously — which can strengthen commercial relationships.

Swift Dispute Resolution and Redress Mechanisms for UK Individuals

UK individuals whose data is transferred under the Bridge have access to free, independent dispute resolution through DPF-approved bodies. They can also raise complaints with the ICO, which can then engage with US authorities. For serious national security concerns, a dedicated UK Signals Intelligence Redress Panel provides an additional layer of oversight.


Challenges, Limitations, and Regulatory Concerns

Regulatory Compatibility Between UK GDPR and US Law

The UK Extension works because the US has made specific commitments about surveillance and redress. But US law — particularly around national security data access — remains structurally different from UK GDPR. The Bridge manages this tension rather than eliminating it. UK organisations should understand that “adequate” doesn’t mean “identical.”

Potential Future Legal Challenges and the Threat of “Schrems III”

Privacy advocates have already signalled intent to challenge the EU-US DPF in European courts. If the EU framework falls, the UK Extension could face pressure too — though the UK’s independent adequacy decision provides some insulation. The lesson from Privacy Shield’s collapse is clear: don’t rely solely on the Bridge without maintaining contingency documentation. Keep your IDTA or SCC templates updated, just in case.


Practical Steps for UK Organisations: How to Rely on the UK/US Data Bridge

Step 1: Verify the US Recipient’s DPF Certification and UK Extension Status

Check the official DPF list at dataprivacyframework.gov. Search for the US organisation by name. Confirm their certification is active (not lapsed) and that it explicitly covers the UK Extension.

Step 2: Confirm Certification Covers the Specific Data Types (HR vs. Non-HR)

If you’re transferring HR data, check the certification specifically covers HR data. This is listed separately on the DPF register. Don’t assume — verify.

Step 3: Update Existing Privacy Policies and Transparency Notices

Your privacy notice must accurately reflect how and where personal data is transferred. Update it to reference the UK/US Data Bridge as the transfer mechanism for relevant US recipients. For ready-to-use templates, our GDPR data protection policy templates can save you significant time.

Step 4: Revise Records of Processing Activities (RoPA)

Your RoPA must document the legal basis for each international transfer. Update entries for US-based recipients to reference the UK Extension adequacy regulation. This is a key document the ICO may request during an investigation.

Step 5: Conduct Ongoing Due Diligence on US-Based Partners

Certification can lapse. US businesses can withdraw from the DPF. Build a periodic review process — at least annually — to re-verify that your US partners remain certified. A lapsed certification means the Bridge no longer applies, and you’d need to revert to an alternative safeguard immediately.


What to Do If the US Business is Not Registered or Certified

UK/US Data Bridge: What It Means for Transatlantic Transfers

Alternative Safeguards for International Data Transfers

If a US recipient isn’t certified under the DPF or UK Extension, you cannot rely on the Data Bridge. You’ll need an alternative transfer mechanism. The main options under UK GDPR are:

  • UK International Data Transfer Agreement (IDTA)
  • UK Addendum to EU Standard Contractual Clauses
  • Binding Corporate Rules (BCRs)
  • Derogations (for specific, limited circumstances)

Using the UK International Data Transfer Agreement (IDTA) or UK Addendum to SCCs

The IDTA is the UK’s standalone transfer agreement, approved by the ICO. The UK Addendum allows organisations to use the EU’s SCCs with a UK-specific addendum attached. Both are valid transfer mechanisms under UK GDPR. They require more documentation than the Bridge but remain widely used — especially for transfers to uncertified US businesses.

Relying on Binding Corporate Rules (BCRs) and Derogations

BCRs are approved internal data transfer policies used by multinational corporate groups. They require ICO approval and are typically used by large organisations. Derogations — such as explicit consent or necessity for contract performance — are available but should only be used for occasional, specific transfers, not systematic ones.

Transfer Risk Assessments (TRAs): Are They Still Required?

When relying on the UK/US Data Bridge, a TRA is not required — the adequacy decision does that work for you. However, if you’re using the IDTA or SCCs, a TRA is still necessary. For broader compliance checks, our GDPR compliance audit guide covers TRAs in detail.


How a GDPR Consultancy Firm Can Help Ensure Your Data Bridge Compliance

Comprehensive International Data Transfer Audits

A GDPR consultancy can map all your international data flows, identify which US recipients are certified, and flag gaps where alternative safeguards are needed. This gives you a clear picture of your current transfer position — and what needs fixing.

Drafting and Updating Vendor Contracts and Privacy Documentation

Contracts with US vendors need to reflect the correct transfer mechanism. A consultancy can update your data processing agreements, privacy notices, and RoPA entries to accurately document your reliance on the Bridge or alternative safeguards.

Tailored DPF Verification and Vendor Due Diligence

Rather than checking certifications manually, a consultancy can build a structured due diligence process for your US vendor portfolio — including periodic re-verification schedules and escalation procedures for lapsed certifications.

Ongoing DPO Support and Regulatory Guidance

If your organisation doesn’t have an in-house DPO, outsourced DPO services provide ongoing expert support — including monitoring regulatory developments around the UK/US Data Bridge and advising on any changes that affect your compliance position. You can also explore what a Data Protection Officer actually does to understand when you might need one.


Frequently Asked Questions (FAQs) About the UK/US Data Bridge

When Did the UK/US Data Bridge Come Into Effect?

The UK/US Data Bridge came into effect on 17 October 2023, following a formal adequacy assessment by the UK Secretary of State under the UK GDPR and Data Protection Act 2018.

Does the Data Bridge Replace the IDTA and SCCs Entirely?

No. The Data Bridge only applies when transferring data to a certified US recipient that has opted into the UK Extension. For all other US transfers — and transfers to other non-adequate countries — the IDTA, UK Addendum to SCCs, or other safeguards remain necessary.

Is it Mandatory to Use the UK/US Data Bridge?

No. It’s a permitted transfer mechanism, not a requirement. UK organisations can still use the IDTA or SCCs for US transfers if they prefer, even when the recipient is DPF-certified. The Bridge is simply the most administratively straightforward option when available.

How Must UK Exporters Flag Sensitive Data to US Importers?

When transferring sensitive or special category data, UK exporters must inform the US recipient that the data is sensitive and requires heightened protection under the UK Extension principles. This should be documented in your data transfer agreement or covering correspondence.

Can a US Business’s DPF Certification Lapse?

Yes. US businesses must renew their DPF certification annually. If a certification lapses, the Data Bridge can no longer be relied upon for transfers to that organisation. UK exporters should monitor their US partners’ certification status regularly.

Does the UK/US Data Bridge Apply to Processors as Well as Controllers?

Yes. The Bridge can be relied upon whether the US recipient is acting as a data controller or a data processor — provided they hold valid DPF certification covering the UK Extension.

What Happens to the UK/US Data Bridge if the EU-US DPF is Struck Down?

The UK Extension is a separate UK adequacy decision, so it wouldn’t automatically fall if the EU-US DPF were invalidated by European courts. However, if the underlying US commitments that support both frameworks were undermined, the UK’s own adequacy decision could come under review.

Where Can I Check if a US Organisation is DPF Certified?

The official public list is maintained at dataprivacyframework.gov. You can search by organisation name and filter for UK Extension coverage.

Does the Data Bridge Cover B2B Data or Only Consumer Data?

It covers both. The Bridge applies to any personal data transferred from a UK organisation to a certified US recipient — whether that data relates to consumers, employees, business contacts, or other individuals.

How Does the UK/US Data Bridge Interact with the Data Use and Access Act 2025?

The Data Use and Access Act 2025 introduces reforms to the UK’s data protection framework. The adequacy regulation underpinning the UK/US Data Bridge sits within the existing UK GDPR framework, and the DUAA’s changes may affect how adequacy decisions are assessed going forward. Organisations should monitor ICO guidance as the DUAA provisions come into force.

Is the UK/US Data Bridge Relevant to US Companies Receiving UK Data?

Absolutely. US organisations that receive personal data from UK partners need to understand whether their DPF certification covers the UK Extension — and ensure their privacy policies and data handling practices reflect their UK Extension commitments. For more on how GDPR affects US businesses, see our guide on whether GDPR affects US companies.

Do Small UK Businesses Need to Worry About the Data Bridge?

Yes — if they transfer any personal data to US-based tools, platforms, or partners (think CRM systems, cloud storage, email marketing platforms), the Data Bridge is directly relevant. The good news is that for certified US recipients, it simplifies compliance considerably.


Conclusion: Next Steps for Securing Your Transatlantic Data Sharing

The UK/US Data Bridge is a genuinely useful tool for UK organisations that regularly share personal data with US businesses. It cuts compliance overhead, provides legal clarity, and gives individuals meaningful redress rights. But it only works when used correctly.

Here’s what to do now:

  1. Audit your US data flows. List every US-based tool, vendor, or partner that receives UK personal data.
  2. Check DPF certification status. Visit dataprivacyframework.gov and verify each recipient’s certification — including UK Extension coverage.
  3. Separate HR data transfers. Confirm that any US recipients handling employee data are certified for HR data specifically.
  4. Update your documentation. Privacy notices, RoPA entries, and vendor contracts should all reflect the correct transfer mechanism.
  5. Build a review schedule. Certifications can lapse. Set a calendar reminder to re-verify at least annually.
  6. Prepare a contingency plan. Keep IDTA or SCC templates ready in case a certification lapses or the framework faces legal challenge.

Not sure where to start? A GDPR gap analysis can identify exactly where your international transfer documentation needs work — and give you a clear action plan. Or if you’d prefer expert hands-on support, get in touch with the GDPR Advisor team to discuss how we can help.

Transatlantic data transfers don’t have to be complicated. With the right knowledge and the right processes in place, the UK/US Data Bridge can make your US data relationships simpler, safer, and fully compliant.


References

  • UK Government. (2023). UK-US Data Bridge: Adequacy Regulations. GOV.UK. https://www.gov.uk/government/publications/uk-us-data-bridge-adequacy-regulations
  • Information Commissioner’s Office. (2023). UK-US Data Bridge. ICO. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-transfers-a-guide/the-uk-us-data-bridge/
  • US Department of Commerce. (2023). Data Privacy Framework Program. https://www.dataprivacyframework.gov
  • European Commission. (2023). EU-US Data Privacy Framework. https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en
  • Court of Justice of the European Union. (2020). Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems (Schrems II). Case C-311/18.
  • Information Commissioner’s Office. (2022). International Data Transfer Agreement (IDTA). ICO. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/