Adequacy And Sccs After Brexit .

1. Background: what changed after Brexit?

Before Brexit, the UK was an EU Member State, so personal data could move freely between the UK and other EU/EEA countries under the GDPR framework.

After the end of the Brexit transition period on 31 December 2020, the UK became a “third country” for purposes of EU data-protection law. Consequently, transfers of personal data:

EU/EEA → UK

became international transfers under Chapter V of the EU GDPR.

The principal mechanisms for making such transfers lawful are:

  1. Adequacy decision under Article 45 EU GDPR;
  2. Appropriate safeguards, particularly SCCs under Article 46;
  3. Derogations/exceptions under Article 49.

The UK simultaneously retained a domestic version of the GDPR — the UK GDPR, together with the Data Protection Act 2018.

2. What is an Adequacy Decision?

An adequacy decision is a formal decision by the European Commission that a third country provides a level of protection for personal data that is “essentially equivalent” to the protection available within the EU.

Under Article 45 EU GDPR, where an adequacy decision applies, personal data can be transferred to that country without requiring SCCs or another Article 46 safeguard.

Why is adequacy important?

It is the simplest mechanism because:

EU → Adequate country = transfer can generally take place without SCCs.

There is therefore no requirement to negotiate individual contractual safeguards merely because the recipient is outside the EU.

3. The UK's EU Adequacy Decision after Brexit

Following Brexit, the EU initially granted the UK adequacy under two decisions:

  • EU GDPR adequacy decision, and
  • Law Enforcement Directive (LED) adequacy decision.

The original decisions were adopted in June 2021.

The situation has since been renewed. The European Commission adopted renewed UK adequacy decisions on 19 December 2025, and they currently run until 27 December 2031.

Therefore, as of August 2026:

EU → UK

EU/EEA organisation → UK organisation

can generally transfer personal data without SCCs because the UK currently has an EU adequacy decision.

This is a crucial point for examinations: Brexit did not ultimately result in a permanent requirement for SCCs between the EU and UK.

4. What does “adequate” actually mean?

Adequacy does not require the third country to have laws identical to the GDPR.

The test is essentially whether the third country's system provides protection that is essentially equivalent to EU protection.

The assessment considers matters such as:

  • rule of law;
  • respect for human rights;
  • existence and effectiveness of data-protection rights;
  • independent supervisory authorities;
  • judicial remedies;
  • government access to personal data;
  • surveillance laws;
  • restrictions on onward transfers;
  • enforcement mechanisms.

The UK adequacy decision therefore represents an assessment of the UK's overall legal system, rather than an approval of every individual UK company.

5. Standard Contractual Clauses (SCCs)

SCCs are standardised contractual provisions approved by the European Commission which impose data-protection obligations on the parties to an international transfer.

They are an Article 46 safeguard.

The basic idea is:

If the destination country does not have an adequacy decision, the parties can use SCCs to provide legally enforceable safeguards for the transferred data.

For example:

French company → Indian processor

If India is not covered by an EU adequacy decision, the French company may use the EU SCCs, subject to the requirements of EU GDPR.

6. Brexit and SCCs

Brexit created an interesting two-way problem.

Before Brexit

The UK was part of the EU.

Therefore:

UK → US/India/etc.

could use the EU SCCs.

After Brexit

The UK developed its own international-transfer regime.

For transfers subject to UK GDPR, the UK now has:

  • International Data Transfer Agreement (IDTA); and
  • UK Addendum to the EU SCCs.

The ICO explains that the EU SCCs cannot by themselves be relied upon for a restricted transfer under UK GDPR; the UK Addendum can be used alongside the EU SCCs to make them work for UK GDPR transfers.

Thus:

SituationMechanism
EU → UKEU adequacy decision
UK → EU/EEAUK adequacy regulations
EU → non-adequate third countryEU SCCs / other Article 46 safeguards
UK → non-adequate third countryUK IDTA or UK Addendum + EU SCCs
Exceptional transferArticle 49 derogation

7. The UK itself considers the EU/EEA adequate

The relationship is reciprocal in practical terms.

The UK has recognised the EU/EEA as adequate for UK GDPR transfers. Therefore:

UK → EU/EEA

generally does not require an IDTA or SCC merely because the data is leaving the UK.

Consequently, the current position can be simplified as:

EU ⇄ UK = generally free data flow because both sides recognise the other as adequate.

8. The most important case: Schrems II

Data Protection Commissioner v Facebook Ireland and Maximillian Schrems

Case C-311/18, Schrems II (2020)

This is probably the most important case for understanding SCCs after Brexit.

The claimant, Maximilian Schrems, challenged transfers of his personal data from Facebook Ireland to the United States.

The CJEU considered:

  1. the validity of the EU-US Privacy Shield; and
  2. the validity of the SCC mechanism.

Decision

The CJEU invalidated the EU-US Privacy Shield.

However, it upheld the validity of SCCs in principle.

But there was an important qualification.

SCCs cannot simply be treated as automatically sufficient regardless of the destination country's law.

The exporter must consider whether the law and practices of the recipient country allow the SCC protections to be respected in practice.

Where necessary, the parties must introduce supplementary measures.

This principle is fundamental to international data transfers today. The UK government also recognises that Schrems II confirmed SCCs as a valid transfer mechanism but required additional protections where the law of the destination country undermines their effectiveness.

9. Why is Schrems II relevant after Brexit?

It is relevant for two reasons.

First

It establishes that an SCC is not a magic piece of paper.

You cannot simply sign SCCs and assume the transfer is lawful.

The exporter has to consider:

  • surveillance laws;
  • government access;
  • judicial remedies;
  • enforceability of the contractual obligations;
  • practical ability of the importer to comply.

Second

It influenced the UK's post-Brexit transfer regime.

The UK developed the IDTA and UK Addendum, together with transfer-risk assessment requirements.

The ICO currently states that organisations using the UK IDTA or Addendum must complete a transfer risk assessment (TRA) to ensure that the level of protection is not materially lower after the transfer.

10. Schrems I

Another foundational case is:

Maximillian Schrems v Data Protection Commissioner

Case C-362/14 (2015)

This case concerned the EU-US Safe Harbour arrangement.

The CJEU invalidated the Safe Harbour decision.

The Court emphasised that an adequacy decision does not place the third country beyond judicial scrutiny. The case demonstrated that the EU's protection of fundamental rights could invalidate an international-transfer arrangement where the destination country's legal framework did not provide adequate protection.

Importance

Schrems I → invalidated Safe Harbour

Schrems II → invalidated Privacy Shield

Both cases demonstrate that:

Adequacy must provide genuinely effective protection, not merely formal contractual or political assurances.

11. SCCs and government surveillance

The central concern in Schrems II was US surveillance legislation.

Suppose:

EU company → US cloud provider

The parties sign SCCs.

But US law may permit public authorities to access certain data.

The question becomes:

Can the SCC protections actually protect the individual's data against that government access?

If the answer is no, merely signing the SCCs is insufficient.

This is why the post-Schrems II framework involves an assessment of the destination country's legal environment and, where necessary, supplementary measures.

12. Schrems II and the principle of “essential equivalence”

The CJEU's jurisprudence essentially requires protection in the third country that is sufficiently equivalent to EU protection.

But “equivalent” does not mean “identical.”

A third country does not have to copy every provision of the GDPR.

Instead, the overall system must provide an effective level of protection comparable in substance.

This principle is particularly important when evaluating:

  • adequacy decisions;
  • SCC transfers;
  • surveillance legislation;
  • government access to data;
  • judicial remedies.

13. UK position: IDTA and EU SCC Addendum

After Brexit, the UK could no longer simply rely upon the European Commission's SCCs as its own domestic transfer instrument.

The ICO therefore introduced the:

International Data Transfer Agreement (IDTA)

and

International Data Transfer Addendum

The Addendum allows organisations that already use the EU SCCs to extend them so that the transfer also complies with UK GDPR.

The ICO currently describes these as the two standard data-protection clauses available under the UK GDPR.

This is especially useful for multinational companies operating simultaneously under:

  • EU GDPR; and
  • UK GDPR.

14. Transfer Risk Assessment

A major post-Schrems II development is the need to consider the actual risks of the transfer.

The organisation should assess, among other things:

A. Nature of the data

For example:

  • health information;
  • financial information;
  • employment records;
  • ordinary contact details.

B. Destination country

What laws govern government access?

C. Recipient

Is the recipient:

  • controller;
  • processor;
  • cloud provider;
  • multinational group company?

D. Technical safeguards

Such as:

  • encryption;
  • pseudonymisation;
  • access controls.

E. Practical enforceability

Can individuals actually enforce their rights?

Under current UK ICO guidance, a TRA is part of the process for using the IDTA/Addendum as an appropriate safeguard.

15. Adequacy vs SCCs

This distinction is extremely important.

AdequacySCCs
Government/Commission decisionContractual mechanism
Article 45Article 46
Destination country recognised as adequateDestination country need not be adequate
No SCC required merely for transferSCC provisions must be implemented
Generally simplerMore administrative burden
Based on country's legal frameworkBased on contractual safeguards plus transfer assessment
Can be reviewed/withdrawnCan become ineffective if destination-country law undermines protection

In simple words:

Adequacy = “The country itself provides sufficient protection.”

SCC = “The parties contractually provide safeguards because the country does not have an adequacy decision.”

16. Brexit's wider constitutional significance

Brexit created an interesting example of legal divergence.

The UK retained the GDPR framework through the UK GDPR, but it became legally separate from the EU.

Therefore, there are now two closely related systems:

EU GDPR

Applied by the EU Member States.

UK GDPR

Applied in the UK, alongside the Data Protection Act 2018.

They remain highly similar, but they are not legally identical.

The result is that multinational organisations must sometimes satisfy both regimes simultaneously.

17. Current position in 2026

For an examination answer, the current position can be stated as follows:

EU → UK

The UK currently has EU adequacy.

The renewed EU adequacy decision was adopted on 19 December 2025 and lasts until 27 December 2031.

Therefore, an EU organisation can generally transfer personal data to the UK without relying on SCCs.

UK → EU

The UK recognises the EU/EEA as adequate for UK GDPR purposes, allowing relevant transfers without additional safeguards.

UK → non-adequate third country

The organisation may use:

  • UK IDTA;
  • UK Addendum + EU SCCs;
  • BCRs;
  • other Article 46 safeguards;

subject to the applicable transfer-risk/data-protection assessment.

18. Important case-law principles

For an exam, remember these cases:

1. Schrems I — C-362/14 (2015)

Principle: Safe Harbour invalidated.

Importance: A third-country transfer mechanism must provide effective protection for fundamental rights.

2. Schrems II — C-311/18 (2020)

Principle: Privacy Shield invalidated; SCCs remain valid in principle.

Importance: SCCs require scrutiny of the destination country's laws and may require supplementary measures.

3. Digital Rights Ireland — Joined Cases C-293/12 and C-594/12 (2014)

Principle: Data-retention legislation must comply with fundamental rights.

Importance: Demonstrates the CJEU's strict approach to privacy and proportionality.

4. Tele2 Sverige / Watson — Joined Cases C-203/15 and C-698/15 (2016)

Principle: General and indiscriminate retention of communications data is subject to stringent EU fundamental-rights requirements.

Importance: Relevant when considering government access and surveillance in adequacy assessments.

5. La Quadrature du Net — Joined Cases C-511/18, C-512/18 and C-520/18 (2020)

Principle: National-security/public-security measures involving communications data remain subject to EU fundamental-rights requirements, although specific circumstances may justify certain forms of retention.

Importance: Helps explain the standards applied to state access to personal data.

19. Critical evaluation

The post-Brexit system has advantages but also problems.

Advantages

1. Continuity

The UK retained a GDPR-based system, reducing disruption.

2. EU adequacy

The adequacy decision permits relatively frictionless EU-UK data flows.

3. Business flexibility

Where adequacy is unavailable, organisations have contractual mechanisms such as SCCs/IDTA.

4. Strong fundamental-rights protection

Schrems I and Schrems II prevent governments from treating international data transfers as merely commercial arrangements.

Problems

1. Adequacy is not permanent

The EU can review and potentially withdraw an adequacy decision.

2. Regulatory divergence

Future UK changes to data-protection law could make the EU reconsider whether UK protection remains essentially equivalent.

3. SCC compliance is complex

SCCs require more than simply signing a template.

4. Surveillance concerns

Government access to personal data remains a major issue in adequacy assessments.

5. Dual compliance

International organisations may need to comply with both EU GDPR and UK GDPR.

20. Conclusion

The best way to understand Adequacy and SCCs after Brexit is through a three-stage development:

Before Brexit:
UK was inside the EU → EU GDPR applied → intra-EU transfers were generally unrestricted.

After Brexit:
UK became a third country → EU-UK transfers required an Article 45 adequacy decision or another Article 46 mechanism.

Current position:
The EU has renewed the UK's adequacy status until 27 December 2031, while the UK recognises the EU/EEA as adequate. Consequently, ordinary EU-UK transfers can generally take place without SCCs. For transfers to countries without adequacy, SCCs/IDTA/Addendum remain crucial safeguards.

The key judicial lesson from Schrems I and Schrems II is that data-transfer safeguards must provide effective protection in practice, not merely appear protective on paper.

Exam-ready formula

Brexit → UK became a third country → Article 45 adequacy or Article 46 safeguards became necessary → UK received EU adequacy in 2021, renewed in 2025 → EU-UK transfers are currently facilitated by adequacy → SCCs remain essential for transfers involving non-adequate countries → Schrems I and II require effective, essentially equivalent protection and scrutiny of third-country surveillance laws.

LEAVE A COMMENT