SEO

UK Data Protection Rules for Overseas SEO Suppliers

The ICO three step test, adequacy gaps, IDTA choices and the new PECR ceiling, set out for procurement teams reviewing a vendor abroad.

A UK marketing director shortlisting an SEO agency abroad usually asks the wrong question first. The question they ask is whether it is legal. The question that decides the outcome is narrower and much more awkward: which specific instrument covers the moment your agency logs into your Search Console, and who signs it.

That is not a technicality. Search work touches analytics accounts, lead form submissions, CRM exports, CMS user records and tag configurations. Several of those contain personal data belonging to people in the UK. The instant a supplier outside the UK can see them, a set of obligations under Chapter V of the UK GDPR switches on, and the paperwork stops being paperwork.

Three things changed in 2026 that make the old answers stale. The Information Commissioner's Office rewrote its international transfers guidance on 15 January. The statutory standard for assessing a transfer changed on 5 February. And the maximum fine for the marketing and tracking rules jumped by a factor of thirty-five on the same date. Anyone quoting 2024 guidance at you is quoting a different regime.

Start with the three step test, because it decides everything downstream

Before January 2026 the ICO's guidance on what counted as a restricted transfer was, by its own admission, hard to navigate. The rewrite broke the old single guide into task-based documents and introduced a plain three step test. It is short enough to run in a meeting.

Step one: does the UK GDPR apply to the processing of the personal data you are sending. Step two: is the transfer to an organisation outside the UK. Step three: is the organisation receiving the information a separate legal entity from the sender. Answer yes to all three and you are making a restricted transfer, and the international transfer rules apply.

Two details in that test catch people out. The rules apply even where the recipient is itself subject to the UK GDPR, so a supplier telling you they are already GDPR compliant has not answered the question. And the trigger is not only sending. Making personal data accessible counts, which means granting a login is a transfer even though nothing was emailed anywhere.

The ICO's guidance is also less onerous in places than the equivalent European position, which matters if you operate across both regimes and had assumed a single approach would cover you. It will not. The UK and EU frameworks have begun to diverge in ways that are now worth mapping separately.

ICO guidance, 15 January 2026

Four Decisions Between a Login Request and a Signature

Each one narrows the options. By the fourth there are only two instruments left, and one assessment you cannot skip.

Is it a restricted transfer at all

Three questions. Does UK GDPR apply to this processing, is the transfer to an organisation outside the UK, and is the recipient a separate legal entity. Yes to all three and the rules apply, even if the recipient is already subject to UK GDPR itself.

Can adequacy carry it

Full UK adequacy covers Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, Switzerland and Uruguay, alongside the EEA and partial mechanisms such as the UK extension to the EU-US framework. Most of Asia is not on that list.

Which Article 46 instrument

The International Data Transfer Agreement, or the UK Addendum bolted onto the 2021 EU Standard Contractual Clauses. Both in force since 21 March 2022. The legacy EU SCC route closed on 21 March 2024 and is not available for anything now.

The assessment you cannot skip

A transfer risk assessment, tested against a standard that changed on 5 February 2026. Protection in the destination must be not materially lower than under UK law. The previous wording was sufficiently similar. The words are different and so is the threshold.

And the obligation follows whoever initiated it

The ICO is explicit on this point in the 2026 guidance. The party that initiates the restricted transfer is responsible for making sure it is covered, and that allocation applies regardless of whether the initiating party acts as controller or processor. Responsibility follows the reality of who initiated and who procured, not an assumption about which side of the relationship ought to own transfer risk. Anyone assuming their processor absorbs it by default is assuming wrongly.

Sources: ICO, A guide to international transfers, updated 15 January 2026 • ICO adequacy regulations • Data (Use and Access) Act 2025, transfer provisions effective 5 February 2026
Created by Arfadia • arfadia.com/blog

Adequacy will not cover a supplier in Southeast Asia

Adequacy is the efficient route. Where the UK government has assessed a country as providing protection that is not materially lower than UK law, data can flow without additional safeguards. The list is short.

Full adequacy currently covers Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, Switzerland and Uruguay, alongside the EEA. There are partial mechanisms too, including the UK extension to the EU-US Data Privacy Framework, which only US businesses regulated by the Federal Trade Commission or the Department of Transportation can join, and only for the data categories they have registered to receive.

Indonesia is not on the list. Neither are most of the jurisdictions where offshore digital delivery actually happens. That is a factual statement about a published register, not a judgement about anybody's security practices, and it is worth stating plainly rather than dancing around: adequacy cannot be the basis, so an Article 46 safeguard is required.

One divergence worth knowing. Brazil now holds a European Commission adequacy decision but is not covered by UK adequacy regulations. The two lists were near-identical after Brexit and are drifting apart. If your compliance register was built by copying the EU position, it has started to go out of date.

Two instruments, and only two

Where adequacy does not apply, the ICO has approved two sets of standard clauses. The International Data Transfer Agreement is a standalone UK contract. The UK Addendum is an add-on that modifies the 2021 EU Standard Contractual Clauses so they work under UK law.

The choice between them is practical rather than principled. The IDTA usually reaches signature faster because there are fewer variables to negotiate. The Addendum route suits organisations already running EU SCCs for European transfers, because it avoids papering the same relationship twice. Where a relationship is high value or high risk, the SCC and Addendum combination produces a more granular contractual record, which is an advantage if a dispute arrives later.

What is not a choice is the timeline. Both instruments came into force on 21 March 2022. New arrangements have had to use one of them since 22 September 2022. Existing arrangements resting on the old Directive-era EU SCCs had until 21 March 2024 to be repapered. That deadline has passed. Any contract still relying on the old clauses for a UK restricted transfer is transferring data without appropriate safeguards, which is a live compliance failure rather than a housekeeping item.

Point of comparison International Data Transfer Agreement UK Addendum to the EU SCCs
What it isA standalone UK contract, drafted by the ICO specifically for UK restricted transfers.An add-on that modifies the 2021 EU Standard Contractual Clauses so they operate under UK law.
In force since21 March 2022.21 March 2022.
Best suited toOrganisations subject only to the UK GDPR, and low-complexity vendor relationships where speed to signature matters.Organisations already running the 2021 EU SCCs for European transfers, who want one contractual approach rather than two.
Negotiation loadLower. Fewer variables, so it typically reaches signature faster.Higher. Requires selecting which SCC modules and clauses apply and pointing to where the Annexes live.
Contractual recordAdequate, but less granular.More granular, which helps if a dispute arrives later. Preferable for high-value or high-risk transfers.
Transfer risk assessmentRequired before the transfer.Required before the transfer.
Covers Article 28 processor termsOnly through a linked agreement. A separate data processing agreement is still needed.The underlying SCCs address processor terms, but the wider processing relationship still needs its own agreement.
Obligations on the importerDirect, and enforceable by data subjects.Direct, and enforceable by data subjects.

One more thing the IDTA does not do. It handles processor obligations through a linked agreement, which means a separate data processing agreement covering Article 28 terms is still needed. Suppliers sometimes present the IDTA as covering the whole relationship. It does not.

The transfer risk assessment, and the standard that changed

An organisation relying on an Article 46 safeguard has to complete a transfer risk assessment before the data moves. The assessment tests whether protection after the transfer holds up, and whether extra measures are needed to make it hold up.

Here is where 2026 matters. The Data (Use and Access) Act 2025 amended the description of the required level of protection for both adequacy and appropriate safeguards, adopting a not materially lower standard. Those rules took effect on 5 February 2026. The ICO has aligned its terminology with the statutory concept of a data protection test while continuing to use transfer risk assessment for the practical process, and its guidance explains how one maps onto the other.

The ICO recognises three ways to conduct the assessment: its own TRA tool, the European Data Protection Board methodology used as a comparator, or an alternative approach the organisation can justify. Assessments completed before the new rules took effect, in line with the previous law, can still be relied on. That is a genuine relief for anyone who did the work in 2023 and dreaded doing it again.

What a supplier can usefully contribute to that assessment is specific: data flow and system mapping, clarity on controller, processor and subprocessor roles, a current subprocessor list, a security schedule, incident notification and breach response, retention and deletion procedures, onward transfer controls, and named hosting and collaboration locations. None of that is exotic. All of it is faster to hand over than to invent under procurement pressure.

Then there is PECR, which is where the money is now

Most conversations about data and search work stop at the transfer question. That is a mistake, because the sharper financial exposure in 2026 sits somewhere else entirely.

For twenty-two years the maximum fine for breaching the Privacy and Electronic Communications Regulations was £500,000. That cap had been in place since PECR arrived in 2003, and for a company with real revenue it functioned as a rounding error. The Data (Use and Access) Act 2025 raised it to the higher of £17.5 million or 4% of global annual turnover, bringing PECR into line with UK GDPR maxima.

The date matters enormously and is widely misreported. The Act received Royal Assent on 19 June 2025, but the new ceiling did not arrive with it. Commencement Order No. 6 brought the relevant provisions into force on 5 February 2026, and the ICO has confirmed the new powers apply to conduct occurring after that date. Breaches before 5 February 2026 remain under the old cap. Anyone telling you the £17.5 million ceiling has applied since mid-2025 is wrong by roughly eight months.

Two other changes travel with it. The requirement to prove that a breach caused substantial damage and distress has been removed, lowering the bar for enforcement action. And the ICO gained wider powers, including compelling witnesses to attend interviews and requesting technical reports and audits.

For a small or mid-sized business the 4% measure is the relevant one rather than the headline. A company turning over £2 million faces a theoretical maximum of £80,000 under the percentage calculation. Smaller than £17.5 million, still large enough to hurt, and now calibrated to hurt proportionally. The enforcement history explains why this is not hypothetical: between 2019 and 2025 the ICO issued 119 fines under PECR against just 16 under the UK GDPR, because the evidential threshold for PECR is lower and the trails are cleaner.

Dates that are commonly misquoted

Five Dates, and Why Getting Them Wrong Costs You

Royal Assent is not commencement. Coming into force is not the end of a transition period. Both distinctions have money attached.

21 March 2022

The IDTA and the UK Addendum come into force. From 22 September 2022 onward, no new arrangement can rest on the old Directive-era EU SCCs.

21 March 2024

The repapering deadline for legacy contracts. After this date the old clauses are not a valid safeguard for a UK restricted transfer under any circumstances. The transition is over, not ongoing.

15 January 2026

ICO publishes rewritten international transfers guidance: the three step test, a brief guide, quick-reference FAQs, a glossary, worked examples and an interactive tool, with further guidance on TRAs, the IDTA and cloud services still to come.

5 February 2026

The single most consequential date. New TRA rules take effect, the not materially lower standard replaces sufficiently similar, and the PECR fine ceiling rises from £500,000 to £17.5 million or 4% of global turnover, applying to conduct from this date onward.

29 April 2026

The ICO finalises its guidance on storage and access technologies after two consultation rounds, the first opened in December 2024. It deliberately drops cookies as the organising frame in favour of a category covering tracking pixels, device fingerprinting, web storage, scripts, tags and link decoration, all within PECR Regulation 6. Two new sub-chapters were added at final stage, including one on using a single technology for multiple purposes.

Sources: ICO guidance updates, 15 January 2026 and 29 April 2026 • Data (Use and Access) Act 2025, Royal Assent 19 June 2025, Commencement Order No. 6 effective 5 February 2026 • ICO transitional provisions for the IDTA and UK Addendum
Created by Arfadia • arfadia.com/blog

The mixed purpose rule that catches real campaigns

The ICO finalised its guidance on storage and access technologies on 29 April 2026, following consultations that began in December 2024 and continued after the Data (Use and Access) Act changed the underlying rules. The framing shift is the first thing to notice. Cookies are no longer the organising concept. The guidance addresses storage and access technologies as a category: cookies, tracking pixels, device fingerprinting, web storage including HTML5 local storage and IndexedDB, scripts, tags and link decoration. The ICO's position is that where a technology stores information on a device or accesses information stored there, it is potentially in scope regardless of what it is called.

The Act also introduced five categories exempt from the consent requirement, effective 5 February 2026. Technologies used for transmitting a communication. For providing a service the user has requested. For collecting statistical information about visitors in order to improve the service. For adapting the appearance of a service to a user's preference. And for identifying a user who requires emergency assistance.

The statistical category looks like a gift to analytics teams. It is not, and this is the single most practically important line in the whole guidance. Where one technology serves both an exempt purpose and a non-exempt purpose, the two cannot be collapsed into a single deployment and called exempt. Either the technologies are separated, deploying one for the exempt purpose and obtaining consent for the other, or consent is obtained for all of it.

Consider what that means for an ordinary search engagement. An analytics tool that also feeds advertising measurement is the default configuration in most of them. It does not become exempt because part of what it does would have qualified. The exemptions are purpose-limited in a strict sense, and the ICO has said so directly.

Which is why a supplier should never tell you analytics cookies are always exempt. Configuration, purpose, data use and the applicable exception determine the answer, and the answer differs between two implementations of the same tool. The correct response to that question is a request to see the configuration, not a reassurance.

Enforcement context is worth having. The ICO reviewed the UK's top 1,000 websites and reported that by April 2026 around 99% met its cookie compliance checks, with a stated intention to keep testing periodically. The exposure sits with the organisations whose banner renders but does not actually block anything, because that is a breach that looks like compliance from the inside.

The territorial scope question nobody should answer confidently

There is one more layer, and it is the one where overseas suppliers most often overreach. A supplier outside the UK is not automatically limited to the role of processor acting on instructions. It can fall directly within the UK GDPR's territorial scope, particularly where it offers goods or services to people in the UK or monitors their behaviour.

Whether that applies is fact-specific. It depends on what the supplier does, for whom, and how the relationship is structured. A processor acting only on a UK client's instructions still needs appropriate contractual and security controls even where the client remains principally responsible for the transfer mechanism.

Related to this is Article 27, which requires controllers and processors outside the UK to appoint a UK representative in certain circumstances, with an exemption where processing is occasional, does not involve large-scale special category or criminal offence data, and is unlikely to result in a risk to individuals' rights. Those conditions are cumulative. Fail any one and the exemption is gone.

Some suppliers reach for that exemption and conclude that ordinary search work sits comfortably inside it. Be careful with that reasoning. Occasional is not defined in the regulation, and regulatory guidance interprets it narrowly. In practice few organisations qualify, particularly those operating online services. Processing that recurs and forms part of regular business activity, which describes a monthly retainer precisely, is the paradigm case of processing that is not occasional.

The honest position on both questions is that they need legal input, not a confident paragraph on a supplier's website. Any page that hands you a clean yes or no is telling you more about its own risk appetite than about your obligations.

What to actually ask, and in what order

Turn all of this into procurement questions and the list gets short. Which legal entity is contracting with us. Which named people and which subcontractors can access our systems or personal data. Where is data processed and stored, by region. Which Article 46 instrument will cover access from outside the UK, the IDTA or the Addendum. What will you provide as input to our transfer risk assessment. Who has authority to publish content or alter production systems. What can we retain on exit, covering accounts, data, dashboards, briefs and assets.

Two of those questions are worth more than the rest. The subprocessor question, because onward transfers are where mapped data flows quietly stop being mapped. And the exit question, because a supplier that cannot answer it cleanly has usually built something you cannot take with you.

Notice what is not on the list. Nothing about whether a supplier feels strongly about data protection. The list is entirely about documents, named locations and specific instruments, because those are the things a vendor security review can actually verify. Sentiment is not verifiable and does not survive an audit.

Why this is the first thing rather than the last

Research into UK buyer objections to overseas delivery converges on an uncomfortable finding. The blocker is rarely capability. It is compliance and trust, and the concern is legitimate rather than prejudiced. UK agency shortlists actively market UK-based support and no outsourcing as a differentiator, which tells you the objection converts.

The response that works is not a lower price. It is putting the compliance position in writing before anyone has to ask for it, in a form a procurement team can lift straight into a vendor security review. Everything in this article is publicly verifiable against ICO guidance and the statute, which is exactly what makes it useful. Claims about a supplier's own diligence are not checkable. Statements about what the regulator requires are.

The same principle runs through how we approach organic search work for the UK market. Sourced, dated, and stated with its limits. If a figure is contested, that gets said on the page rather than quietly resolved in whichever direction flatters the argument.

This article is operational information rather than legal advice. Engagements involving UK personal data should be reviewed by qualified counsel, and the analysis here is intended to make that conversation shorter rather than to replace it.


Frequently Asked Questions


Is it legal for a UK business to use an SEO agency based outside the UK?

Yes, and it is common. Location is not a prohibition. What follows from location is a set of obligations under Chapter V of the UK GDPR once personal data is sent or made accessible to a separate legal entity outside the UK. The compliance question is which safeguard covers the transfer and who completes the assessment, not whether the arrangement is permitted.


What is the ICO's three step test?

Introduced in the ICO's rewritten international transfers guidance published on 15 January 2026, it asks three questions. Does the UK GDPR apply to the processing of the personal data being sent. Is the transfer to an organisation outside the UK. Is the recipient a separate legal entity from the sender. Yes to all three makes it a restricted transfer, and the international transfer rules apply even where the recipient is itself subject to the UK GDPR.


Does granting a supplier access to Search Console count as a transfer?

It can. The rules are triggered by making personal data accessible, not only by sending it. Granting a login to a system containing personal data relating to people in the UK is capable of being a restricted transfer even though nothing was emailed or exported. This is why access provisioning belongs in the data flow map rather than being treated as an IT housekeeping task.


Which countries hold UK adequacy, and does it cover Southeast Asia?

Full UK adequacy currently covers Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, Switzerland and Uruguay, alongside the EEA, with partial mechanisms including the UK extension to the EU-US Data Privacy Framework. Most jurisdictions where offshore digital delivery happens, including Indonesia, are not covered, so an Article 46 safeguard is required instead. Note also that the UK and EU lists have started to diverge: Brazil holds an EU adequacy decision but is not covered by UK adequacy regulations.


Should we use the IDTA or the UK Addendum?

Either satisfies the requirement, so the choice is practical. The International Data Transfer Agreement is a standalone UK contract and usually reaches signature faster because there are fewer variables to negotiate. The UK Addendum modifies the 2021 EU Standard Contractual Clauses and suits organisations already running those clauses for European transfers, avoiding papering the same relationship twice. For high-value or high-risk relationships the SCC and Addendum route produces a more granular contractual record. Note that the IDTA handles processor obligations through a linked agreement, so a separate data processing agreement covering Article 28 terms is still needed.


Can we still rely on the older EU Standard Contractual Clauses?

No. The IDTA and UK Addendum came into force on 21 March 2022. New arrangements have had to use one of them since 22 September 2022, and existing arrangements resting on the Directive-era EU SCCs had until 21 March 2024 to be repapered. That deadline has passed, so a contract still relying on the old clauses for a UK restricted transfer is transferring data without appropriate safeguards. That is a live compliance failure rather than an administrative backlog item.


What standard does a transfer risk assessment apply, and did it change?

It changed on 5 February 2026. The Data (Use and Access) Act 2025 amended the description of the required level of protection for both adequacy and appropriate safeguards, adopting a standard that protection in the destination must be not materially lower than under UK law. The previous formulation was sufficiently similar. The ICO recognises three approaches to conducting the assessment: its own TRA tool, the European Data Protection Board methodology as a comparator, or an alternative the organisation can justify. Assessments completed before the new rules took effect in line with the previous law can still be relied on.


Who is responsible for making sure a restricted transfer is covered?

The party that initiates the transfer. The ICO's 2026 guidance is explicit that this allocation applies regardless of whether the initiating party is acting as controller or processor, so responsibility follows the reality of who initiated and who procured rather than an assumption about which side of the relationship owns transfer risk. Where a controller relies on a processor, the controller's duty is to make reasonable and proportionate checks under its Article 28 obligation that the processor provides sufficient guarantees.


How much can the ICO now fine a business for a PECR breach?

The higher of £17.5 million or 4% of global annual turnover, up from a £500,000 cap that had stood since 2003. The critical detail is the date. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, but the new ceiling arrived through Commencement Order No. 6 on 5 February 2026 and applies only to conduct from that date onward. Earlier breaches remain under the old cap. The requirement to prove substantial damage and distress has also been removed, lowering the bar for enforcement.


Are analytics cookies exempt from consent under PECR?

Not automatically. Five exemption categories have applied since 5 February 2026, including collecting statistical information about visitors to improve a service, but they are purpose-limited in a strict sense. Where one technology serves both an exempt and a non-exempt purpose, the two cannot be collapsed into a single deployment and treated as exempt. An analytics tool that also feeds advertising measurement, which is the default configuration in most search engagements, does not qualify because part of what it does would have. Either the technologies are separated or consent is obtained for all of it.


What counts as a tracking technology under the current guidance?

More than cookies. The ICO's finalised guidance of 29 April 2026 deliberately drops cookies as the organising frame and addresses storage and access technologies as a category, covering cookies, tracking pixels, device fingerprinting, web storage including HTML5 local storage and IndexedDB, scripts, tags and link decoration. The ICO's position is that where a technology stores information on a device or accesses information stored there, it is potentially within PECR Regulation 6 regardless of how it is labelled or deployed.


Does an overseas supplier need to appoint a UK representative under Article 27?

It depends, and the exemption is narrower than suppliers often assume. Article 27 requires a UK representative where a controller or processor outside the UK is caught by the extraterritorial scope provisions, with an exemption where processing is occasional, does not include large-scale processing of special category or criminal offence data, and is unlikely to result in a risk to individuals' rights. Those conditions are cumulative, so failing any one removes the exemption. Occasional is not defined in the regulation and regulatory guidance interprets it narrowly. Processing that recurs and forms part of regular business activity, which describes a monthly retainer, is the paradigm case of processing that is not occasional. This needs legal input rather than a confident answer from a supplier.

Sources & References:

  • Information Commissioner's Office, "A guide to international transfers", updated 15 January 2026. The update broke the previous single guide into task-based detailed guides and introduced a three step test for identifying restricted transfers, alongside a brief guide, quick-reference FAQs, a glossary, worked examples and an interactive tool. Further ICO guidance on transfer risk assessments, the IDTA and cloud services was flagged as still to come.
  • ICO, "Adequacy regulations" and "Is the restricted transfer covered by adequacy regulations?". Full UK adequacy: Andorra, Argentina, Faroe Islands, Gibraltar, Guernsey, Isle of Man, Israel, Jersey, New Zealand, Switzerland, Uruguay, alongside the EEA. Partial mechanisms include the UK extension to the EU-US Data Privacy Framework, restricted to US businesses regulated by the FTC or DOT and to the data categories they have registered to receive. Page updated 30 July 2026 to clarify that UK adequacy regulations for the US are independent of the EU's adequacy finding.
  • Transitional provisions for the IDTA and UK Addendum: both instruments laid before Parliament 2 February 2022 and in force 21 March 2022. New arrangements required to use them from 22 September 2022. Repapering deadline for legacy Directive-era EU SCCs, 21 March 2024. Verified across analysis from Bird & Bird, Travers Smith, Freshfields, DWF, Orrick and the DPO Centre.
  • Data (Use and Access) Act 2025: Royal Assent 19 June 2025, passed by Parliament 11 June 2025. Majority of provisions commenced 5 February 2026 via Commencement Order No. 6, with further obligations following 19 June 2026 including a formal complaints procedure requirement with a 30-day acknowledgement obligation. Transfer provisions adopt a "not materially lower" data protection test, replacing "sufficiently similar". Verified across Mayer Brown, Addleshaw Goddard, Blake Morgan and Kennedys Law analysis.
  • PECR penalty change: maximum fine raised from £500,000 to the higher of £17.5 million or 4% of global annual turnover, aligning PECR with UK GDPR maxima. Applies to conduct occurring after 5 February 2026; earlier breaches remain under the previous cap. The requirement to prove substantial damage and distress has been removed. ICO enforcement powers extended to compelling witness interviews and requesting technical reports and audits.
  • PECR enforcement history: between 2019 and 2025 the ICO issued 119 fines under PECR against 16 under the UK GDPR, reflecting the lower evidential threshold for PECR. Analysis by DPAS, December 2025.
  • ICO, "Guidance on the use of storage and access technologies", finalised 29 April 2026 following two consultations, the first opened December 2024 and the second on PECR changes under the Data (Use and Access) Act in July 2025. Two new sub-chapters added at final stage, covering what a simple means of objecting means and whether the same technology can be used for multiple purposes. Scope covers cookies, tracking pixels, device fingerprinting, web storage, scripts, tags and link decoration under PECR Regulation 6. Published alongside an update to the ICO's online tracking strategy, and separate from ongoing ICO work reviewing PECR Regulation 6 for online advertising purposes.
  • Five DUAA exemption categories effective 5 February 2026: transmission of a communication; providing a service requested by the user; collecting statistical information about visitors to improve the service; improving or adapting the appearance of a service to a user's preference; identifying a user requiring emergency assistance. Exemptions are purpose-limited; a technology serving both exempt and non-exempt purposes cannot be treated as exempt.
  • ICO cookie compliance testing: review of the UK's top 1,000 websites, with approximately 99% reported as meeting compliance checks by April 2026, and a stated intention to continue periodic testing. ICO actions on cookie compliance, January 2025 and December 2025.
  • Allocation of responsibility: the ICO's 2026 guidance states that the party initiating a restricted transfer is responsible for ensuring it is covered by adequacy regulations, Article 46 appropriate safeguards or an Article 49 derogation, and that this allocation applies regardless of whether the initiating party acts as controller or processor. Where a controller relies on a processor, the controller must make reasonable and proportionate checks under its Article 28 obligation.
  • UK GDPR Article 27 and the Article 27(2) exemption: conditions are cumulative, requiring processing that is occasional, does not include large-scale processing of special category data under Article 9(1) or criminal offence data under Article 10, and is unlikely to result in a risk to the rights and freedoms of individuals. "Occasional" is not defined in the regulation and is interpreted narrowly in regulatory guidance; in practice few organisations operating online services qualify.
  • UK and EU divergence: Brazil is the subject of a European Commission adequacy decision but is not covered by UK adequacy regulations. Freshfields analysis of the ICO's 2026 guidance, March 2026.
  • This article is operational information for procurement and marketing teams, not legal advice. Engagements involving UK personal data should be reviewed by qualified counsel.
0 Comments 0 Comments
0 Comments 0 Comments