Rows of green data characters on a dark screen, representing data governance, international transfers and accountability

Data Governance, Transfers and Accountability

A controller must be able to show from its own records what personal data it processes, why, on what legal basis and where it goes (Article 5(2) and Article 30 UK GDPR). Where those records do not match what the business actually does, the controller cannot defend a transfer, explain its reliance on legitimate interests to the ICO, or answer a breach investigation with anything the regulator can check.

When data governance and accountability obligations apply

On an audit or investigation, the ICO can require the record of processing activities (ROPA) that Article 30 UK GDPR obliges the controller to maintain, and an assessment notice under section 146 of the Data Protection Act 2018 can require premises, documents, information and equipment to be made available and a report to be commissioned from an approved person at the controller’s expense. What the ICO then reads is the record as it stands, the controller and processor agreements as signed, and whatever legitimate interests assessment (LIA) the controller in fact wrote. On an M&A transaction, the buyer’s lawyers will examine whether the target has documented its processing accurately, governed cross-border transfers through compliant mechanisms and maintained accountable relationships with third parties. When a breach occurs, a customer objects or a regulator opens an investigation, the documentation is the evidence, and a controller whose records are out of date cannot explain its processing, justify the legal basis it relied on or defend its transfer mechanism.


Why governance and accountability matter now

The Data (Use and Access) Act 2025 (DUAA) rebuilt Chapter V of the UK GDPR with effect from 5 February 2026, and two different tests now share one phrase. Articles 44 and 45 are omitted. Under Article 45A the Secretary of State may approve transfers to a third country by regulations, and may do so only where the Secretary of State considers that the data protection test in Article 45B is met, namely that the standard of protection in that country is not materially lower, taken as a whole, than the standard under the UK GDPR and the relevant Parts of the Data Protection Act 2018. Where a controller or processor instead relies on appropriate safeguards, Article 46(1A) requires both safeguards of a kind listed in Article 46(2) or (3) and the controller’s or processor’s own judgement, reached reasonably and proportionately, that the protection for the data subject after the transfer would not be materially lower than the UK standard (Article 46(6)). The adequacy question is for the Secretary of State; the transfer question is for the controller. The transfer risk assessment (TRA) is the ICO’s method for answering the second, not a separate statutory duty. The ICO updated its international transfers guidance on 15 January 2026, setting out a three-step test for identifying a restricted transfer, and has said that its approach to transfer risk assessments will be developed further. The recognised legitimate interests basis in Article 6(1)(ea) of the UK GDPR (as retained in UK law and amended by the DUAA) is narrower than it sounds. Article 6(5) allows it only where the processing is necessary for a purpose that meets one of the conditions in Annex 1 to the UK GDPR, and Article 6(6) lets the Secretary of State add to or vary that list by regulations. It is not open to a public authority in the performance of its tasks. A controller relying on it should record which Annex 1 condition applies and why the processing is necessary for that purpose, and should say so in its privacy notice. A statutory complaints duty applies to complaints received on or after 19 June 2026 under section 164A of the Data Protection Act 2018, inserted by section 103 of the DUAA and commenced by SI 2026/82. A controller must facilitate the making of complaints, by steps such as providing a complaint form that can be completed electronically and by other means, must acknowledge receipt within 30 days beginning when the complaint is received, and must without undue delay take appropriate steps to respond and inform the complainant of the outcome. The DUAA also gave the ICO new enforcement powers, and the three that matter here all took effect on 5 February 2026. Section 98 added to the assessment notice power in section 146 of the Data Protection Act 2018: a notice may now require the controller or processor to make arrangements for an approved person to prepare a report on a specified matter, and the controller or processor is liable for that person’s remuneration and expenses. Section 99 removed the restriction in section 147(6) that had prevented an assessment notice being given to Ofsted. Section 100 inserted sections 148A to 148C, which allow the Commissioner, when investigating a suspected failure or offence, to require by interview notice that an individual who is or was the controller or processor, worked for it, or was concerned in its management or control, attend at a specified place and answer questions; where the Commissioner states that attendance is needed urgently and gives reasons, the notice may not require attendance before the end of 24 hours beginning when it is given. A controller served with an assessment notice must produce the records as they stand, and an individual served with an interview notice must attend and answer.


Where governance frameworks fail

Record of Processing Activities exist but are never updated. They describe processing in high-level categories rather than specific systems, tools, and data flows. They do not reflect changes to technology infrastructure, vendor relationships, or business objectives. Controller and processor agreements are boilerplate, often missing clauses that reflect the actual scope of the processor’s authority and decision-making role. International transfer mechanisms are chosen on cost grounds without running a Transfer Risk Assessment aligned to the ICO’s updated guidance and the DUAA’s “not materially lower” test. Legitimate Interests Assessments pre-date the DUAA and do not address recognised legitimate interests or updated ROPAs. Privacy notices use abstract language about “marketing and business development” without explaining how personal data flows to specific systems, marketing platforms, and third parties. Controller and processor roles are misaligned with contractual structures: a party claims to be a processor when in practice they are making processing decisions, or vice versa. Governance documentation is drafted once, filed and not revisited when the law or the business changes. A controller whose records describe processing it no longer carries out cannot rely on them in an investigation.


What effective data governance looks like

Records of Processing Activity must link directly to actual data flows. Article 30(1) requires the record to state the purposes of the processing, the categories of data subject and of personal data, the categories of recipient, transfers to third countries, the envisaged erasure periods where possible and a general description of the security measures. A workable entry also names the system and the lawful basis and cross-refers to any Legitimate Interests Assessment. As recommended practice, these records should be reviewed quarterly. When business processes change, ROPAs are updated. When a data processor relationship ends, the ROPA is amended. When a new service (such as a marketing automation platform) is adopted, a new ROPA entry is created. Controller and processor allocations must reflect substantive analysis, not contractual labels. If a third party in practice jointly determines the purposes and essential means of processing, that party is a joint controller and must be named as such in the legal documents and privacy notices. A service provider that processes only on the controller's documented instructions is a processor, even where it exercises discretion over non-essential technical and organisational means. That allocation must be documented and periodically audited. International transfer arrangements should be proportionate to the organisation’s risk profile. For low-risk personal data transfers (such as aggregate anonymised data or non-sensitive business contact information) to countries with mature legal frameworks, controllers may run a streamlined Transfer Risk Assessment. For sensitive personal data transfers to countries with broader law enforcement access or fewer data protection laws, a detailed assessment is warranted. The ICO’s three-step test and updated guidance provide the methodology. Reliance on recognised legitimate interests must be documented. Where processing relies on Article 6(1)(ea), the controller must identify which condition in Annex 1 applies, explain why the processing is necessary for that purpose, update the ROPA, and ensure the privacy notice explains the basis and that no balancing test applies to it. Privacy programme design must be tailored to the organisation’s risk profile and structure. A large group with processing in multiple jurisdictions requires a more elaborate governance framework than a small practice handling UK-only data. The governance framework should specify roles and responsibilities, escalation routes for data subject access requests and complaints, incident response procedures, and regular audit cycles.


When to instruct a specialist on data governance

Bratby Law advises on data governance in three engagement models: Direct Legal Advice for specific governance challenges; Specialist Co-counsel where internal legal teams are managing governance but need expert input on complex areas; and Fractional General Counsel for organisations without in-house data protection resources. Specialist input is warranted for international transfer arrangements (particularly where an organisation is applying the DUAA’s “not materially lower” test and designing compliant mechanisms across multiple jurisdictions), ICO engagement (especially where the ICO has served an assessment notice requiring a report from an approved person, or has opened an investigation), M&A data protection due diligence (buying or selling a business), DUAA 2025 implementation (updating ROPAs, Legitimate Interests Assessments, privacy notices, and complaints procedures), and designing governance frameworks for complex group structures or high-risk processing. Controller and processor relationships should also be reviewed where there is uncertainty about role allocation or where contractual relationships do not reflect actual practice.


FAQs

What is the “not materially lower” standard and how does it differ from “essentially equivalent”?

The DUAA put a statutory data protection test in place of the adequacy framework in the former Article 45. Where the Secretary of State approves transfers to a third country by regulations, Article 45B asks whether the standard of protection there is not materially lower than the UK standard, taken as a whole, and lists what the Secretary of State must consider: respect for the rule of law and for human rights, the existence and powers of an authority enforcing data protection, judicial and non-judicial redress, onward transfer rules, relevant international obligations, and the constitution, traditions and culture of the country. “Essentially equivalent” does not appear in the UK statute. It is the formulation the European Data Protection Board uses when assessing a third country, and the Board has said the UK test removes elements that figured in the previous UK adequacy test and that play an important role in that assessment (Opinion 26/2025 on the UK adequacy decision, adopted 16 October 2025, paragraphs 42 and 87). How the UK test is applied in practice will be settled by ICO guidance and, in time, by decided cases. On the appropriate safeguards route the test is the one in Article 46(6) and the judgement is the controller’s.

Do we need to update our ROPAs and privacy notices for recognised legitimate interests?

Yes. Article 6(1)(ea) UK GDPR is available only where the processing is necessary for a purpose that meets one of the conditions in Annex 1 to the UK GDPR: disclosure to another person who needs the data for a task described in Article 6(1)(e); safeguarding national security, protecting public security or defence purposes; responding to an emergency within the meaning of Part 2 of the Civil Contingencies Act 2004; detecting, investigating or preventing crime, or apprehending or prosecuting offenders; and safeguarding a vulnerable individual. Under Article 6(6) the Secretary of State may add to or vary that list by regulations. Record in the ROPA which condition applies and why the processing is necessary for that purpose, and say in the privacy notice that the basis is Article 6(1)(ea) and that no balancing test applies to it. The basis is not open to a public authority in the performance of its tasks.

What does the new complaints handling obligation require?

Section 164A of the Data Protection Act 2018 applies to complaints a controller receives on or after 19 June 2026. A data subject may complain to the controller about an infringement of the UK GDPR or Part 3 of the 2018 Act. The controller must facilitate the making of complaints, by steps such as providing a complaint form that can be completed electronically and by other means; must acknowledge receipt within 30 days beginning when the complaint is received; and must, without undue delay, take appropriate steps to respond and inform the complainant of the outcome. Taking appropriate steps includes making enquiries into the subject matter to the extent appropriate and informing the complainant about progress. There is no small-organisation exemption of the kind Article 30(5) UK GDPR gives for records of processing, so a sole practitioner needs a process too, however short.

How should we assess international transfers under the DUAA and ICO guidance?

Start with the ICO’s three-step test for whether the transfer is a restricted one: does the UK GDPR apply to your processing of the information you are sending, are you the organisation initiating the transfer to an organisation located outside the UK, and is the receiving organisation a separate legal entity from you. If all three are met, check first whether regulations under Article 45A approve transfers to that country. If they do not, you are on the appropriate safeguards route, and Article 46(1A) requires you to reach your own view, reasonably and proportionately, that the protection for the data subject after the transfer would not be materially lower, taken as a whole, than the UK standard. That is what a transfer risk assessment records: the legal protections in the destination country, the access regimes that bear on them, and the practical safeguards such as encryption or minimisation.

What should our controller and processor agreement cover?

The agreement should specify who determines the purposes and essential means of processing. A provider that determines those jointly with you is a joint controller; discretion limited to non-essential technical means leaves it a processor. Where the provider is a processor, the agreement should set out its instructions, the permitted sub-processors, the duration of processing and the controller’s audit rights. The agreement must reflect actual data flows and decision-making authority. If the contractual relationship does not match practice, the agreement is not a credible defence in an ICO investigation or court proceeding.

How often should we review and update our governance documentation?

As recommended practice, quarterly for ROPAs, Legitimate Interests Assessments, and transfer documentation; the UK GDPR prescribes no review interval, but Article 30 requires the record to contain the information it lists and Article 5(2) requires the controller to be able to demonstrate compliance. More frequent reviews are warranted if you deploy new processing systems, change data processors, enter new international markets, or materially change the scope of processing.

Advice on data governance and international transfers

Representative experience

Recent and representative matters include:

  • Designed a data governance framework for a telecoms group, establishing controller/processor mapping, data flow documentation and Article 30 records across 12 operating entities.
  • Advised a multinational technology company on the transfer mechanisms available for UK-to-US and UK-to-Asia data flows under the UK GDPR, including the UK International Data Transfer Agreement.
  • Negotiated and drafted data processing agreements under Article 28 for a SaaS platform with sub-processors across multiple jurisdictions, including the implementation of UK Addendum to the EU SCCs.
  • Reviewed binding corporate rules for a global financial services group, assessing their compliance with the UK GDPR transfer provisions and the ICO’s approval criteria.
  • Advised on the data protection implications of a corporate restructuring involving the transfer of customer databases between group entities, including controller succession and re-consenting requirements.

Rob Bratby advises on data governance and international transfers drawing on his regulatory background and General Counsel experience at businesses processing large volumes of personal data. The Lexology Index recognises Rob Bratby as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection.

Related data protection pages

See also our other data protection pages:

UK GDPR Compliance
Lawful Basis and Legitimate Interests
Data Protection Impact Assessments
UK/EU Data Protection Divergence
AI and Automated Decision-Making
The EU AI Act: what UK businesses need to know
Sector-Specific Data Protection
Data Breach Response and ICO Notification
PECR and ePrivacy

How does data governance differ from data protection compliance?

Data governance is broader than compliance with any single regulation. It encompasses the organisational policies, processes and controls for managing data across the business, including data quality, classification, retention and access. Data protection compliance is one element of data governance, which also covers commercial data use and data ethics. A controller can only demonstrate accountability under Article 5(2) UK GDPR from records that are current.

Independent directory rankings

Our specialist expertise is recognised in major independent legal directories:

  • Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
  • The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
  • Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology
Chambers and Partners accreditation
Legal 500 accreditation
Lexology Global Elite Thought Leader accreditation

The Core Communication and TelXL case studies cover data governance and international transfers.

Discuss your matter