International Personal Data Transfer Safeguards Procedure
- Version
- v1
- Updated
- 7 October 2026
- Reviewed
- 7 October 2026
Fields in brackets are completed when you adapt this template.
This procedure applies to [school name] only where the school makes or relies on international transfers of personal information, including transfers through suppliers or cloud services. Where no such transfer is made or relied upon, this procedure is not applicable.
1. Identify the transfer
The [procedure owner role] should identify whether personal information is transferred internationally, including whether a supplier or cloud service transfers or provides access to the information outside the relevant jurisdiction.
Record the relevant transfer in the school’s transfer and supplier inventories, including the destination and the supplier or service involved where applicable.
2. Determine the applicable safeguards
For each identified transfer, determine the transfer agreement and contractual safeguards that apply to the destination, transfer mechanism, supplier arrangements and available evidence.
Where binding corporate rules may be relevant, consider them as part of the available safeguards and record the basis for the decision.
3. Carry out a transfer risk assessment where required
Carry out a transfer risk assessment where required for the transfer and record the assessment, its scope, the destination considered and the safeguards relied upon.
If the available information or evidence does not support the proposed safeguards, refer the matter to [escalation role] before relying on the transfer arrangement.
4. Complete supplier due diligence
For transfers involving a supplier or cloud service, document the processor due diligence undertaken and retain the relevant supplier information, transfer arrangements and contractual safeguards.
5. Maintain the records
Keep the transfer and supplier inventories, transfer agreements, transfer risk assessments, contractual safeguards, records of destinations and processor due diligence together with the relevant transfer record.
Update the records when the destination, transfer mechanism, supplier arrangements or available evidence changes.
Sources
- UK GDPR guidance and resources | ICOInformation Commissioner's Office (ICO)
