Sending legal work offshore: the IDTA and the data protection test
17 August 2026 · 8 minute read
General orientation for firms considering outsourced legal support, not legal advice. Rules change and every firm's position differs, so check the current text of anything referred to here and take your own advice before relying on it. Northbound Legal Ltd is not a law firm and is not authorised or regulated by the Solicitors Regulation Authority.
A firm considering offshore legal support usually asks the data protection question second, after price and quality. It is worth asking first, because it is the one with a wrong answer that is expensive to unwind, and because the answer shapes how the arrangement should be built rather than merely whether it is allowed.
What triggers the analysis
Under UK GDPR, sending personal data outside the UK to a separate organisation is a restricted transfer. Matter files are full of personal data: clients, witnesses, opponents, beneficiaries, medical and financial detail. So if a delivery team sits outside the UK and receives that material, a restricted transfer is happening and it needs a lawful basis for the transfer on top of the ordinary lawful basis for processing.
There are three broad routes. The transfer is to a country covered by UK adequacy regulations; or it relies on an Article 46 safeguard such as the International Data Transfer Agreement, the Addendum to the EU Standard Contractual Clauses, or binding corporate rules; or it falls within one of the narrow exceptions. For most offshore delivery arrangements the middle route is the relevant one.
The IDTA and the Addendum
The UK has two standard instruments. The IDTA is a standalone UK agreement. The Addendum is a short document that bolts the UK requirements onto the EU Standard Contractual Clauses, which is convenient where an organisation already uses the EU clauses across a group. They achieve the same thing. Which one you use is a practical choice about paperwork, not a difference in protection.
Neither is a form to be signed and filed. They allocate obligations, and the schedules describing the transfer, the categories of data and the security measures are the part that actually gets read if anything goes wrong. A provider that hands you a signed IDTA with empty or generic schedules has given you a document, not a safeguard.
The assessment behind it, now called the data protection test
Relying on an Article 46 safeguard is not sufficient on its own. The transferring organisation also has to assess whether the protection for people's information will still hold up in the destination country. The ICO has long called this a transfer risk assessment. Note the change of vocabulary: following the Data (Use and Access) Act, the legislation now refers to this as a data protection test, and the ICO's guidance has followed suit.
The standard is that, acting reasonably and proportionately, you conclude the protection for people's information is not materially lower than it would be in the UK. That wording rewards proportion. It does not ask you to prove the destination is identical to the UK, and it does not let you wave the question through because the contract looks tidy.
Two practical points firms get wrong. First, the obligation sits with whoever initiates the restricted transfer, which is the firm, not the provider. A provider can supply the material to make the assessment straightforward, and a good one will, but it cannot do the assessment for you. Second, the assessment is about the destination country's legal environment as well as the provider's controls, so "they use encryption" is an input, not a conclusion.
Where South Africa sits
South Africa is not covered by UK adequacy regulations. A transfer of matter data to a South African delivery team is therefore a restricted transfer needing a safeguard and the data protection test behind it, exactly as set out above.
Two things make the analysis more comfortable than the bare position suggests. South Africa has its own comprehensive data protection statute, the Protection of Personal Information Act 2013, so the delivery operation is regulated at home rather than operating in a vacuum. And the common law tradition means the substantive work translates, which is a quality point rather than a data protection one, but it is usually the next question anyway.
The option that removes the question
There is a route that is easy to overlook: do not transfer the data at all. Where the delivery team works under scoped access inside the firm's own case management system, matter data stays in systems the firm controls. Access from abroad still needs thinking about, and the firm should treat remote access with the same seriousness as any other access, but the analysis is materially simpler than shipping copies of files to a third party's environment.
In our experience most firms that start with "we cannot send data offshore" are able to proceed on this basis, because their objection was to the copy leaving, not to the person working.
What to ask a provider
- Which mechanism do you sign, the IDTA or the Addendum, and can we see it now?
- Will you give us the information we need for our data protection test, including your security measures and any local law issues you are aware of?
- Can your team work inside our systems instead, and what would that require?
- Who exactly has access, and how is that access removed when someone moves off our work?
- What is your breach notification commitment, in hours, and to whom?
- On exit, is data returned or deleted, at whose election, and how is that evidenced?
A provider that answers these crisply has done this before. One that treats them as obstacles will treat your clients' data the same way.
Our own answers to all of the above are in our privacy and data processing notice, including the sub-processors we use and where they sit.
Sources
- ICO: international transfers
- ICO: what are standard data protection clauses, the UK IDTA and the Addendum
- ICO: transfer risk assessments and the data protection test
Talk to us about your caseload
The fastest way to judge whether this works for your firm is to give us one real task for a fixed fee of £250, credited in full against your first month.