---
visibility: public
Language:
  - English
tags:
  - Privacy
  - international-transfers
  - United-Kingdom
Publication Date: '2023-10-03'
Publication Type:
  - Blog Post
Ext. Link: >-
  https://www.cyberlawwatch.com/2023/10/03/uk-government-approves-adequacy-of-uk-us-data-bridge/
Source: K&L Gates Hub
Author(s):
  - '[[Claude-Étienne Armingaud]]'
  - '[[Nóirín McFadden]]'
NoteType: Publications
icon: "\U0001F4DA"
date: '2023-10-03'
title: UK Government Approves Adequacy of UK-US Data Bridge
created: '2023-10-03'
modified: '2023-10-03'
published: '2023-10-03'
---

The UK Government has [**laid adequacy regulations before Parliament**](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-explainer) that, once in force from 12 October 2023, will permit use of the UK – US “Data Bridge” as a safeguard for [[personal data]] transfers from the UK to the US under [**Article 44 UK GDPR**](https://www.legislation.gov.uk/eur/2016/679/article/44).

The UK – US “Data Bridge,” AKA the UK Extension to the [**EU – US Data Privacy Framework**](https://www.dataprivacyframework.gov/s/) (Framework), allows UK organisations to transfer personal data to organisations located in the United States that have self-certified their compliance with certain data protection principles and appear on the [**Data Privacy Framework List**](https://www.dataprivacyframework.gov/s/). This scheme, administered by the [**US Department of Commerce**](https://www.commerce.gov/), provides a redress mechanism for [[data subject|data subjects]] in the European Union to enforce their rights under the **EU [[Official Texts/GDPR|GDPR]]**, in relation to a participating US organisation’s compliance with the Framework, and to US national security agencies’ access to personal data. This new redress mechanism attempts to prevent a challenge to the Framework similar to the [[Data Protection Commissioner v Facebook Ireland Ltd, Maximillian Schrems (Schrems II)|Schrems II]], which invalidated the Framework’s predecessor, the EU-US Privacy Shield (see our alert [[EU Data Protection - Privacy Shield Shattered by the Sword of European Justice - What Comes Next for Transatlantic Dataflows]]). Despite this, the Framework has already been the subject of a short-lived [**case**](https://www.politico.eu/wp-content/uploads/2023/09/07/4_6039685923346583457.pdf) at the Court of Justice of the EU, and there may be more legal challenges.

Alongside the adequacy regulations, the UK government published an [**analysis**](https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1185427/analysis_of_the_uk_extension_to_the_eu-us_data_privacy_framework.pdf) of the US laws relating to US national security agencies’ access to the personal data of European data subjects. This analysis effectively completes the international data [**transfer risk assessment**](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-data-transfer-agreement-and-guidance/international-data-transfer-agreement-and-guidance/transfer-risk-assessments/) (TRA), which UK organisations have been required to carry out before transferring personal data to the US. It is likely that UK organisations relying on the other [**Article 44 UK GDPR**](https://www.legislation.gov.uk/eur/2016/679/article/44) safeguards, such as the **[[International Personal Data Transfers An Eventful Week|International Data Transfer Agreement]]**, may also rely on this analysis in place of completing a TRA.

**First published** on [K&L Gates Cyber Law Watch](https://www.cyberlawwatch.com/2023/10/03/uk-government-approves-adequacy-of-uk-us-data-bridge/) By [**Claude-Étienne Armingaud**](https://www.linkedin.com/in/armingaud/) and [**Nóirín McFadden**](https://www.klgates.com/Noirin-M-McFadden)
