A UK company hiring an engineer in Warsaw doesn't need an international data transfer agreement. Neither does an EU company sending data to an engineer working from the UK. The European Commission's adequacy decision for the UK, renewed in December 2025, covers the EU-to-UK direction, and the UK's own adequacy regulations cover every EU member state going the other way. A transfer agreement only becomes necessary when data leaves that adequacy zone, for example to an engineer in Serbia.
What is an international data transfer agreement?
The phrase "international data transfer agreement" gets used for three separate tools: the UK's International Data Transfer Agreement (IDTA), the UK Addendum to the EU's Standard Contractual Clauses (the Addendum), and the EU's own Standard Contractual Clauses (SCCs). Each is a legal safeguard a company signs when it moves personal data to a country that doesn't already have an adequacy decision covering it.
The ICO's international transfers guide sets out three ways a UK exporter can lawfully make a restricted transfer: rely on adequacy regulations, put an appropriate safeguard in place (the IDTA, the Addendum, or binding corporate rules), or fall back on one of a short list of exceptions. Adequacy comes first because, where it applies, no separate agreement is needed at all.
Before working through which of the three applies to your engagement, settle a narrower question first. Whether your development partner is a data controller or processor determines who's responsible for the data once it moves, and you need that answer before the transfer question is answerable at all.
This sits inside the broader set of compliance questions a company hiring across EU and UK borders has to work through, alongside IP assignment and Article 28 processor terms, covered in EU engineering hiring compliance: contracts, IP and GDPR.
When you don't need one: adequacy decisions between the UK and EU
A UK company hiring an engineer in Poland, Hungary, Slovakia, Slovenia, Romania, or Spain doesn't need an IDTA, an Addendum, or an SCC. All six are EU member states, and the UK's adequacy regulations give the EU and the wider EEA "full" adequacy status, the same tier as Switzerland or New Zealand. Full adequacy means the ICO treats the transfer as though it were happening inside the UK. No extra safeguard, no separate agreement, no Transfer Risk Assessment.
The direction runs the other way too. An EU company sending personal data to a UK-based engineer, or to a UK staff-augmentation vendor whose systems that engineer works inside, is covered by the Commission's adequacy decision for the UK named above, first adopted 28 June 2021 and renewed in December 2025. That decision covers both general and law-enforcement processing, and it means an EU exporter doesn't need SCCs to send data to a UK recipient either.
Adequacy isn't a formality to note and move past. It's the actual answer for most UK-EU engineering hiring, and it's the answer that gets skipped in most write-ups of this topic, which default straight to "which transfer tool do I need."
UK IDTA vs the UK Addendum to the EU SCCs: which one applies
Once a transfer isn't covered by adequacy, a UK exporter needs one of two UK-specific tools, and the choice between them is mechanical rather than a judgment call. The ICO's guidance on the UK IDTA and the Addendum sets out both. The IDTA is a standalone agreement, issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018 and recognized as an Article 46(2)(d) UK GDPR safeguard in its own right; it's been in force since 21 March 2022. The Addendum does a narrower job. It amends the EU's own SCCs so that they operate under UK law, rather than replacing them with a separate document.
Pick the Addendum, not a fresh IDTA, if the exporter already has EU SCCs in place covering the same processing across both UK and EEA operations. It's faster to attach, and it keeps one set of clauses governing both jurisdictions instead of running two parallel agreements for the same transfer. Pick the standalone IDTA if the transfer is UK-only, with no EU leg to align it against.
Both documents are due for an update. The ICO has said it plans to revise the IDTA and the Addendum during 2026 to reflect the Data (Use and Access) Act 2025, and the current versions stay valid until that update lands. There's no reason to hold off signing one now.
EU SCCs: when an EU company needs them
An EU-based buyer runs into a mirror version of the same question. If the recipient's country doesn't hold an EU adequacy decision, the exporter needs a transfer safeguard, and SCCs are the standard choice, the EU's equivalent of the IDTA. The parallel is deliberate: UK GDPR retained the EU's transfer framework after Brexit, which is why the mechanism names differ but the underlying logic, adequacy first, safeguard if not, doesn't.
HighCircl's guide to software development agreement clauses for EU hiring works through the point at which an EU buyer needs SCCs in more detail, including why an EU-to-EU engagement doesn't trigger them even though it still needs a separate data-processing clause under Article 28. That distinction, transfer mechanism versus processor obligation, trips up more buyers than the IDTA-versus-Addendum choice does.
The one case in nearshore hiring that actually needs a transfer agreement: non-adequate countries
HighCircl hires across seven European countries: Poland, Hungary, Slovakia, Serbia, Slovenia, Romania, and Spain. Six are EU member states, covered by adequacy in both directions as set out above. Serbia isn't an EU member, and it doesn't appear on the Commission's adequacy decisions list either, so a data transfer to or from a Serbia-based engineer's own systems doesn't get the free pass the other six countries do. Serbia is also absent from the ICO's adequacy country list, so the gap runs both directions: UK-to-Serbia and EU-to-Serbia.
Route personal data through a Serbian engineer's own tools and infrastructure, and a UK exporter needs an IDTA, or the Addendum if EU SCCs already cover the rest of the arrangement, while an EU exporter needs SCCs. That's the one country in HighCircl's own footprint where a transfer agreement is the actual answer, not a formality to skip past. In staff augmentation specifically, where the engineer typically works inside the buyer's own systems rather than a separate vendor environment, that exposure is smaller than it looks on paper. It doesn't disappear just because the engineer is embedded in your team.
How to work out which transfer mechanism you need
1. Identify the exporter's and importer's jurisdiction
Name which country the personal data is leaving from, and which country the recipient, the engineer, the agency, or the vendor's own systems actually sits in. With staff augmentation, the importer's jurisdiction isn't always the vendor's headquarters. It's wherever the engineer's own device or environment lives.
2. Check the relevant adequacy list
If the exporter is in the UK, check the ICO's adequacy list above. If the exporter is in the EU, check the Commission's adequacy list above. If the importer's country appears on the applicable list, stop here. No agreement is needed.
3. Choose the safeguard that matches the exporter
If the exporter is in the UK and the transfer isn't covered by adequacy, choose a standalone IDTA, or the Addendum if EU SCCs already cover the same processing elsewhere. If the exporter is in the EU, choose SCCs.
4. Complete a Transfer Risk Assessment before relying on any safeguard
The ICO's international transfers guide requires a Transfer Risk Assessment before a UK exporter relies on the IDTA, the Addendum, or binding corporate rules. Adequacy is the only mechanism that skips this step. Assess the destination country's laws and practices around government access to data, and document that the safeguard provides protection equivalent to UK or EU law before you sign anything.
FAQ
Does a UK company hiring a developer in Poland need an international data transfer agreement?
No. Poland is an EU member state, and the UK's adequacy regulations already give the EU full adequacy status. No IDTA, Addendum, or SCC is needed for that transfer in either direction.
What's the difference between the IDTA and the UK Addendum?
The IDTA is a standalone UK agreement, used on its own. The Addendum amends the EU's SCCs so they work under UK law, used when EU SCCs already cover the same processing across both UK and EEA operations. Pick the Addendum if you're already running EU SCCs; pick the IDTA if the transfer is UK-only.
Do EU companies use the IDTA?
No. The IDTA is a UK-specific instrument, issued under UK law for a UK exporter. An EU-based company uses the EU's own SCCs instead when a transfer needs a safeguard.
Is a data transfer agreement the same as a data processing agreement?
No. A transfer agreement, the IDTA, the Addendum, or SCCs, governs whether personal data can lawfully move to another country. A data processing agreement, required under GDPR Article 28 whenever a processor handles personal data on a controller's behalf, governs something separate: what the processor is allowed to do with that data once it has it. An engagement can need one, both, or neither, depending on where the data moves and who's handling it.
