Storing UK client data in the EU: is it allowed?
UK law treats transfers to EEA states as approved, so no IDTA is needed. Here is what the texts say and what you still have to do.
Countries covered : United Kingdom
What a "transfer" of client data means
A restricted transfer is when you send personal data to a separate organisation located outside the UK, or make it accessible to one. That is how the ICO defines it in its international transfers guide, updated on 15 January 2026.
The definition is wide. The ICO says it covers sending data and also giving an organisation abroad access to it. Its example is a UK business that lets a customer services provider in India access its systems. The ICO also says the rules apply even to small, infrequent transfers.
So if you are a counsellor, psychotherapist, psychologist, speech and language therapist, occupational therapist or physiotherapist in the UK, and your notes software stores data on servers run by a company in France or Ireland, you are very likely making a restricted transfer. The question is not whether it is a transfer. The question is what the law requires for it.
Many practitioners hesitate at this point. They have heard that data must stay in the UK, or they have seen tools advertise UK hosting. This article looks at what the texts actually say about the EEA, what you still have to do, and where the line sits between a legal rule and a preference.
What the law says about the EEA
Schedule 21, paragraph 4: transfers treated as approved
The starting point is paragraph 4 of Schedule 21 to the Data Protection Act 2018. It says that, for the purposes of the UK GDPR, a transfer to a destination listed in paragraph 5 is treated as approved by regulations under article 45A of the UK GDPR.
The current wording of paragraph 4 dates from 5 February 2026. On that date, the Data (Use and Access) Act 2025 changed the words of the paragraph, through commencement regulations SI 2026/82. The legislation.gov.uk page states that the paragraph is up to date with changes in force on or before 3 October 2026.
Schedule 21, paragraph 5: the listed destinations
Paragraph 5 lists the destinations. They include:
- an EEA state;
- Gibraltar;
- EU institutions, bodies, offices and agencies, and equivalent EEA bodies;
- countries covered by certain older EU decisions, such as Switzerland, Canada (under its private sector data law), Argentina, Guernsey, Jersey, the Isle of Man, Israel, New Zealand and Japan;
- countries or organisations covered by an EU adequacy decision made before the end of the Brexit transition period, unless it had been repealed or suspended by then.
The EEA is therefore one group among several. France, as an EEA state, falls within paragraph 5(1)(a).
Article 45A UK GDPR: approval by regulations
Article 45A of the UK GDPR lets the Secretary of State approve transfers to a third country or international organisation by regulations. The Secretary of State can only do so if they consider that the "data protection test" is met. Article 45A was inserted by the Data (Use and Access) Act 2025. According to legislation.gov.uk, it came into force for some purposes on 19 June 2025 and for all other purposes on 5 February 2026. The commencement regulations are SI 2026/82.
Put simply, the EEA destinations in paragraph 5 sit inside the new article 45A system. Transfers to them are treated as if regulations had approved them.
The list can change
Paragraph 4(3) lets the Secretary of State make regulations that repeal these provisions, remove a destination from paragraph 5, or narrow an entry. So the position described here is the law as it stands on legislation.gov.uk today. It is worth checking again if you read this much later, or if you hear of a change to the UK's approach to the EU.
No IDTA or Addendum for the EEA
When a transfer is not covered by an approval, you need another route. The usual ones are the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses. The ICO says that if you rely on such a safeguard, you must also complete a transfer risk assessment.
The ICO guide uses the term "UK adequacy regulations" and does not list the EEA by name. For a destination covered by adequacy regulations, it says information can flow freely from the UK "without you needing to put in place any additional safeguard". It also calls adequacy "the most efficient way" to make a restricted transfer.
Read together with Schedule 21, this suggests that a provider hosting your client data in France does not need to sign an IDTA or an Addendum with you for that transfer. If a provider offers one anyway, it does no harm. It is just not what the law asks for here.
What you still have to do
Approval of the destination answers one question only: can the data go there? It does not remove your other duties as controller. The ICO says so directly: under adequacy, "you should still make checks on any organisation you share personal information with under your other UK GDPR obligations."
Here is what that means in practice.
1. Mention the provider and the transfer in your privacy notice
The ICO's guidance on privacy information says to tell people who you share their data with. It adds that this includes any organisation that processes the data for you, as well as other organisations. It also says to tell people if you transfer their data abroad and on what basis. A simple sentence can work. For example, that your notes software is provided by a company that stores data in France, and that UK law treats transfers to EEA states as approved.
2. Sign a contract that meets article 28 (a data processing agreement)
Your notes provider is usually your processor. You are the controller. The ICO's page on what the contract must include lists the details it must set out:
- the subject matter and duration of the processing;
- the nature and purpose of the processing;
- the type of personal data and categories of data subject;
- the controller's obligations and rights.
It also lists minimum terms. These include processing only on your documented instructions, confidentiality of staff, security, help with clients' rights, what happens to the data at the end of the contract, and audits. On instructions, the ICO notes that this includes "when making an international transfer of personal data". Ask any provider for its data processing agreement and read it.
3. Check the sub-processors
Under the same ICO page, a processor must not use a sub-processor without your prior specific or general written authorisation. With general authorisation, the processor must tell you about intended changes and give you a chance to object. The processor must pass equivalent obligations to each sub-processor, and remains liable to you for their compliance.
So ask for the list of sub-processors and where each one is located. This is where the real transfer questions often sit.
4. Choose a provider that offers sufficient guarantees
The ICO's page on controllers using a processor reminds you that a controller must only use a processor that can provide "sufficient guarantees". It adds that controllers should ensure a processor's compliance on an ongoing basis. In practice: read the security page, the contract, and the sub-processor list, and keep a copy of what you checked and when.
5. Do a DPIA where the risk calls for it
The ICO's DPIA guidance says you must do one where processing is likely to result in a high risk to people's rights and freedoms. Its list of likely high risk processing includes innovative technology and the processing of special category data. Session notes are health data. The ICO also says: "If in any doubt, we would always recommend that you do a DPIA". If you are bringing in a new AI note-taking tool, a short DPIA is a sensible step.
Onward transfers outside the EEA: a separate question
The approval in Schedule 21 covers the destination it names. If your French provider passes data to a sub-processor in the United States, or lets support staff elsewhere access it, that is a different leg of the journey.
The ICO says the transfer rules apply wherever an organisation sits in the processing chain, whether it is a controller, a processor or a sub-processor. So the question to ask a provider is concrete: which sub-processors touch client data, in which countries, and on what basis? A provider hosted in the EEA but using AI processing outside it raises different points from one that keeps everything in the EEA.
The same applies to UK-based providers. A tool hosted in London can still use sub-processors in other countries. Asking about sub-processors and their locations is useful whatever the hosting country.
Legal requirement versus preference
Some providers advertise that client data never leaves the UK. That is a fair commercial choice and some practitioners prefer it. It may also suit organisations whose own policies or contracts require UK hosting.
It is not, on the texts above, a requirement of UK data protection law for transfers to the EEA. The law treats those transfers as approved. What it does require is the rest: transparency, a proper contract, checks on the provider, security and, where relevant, a DPIA.
So when you compare tools, separate two questions:
- Is it legal for me to use this tool? Here, the hosting country matters less than the contract, the sub-processors and the security.
- Do I or my clients prefer UK hosting? That is a choice, and you can make it for your own reasons.
Your professional body may also have something to say on how you store notes. Read its guidance alongside the law. If your situation is unusual, for example you work under an NHS contract or with a commissioning organisation that sets its own rules, check those contracts too. If you are unsure, take advice.
A short checklist before you sign up
- Where is client data stored, and where is it processed (including any AI processing)?
- Can I get the provider's data processing agreement, and does it cover the article 28 terms?
- What is the list of sub-processors, and where is each one located?
- If any sub-processor is outside the UK and outside the destinations listed in Schedule 21, what transfer mechanism is used?
- What security measures are described, and is data encrypted?
- Have I updated my privacy notice to name the provider and the transfer?
- Have I done, or at least considered, a DPIA?
For a wider view of your data protection duties, see our UK GDPR checklist for counsellors. For questions of confidentiality when using AI, see professional confidentiality and AI.
Where Delta fits
Delta is an AI assistant for mental health and allied health practitioners. During the session, it transcribes what is said, then prepares a session report that you review. You can also dictate observations right after the session, or add written notes.
On data location, here are the facts. Data is hosted in France with a host certified for health data (HDS, the French health data hosting certification). AI processing, transcription included, runs on servers located in France. The client's name and identifying details are pseudonymised before AI processing. No audio file is kept. Data is never used to train models. Data is encrypted in transit and at rest. You can read more on the security page and in our article on HDS certified hosting.
France is an EEA state, which is the first destination listed in paragraph 5 of Schedule 21. As with any provider, ask Delta for its data processing agreement and its list of sub-processors before you start, and mention it in your privacy notice. More on how it works for therapists is on the therapists page.
Can a UK therapist use software hosted in the EU?
On the current texts, yes. Schedule 21 to the Data Protection Act 2018 treats transfers to EEA states as approved under article 45A of the UK GDPR. You still need a data processing agreement, a privacy notice that mentions the provider, and checks on the provider and its sub-processors.
Do I need an IDTA to store client notes in France or Ireland?
Not on the current texts. The ICO says that where a transfer is covered by adequacy regulations, no additional safeguard is needed. The IDTA and the UK Addendum are for transfers to destinations that are not covered by an approval.
Is the EU still adequate for UK GDPR after the Data (Use and Access) Act 2025?
The Act changed the legal wording. Since 5 February 2026, Schedule 21 says transfers to EEA states are treated as approved by regulations under article 45A. The Secretary of State can change the list by regulations, so check legislation.gov.uk if in doubt.
Does client data have to stay in the UK?
Not under the texts covered here, for transfers to the EEA. UK hosting is a preference some providers advertise and some practitioners choose. Your own contracts, an NHS arrangement or your professional body may set extra conditions, so check those.
What should I ask an EU-hosted provider before signing up?
Ask for its data processing agreement, its list of sub-processors and their locations, and its security measures. Ask where AI processing takes place, not only where data is stored. Keep a note of the answers.
Do I have to mention an EU provider in my privacy notice?
Yes. The ICO says to tell people who you share their data with, including anyone who processes it for you. It also says to tell people about transfers abroad and the basis for them.
Sources
- Data Protection Act 2018, Schedule 21, paragraph 4 (legislation.gov.uk)
- Data Protection Act 2018, Schedule 21, paragraph 5 (legislation.gov.uk)
- UK GDPR, article 45A: transfers approved by regulations (legislation.gov.uk)
- ICO, International transfers: a guide (15 January 2026)
- ICO, What privacy information should we provide?
- ICO, What needs to be included in the contract?
- ICO, Responsibilities and liabilities for controllers using a processor
- ICO, When do we need to do a DPIA?
Try Delta for 14 days
Try Delta free for 14 days, no card needed, and ask us for our data processing agreement.
Try it free