NODE · LON-01|LONDON --:--:--
DC-Services — Digital Claims Services Limited
Legal Documentation

DC-Services UK International Data Transfers

When data may leave the UK or EEA, and the safeguards that must be in place first.

This page explains how Digital Claims Services Limited (trading as DC-SERVICES UK) handles cross-border transfers of personal data and client records. It is informational only and is not financial, investment, legal or tax advice.

Last reviewed: February 2026 · 20 sections

international-data-transfers.pdf · A4 · brandedAll documents
01

Purpose of the transfer statement

  1. 1.1DC-SERVICES UK publishes this page so clients understand when, where and how their data may move across borders.
  2. 1.2An international transfer occurs whenever personal data is sent to or accessed from a country outside the UK.
  3. 1.3Each transfer is assessed and recorded before it begins.
  4. 1.4Clients can consult this page to confirm the safeguards applied to their data.
02

Default data location approach

  1. 2.1By default, personal data and client records are processed within the UK and, where necessary, within the EEA.
  2. 2.2The UK and EEA are treated as the primary processing area to keep data subject to UK GDPR and equivalent rules.
  3. 2.3Non-UK/EEA processing is the exception, not the norm, and requires recorded justification.
  4. 2.4Clients are told if their engagement requires a departure from this default.
03

UK data handling position

  1. 3.1Data processed in the UK is subject to the UK GDPR, the Data Protection Act 2018 and supervisory oversight by the ICO.
  2. 3.2UK processing is preferred where technically and operationally feasible.
  3. 3.3Hosting, backup and recovery sites are selected with UK location in mind.
  4. 3.4UK processing is the documented baseline against which other options are compared.
04

EEA data handling position

  1. 4.1Data processed in the EEA is subject to the EU GDPR and supervision by the relevant EEA authority.
  2. 4.2EEA processing is treated as functionally equivalent to UK processing for the purposes of this page.
  3. 4.3Where the engagement reaches data subjects in the EEA, EEA-side rules are observed alongside UK rules.
  4. 4.4Clients are told which EEA country processes their data, where requested.
05

Restricted transfers

  1. 5.1A restricted transfer is any transfer of personal data outside the UK that requires an Article 44 safeguard before it can proceed.
  2. 5.2Restricted transfers are recorded with origin, destination, purpose, safeguard and lawful basis.
  3. 5.3They are not initiated until the chosen safeguard is in place and documented.
  4. 5.4Clients are told before a restricted transfer affecting their data begins.
06

Approved jurisdictions

  1. 6.1Approved jurisdictions are countries with a current UK adequacy regulation or equivalent recognition.
  2. 6.2Transfers to approved jurisdictions proceed without the need for an additional contractual safeguard.
  3. 6.3The list of approved jurisdictions is maintained centrally and reviewed when the UK adequacy position changes.
  4. 6.4Clients can be told the current approved-jurisdiction list on request.
07

Transfer safeguards

  1. 7.1Where the destination is not an approved jurisdiction, transfers rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
  2. 7.2The chosen safeguard binds the recipient to UK-equivalent data-protection standards.
  3. 7.3The safeguard is supplemented by a Transfer Risk Assessment that records context-specific risks and mitigations.
  4. 7.4The safeguard in force for a given transfer can be disclosed to affected data subjects.
08

Contractual protections

  1. 8.1Provider contracts include UK GDPR Article 28-aligned terms covering purpose, instructions, security, sub-processing and breach notification.
  2. 8.2Contractual protections survive provider staff changes and corporate restructuring.
  3. 8.3Breach of these terms is grounds for suspension or termination of the provider relationship.
  4. 8.4Contracts are reviewed at least annually and on material change.
09

Technical safeguards

  1. 9.1Technical safeguards layer on top of contractual ones and reduce reliance on legal-only protections.
  2. 9.2They include encryption, key management, network segmentation and access control.
  3. 9.3Technical safeguards are documented per provider and per data category.
  4. 9.4Where technical safeguards weaken, the underlying transfer is paused and re-assessed.
10

Encryption in transit

  1. 10.1All transfers of personal data over public networks are protected by industry-standard transport encryption.
  2. 10.2Encryption in transit means data is unreadable to unauthorised parties between sender and recipient.
  3. 10.3Insecure transport protocols are disabled at the perimeter of our systems.
  4. 10.4Clients can request the current transport-security baseline applied to their data.
11

Encryption at rest

  1. 11.1Personal data stored within our managed systems is encrypted at rest using strong, modern algorithms.
  2. 11.2Encryption at rest means stored data is unreadable without access to the relevant keys.
  3. 11.3Keys are managed under documented procedures separate from the data they protect.
  4. 11.4Loss of an encrypted device does not, on its own, constitute access to the data it stored.
12

Access restrictions

  1. 12.1Access to data in any jurisdiction is restricted to staff who need it to perform documented tasks.
  2. 12.2Access is granted by role, time-bounded where appropriate and logged.
  3. 12.3Access reviews are performed regularly and on staff changes.
  4. 12.4Clients can be told the high-level access model applied to their data.
13

Vendor review

  1. 13.1Vendors that process personal data outside the UK or EEA are reviewed with greater scrutiny than UK/EEA-only vendors.
  2. 13.2Review covers legal regime, surveillance laws, breach history and corporate ownership.
  3. 13.3Findings drive contractual additions or, where unmitigated, decline of the vendor.
  4. 13.4Clients are told when a non-UK/EEA vendor materially supports their engagement.
14

Emergency access scenarios

  1. 14.1Emergency access may be needed to recover from outages, security incidents or data-loss events.
  2. 14.2Emergency access procedures are pre-approved, time-bounded and fully logged.
  3. 14.3Emergency access does not bypass encryption, identity or audit controls.
  4. 14.4Where emergency access affects personal data, the event is reviewed and recorded.
15

Legal request scenarios

  1. 15.1Lawful disclosure requests from public authorities are handled in accordance with the Law Enforcement Guide.
  2. 15.2Each request is reviewed for legal basis, scope and proportionality.
  3. 15.3Where law allows, the affected data subject is notified.
  4. 15.4Records of requests received and the response provided are retained internally.
16

Client notification where applicable

  1. 16.1Where a restricted transfer or non-UK/EEA processing materially affects an engagement, the client is notified in writing.
  2. 16.2Notification describes the destination, the safeguard and the categories of data involved.
  3. 16.3Notification is sent through the secure portal and the engagement email address.
  4. 16.4Clients may raise objections before the transfer begins.
17

Record keeping

  1. 17.1A record of restricted transfers is maintained as part of the Record of Processing Activities.
  2. 17.2The record covers data category, recipient, country, safeguard and Transfer Risk Assessment outcome.
  3. 17.3Records are retained for the duration required by law plus a documented buffer.
  4. 17.4Records can be made available to the ICO on lawful request.
18

Transfer risk assessment

  1. 18.1A Transfer Risk Assessment is recorded for every restricted transfer before it begins.
  2. 18.2It evaluates the destination's legal regime, the categories of data and the mitigations in place.
  3. 18.3Where residual risk is unacceptable, the transfer does not proceed.
  4. 18.4Assessment outcomes are reviewed when the destination regime changes.
19

User rights and contact route

  1. 19.1Data subjects may exercise their UK GDPR rights in respect of any transferred data.
  2. 19.2Requests are routed to the Data Protection Officer at dataprotection@dc-service.uk.
  3. 19.3Responses are provided within one calendar month, subject to lawful exceptions.
  4. 19.4Data subjects may also complain to the ICO at any time.
20

Review and update process

  1. 20.1This page is reviewed at least annually and whenever the UK adequacy landscape materially changes.
  2. 20.2Reviews are owned by the Data Protection Officer and approved by the Compliance Office.
  3. 20.3Updates are version-controlled and published with a new 'Last reviewed' date.
  4. 20.4Active clients are notified of changes materially affecting them.
Frequently Asked Questions

Questions about this page

Where is my data processed by default?
Within the UK and, where necessary, the EEA. Non-UK/EEA processing is the exception and requires a recorded safeguard.
What safeguard do you use for transfers outside the UK?
The UK IDTA or the UK Addendum to the EU SCCs, supported by a Transfer Risk Assessment and technical measures such as encryption.
Will I be told before a restricted transfer affecting me?
Yes. Active clients are notified in writing before a restricted transfer begins and may raise objections within the notification window.
Where can I complain about a transfer?
Contact the Data Protection Officer first. You can also complain to the Information Commissioner's Office (ICO) at any time.