For Heads-of · Practitioner

Cross-border AI data transfer risk

Personal data processed by an AI system, including via a cloud or model provider, is transferred outside the UK without an adequate transfer mechanism.

  • medium
  • data-protection
  • international-transfer
  • vendor-risk

How it happens

An AI vendor or cloud model provider processes personal data on infrastructure located outside the UK, and the transfer safeguard (adequacy decision, standard contractual clauses, or equivalent) is never checked because the transfer is treated as an infrastructure detail, not a data protection decision.

Why it matters

The transfer mechanism is a distinct legal requirement from having a lawful basis to process the data in the first place, and AI vendor contracts are exactly where this gets missed, since the data flow often isn't obvious from the product description.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
SS2/21: Outsourcing and Third-Party Risk ManagementChapter 8Access, audit and information rights
UK General Data Protection RegulationArticle 5Principles relating to processing of personal data

Related resources

The external sources behind this risk, from the Resources library.