For Heads-of · Practitioner
Cross-border AI data transfer risk
Personal data processed by an AI system, including via a cloud or model provider, is transferred outside the UK without an adequate transfer mechanism.
- medium
- data-protection
- international-transfer
- vendor-risk
How it happens
An AI vendor or cloud model provider processes personal data on infrastructure located outside the UK, and the transfer safeguard (adequacy decision, standard contractual clauses, or equivalent) is never checked because the transfer is treated as an infrastructure detail, not a data protection decision.
Why it matters
The transfer mechanism is a distinct legal requirement from having a lawful basis to process the data in the first place, and AI vendor contracts are exactly where this gets missed, since the data flow often isn't obvious from the product description.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Data minimisation and lawful basis review
A documented check that any personal data used to train, fine-tune, or ground an AI system has a valid lawful basis and is limited to what's necessary.
Third-party model and vendor due diligence
Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| SS2/21: Outsourcing and Third-Party Risk Management | Chapter 8 | Access, audit and information rights |
| UK General Data Protection Regulation | Article 5 | Principles relating to processing of personal data |
Related resources
The external sources behind this risk, from the Resources library.