Microsoft 365 & cloud

Cloud Compliance for UK Businesses: UK GDPR, Data Transfers and the Data Bridge

Moving email, files and line-of-business systems into the cloud makes a lot of things easier. It doesn’t move your legal responsibilities. If your business decides what personal data is collected and why, you’re the controller under UK GDPR, and that stays true whether the data sits on a server in your office or in a data centre run by Microsoft, Google or anyone else.

This post covers the rules a UK business needs to think about when using cloud services. If you’re choosing a storage service, our cloud storage checklist puts these points into a buying decision.

Who is responsible for what

The cloud provider runs the data centres, the hardware and the core software. You are responsible for how you use the service: who has accounts, what they can see, how sharing is set up and what data you put in. The NCSC describes this as a shared responsibility model, and the split depends on the type of service. For software you simply use, such as Microsoft 365, the provider does more; for virtual servers you run yourself, you do more.

Two consequences matter in practice:

  • The provider’s security certificates cover their part, not yours. A misconfigured SharePoint site that shares client files with anyone who has the link is your breach, not Microsoft’s.
  • Cyber Essentials agrees. The current requirements (v3.3, April 2026) say cloud services holding your data can’t be excluded from scope, and that signing in to cloud services must always use multi-factor authentication.

What UK GDPR expects

A proper contract with the provider

A cloud provider holding personal data for you is your processor. UK GDPR requires a written contract that, among other things, limits the provider to acting on your instructions, requires appropriate security, controls the use of sub-processors, and requires data to be deleted or returned at the end. The big providers include these terms in their standard agreements; check that you’ve accepted the business version, not a consumer one.

Appropriate security

The security principle requires “appropriate technical and organisational measures”. For cloud services that usually means multi-factor authentication for everyone, access based on role, sensible sharing settings, encryption, audit logging, a process to remove leavers, and backups you can restore. The ICO’s guide to data security sets out what it expects.

Knowing where the data goes

Sending personal data outside the UK, including storing it in a data centre abroad or letting a provider’s support staff overseas access it, is a “restricted transfer”. It needs one of the following, according to the ICO:

  1. UK adequacy regulations. The UK recognises the EU and EEA, among others, as adequate. For the US, adequacy covers only companies certified to the UK Extension of the EU-US Data Privacy Framework, known as the UK-US data bridge, in force since 12 October 2023.
  2. Appropriate safeguards. Usually the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses, backed by a transfer risk assessment.
  3. Exceptions. Limited, occasional cases such as explicit consent. Not a basis for routine cloud use.

The UK-US data bridge

The data bridge lets you send personal data to a US company without extra safeguards, but only if that company is on the Data Privacy Framework List, has signed up to the UK Extension, and its certification covers the type of data you’re sending (HR data, non-HR data or both). The ICO recommends checking all three.

The EU’s version of the framework is the subject of an appeal at the Court of Justice of the EU. The ICO has pointed out that the UK’s adequacy regulations for the US are independent of the EU’s decision. Even so, it’s sensible to know which of your providers you rely on it for, and whether they offer UK or EU storage as an alternative.

What changed with the Data (Use and Access) Act 2025

Most of the Act’s data protection changes came into force on 5 February 2026, with the new complaints duty following on 19 June 2026. For international transfers, the main change is to the test you apply. A transfer risk assessment is now called a “data protection test” in the legislation, and the question is whether the protection people get after the transfer is “not materially lower” than in the UK. The ICO still uses the term transfer risk assessment in its guidance.

Two other points worth knowing:

  • In December 2025 the European Commission renewed its adequacy decisions for the UK, having considered the Act’s changes. Data can keep flowing from the EU to the UK, and the decisions run until 27 December 2031.
  • On 30 September 2026 the Information Commissioner’s Office became the Information Commission. The regulator’s role, powers and guidance didn’t change.

Our UK privacy compliance checklist covers the Act’s other changes.

Standards that help you show compliance

  • Cyber Essentials and Cyber Essentials Plus cover the basic technical controls, including your cloud services. Many clients and insurers ask for them.
  • ISO 27001 is the international standard for managing information security. It’s useful both for checking your providers and, for larger or more regulated companies, as a framework for your own controls.
  • PCI DSS applies if you take card payments. Ask your payment provider which parts are your responsibility.
  • Your sector regulator. Solicitors must keep client affairs confidential and manage material risks under the SRA Code of Conduct for Firms; financial services companies also have FCA requirements.

A practical checklist

  • List every cloud service you use, including the small ones staff signed up to themselves.
  • For each one, record what personal data it holds, where it’s stored, and the transfer basis if it leaves the UK.
  • Confirm you’ve accepted the provider’s business data processing terms.
  • Check your data location settings. In Microsoft 365, the admin centre shows it under Settings, Org settings, Organization profile, Data location; tenants set up in the UK have a commitment to store core data in the UK.
  • Turn on multi-factor authentication for everyone, and review sharing settings and admin accounts.
  • Make sure you have a separate, tested backup.
  • Review it all at least once a year.

If you’d like help with any of this, our page on IT support for regulated businesses explains how we help companies that have to prove they take security seriously.

Questions people ask

Is it legal to store UK personal data with a US cloud provider?

Yes, if the transfer is covered. Many large US providers are certified to the UK Extension of the Data Privacy Framework (the UK-US data bridge). Otherwise you can use the IDTA or the UK Addendum with a transfer risk assessment. Many providers also store UK customers’ data in the UK or EU.

What is the “data protection test”?

It’s the Data (Use and Access) Act 2025 name for what the ICO still calls a transfer risk assessment: deciding, reasonably and proportionately, that the protection people get after a transfer is not materially lower than in the UK.

Does the EU still accept data transfers to the UK?

Yes. In December 2025 the European Commission renewed its adequacy decisions for the UK, which now run until 27 December 2031.

Is the ICO still the regulator?

Since 30 September 2026 the regulator has been the Information Commission, which took over the ICO’s functions. Its role, powers and guidance are unchanged.

Sources

More on microsoft 365 & cloud

All microsoft 365 & cloud articles