
Cross-border data transfers are under increasing regulatory scrutiny in 2026.
United Kingdom
The United Kingdom’s Information Commissioner’s Office (ICO) issued updated guidance clarifying when a “restricted transfer” occurs under UK GDPR, introducing a practical 3-step test and reinforcing the need for transfer risk assessments and appropriate safeguards. Processors may also bear responsibility when engaging overseas subprocessors.
China
China’s amended Cybersecurity Law (effective 1 January 2026) strengthens oversight of cross-border data flows, aligns enforcement with PIPL and the Data Security Law, and raises compliance and penalty risks. Authorities also clarified the three outbound transfer mechanisms: standard contracts, security assessments and certification.
What’s the Trend?
• Clearer rules
• Higher accountability
• Stronger enforcement
• Greater focus on cross-border transfers
Cross-border compliance is now a strategic governance issue — not just a legal checkbox.
How S8fe.ai Helps
S8fe.ai enables organisations to manage cross-border data transfers with structured risk assessments, automated documentation, and clear compliance tracking across the UK and China — turning regulatory complexity into operational control.
Sources:
• https://www.stephensonharwood.com/insights/data-and-cyber-update-january-2026/
• https://www.twobirds.com/en/insights/2026/china/china-cybersecurity-and-data-protection-monthly-update–january-2026-issue
