What does the UK DUAA change for companies using offshore dev vendors?
The UK Data (Use and Access) Act, or DUAA, makes it easier and better-defined to send personal data to offshore development and AI vendors, while still requiring documented vendor diligence. The headline change for outsourcing is a new risk-based international-transfer test: instead of proving the destination country offers protection that is "essentially equivalent" to the UK's, you now assess whether protection is "not materially lower" than the UK standard. That is a lower, more practical bar for transfers to places like India, but it is a judgement you must record, not a free pass.
The main data-protection provisions of the DUAA came into force on 5 February 2026 under the Commencement No. 6 Regulations. For a UK company that offshores software or AI work, the practical effect is a lighter compliance burden on paper, paired with an unchanged expectation that you actually vet the vendor and document your decisions.
What exactly changed on 5 February 2026?
The DUAA reforms several parts of the UK data-protection regime at once. The changes most relevant to outsourcing are:
- A statutory list of "recognised legitimate interests", giving firmer footing for certain processing without a separate balancing test.
- Relaxed rules on automated decision-making, which matter when an offshore AI vendor's system makes or supports decisions about people.
- A codified "reasonable and proportionate" standard for responding to data subject access requests (DSARs), clarifying how far you must search.
- The risk-based international-transfer test, replacing "essentially equivalent" with "not materially lower" for assessing destination-country protection.
The Information Commissioner's Office updated its international-transfer guidance in January 2026 to reflect the new approach. Separately, and importantly for context, the EU renewed the UK's own data-adequacy decisions in December 2025, valid through 2031, so UK-EU flows remain smooth even as the UK adjusts its outbound-transfer rules. A further DUAA duty on data-protection complaints procedures, under section 103, commenced on 19 June 2026.
Old transfer test versus the new risk-based test
The shift in the transfer standard is subtle but consequential. Here is the comparison:
| Aspect | Old standard (pre-DUAA) | New DUAA standard (from 5 Feb 2026) |
|---|---|---|
| Test wording | "Essentially equivalent" protection | "Not materially lower" protection |
| Nature of assessment | Strict equivalence | Risk-based and proportionate |
| Practical bar for India transfers | Harder to satisfy | More achievable, if documented |
| Documentation still required | Yes | Yes |
| Vendor diligence still required | Yes | Yes |
The change lowers the height of the bar without removing it. You still have to reach a reasoned conclusion and keep the paperwork that shows how you got there.
What should UK companies update in their offshore contracts and processes?
If you send personal data to an offshore dev or AI vendor, treat the DUAA commencement as a prompt to refresh your documentation rather than to relax. Concretely:
- Re-run and record your transfer risk assessment against the new "not materially lower" standard for each offshore destination, using the ICO's updated January 2026 guidance.
- Update your Data Processing Agreements (DPAs) with offshore vendors to reflect the current transfer mechanism and the risk-based rationale.
- Revisit your DPIAs, especially where an offshore AI system performs automated decision-making now covered by the relaxed rules.
- Recalibrate your DSAR process to the codified "reasonable and proportionate" standard, so offshore teams handling data know how far searches must go.
- Wire up your complaints flow to meet the section 103 complaints-procedure duty that commenced on 19 June 2026.
The through-line is that lighter law does not mean lighter diligence on the vendor itself. You still need to know who touches the data, where, and under what controls. Our guide to the legal and compliance essentials of hiring developers in India covers the contractual and IP groundwork that sits alongside these data-protection steps.
Does the DUAA make offshoring to India easier or riskier?
On balance it makes compliant offshoring to India more workable, provided you do the documented assessment. The risk-based test acknowledges that a destination need not be a carbon copy of the UK regime to be acceptable, which better reflects how mature Indian delivery centres actually operate. But the reform does not touch the operational risks of choosing the wrong vendor, and it does not remove your accountability if a transfer goes wrong. The decision of where a team sits still deserves the same scrutiny it always did, which our comparison of offshore vs nearshore vs onshore development lays out in full.
Cost remains part of the calculation too, and a lighter transfer regime does not change the underlying economics of building in India versus the UK. For that, see our breakdown of the cost to hire a developer in India vs Europe, which sits alongside the compliance picture rather than replacing it.
Why vendor seniority still matters under lighter rules
A risk-based transfer test rewards vendors that can demonstrably handle data well, which in practice means senior teams with mature security and documentation habits. Junior-heavy offshore shops that cannot evidence their controls make your "not materially lower" assessment harder to defend, not easier. Choosing pre-vetted senior engineers who understand European data expectations is the simplest way to keep the paperwork clean. That is the profile ILMTEC's senior India and UAE engineer sourcing is built around: engineers used to working to European compliance standards, not cutting corners on them.
How ILMTEC helps
ILMTEC builds and staffs offshore engineering teams for UK and European companies, with delivery centres in Pune, Dubai, and Berlin. Through Talenlio we source senior India and UAE engineers who work to European data-protection and security expectations, and we support the contractual scaffolding, DPAs, IP assignment, and clear data-handling responsibilities, that keeps your DUAA transfer assessments defensible. The DUAA lowers the bar; we help you clear it with documentation you can stand behind. This article is general information, not legal advice, so confirm specifics with your data-protection counsel.