UK International Data Transfer Addendum / IDTA review
UK Addendum to EU SCCs or standalone UK IDTA. Checks cover Tables/Parts completion, mandatory-clauses integrity, TIA/TRA, adequacy-decision posture, and onward transfers.
Review your document — free → See a sample report- 10 document-specific checks
- + 107 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
UK Addendum: Table 1 (Parties)
UK Addendum Table 1 (Parties) must be completed.
Warning · TRANSFER-011
UK Addendum: Table 2 (Selected SCC Modules)
UK Addendum Table 2 (Selected SCC Modules) must be completed.
Warning · TRANSFER-012
UK Addendum: Table 3 (Appendix Information)
UK Addendum Table 3 (Appendix Information) must be completed.
Warning · TRANSFER-013
UK Addendum: Table 4 (Ending This Addendum)
UK Addendum Table 4 (Ending This Addendum When the Approved Addendum Changes) must be completed.
Warning · TRANSFER-014
UK Addendum: mandatory clauses modified
Flags modification of the UK Addendum mandatory clauses — forbidden.
Critical · TRANSFER-015
UK IDTA: Parties identified (Part 1 / Table 1)
UK IDTA Part 1 (or UK Addendum Table 1) must identify the Parties.
Warning · TRANSFER-016
Adequacy: reliance on the EU-US Data Privacy Framework
Flags reliance on the EU-US Data Privacy Framework (or its UK extension) so the importer's certification and a fallback transfer mechanism are confirmed.
Warning · TRANSFER-017
Adequacy decision currency clause
Where an adequacy decision is relied on, the DPA should anchor the reliance with a fallback for invalidation.
Warning · TRANSFER-018
TIA / Transfer Risk Assessment reference
Where SCCs / IDTA cover transfers to a non-adequate country, the DPA must reference a TIA / TRA.
Critical · TRANSFER-019
Onward-transfer terms (Clause 8.8; Clause 8.7 in Module One)
Where SCCs apply, the DPA should address onward-transfer terms (SCC Clause 8.8 in Modules Two and Three; Clause 8.7 in Module One).
Warning · TRANSFER-020
Every run also applies 107 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Sources
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Cookie / Tracking Notice
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA)
- DPA — Processor to Sub-Processor (EU/UK GDPR)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- Vendor Security Addendum
- Vendor Security Questionnaire (SIG / CAIQ)