International Data Transfer Statement
- Document reference
- FGL-LEG-07
- Version date
- 1 July 2026
- Applies to
- Fratres Limited
1.Purpose, scope and application
2.Interpretation and definitions
In this Statement, the following terms have the following meanings.
- Addendum
- The International Data Transfer Addendum to the European Commission’s standard contractual clauses for international data transfers, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, laid before Parliament and in force from 21 March 2022.
- Adequacy Regulations
- Regulations made by the Secretary of State under section 17A of the Data Protection Act 2018 (and Article 45 of the UK GDPR) determining that a country, territory, sector or international organisation provides an adequate level of protection for Personal Data.
- Data Subject
- An identified or identifiable living individual to whom Personal Data relates.
- EU SCCs
- The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
- Exporter
- The party making a Restricted Transfer, being the Company except where expressly stated otherwise.
- IDTA
- The International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, laid before Parliament and in force from 21 March 2022.
- Importer
- The party receiving Personal Data under a Restricted Transfer.
- Personal Data
- Has the meaning given in Article 4(1) of the UK GDPR, and includes Special Category Data and criminal offence data within the meaning of Article 10 of the UK GDPR.
- Restricted Transfer
- A transfer of Personal Data to a receiver located outside the United Kingdom, or the making available of Personal Data to such a receiver, where the receiver is legally distinct from the Exporter and the receiver’s processing of that Personal Data is not itself subject to the UK GDPR.
- Special Category Data
- Personal Data of the kinds listed in Article 9(1) of the UK GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for identification, data concerning health, and data concerning a person’s sex life or sexual orientation.
- Supplementary Measures
- Technical, organisational and contractual measures applied in addition to a transfer tool in order to bring the protection of transferred Personal Data up to the standard required by UK data protection law.
- Third Country
- Any country or territory outside the United Kingdom, including the member states of the European Economic Area.
- Transfer Risk Assessment
- The documented assessment described in clause 8, carried out before a Restricted Transfer is made in reliance on a transfer tool under Article 46 of the UK GDPR.
- UK GDPR
- Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland, read with the Data Protection Act 2018 and as amended, including by the Data (Use and Access) Act 2025.
3.Legal framework and the general principle
- (a)the destination is covered by Adequacy Regulations (Article 45 of the UK GDPR and section 17A of the Data Protection Act 2018);
- (b)the transfer is subject to appropriate safeguards under Article 46 of the UK GDPR, on condition that enforceable Data Subject rights and effective legal remedies are available;
- (c)the transfer is made under binding corporate rules approved under Article 47 of the UK GDPR; or
- (d)a derogation under Article 49 of the UK GDPR applies, within the strict limits set out in clause 10.
4.When personal data leaves the United Kingdom
- (a)access by, or disclosure to, the Company’s Personnel and representatives based in Bangladesh in the course of delivering mandates and managing the Company’s own operations;
- (b)disclosure to sponsors, project partners, joint venture participants, investors, lenders and other counterparties in the course of originating, structuring and delivering transactions;
- (c)disclosure to public authorities, ministries, regulators and investment promotion bodies where the disclosure is required or permitted by law in connection with registration, licensing, approval or reporting;
- (d)disclosure to professional advisers, including legal, accountancy, tax, technical, environmental, engineering and insurance advisers, engaged by the Company or by a client in connection with a mandate;
- (e)processing by technology and business service providers whose infrastructure, support functions or personnel are located outside the United Kingdom;
- (f)processing by providers of identity verification, sanctions, politically exposed person and adverse media screening services engaged to meet obligations under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 and the Sanctions and Anti-Money Laundering Act 2018; and
- (g)disclosure in connection with the establishment, exercise or defence of legal claims, including cross-border litigation, arbitration and regulatory proceedings.
5.Transfer mechanisms and order of preference
- (a)first, Adequacy Regulations, where the destination is covered;
- (b)second, a transfer tool under Article 46 of the UK GDPR, being the IDTA or, where the same transfer relationship is also governed by the EU SCCs, the Addendum; and
- (c)third, and only where clause 10 permits, a derogation under Article 49 of the UK GDPR.
6.Adequacy regulations
- —the member states of the European Economic Area and Gibraltar, which are treated as adequate under transitional provisions preserved in United Kingdom law by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019;
- —countries and territories that were the subject of European Commission adequacy decisions preserved in United Kingdom law on the same basis, and any country or territory subsequently made the subject of Adequacy Regulations by the Secretary of State; and
- —organisations in the United States of America that are certified under the UK Extension to the EU–U.S. Data Privacy Framework, commonly known as the UK–US Data Bridge, established by Adequacy Regulations in force from 12 October 2023.
7.The IDTA and the UK Addendum
8.Transfer risk assessment
- (a)the categories, volume, sensitivity and frequency of the Personal Data to be transferred, and whether Special Category Data or criminal offence data is involved;
- (b)the categories of Data Subject affected and the nature and severity of the harm they could suffer if the Personal Data were accessed, altered, disclosed or lost;
- (c)the transfer tool proposed and whether its protections are enforceable in practice in the destination country;
- (d)the law and practice of the destination country relevant to the transfer, including powers of public authorities to compel disclosure or to intercept communications, data localisation requirements, and any obligation on the Importer to provide access to data;
- (e)whether Data Subjects in the United Kingdom have access to effective administrative and judicial redress in the destination country;
- (f)the Importer’s technical and organisational capability and its practical ability to comply with the transfer tool, including its record of resisting unlawful requests;
- (g)any onward transfers the Importer may make, and the controls applicable to them; and
- (h)the Supplementary Measures available and whether, taken together with the transfer tool, they secure the required standard of protection.
9.Supplementary measures
- —encryption of Personal Data in transit using current, industry-accepted transport layer security, and encryption at rest using strong, industry-accepted algorithms;
- —retention of encryption keys within the United Kingdom or a country covered by Adequacy Regulations, under the Company’s sole control, so that the Importer cannot decrypt Personal Data without the Company’s involvement;
- —pseudonymisation, tokenisation or redaction of identifiers before transfer, where the purpose of the transfer can still be achieved;
- —transfer of extracts rather than complete records, and provision of access to a hosted environment in place of transfer of copies;
- —multi-factor authentication, device management and controlled endpoints for all remote access from outside the United Kingdom; and
- —logging of access and transfer events, with the logs held by the Company and reviewed periodically.
10.Article 49 derogations and their limits
- (a)is made with the Data Subject’s explicit consent, given after the Data Subject has been informed of the possible risks arising from the absence of Adequacy Regulations and appropriate safeguards;
- (b)is necessary for the performance of a contract between the Data Subject and the Company, or for the implementation of pre-contractual measures taken at the Data Subject’s request;
- (c)is necessary for the conclusion or performance of a contract concluded in the interest of the Data Subject between the Company and another person;
- (d)is necessary for important reasons of public interest recognised in the law of the United Kingdom;
- (e)is necessary for the establishment, exercise or defence of legal claims;
- (f)is necessary to protect the vital interests of the Data Subject or of another person, where the Data Subject is physically or legally incapable of giving consent; or
- (g)is made from a register which, under United Kingdom law, is intended to provide information to the public, subject to the conditions in Article 49(2).
A derogation permits a specific, occasional transfer. It does not create a standing route for a data flow. Where the same transfer is required more than occasionally, the Company will put an IDTA or the Addendum in place, supported by a Transfer Risk Assessment, and will suspend the flow until that is done.
11.Transfers to Bangladesh
- (a)confirm the legal basis for the requirement and the identity and authority of the requesting body before disclosing;
- (b)disclose only the Personal Data that the requirement actually calls for;
- (c)inform the affected Data Subject in advance where it is lawful and practicable to do so, and otherwise as soon as it becomes lawful and practicable; and
- (d)record the disclosure, its basis and its scope in the transfer register.
12.Advisers, counterparties and other jurisdictions
13.Onward transfers and sub-processors
- (a)the onward recipient is located in a country covered by Adequacy Regulations;
- (b)the onward transfer is made under a transfer tool, or equivalent binding arrangement, that affords a standard of protection no lower than that afforded by the transfer tool between the Company and the Importer;
- (c)the Company has given prior written authorisation to the specific onward transfer; or
- (d)the onward transfer is required by law, in which case clause 14 applies.
14.Requests from public authorities
- (a)notify the Company promptly, unless prohibited by law from doing so;
- (b)where notification is prohibited, use all reasonable efforts to obtain a waiver of the prohibition and to provide as much information as it is lawfully able, including aggregate information about the number and type of requests received;
- (c)review the lawfulness of the request and challenge it, including by seeking interim relief, where there are reasonable grounds to consider it unlawful, defective or excessive;
- (d)disclose no more than the minimum amount of Personal Data required, assessed on a reasonable interpretation of the request; and
- (e)record the request, the response and the reasoning, and provide that record to the Company on request.
15.Rights of data subjects in respect of transfers
A Data Subject who is dissatisfied with how the Company has handled an international transfer may complain to the Company through the enquiry form at fratresgroup.com/contact, and may lodge a complaint with the Information Commissioner’s Office under Article 77 of the UK GDPR and section 165 of the Data Protection Act 2018.
Complaining to the Company first is encouraged but is not a precondition. A Data Subject also has the right to an effective judicial remedy under section 167 of the Data Protection Act 2018 and the right to compensation for damage suffered as a result of a contravention, under Article 82 of the UK GDPR and section 168 of that Act.