facebook-pixel
Restricted transfer

properly documented

ISO/IEC 27001:2022 certified

independently audited

Data processing agreement

already in place

Transfer risk assessment

support provided

The short version

We help the protection travel with the data.

UK GDPR does not require personal data to stay in the UK. It requires that when data leaves, the protection travels with it. Where a country has no UK adequacy regulations, you use an approved safeguard instead. That is what the International Data Transfer Agreement and the UK Addendum exist for, and they are used routinely by UK businesses transferring data to Australia, Canada, India and elsewhere.

Transferring data to Gatheroo is lawful, it requires documentation, and we provide it.

Why this is a restricted transfer

The legal position

Compliance through documentation

UK GDPR permits transfers to Australia

Article 46 UK GDPR applies and an appropriate safeguard is required.

Gatheroo is a processor

Your practice is the controller

The obligation to have a safeguard in place and to carry out a transfer risk assessment sits with you. Our job is to give you what you need to do it properly.

February 2026 changes

The Data (Use and Access) Act 2025

New transfer risk assessment rules took effect in February 2026 requiring the satisfaction of a “not materially lower” test.

Documentation

What you need from us and what we hand over.

Data Processing Agreement

Already in place, nothing to chase.

Part B of our Terms and Conditions, applying automatically from the moment you have an account. It sets your role as controller and ours as processor, and covers sub-processors, breach notification and retention.

Transfer mechanism

Completed and ready to issue.

We hold a completed International Data Transfer Agreement for UK customers. Email security@gatheroo.io and we will send it with the supporting information for your transfer risk assessment.

Transfer risk assessment support

Most of it is already published.

Our hosting, sub-processors, encryption and certification are all on the security page and in the Trust Centre. Anything further your assessment needs, including Australian government access, just ask.

Need this for a vendor assessment?

Send your security questionnaire, transfer risk assessment template, or procurement pack to security@gatheroo.io and we will return it completed with supporting evidence.

Beyond the paperwork

A transfer safeguard is a contract. These are the controls behind it.

A safeguard only means something if the technical measures stand up.

What protects the data

Hosted on AWS in Australian data centres, with no data leaving Australia in the ordinary course of operating the service

Certified to ISO/IEC 27001:2022, certificate 1357-I-1, issued under JAS-ANZ accreditation, with Gatheroo inside the certified scope

TLS 1.2 in transit. Uploaded files encrypted at rest with AES-256. Sensitive text fields encrypted at rest with field-level AES-128-GCM

Role-based, least-privilege, multi-factor authenticated production access, fully logged

Every request carries a timestamped activity log

Named, published sub-processor list

FAQ

Questions we get asked a lot.

Security FAQs: ISO 27001, encryption, data hosting and more.