Skip to the content
Deane & Hallaçi
The office in Pristina, cropped hard top and bottom

Insights · 6 July 2026 · Egzon Hallaçi

Working on your credentials does not avoid a data transfer

The most attractive sentence available to a firm like ours would also be wrong. Here is what UK GDPR actually says about remote access, and what we hand you instead.

There is a sentence every firm in this market would like to be able to write. It goes something like: our people work on your credentials, inside your software, and nothing is ever exported, so no data leaves your systems and no international transfer takes place. The first two thirds of that are true of us and are the reason the firm is built the way it is. The conclusion is wrong, and the person who will notice is whichever solicitor or data protection officer your firm asks to review us.

The Information Commissioner’s Office puts it about as plainly as it can be put. A transfer is not only about sending personal information. It also means making personal information accessible, and that includes allowing an organisation outside the United Kingdom remote access to your systems. The office is equally clear that the location of the server does not decide the question: what decides it is where the receiving organisation is established, and whether it is a separate legal entity from yours.

The ICO even publishes a worked example that is almost exactly our model, with an Indian IT support team reaching UK-held data over a virtual private network. Its conclusion is that a restricted transfer takes place at the moment of access.

So what follows

Kosovo is not covered by UK adequacy regulations. The list runs to the European Economic Area plus a dozen or so others, and we are not on it, so adequacy is not available and the transfer needs an appropriate safeguard. In practice that means the ICO’s International Data Transfer Agreement, or the UK Addendum to the European standard contractual clauses, and before either can be relied on, a transfer risk assessment. The Data (Use and Access) Act now calls that assessment the data protection test. The standard it has to meet is that protection is not materially lower after the transfer than before it.

One more thing worth saying out loud, because it is commercially awkward and true. The obligation to get this right sits with the firm initiating the transfer, which is your firm, not ours. We cannot sign it away for you and we would be lying if we said we could.

What we do about it

We treat the paperwork as part of the product rather than as an obstacle to be got past. Before a seat opens, you get the agreement drafted for your review, the transfer risk assessment with the evidence behind it, a data-handling summary covering vetting, training, premises and equipment, and wording for your own engagement letter and privacy notice that names this firm and names Kosovo.

The last of those is the one clients trip over. It is not there to protect us. It is there because the loudest complaint anybody in this market makes about offshore administration is not that the work was poor. It is that they found out about it from somewhere other than their own adviser.

The obligation to get this right sits with the firm initiating the transfer, which is your firm and not ours. We cannot sign it away for you and we would be lying if we said we could.

None of this makes us unusual. Every provider working from outside the United Kingdom is in exactly the same position, whether or not their website mentions it. What is unusual, on the evidence of an afternoon spent reading twenty of them, is saying so first.

This note is not legal advice, and the pack we hand over is for your own adviser to test rather than to take on trust.

Egzon Hallaçi is a partner of the firm. He answers enquiries himself.

Every engagement begins with a conversation.

Tell us how your operation runs today, and where it strains. A partner replies personally.

Start a conversation