UK-Hosted Conveyancing Data: Why Region Matters Under the SRA and CLC Codes of Conduct
How conveyancing data location affects UK GDPR Chapter V international transfers, the SRA Code of Conduct para 6.3 and CLC Code of Conduct Outcome 3.6. Transfers approved by regulations, the UK-US Data Bridge, Transfer Risk Assessments, and what UK-hosted means in practice.
Quick Answer
Conveyancing transactions involve large volumes of personal data — names, dates of birth, financial information, source-of-funds evidence, sometimes special-category data on TA disclosures. Since 5 February 2026, UK GDPR Chapter V (as amended by the Data (Use and Access) Act 2025) permits a transfer outside the UK only if it is approved by regulations under Article 45A, is made subject to appropriate safeguards under Article 46 (for example the IDTA or approved standard clauses), or falls within a derogation in Article 49 (Article 44A). For most conveyancing firms the cleanest position is UK-hosted document tools — data stays within UK borders, no restricted international transfer under UK GDPR Chapter V arises, no separate transfer impact assessment is needed. The SRA Code of Conduct for Solicitors paragraph 6.3 (confidentiality of client information) and CLC Code of Conduct Outcome 3.6 reinforce a duty to think about data location, not just data security. Choose a tool that confirms its data-region in writing before you start sending TA forms through it.
Why data-region matters in conveyancing specifically
Conveyancing data is unusually sensitive. A single transaction file contains:
- Names, dates of birth, marital status of the parties
- Property address (sometimes a vulnerable person's home address)
- Buyer's source of wealth and source of funds — bank statements, employment evidence, gift letters
- Seller's TA6 disclosures including neighbour disputes, insurance claims, alterations
- Financial figures — purchase price, deposit, mortgage advance
- Sometimes special-category data on disability adaptations, mental health on neighbour disputes, age-related information
A data breach in conveyancing is high-impact: the data identifies real people, real addresses, real money, and supports identity theft if leaked.
UK GDPR Article 5(1)(f) requires "appropriate security" — and what counts as appropriate scales with risk. For conveyancing data, that is a high bar.
For conveyancing firms, the cleanest position is UK hosting: the data does not leave the UK, so no transfer risk assessment is needed.
The UK GDPR Chapter V transfer rules
Since 5 February 2026, UK GDPR Chapter V (as amended by the Data (Use and Access) Act 2025) permits a transfer outside the UK only if it is approved by regulations under Article 45A, is made subject to appropriate safeguards under Article 46 (for example the IDTA or approved standard clauses), or falls within a derogation in Article 49 (Article 44A). In outline:
-
Transfers approved by regulations (Article 45A) — UK regulations cover the EEA and a number of other jurisdictions including Andorra, Argentina, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, Uruguay, and certain Canadian commercial organisations (DPA 2018 Sch 21 paras 4–5, as amended, treat these transfers as approved under Article 45A). Check the Secretary of State's published list of approved destinations (UK GDPR Art 45C(4)). The UK-US Data Bridge (effective 12 October 2023; Data Protection (Adequacy) (United States of America) Regulations 2023 (SI 2023/1028)) extends UK adequacy to US organisations certified under the EU-US Data Privacy Framework with the UK Extension
-
Appropriate safeguards (Article 46) — the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or Binding Corporate Rules
-
Specific derogation (Article 49) — explicit consent, contract necessity, public interest, etc.
A document tool hosted in the United States, India, Singapore, or Australia involves an international transfer of any personal data uploaded to it. For US-hosted tools, the Data Bridge for Personal Data Transfers between the UK and US (effective October 2023) provides one route — but it requires the US provider to be certified under the EU-US Data Privacy Framework with the UK Extension. Not every US-hosted SaaS product is.
For conveyancing firms, the cleanest position is: UK-hosted, no transfer.
What "UK-hosted" actually means
Not every cloud product that says "UK-hosted" actually keeps your data in the UK at all times. Three distinctions to check:
1. Storage location
The primary location where your data sits at rest. UK-hosted means UK data centres — typically in London, Manchester, Cardiff, or Edinburgh. The major cloud providers all offer UK regions: AWS London (eu-west-2), Azure UK South / UK West, Google Cloud London (europe-west2).
2. Backup location
Where backups are stored. Some products store primary data in the UK but back up to the US or EU. UK GDPR treats backups as a separate transfer point — if a backup leaves the UK, it is a restricted transfer under UK GDPR Chapter V even if the primary is local.
3. Processing location
Where the data is processed. A UK-hosted tool with US-based machine-learning services processes UK data in the US during certain operations. This too is a transfer.
The right question to ask a vendor is: "Where does my data live, where does it back up, and where is it processed?" The answer should be UK for all three.
What the SRA and CLC expect
Neither the SRA nor the CLC mandates UK-only hosting. Both require firms to consider data location as part of overall information governance.
SRA Code of Conduct paragraph 6.3 and the SRA Principles
Code of Conduct paragraph 6.3 requires firms to keep affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents (which interlocks with UK GDPR confidentiality obligations). Behind it sits SRA Principle 2, which requires solicitors to act in a way that upholds public trust and confidence in the solicitors' profession and in legal services provided by authorised persons.
Practical effect: if you choose a US-hosted tool for conveyancing, you should be able to demonstrate:
- The transfer mechanism (adequacy / IDTA / SCCs)
- A transfer risk assessment
- Continuing oversight of the third country's surveillance regime — particularly relevant for US providers not certified under the Data Bridge, where transfers rely on the UK IDTA or SCCs and a Transfer Risk Assessment is required (the assessment must engage with FISA Section 702, Executive Order 14086 safeguards, and Executive Order 12333). For Data-Bridge-certified US providers, the adequacy regulations carry much of this assessment load
- Client awareness of cross-border processing where consent is the basis
That is a substantial compliance overhead for a sole practitioner. UK-hosting removes the overhead.
CLC Code of Conduct
The CLC Code of Conduct is built around six Overriding Principles for individuals and entities. Confidentiality of client information is dealt with under Overriding Principle 3 ('Act in the best interests of your Clients'), with confidentiality at Outcome 3.6. The CLC's confidentiality obligations are principle-based — they don't say "use a UK-hosted tool" — but the reasoning of why a tool's location matters tracks the same logic.
Cyber Essentials and Cyber Essentials Plus
Check whether your lender panels or insurers require Cyber Essentials certification. Cyber Essentials does not mandate UK hosting; it covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
What a UK-hosted document tool looks like
A document tool you can confidently use for conveyancing data should publish (or be able to confirm in writing):
| Attribute | What good looks like |
|---|---|
| Primary data location | UK region — London, Manchester, Cardiff, or Edinburgh data centre |
| Backup location | UK region (or EEA with adequacy if you are comfortable with that) |
| Processing location | UK for all operations |
| Encryption at rest | AES-256 (or equivalent strength) |
| Encryption in transit | TLS 1.3 |
| Access control | Role-based, audit-logged |
| Multi-factor authentication | Required for all admin access |
| Data Processing Addendum (DPA) | Available, signed at onboarding |
| Subprocessor list | Published, with locations |
| Data retention | Configurable to your firm's policy |
| Data deletion on request | Documented process |
| Incident notification | 72-hour ICO-aligned breach notification |
A vendor that cannot answer those questions or that has subprocessors in jurisdictions that worry you is not the right tool for conveyancing personal data.
What about consumer cloud services?
Sole practitioners sometimes use Dropbox, Google Drive, OneDrive, or WeTransfer for ad-hoc file sharing.
Check the storage region, subprocessors, audit logging and data processing terms of the plan you use.
For one-off internal file storage of non-personal data, these are fine. For sharing TA forms with a buyer's solicitor, use a plan whose storage region and data processing terms you have checked, or a purpose-built secure-share tool with UK hosting.
A worked compliance example
You are a sole practitioner SRA-regulated firm. You are choosing a document tool to assemble completion packs and share them with the buyer's solicitor.
Option A — A US-hosted SaaS tool
To use this tool lawfully under UK GDPR for conveyancing data, you need to:
- Sign a Data Processing Addendum that includes the UK IDTA (or rely on the US Data Bridge if the vendor is certified)
- Conduct a Transfer Risk Assessment (using the ICO's TRA tool) evaluating US surveillance laws and the safeguards relied on
- Document the assessment for your file
- Update your client privacy notice to disclose the cross-border transfer
- Train any other staff on the chosen safeguard
- Re-assess if the vendor changes subprocessors
Option B — A UK-hosted tool
To use this tool lawfully, you need to:
- Sign the Data Processing Addendum
- (Optionally) include the tool in your standard privacy notice as a UK-region processor
- Maintain it in your record of processing activities
Option B is cheaper in compliance overhead. Both can be lawful — but Option A requires substantial ongoing work.
Frequently asked questions
Are EEA-hosted tools acceptable?
Yes. Transfers to EEA countries are treated as approved under Article 45A (DPA 2018 Sch 21 paras 4–5), so no further safeguard is needed. A tool hosted in Dublin, Frankfurt, or Stockholm falls within that approval.
What about US-hosted tools certified under the Data Bridge?
Lawful but with conditions. The vendor must be certified under the EU-US Data Privacy Framework with the UK Extension. Certification is verifiable on the Data Privacy Framework site. The certification can be revoked, in which case your firm needs to switch quickly.
Do I need to tell my clients where their data is processed?
Yes, where data is transferred outside the UK: your privacy notice must say so and state whether the transfer is approved by regulations under Article 45A or, if not, the safeguards relied on and how to obtain a copy of them (UK GDPR Arts 13(1)(f) and 14(1)(f)). Many firms also state the location in their client engagement letter. Where the data stays in the UK, no transfer information is needed.
What if my case management is US-hosted but my document tool is UK?
That works — you have made a deliberate choice to host the documents in the UK while using a US-hosted case management. The compliance overhead applies to the case management tool, not to the document tool.
Does Cyber Essentials Plus mandate UK hosting?
No. Cyber Essentials Plus is a security certification, not a data-region certification.
What about backup tapes and disaster recovery?
The same rules apply to backups as to live data. UK-hosted backups are simplest. Backups in another country are a restricted transfer under UK GDPR Chapter V even if the live data does not leave the UK.
Is on-premises hosting (firm-owned servers) better than UK cloud?
Not necessarily. On-premises gives you full control but the compliance burden falls on you (encryption, backup, incident response, hardware refresh). UK cloud transfers most of that to the vendor and often delivers better security than a single-handed firm can manage in-house.
How BundleCreator helps
BundleCreator's data infrastructure is fully UK-hosted:
- Primary data location: Google Cloud London region (europe-west2)
- Backup location: UK only
- Processing location: UK only
- Encryption at rest: AES-256
- Encryption in transit: TLS 1.3
- Access control: Role-based, audit-logged
- MFA: Available for all users
- Data Processing Addendum: Available on request
For conveyancing firms, this means TA forms, source-of-funds evidence, and completion packs do not cross UK borders during processing. No transfer risk assessment, no IDTA paperwork, no ongoing assessment of foreign surveillance regimes.
Further reading
- UK GDPR — Chapter V (Articles 44A-49) on international transfers
- ICO — International transfers guidance
- SRA Principles — Principle 2
- SRA Code of Conduct — paragraph 6.3
- CLC Code of Conduct
- Conveyancing Document Tools for Sole Practitioners and Licensed Conveyancers
- Redacting Personal Data from TA Forms: UK GDPR Compliance
Free tools mentioned in this article
Watch the short walkthrough
Short tutorial videos showing the exact BundleCreator features mentioned in this article.

Knowing the Boundary
How BundleCreator Handles Your Data
Your bundles, documents, and case details are stored and processed in the United Kingdom. BundleCreator is hosted on Google Cloud Run in the London region (europe-west2). Limited supporting services — payment processing and authentication — operate under UK GDPR-compliant transfer safeguards. Documents are encrypted at rest with AES-256 and in transit with TLS 1.3. UK GDPR and the Data Protection Act 2018 apply; the Information Commissioner's Office is the regulator. Particular reassurance for sensitive cohorts including domestic abuse, public children law, and redacted-document workflows.

Onboarding
Getting Started with BundleCreator
Your first thirty seconds in BundleCreator — the dashboard, the trial banner, the Create Bundle button top right, the area-of-law modal covering 24 areas of law plus a Pro-tips practice tile, and the editor with sections, document, toolbar, and the Sections / Continuous numbering toggle. Built for litigants in person and legal professionals across England and Wales.

Onboarding
Creating Your First Bundle
Create a bundle in three clicks — from the dashboard Create Bundle button, through the 23-area-of-law picker, to picking a hearing type and watching the editor open. This walkthrough uses the Pro-tips Starter Bundle as the example so you see the flow without real-case complexity.
About the Author
Stevie Hayes
Legal Technology Compliance Specialist & Founder
Former Head of Data Security at Holland & Barrett, a Governance, Risk and Compliance specialist, Stevie brings over 30 years of technology expertise—including delivery for Sky, Disney, and BT—to court bundle compliance. His five years navigating the UK Family Court, both with legal representation and as a litigant in person, revealed the gap between what courts require and what tools deliver.
Areas of Expertise:
ISO 27001 Information Security • Data Security & Compliance • Practice Direction 27A • UK Family Court Procedures