Administrative Arrangement
In the data protection context, an administrative arrangement is a document, such as a memorandum of understanding, agreed between public bodies (or between a public body and an international organisation) to provide safeguards for personal data transferred between them. It offers a way to protect data being sent internationally where the parties are public authorities. Because it is not legally binding in the same way as a contract, it must be authorised by the relevant supervisory authority before it can be relied upon as a safeguard.
Under the UK GDPR, an administrative arrangement is a transfer mechanism that can serve as an appropriate safeguard for international transfers of personal data between public authorities and bodies, and typically takes the form of a non-legally binding instrument such as a memorandum of understanding. Per ICO guidance, it is usually made between a public body and another public body, an international organisation, or a similar counterpart, and requires authorisation by the ICO (as the competent supervisory authority) before it can be used as a valid transfer tool. This entry describes the position under the UK GDPR framework as reflected in ICO guidance; the equivalent mechanism exists in the EU GDPR regime, and readers should verify the applicable statutory provisions, the current authorisation requirements, and any relevant conditions against the official text, as this is distinct from other administrative-arrangement concepts (for example, Australian Administrative Arrangements Orders allocating executive responsibility) that share the name but are unrelated to data protection safeguards.
Why it matters
International transfers of personal data between public bodies raise a specific problem: the usual contractual transfer tools do not always fit the way public authorities operate or hold their powers. An administrative arrangement addresses this by allowing public bodies, or a public body and an international organisation, to set out data protection safeguards in an instrument such as a memorandum of understanding. This gives public-sector actors a route to move personal data across borders while still providing appropriate safeguards, rather than being left without a usable mechanism.
The critical feature to understand is that an administrative arrangement is typically not legally binding in the same way as a contract. Because of this, it cannot simply be adopted and relied upon by the parties on their own initiative. Under the UK GDPR framework as reflected in ICO guidance, it must be authorised by the ICO as the competent supervisory authority before it can function as a valid transfer tool. That authorisation requirement is what distinguishes it from transfer mechanisms that parties can put in place without prior regulatory sign-off, and it means the safeguards will have been scrutinised before the transfer proceeds.
The term also carries a real risk of confusion, which matters for anyone researching or drafting compliance documents. The phrase "administrative arrangement" is used in wholly unrelated contexts, most notably the Australian Administrative Arrangements Orders, which allocate executive responsibility among ministers and departments and have nothing to do with data protection safeguards. Practitioners should confirm they are relying on the data protection meaning and verify the applicable statutory provisions and current authorisation requirements against the official text, as the equivalent EU GDPR mechanism should be checked separately.
Who it's relevant to
Inside Administrative Arrangement
Common questions
Answers to the questions practitioners most commonly ask about Administrative Arrangement.