Regulations › United Kingdom

UK GDPR

UK GDPR and Data Protection Act 2018

In force privacy consumer rights transfers
WhenIn effect since 1 January 2021
Who enforces itInformation Commissioner's Office
Who it applies toOrganizations established in the UK, and those outside it offering goods or services to or monitoring people in the UK.

The UK's version of the GDPR after Brexit, now diverging in places through the Data (Use and Access) Act 2025.

The law in brief

The UK GDPR is the United Kingdom's version of the GDPR, kept in UK law after Brexit and read together with the Data Protection Act 2018. Its principles, legal bases and rights closely follow the EU text, so a GDPR program is a strong starting point, but UK-specific rules on transfers, the regulator and recent reforms now differ.

It is enforced by the Information Commissioner's Office (ICO).

Who it applies to

  • Organizations established in the UK, for processing in the context of that establishment.
  • Organizations outside the UK that offer goods or services to people in the UK or monitor their behavior there; they may need a UK representative.
  • It covers personal data about identified or identifiable living people; purely personal or household activity is outside it.
  • Most organizations that process personal data must also pay a data protection fee to the ICO.

What it requires

A lawful basis for every use

Each purpose needs a lawful basis, as under the EU GDPR; the Data (Use and Access) Act adds recognized legitimate interests that need no balancing test.

Report breaches to the ICO within 72 hours

Report a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people.

Transfers out of the UK

Send personal data outside the UK only under UK adequacy regulations, appropriate safeguards such as the International Data Transfer Agreement, or a listed exception.

Records, security and impact assessments

Keep records of processing, secure personal data appropriately, and carry out a data protection impact assessment before high-risk processing.

People's rights

People have the same core rights as under the EU GDPR: to be informed, to access their data, to rectification and erasure, to restrict processing, to data portability, to object, and protections around automated decision-making. Requests are generally answered within one month.

Enforcement and penalties

Two tiers of fines: up to £17.5 million or 4% of worldwide annual turnover, whichever is higher, for the most serious infringements, and up to £8.7 million or 2% for others. The ICO also issues reprimands, enforcement notices and assessment notices.

What's changing

Reform under way. The Data (Use and Access) Act 2025 amends the UK GDPR and the Data Protection Act 2018, including recognized legitimate interests, more flexibility for automated decision-making with safeguards, new cookie exemptions, and a duty to handle complaints. Its provisions are coming into force in stages; check which apply now. Regulatory Watch reports each stage.

What to do first

  1. Start from your GDPR program, and note where UK rules differ.
  2. Pay the ICO data protection fee if you have not.
  3. Review transfers out of the UK and use the UK's own mechanisms, such as the International Data Transfer Agreement or the UK Addendum.
  4. Track the Data (Use and Access) Act changes as they come into force, and update notices, cookies and complaints handling.
  5. Keep 72-hour breach reporting to the ICO ready.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources