Loading…
The UK's framework combines the UK GDPR and the Data Protection Act 2018 with rules on electronic marketing and cookies, cybersecurity requirements for certain operators, and sector-specific regulation. Depending on its activities, an organisation may need to consider several of these alongside one another.
The requirements applicable to an organisation depend on its activities, sector, processing operations, and whether it is established in the UK.
The UK GDPR is the retained version of the EU GDPR, as amended for the UK. It sets the core principles, lawful bases, individual rights, and controller and processor obligations for processing personal data.
Depending on applicability, organisations may need to address:
Organisations should assess the UK GDPR's territorial scope, available exemptions, and their specific role before determining which obligations apply.
The Data Protection Act 2018 sits alongside the UK GDPR. It sets out exemptions, conditions for processing special category and criminal offence data, and separate regimes for law enforcement and intelligence services processing.
It also establishes the Information Commissioner's functions, enforcement powers, and criminal offences. The UK GDPR and the Act should be read together.
The Data (Use and Access) Act 2025 received Royal Assent in June 2025. It amends the UK GDPR, the Data Protection Act 2018, and PECR rather than replacing them.
Its changes include a list of recognised legitimate interests, adjustments to the rules on automated decision-making, a requirement to handle data protection complaints, and higher maximum fines under PECR. Provisions are being brought into force in stages.
Organisations should confirm which provisions have commenced before relying on any change introduced by the Act.
PECR governs electronic direct marketing, cookies and similar technologies, and the security of public electronic communications services.
Organisations should review their marketing consents, cookie banners, and tracking technologies against PECR as well as the UK GDPR, since both can apply to the same activity.
The NIS Regulations impose security and incident reporting duties on operators of essential services and relevant digital service providers.
Organisations within scope should coordinate cyber incident handling with personal data breach assessment where an incident may involve personal data. The UK government has proposed further cyber security legislation, so this area should be monitored.
Businesses operating in regulated industries may face additional obligations beyond general data protection law.
Sector considerations:
UK data protection requirements may apply to:
Controllers and processors that process personal data in the context of a UK establishment.
Businesses outside the UK that offer goods or services to individuals in the UK or monitor their behaviour there, which may also need a UK representative.
Companies processing customer, employee, user, or account information, whether as a controller or as a processor for their customers.
Businesses using cookies, tracking technologies, and electronic marketing, which fall under PECR as well as the UK GDPR.
Organisations handling employee records, recruitment data, workplace monitoring, and other employment-related personal data.
Services likely to be accessed by children, which should consider the ICO's Age Appropriate Design Code.
The precise obligations depend on the organisation's role, processing activities, size, risk profile, and territorial scope.
Controllers decide why and how personal data is processed; processors act on their instructions. Each role carries its own obligations, and contracts between them must contain specified terms. Organisations should confirm their role for each processing activity.
Each processing activity needs a lawful basis, with further conditions for special category and criminal offence data. Privacy notices should explain what is collected, why, on what basis, who receives it, and how long it is kept.
Organisations should maintain processes for requests such as access, rectification, erasure, restriction, portability, and objection. Requests generally require a response within one month, subject to permitted extensions and exemptions.
A notifiable personal data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Affected individuals must also be told where the breach is likely to result in a high risk to them.
Transfers of personal data outside the UK need a valid mechanism, such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or binding corporate rules, supported by a transfer risk assessment where required.
Organisations outside the UK that offer goods or services to, or monitor, individuals in the UK may need to appoint a UK representative under Article 27. Some organisations must also appoint a Data Protection Officer, and most controllers must pay the ICO's data protection fee.
An EU representative does not satisfy the UK requirement, and a UK representative does not satisfy the EU one. Organisations covered by both regimes may need both.
Individuals have a number of rights over their personal data. Depending on the circumstances, these may include:
Individuals should be told how and why their personal data is used, usually through a privacy notice.
Individuals may request a copy of their personal data and information about how it is processed.
Individuals may ask for inaccurate data to be corrected and, in certain circumstances, for their data to be erased.
Individuals may ask for processing to be restricted or object to it, including an absolute right to object to direct marketing.
Where applicable, individuals may receive their data in a structured, commonly used, machine-readable format.
Safeguards apply to significant decisions based solely on automated processing, as amended by the Data (Use and Access) Act 2025.
Requests generally require a response within one month. Organisations should assess which rights and exemptions apply in each case rather than treating every right as absolute.
The UK's data protection framework has developed through several stages since 2018.
The Data Protection Act 2018 took effect alongside the EU GDPR, which applied in the UK while it remained within the EU framework.
At the end of the Brexit transition period, the UK GDPR became the UK's own data protection regulation, separate from the EU GDPR.
The International Data Transfer Agreement and the UK Addendum to the EU Standard Contractual Clauses came into force for transfers from the UK.
The Data (Use and Access) Act 2025 received Royal Assent, amending the UK GDPR, the Data Protection Act 2018, and PECR, with staged commencement.
Important: provisions of the Data (Use and Access) Act 2025 commence on different dates. Confirm the status of each provision using official sources before changing your compliance programme.
The Information Commissioner's Office (ICO) is the UK's independent data protection authority. It oversees the UK GDPR, the Data Protection Act 2018, and PECR, issues guidance and codes of practice, and can investigate and take enforcement action.
Other regulators may be relevant depending on the activity, including Ofcom for online safety and communications, and the FCA and PRA for financial services. The Data (Use and Access) Act 2025 also provides for the ICO to be replaced by a new Information Commission.
Organisations should identify which regulators are relevant to their activities rather than assuming that the ICO is the only authority they deal with.
Under the UK GDPR, the most serious infringements can attract fines of up to £17.5 million or 4% of total worldwide annual turnover, whichever is higher. Other infringements fall under a lower maximum of £8.7 million or 2% of turnover.
The ICO can also issue information and assessment notices, reprimands, and enforcement notices requiring changes to processing. Individuals may claim compensation for damage, and the Data (Use and Access) Act 2025 raises the maximum fines under PECR to the UK GDPR levels once the relevant provisions are in force.
RegulatoryBridge helps organisations assess the UK's regulatory requirements and coordinate their compliance activities with wider international programmes.
Review your processing activities, notices, lawful bases, policies, governance arrangements, and operational controls to identify potential gaps.
Determine whether a UK representative or Data Protection Officer is required for your organisation, and how those roles should work alongside any EU arrangements.
Review request-handling processes, response timelines, complaint procedures, and related documentation against the requirements applicable to you.
Evaluate incident procedures, escalation responsibilities, ICO notification readiness, and coordination between privacy, security, legal, and communications teams.
Assess data flows out of the UK, transfer mechanisms, transfer risk assessments, and vendor contracts, and align them with your EU transfer programme.
Review electronic marketing consents, cookie banners, and tracking technologies against PECR and the UK GDPR.
Monitor relevant developments and review compliance plans when legislation, commencement dates, ICO guidance, or enforcement priorities change.
The scope of support is tailored to the organisation's activities, risk profile, and applicable legal requirements.
Assess your organisation's activities, role in processing personal data, industry, and connections to the United Kingdom.
Identify applicable provisions, relevant authorities, effective dates, and sector-specific requirements.
Review existing policies, notices, consent mechanisms, contracts, security controls, and operational processes.
Prioritise remediation activities and establish owners, milestones, documentation requirements, and implementation plans.
Review regulatory developments, reassess relevant obligations, and update compliance processes when required.
We act as your UK representative, support ICO interactions, and help run breach response - so your global product team doesn't have to.