UK GDPR vs EU GDPR used to be a question about the regulator and little else. Until 2025 the two texts were near-identical, and a privacy programme written for one could be pointed at the other with a find-and-replace. The Data (Use and Access) Act 2025 ended that. The UK text now differs from the EU regulation in the lawful bases, purpose limitation, the time limit for rights requests, automated decision-making, international transfers, the complaints route and the age of digital consent, and PECR has diverged from the ePrivacy rules underneath it. This guide sets out every difference that changes what an organisation has to do, and which regime governs which data.
What this guide covers
- UK GDPR vs EU GDPR: which one applies to you
- UK GDPR vs EU GDPR on lawful bases and purpose limitation
- Rights requests: the UK GDPR vs EU GDPR clock runs differently
- Automated decision-making
- Complaints: the sharpest UK GDPR vs EU GDPR difference in a privacy notice
- International transfers
- UK GDPR vs EU GDPR on cookies and marketing
- Where the two regimes still agree
- Running both: what a dual-regime programme needs
- Frequently asked questions on UK GDPR vs EU GDPR

UK GDPR vs EU GDPR: which one applies to you
The two regimes are territorial, and an organisation can be inside both. The UK GDPR, whose amended text is on legislation.gov.uk, applies to processing in the context of a UK establishment, and to organisations outside the UK that offer goods or services to people in the UK or monitor their behaviour there. The EU GDPR applies on the same basis to the EU. A UK company with EU customers is subject to the EU regulation for that processing and must appoint an EU representative under EU Article 27; an EU company with UK customers must appoint a UK representative under UK Article 27. Neither regime recognises the other’s representative.
The first UK GDPR vs EU GDPR consequence is that “we comply with GDPR” is no longer a complete sentence. A programme has to be able to say which rules it applied to which data, and the differences below are where the answer changes.
| Topic | EU GDPR | UK GDPR (as amended) |
|---|---|---|
| Regulator | National supervisory authorities; one-stop-shop lead authority | The Information Commissioner; no one-stop-shop |
| Lawful bases | Six bases in Article 6(1) | Six bases plus Article 6(1)(ea) recognised legitimate interests, with Annex 1 purposes and no balancing test |
| Purpose limitation | Article 6(4) compatibility factors | Article 8A factors and an Annex 2 list of deemed-compatible purposes |
| Rights time limit | One month from receipt, extendable by two | Article 12A applicable time period: one month from the relevant time, extendable by two, paused for clarification |
| Right of access | All personal data undergoing processing | Limited to a reasonable and proportionate search (Article 15(1A)) |
| Automated decisions | Article 22: a general prohibition with exceptions | Articles 22A to 22D: permitted with four safeguards; special category restriction |
| Complaints | Article 77: complaint to a supervisory authority | Article 77 omitted; DPA 2018 s.164A statutory complaint to the controller, 30-day acknowledgement; s.165 complaint to the Commissioner |
| Age of digital consent | 16, member states may lower to 13 | 13 |
| Transfers | Commission adequacy decisions; EU SCCs; essential equivalence | Secretary of State adequacy regulations; IDTA or UK Addendum; “not materially lower” test |
| Penalties | 20 million euros or 4 per cent | 17.5 million pounds or 4 per cent (DPA 2018 s.157) |
| Cookies | ePrivacy Directive Article 5(3) as transposed | PECR regulation 6 and Schedule A1, with statistical and appearance exceptions |
UK GDPR vs EU GDPR on lawful bases and purpose limitation
The EU regulation has six lawful bases. The UK regulation has those six and a seventh, Article 6(1)(ea), inserted on 5 February 2026: processing necessary for a recognised legitimate interest listed in Annex 1, which needs no balancing test. The EU has nothing equivalent. The UK text also names direct marketing, intra-group transmission and network security as examples of ordinary legitimate interests in Article 6(11); the EU says the same only in recitals, which is a weaker place to say it.
The UK GDPR vs EU GDPR gap on purpose limitation opened in the same amendment. The EU applies the compatibility factors in Article 6(4). The UK applies Article 8A, which weighs the nature of the processing rather than the nature of the data, and adds an Annex 2 of purposes deemed compatible. A UK controller reusing data for safeguarding or a public body’s request has a statutory answer; an EU controller still runs the test.
Rights requests: the UK GDPR vs EU GDPR clock runs differently
Under the EU regulation the one-month period for a rights request runs from receipt. Under the UK regulation, since 5 February 2026, Article 12A runs it from the “relevant time”: the latest of receipt, receipt of identity information the controller asked for, and payment of any fee. The UK clock also stops while the controller awaits clarification it reasonably requires, which the EU text does not provide. Both allow a two-month extension for complex or numerous requests.
And the UK right of access is limited, since 19 June 2025, to what a reasonable and proportionate search yields, a limit the EU text does not contain. A single DSAR procedure serving both regimes has to run the stricter EU clock for EU data and may use the UK rules only for UK data; our guide to the UK subject access request time limit sets out the UK timeline.
Automated decision-making
This is the largest UK GDPR vs EU GDPR difference in drafting terms. The EU’s Article 22 is framed as a right not to be subject to a solely automated decision with legal or similarly significant effects, subject to three exceptions. The UK replaced it with Articles 22A to 22D. The UK framing is permissive: such decisions may be made, provided the controller applies four safeguards (information, representations, human intervention, contest), and provided that decisions based on special category data meet a stricter condition.
The UK also defines “meaningful human involvement” in the statute, weighing the extent of profiling. A UK organisation can therefore deploy an automated decision process that an EU organisation cannot, but it has to build the safeguards in. The UK GDPR automated decision-making guide covers the design.
Complaints: the sharpest UK GDPR vs EU GDPR difference in a privacy notice
An EU privacy notice tells the reader they have the right to lodge a complaint with a supervisory authority under Article 77. A UK privacy notice cannot say that, because the UK text no longer contains Article 77. From 19 June 2026 the UK route is Data Protection Act 2018 section 164A: a statutory right to complain to the controller, which must facilitate complaints, acknowledge within 30 days and respond without undue delay, and section 165, the right to complain to the Commissioner.
The EU regulation imposes no acknowledgement clock on controllers at all. A dual-regime organisation needs two complaint paragraphs, and a UK complaints procedure with its own log, described in our guide to the data protection complaints procedure.
International transfers
The UK GDPR vs EU GDPR transfer rules restrict transfers to third countries, but the instruments differ. The EU uses Commission adequacy decisions, the 2021 standard contractual clauses, and the “essentially equivalent” test from the Court of Justice. The UK uses adequacy regulations made by the Secretary of State under Article 45A, the Commissioner’s International Data Transfer Agreement or the UK Addendum to the EU clauses, and a statutory “not materially lower” test in Article 45B, applied by the transferor under Article 46(1A).
EU standard contractual clauses on their own are not a UK safeguard. The two adequacy lists also differ: the UK recognises the Republic of Korea and, for certified organisations, the United States through the UK-US Data Bridge, on its own regulations. Transfers between the two regimes themselves are covered: the UK treats the EU and EEA as adequate, and the European Commission renewed the UK’s adequacy in December 2025 to 27 December 2031. Our international data transfers guide covers the mechanisms.
UK GDPR vs EU GDPR on cookies and marketing
EU cookie rules come from Article 5(3) of the ePrivacy Directive as each member state transposed it, with consent required for anything not strictly necessary. UK rules come from PECR regulation 6 and, since 5 February 2026, Schedule A1, which lists the exceptions: strictly necessary, appearance and preferences, and statistical purposes for improving the service with an objection route. The statistical exception has no EU equivalent, so a UK site can run first-party improvement analytics on information and objection where an EU site needs consent. Marketing enforcement diverged in the other direction: UK PECR contraventions now carry the section 157 maxima and personal officer liability, where EU ePrivacy penalties vary by member state.
Where the two regimes still agree
Much of the UK GDPR vs EU GDPR comparison is agreement. The principles in Article 5, the accountability duty, the contents of privacy notices under Articles 13 and 14, the processor contract terms in Article 28(3), records of processing, security under Article 32, the 72-hour breach notification, the DPIA trigger in Article 35 and the DPO rules in Articles 37 to 39 are the same in substance.
A programme built on the house structure of policy, register, procedure and record can serve both regimes with a UK layer and an EU layer on top, provided each document says which regime it applies. Our data processing agreement guide, for example, applies to both, but a UK agreement must use the UK transfer clause.
Running both: what a dual-regime programme needs
A UK GDPR vs EU GDPR programme needs: two lawful basis registers or one with a regime column; two privacy notice complaint paragraphs; one DSAR procedure that applies the EU clock to EU data; two transfer mechanisms, with the UK Addendum attached to every set of EU clauses used for UK data; a cookie classification that knows which exceptions apply on which site; and a change register for the UK, because the UK text is now the one that moves.
The UK GDPR Toolkit is the UK layer: 90 templates written to the amended text, dated to each commencement, sitting on the same structure as the site’s GDPR Toolkit so the two can be run side by side. For the full list of amendments, see our summary of the Data (Use and Access) Act 2025.
Frequently asked questions on UK GDPR vs EU GDPR
Is the UK GDPR stricter or more lenient than the EU GDPR?
On a UK GDPR vs EU GDPR reading, more lenient in most of the places it differs: the reasonable search, the recognised legitimate interests, the permissive automated decision-making rules, the statistical cookie exception. Stricter in one: the statutory complaints duty with its 30-day acknowledgement, which the EU does not impose on controllers.
Can one privacy notice cover both regimes?
Yes, if it is written in two layers: a common core and a regime-specific section covering the complaint route, the representative, the transfer mechanism and the age of consent. A notice that cites Article 77 to UK readers is wrong; one that omits it for EU readers is also wrong.
Does the UK still have EU adequacy?
Yes. The Commission renewed both UK adequacy decisions in December 2025, with effect to 27 December 2031. Data can flow from the EU to the UK without additional safeguards while they stand.
Do the differences affect processors?
Yes. A processor serving UK controllers must be able to support the Article 12A timeline and the reasonable search, use the UK transfer instruments for onward transfers, and, if it is a communications service provider, meet PECR’s own breach rules.