The UK GDPR is the United Kingdom’s version of the General Data Protection Regulation: the EU text as it was retained at the end of the Brexit transition period, read together with the Data Protection Act 2018, and since 2025 rewritten in important places by the Data (Use and Access) Act 2025. It is enforced by the Information Commissioner, not by an EU supervisory authority, and in 2026 it is no longer safe to treat it as the EU regulation with the flags changed. This guide explains what the UK GDPR is, how the three statutes fit together, what changed and when, and what an organisation has to be able to show.
What this guide covers
- What the UK GDPR is, and what sits beside it
- Who the UK GDPR applies to
- The seven principles and the accountability duty
- Lawful bases under the UK GDPR after 2025
- Rights under the UK GDPR, and the new clocks
- Complaints: Article 77 is gone
- Transfers, security and breaches
- Enforcement and the numbers that changed
- The UK GDPR commencement dates that matter
- What a UK GDPR programme has to contain
- Frequently asked questions about the UK GDPR

What the UK GDPR is, and what sits beside it
Three instruments make up the UK data protection regime, and a compliance programme has to cite all three. The UK GDPR is the regulation itself, as amended. The Data Protection Act 2018 supplements it: it supplies the conditions for special category and criminal offence data in Schedule 1, the exemptions in Schedule 2, the Commissioner’s enforcement powers in Part 6, and the penalty maxima in section 157. The Privacy and Electronic Communications Regulations 2003, PECR, sit alongside both and govern marketing calls, texts and emails, and the storing of information on a user’s device.
The fourth piece is the one pre-2025 guides do not mention. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends all three of the others. It is a set of amendments, not a new law, and it changed the lawful bases, purpose limitation, rights time limits, automated decision-making, transfers, cookies, marketing enforcement and complaints. A UK GDPR programme built on a pre-2025 template will be wrong in each of those places.
| Instrument | What it does | Where a programme cites it |
|---|---|---|
| UK GDPR | The principles, lawful bases, rights, accountability, security, breach, DPIA, DPO and transfer rules | Every policy, notice and procedure |
| Data Protection Act 2018 | Special category conditions (Sch 1), exemptions (Sch 2), complaints (s.164A), enforcement (Part 6), penalties (s.157) | Special category policy, DSAR exemptions, complaints procedure |
| PECR 2003 | Marketing calls, texts and email; cookies and similar technologies; service-provider breach notification | Marketing policy, cookie procedure |
| Data (Use and Access) Act 2025 | Amends all three, in stages from 19 June 2025 to 19 June 2026 | The change register and every dated procedure |
Who the UK GDPR applies to
The UK GDPR applies to the processing of personal data by an organisation established in the United Kingdom, whether or not the processing takes place there, and to organisations outside the United Kingdom that offer goods or services to people in the UK or monitor their behaviour there. An organisation in the second group must appoint a UK representative under Article 27 unless it is exempt. An organisation that also processes data about people in the EU is subject to the EU GDPR for that processing as well; the two regimes now differ enough that it needs to know which rules apply to which data.
It applies to controllers, who decide why and how data is processed, and to processors acting on their behalf. Article 28 requires a written contract between the two with eight mandatory terms, and Article 29 forbids a processor from acting outside the controller’s instructions. Small organisations are not exempt; the Article 30 record-keeping concession for organisations under 250 employees falls away as soon as processing is not occasional or involves special category data, which for almost any employer it does.
The seven principles and the accountability duty
Article 5 sets out the principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and, in Article 5(2), accountability. The last one decides enforcement outcomes. The controller must not only comply but be able to demonstrate compliance, and the Commissioner tests that with records: the lawful basis register, the record of processing, the privacy notice as it stood on the day, the DPIA, the breach log, the training record. A control that left no record is, for regulatory purposes, a control that did not exist.
Purpose limitation was restated by the 2025 Act. A new Article 8A sets out the factors for deciding whether a new purpose is compatible with the one the data was collected for, and an Annex 2 lists purposes that are treated as compatible without a test, such as disclosures needed for another body’s public task or for safeguarding.
Lawful bases under the UK GDPR after 2025
Article 6 still lists the six familiar bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. Since 5 February 2026 it also contains Article 6(1)(ea), the recognised legitimate interests basis. Processing necessary for one of the purposes in the new Annex 1, which covers disclosures requested by a public body for its task, national and public security, emergencies, crime, and safeguarding of vulnerable people, is lawful without the balancing test that ordinary legitimate interests require.
The 2025 Act also added Article 6(11), which names direct marketing, transmission within a corporate group, and network and information security as examples of purposes that may be legitimate interests. That does not remove the legitimate interests assessment; it confirms that those purposes can pass it. Special category data still needs an Article 9 condition and, for most of them, a Schedule 1 condition and an appropriate policy document under Data Protection Act 2018 Schedule 1 paragraph 39.
Rights under the UK GDPR, and the new clocks
The rights are the same list as the EU regulation: access, rectification, erasure, restriction, portability, objection, and protection against automated decisions. Two things changed in how they run. Article 15(1A), in force since Royal Assent on 19 June 2025, limits the right of access to what a reasonable and proportionate search yields.
Article 12A, in force since 5 February 2026, defines the “applicable time period”: one month from the relevant time, which is the latest of receiving the request, receiving any identity information asked for, and receiving any fee; extendable by two months where the request is complex or the person has made several; and paused while the controller awaits clarification it reasonably needs. Our guide to the UK subject access request time limit works through the timeline.
Automated decision-making was rewritten entirely. Article 22 has been replaced by Articles 22A to 22D. A decision is “solely automated” where there is no meaningful human involvement, and “significant” where it has a legal or similarly significant effect. Such decisions are permitted, subject to a special category restriction, provided the controller gives the individual information, a route to make representations, human intervention and a right to contest. The UK GDPR automated decision-making guide covers the four safeguards.
Complaints: Article 77 is gone
In the UK text, Article 77, the right to lodge a complaint with a supervisory authority, has been omitted. In its place, Data Protection Act 2018 section 164A, in force from 19 June 2026, gives data subjects a statutory right to complain to the controller, and requires the controller to facilitate complaints, for example with an electronic form, to acknowledge each one within 30 days, and to respond without undue delay and tell the person the outcome.
The right to complain to the Commissioner continues under section 165. A privacy notice that still says “you have the right to lodge a complaint with a supervisory authority under Article 77” is citing a provision that does not exist in UK law. The data protection complaints procedure guide sets out what to build.
Transfers, security and breaches
International transfers now run under Articles 44A to 49A. A transfer is permitted under adequacy regulations made by the Secretary of State, under an appropriate safeguard, or under a derogation. The test for adequacy, and the test the transferring organisation applies before relying on a safeguard, is whether the standard of protection in the destination is “not materially lower” than the UK’s. The safeguards in practice are the Commissioner’s International Data Transfer Agreement and the UK Addendum to the EU standard contractual clauses, both in force since 21 March 2022; EU clauses on their own are not a UK safeguard. Our international data transfers guide covers the mechanisms in priority order.
Security and breach rules are unchanged in substance: Article 32 measures appropriate to the risk, Article 33 notification to the Commissioner where feasible within 72 hours of awareness unless the breach is unlikely to result in a risk, Article 34 communication to individuals where the risk is high, and a record of every breach. The breach notification guide explains the two thresholds.
Enforcement and the numbers that changed
The Commissioner enforces through information, assessment, enforcement and penalty notices under Part 6 of the 2018 Act. The maximum penalties are set in section 157: a higher maximum of 17.5 million pounds or 4 per cent of annual worldwide turnover, whichever is higher, and a standard maximum of 8.7 million pounds or 2 per cent.
Since 5 February 2026 those same maxima apply to PECR, replacing the old 500,000-pound ceiling for marketing offences, and directors and other officers can be personally liable for marketing contraventions committed with their consent or through their neglect. The data protection fee payable to the Commissioner has three tiers, at the amounts in force since 17 February 2025: 52, 78 and 3,763 pounds.
The UK GDPR commencement dates that matter
The 2025 Act commenced in stages, and a compliance record has to apply the rule in force on the day. The four dates to remember are 19 June 2025 (Royal Assent; the reasonable and proportionate search), 20 August 2025 (PECR breach notification aligned to 72 hours), 5 February 2026 (the main data protection provisions: lawful bases, purpose limitation, Article 12A, automated decisions, transfers, cookies, PECR penalties) and 19 June 2026 (the statutory complaints duty). Our summary of the Data (Use and Access) Act 2025 lists every change against its date, and the UK GDPR vs EU GDPR guide sets out where the two texts have now parted.
What a UK GDPR programme has to contain
At minimum: a data protection policy that names the Commissioner and the three statutes; a lawful basis register that knows about Article 6(1)(ea); privacy notices with the section 164A complaint route; a DSAR procedure on the Article 12A clock; a complaints procedure with a 30-day acknowledgement; a DPIA procedure; an Article 28 processing agreement written for UK law; a transfers procedure that uses the IDTA or the Addendum; a breach procedure; a cookie procedure built on the new Schedule A1 exceptions; and the registers that evidence all of it.
The UK GDPR Toolkit ships those as 90 templates, every one citing the provision it answers and dated to the commencement that applies, with a change register listing what the 2025 Act altered and when.
Frequently asked questions about the UK GDPR
Is the UK GDPR the same as the EU GDPR?
Not any more. They shared a text at the start of 2021, but the Data (Use and Access) Act 2025 amended the UK version in a dozen places: lawful bases, purpose limitation, time limits, automated decisions, transfers, complaints and more. An organisation subject to both needs to know which rules govern which data.
Who enforces the UK GDPR?
The Information Commissioner, using the powers in Part 6 of the Data Protection Act 2018. There is no one-stop-shop mechanism.
Does the UK GDPR apply to small businesses?
Yes. There is no small-business exemption from the regulation. The record-keeping exemption for organisations under 250 employees is narrow and rarely applies in practice, and the data protection fee is payable by almost every organisation that processes personal data.
What is the age of consent under the UK GDPR?
Thirteen, under Article 8, for consent to information society services offered directly to a child. The EU default is sixteen. A form that asks for parental consent below sixteen is applying the wrong regime.