The UK GDPR is not a new law; it is the EU GDPR photocopied into UK statute at the end of the Brexit transition on 1 January 2021, with EU references swapped out and the Data Protection Act 2018 filling in the national detail. That is why most compliance work transfers one-to-one. What has changed since, and keeps changing, is the edges: transfer paperwork, representatives, regulator relationships, and now the substantive amendments of the Data (Use and Access) Act 2025 (DUAA).
| Regulation | UK GDPR + DPA 2018, as amended by DUAA 2025 |
|---|---|
| Max penalty | GBP 17.5M or 4% of global annual turnover |
| Enforcing authority | ICO |
| Official text | legislation.gov.uk retained EU Regulation 2016/679 |
Where the regimes match
Principles (lawfulness, fairness, transparency, minimisation, storage limitation, security, accountability), the six lawful bases, special category rules, data subject rights, controller and processor duties, 72-hour breach notification, DPIAs, and DPO triggers are essentially identical. A program built properly for the EU GDPR satisfies the bulk of the UK regime.
Where they diverge
Transfers. The UK runs its own restricted-transfer regime: the IDTA or the UK Addendum to the EU SCCs, plus a transfer risk assessment. The UK also makes its own adequacy findings (“data bridges”), including a UK extension to the EU-US Data Privacy Framework in force since October 2023.
Representatives and regulators. A non-UK controller caught by the UK’s Article 3 needs a UK representative; a non-EU controller caught by the EU’s needs an EU one. There is no one-stop-shop between the ICO and EU authorities: a breach affecting both populations means two notifications on two portals within the same 72 hours.
DUAA 2025 amendments. The Data (Use and Access) Act 2025 introduced recognised legitimate interests that dispense with the balancing test for listed purposes, loosened Article 22 so solely automated decisions are more broadly permitted outside special category data (with safeguards), codified a reasonable-and-proportionate search standard for DSARs, and restructured the ICO. None of this exists in EU law. Multinationals typically keep applying the EU standard group-wide because it is the stricter common denominator.
Adequacy risk. EU-to-UK flows depend on the EU’s 2021 adequacy decisions, extended in 2025 after the DUAA was assessed. Divergence is therefore self-limiting: if UK reform undercuts essential equivalence, adequacy, and with it frictionless EU data flows, is what is at stake.
Running dual compliance
Keep one control set at the stricter standard, then localise four things: transfer instruments (SCCs and Addendum/IDTA), representative appointments, breach notification playbooks (ICO and the relevant EU authority), and privacy notice jurisdiction language. Check what your site actually does against both regimes’ cookie rules, which live in PECR on the UK side, with a free scan.