UK Privacy Law United Kingdom

UK GDPR vs. EU GDPR: What Actually Diverged After Brexit

The real differences between UK GDPR and EU GDPR: transfer mechanisms, representative duties, the DUAA 2025 reforms, and how to run dual compliance.

Regulation

UK GDPR; Data Protection Act 2018; Data (Use and Access) Act 2025

Max Penalty

GBP 17.5 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

Information Commissioner's Office (ICO)

Official Source

www.legislation.gov.uk

Executive Summary

  • The UK GDPR is the EU GDPR as retained in UK law on 1 January 2021, read alongside the Data Protection Act 2018, so the core principles, lawful bases, and rights are near-identical.
  • The practical divergences are jurisdictional: separate transfer regimes (IDTA/UK Addendum vs. EU SCCs), separate representatives under each Article 27, and separate lead regulators.
  • The Data (Use and Access) Act 2025 amended UK rules on legitimate interests, automated decision-making, and DSAR searches, widening the gap with the EU text.
  • The EU's adequacy decisions for the UK keep EU-to-UK data flowing freely; they were extended in 2025, but remain contingent on the UK not diverging too far.
  • Maximum fines differ only in currency: GBP 17.5 million or 4% of turnover in the UK versus EUR 20 million or 4% in the EU.

The UK GDPR is not a new law; it is the EU GDPR photocopied into UK statute at the end of the Brexit transition on 1 January 2021, with EU references swapped out and the Data Protection Act 2018 filling in the national detail. That is why most compliance work transfers one-to-one. What has changed since, and keeps changing, is the edges: transfer paperwork, representatives, regulator relationships, and now the substantive amendments of the Data (Use and Access) Act 2025 (DUAA).

RegulationUK GDPR + DPA 2018, as amended by DUAA 2025
Max penaltyGBP 17.5M or 4% of global annual turnover
Enforcing authorityICO
Official textlegislation.gov.uk retained EU Regulation 2016/679

Where the regimes match

Principles (lawfulness, fairness, transparency, minimisation, storage limitation, security, accountability), the six lawful bases, special category rules, data subject rights, controller and processor duties, 72-hour breach notification, DPIAs, and DPO triggers are essentially identical. A program built properly for the EU GDPR satisfies the bulk of the UK regime.

Where they diverge

Transfers. The UK runs its own restricted-transfer regime: the IDTA or the UK Addendum to the EU SCCs, plus a transfer risk assessment. The UK also makes its own adequacy findings (“data bridges”), including a UK extension to the EU-US Data Privacy Framework in force since October 2023.

Representatives and regulators. A non-UK controller caught by the UK’s Article 3 needs a UK representative; a non-EU controller caught by the EU’s needs an EU one. There is no one-stop-shop between the ICO and EU authorities: a breach affecting both populations means two notifications on two portals within the same 72 hours.

DUAA 2025 amendments. The Data (Use and Access) Act 2025 introduced recognised legitimate interests that dispense with the balancing test for listed purposes, loosened Article 22 so solely automated decisions are more broadly permitted outside special category data (with safeguards), codified a reasonable-and-proportionate search standard for DSARs, and restructured the ICO. None of this exists in EU law. Multinationals typically keep applying the EU standard group-wide because it is the stricter common denominator.

Adequacy risk. EU-to-UK flows depend on the EU’s 2021 adequacy decisions, extended in 2025 after the DUAA was assessed. Divergence is therefore self-limiting: if UK reform undercuts essential equivalence, adequacy, and with it frictionless EU data flows, is what is at stake.

Running dual compliance

Keep one control set at the stricter standard, then localise four things: transfer instruments (SCCs and Addendum/IDTA), representative appointments, breach notification playbooks (ICO and the relevant EU authority), and privacy notice jurisdiction language. Check what your site actually does against both regimes’ cookie rules, which live in PECR on the UK side, with a free scan.

Frequently Asked Questions

Is the UK GDPR the same as the EU GDPR?

Substantively very close. The UK retained the EU regulation in domestic law at the end of the Brexit transition, adjusted references, and reads it with the Data Protection Act 2018. Principles, lawful bases, rights, and accountability duties match; the differences are in transfers, representatives, regulators, and the amendments made by the Data (Use and Access) Act 2025.

Do I need to comply with both?

If you offer goods or services to, or monitor, people in both the UK and the EU/EEA, yes. Each regime applies extraterritorially on its own terms, so a US company serving both markets owes both, including potentially a UK representative and an EU representative.

Can data still flow between the UK and the EU?

Yes. The EU granted the UK adequacy decisions in June 2021, extended in 2025, so EU-to-UK transfers need no extra safeguards. UK-to-EU transfers are free because the UK treats the EEA as adequate. Adequacy is reviewed and could be withdrawn if UK law diverges too far.

What transfer paperwork does the UK require?

For UK restricted transfers, the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, plus a transfer risk assessment. EU SCCs alone do not cover UK transfers; the Addendum is the common fix for groups already on SCCs.

What did the Data (Use and Access) Act 2025 change?

Among other things: a list of recognised legitimate interests that skip the balancing test, relaxed rules on automated decision-making outside special category data, a 'reasonable and proportionate' standard for DSAR searches, and new ICO governance. EU GDPR has none of these, so dual-compliance programs should apply the stricter EU rule where one program covers both.

Regulatory Crosswalk

EU GDPRUK PECRISO 27701

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.