Global Privacy Law United Kingdom

UK GDPR Overview: The UK's Post-Brexit Privacy Regime

How the UK GDPR and Data Protection Act 2018 work: scope, ICO enforcement, divergences from the EU version, the DUAA 2025 reforms, transfers, and PECR's cookie rules.

Regulation

UK GDPR (retained EU law, amended) with the Data Protection Act 2018, as reformed by the Data (Use and Access) Act 2025; PECR governs cookies and electronic marketing alongside

Max Penalty

Up to £17.5 million or 4% of worldwide annual turnover, whichever is higher; a lower tier of £8.7 million or 2% applies to certain duties; DUAA raises PECR fines to the same levels

Enforcing Authority

Information Commissioner's Office (ICO), transitioning to an Information Commission under the DUAA

Official Source

ico.org.uk

Executive Summary

  • After Brexit, the UK retained the GDPR as domestic law: the UK GDPR plus the Data Protection Act 2018, enforced by the ICO with fines up to £17.5 million or 4% of worldwide turnover.
  • The Data (Use and Access) Act 2025 reformed the regime: recognized legitimate interests, relaxed automated decision-making rules for non-special-category data, a proportionate DSAR search standard, new PECR fine levels, and a restructured regulator.
  • The EU's adequacy decisions for the UK were extended in 2025 through renewed adequacy, keeping EU-to-UK data flows free but making further UK divergence a live risk factor.
  • The UK's transfer toolkit is its own: the IDTA or the UK Addendum to EU SCCs, plus a transfer risk assessment, with the UK Extension to the EU-US DPF covering US flows.
  • PECR governs cookies and electronic marketing separately: consent for non-essential cookies and marketing communications, now backed by GDPR-level fines under the DUAA.

The UK GDPR began as a photocopy and is becoming a fork. The DUAA’s 2025 reforms mark the first deliberate, substantive divergence, looser automated-decision rules, recognized legitimate interests, proportionate DSAR searches, PECR fines at GDPR scale, calibrated to stay inside the EU’s adequacy tolerance while trading on flexibility. For businesses the consequence is a discipline problem, not a philosophy problem: one privacy program can still serve both regimes, but every UK-specific relaxation used must be fenced to UK-only processing, and the renewed EU adequacy that makes the whole arrangement work is a reviewable political artifact, not a law of nature. Run the stricter standard by default, exploit the divergences deliberately and narrowly, and keep the SCC fallback mapped.

RegimeUK GDPR + DPA 2018, amended by the Data (Use and Access) Act 2025
RegulatorICO (becoming the Information Commission)
Fines£17.5M / 4% top tier; PECR raised to match under DUAA
EU adequacyRenewed 2025; divergence remains the standing risk
Transfers outUK adequacy list, IDTA / UK Addendum + TRA, UK Extension to the DPF
GuidanceICO UK GDPR hub

Going deeper

Map the divergences. UK GDPR vs EU GDPR tracks where the twins now differ and what to fence.

Fix the cookie layer. PECR compliance covers banners, soft opt-in, and the new fine exposure.

Paper the transfers. IDTA and Addendum mechanics plus the UK Extension to the DPF for US flows.

Check the children’s code. The Age Appropriate Design Code applies to services likely accessed by under-18s.

PECR enforcement starts with what your site fires pre-consent: check yours with a free scan.

Frequently Asked Questions

How does the UK GDPR differ from the EU GDPR, and what did the DUAA change?

The starting point is convergence: the UK GDPR is the EU text retained into domestic law at Brexit, read with the Data Protection Act 2018, so bases, rights, accountability, breach rules, and fine architecture mirror the EU version (with sterling amounts: £17.5 million/4% and £8.7 million/2%). Divergence arrived with the Data (Use and Access) Act 2025, which amended rather than replaced the regime. Material changes: recognized legitimate interests, a new lawful basis for listed purposes (national security, emergencies, crime prevention, safeguarding, and direct marketing-adjacent purposes via secondary legislation) that skips the balancing test; automated decision-making, the Article 22-style prohibition now applies fully only to special-category data, while other solely automated significant decisions are permitted with safeguards (human-review, contest, and explanation rights), a genuine loosening relative to the EU; DSARs, a codified 'reasonable and proportionate' search standard and stop-the-clock mechanics where controllers await clarification; scientific research, broader consent and reuse provisions; international transfers, a recalibrated 'data protection test' for adequacy-style judgments; PECR, fines raised from the old £500,000 cap to full UK GDPR levels, plus limited cookie-consent exceptions for low-risk purposes like statistics (with details in secondary legislation); and the regulator itself restructured from the Information Commissioner into an Information Commission. For dual-regime companies the operational read: the UK is now the more permissive twin in specific, nameable places, and each divergence you exploit (recognized legitimate interests, relaxed ADM) must be scoped to UK-only processing or it becomes an EU violation.

Who must comply, and what does the ICO expect day to day?

Scope mirrors the EU model with UK geography: UK establishments processing personal data, and organizations outside the UK offering goods or services to, or monitoring the behavior of, people in the UK, with a UK representative required for the latter in most cases. The DPA 2018 adds regimes the EU regulation leaves to member states: criminal-offense data conditions, law-enforcement and intelligence processing parts, and exemptions (immigration, journalism, research). Day-to-day expectations track the familiar artifact set: a lawful basis per purpose with documentation; privacy notices meeting Articles 13-14; records of processing; DPIAs for high-risk processing (the ICO publishes trigger lists); security proportionate to risk; processor contracts with the Article 28 clauses; breach notification to the ICO within 72 hours where risk is likely, and to individuals where risk is high; DPO appointment on the standard triggers; and, distinctively British, the data protection fee, most UK controllers must pay the ICO an annual fee (tiered by size, up to £3,763 for the largest under the 2025 structure), and non-payment is a routinely enforced offense with monetary penalties, the most common ICO enforcement action by volume. The ICO's operating style favors guidance, audits, reprimands, and enforcement notices before headline fines, with published reprimands (a post-2022 practice) doing reputational work; but the fine authority is real, and the DUAA's Information Commission restructuring came with strategic priorities emphasizing children's privacy, adtech, and AI.

How do international transfers work from the UK, and how stable is EU-UK adequacy?

Two directions matter. Outbound from the UK: personal data leaves the UK under UK adequacy regulations (the UK maintains its own adequacy list, largely tracking the EU's, including the EEA and, for US flows, the UK Extension to the EU-US Data Privacy Framework, operative since October 12, 2023); or appropriate safeguards, the UK's own International Data Transfer Agreement (IDTA) or the UK Addendum bolted onto EU SCCs (the near-universal choice for companies already running SCCs), both requiring a transfer risk assessment (the ICO's TRA tool offers a lighter path than the EU's Schrems II methodology); or narrow exceptions. The DUAA's revised 'data protection test' recalibrates how the Secretary of State judges adequacy, standards 'not materially lower' rather than 'essentially equivalent', a wording change watched closely in Brussels. Inbound from the EU: the EU's 2021 adequacy decisions for the UK were due to sunset in June 2025; the Commission granted a technical extension to December 27, 2025, then renewed adequacy for a further period (with the DUAA's reforms assessed as compatible), keeping EU-to-UK flows free without SCCs. The risk register entry remains live though: EU adequacy is reviewable and challengeable, further UK divergence (or aggressive use of the new adequacy test) is the named threat, and prudent UK-dependent groups keep an SCC fallback mapped for their EU-to-UK flows, the same springing-safeguards logic used for US transfers.

What is PECR, and why do UK cookie and marketing rules bite separately?

The Privacy and Electronic Communications Regulations 2003 (PECR, implementing the EU ePrivacy Directive) govern electronic marketing, cookies, and communications security in parallel with the UK GDPR, and they are the regime most website operators actually violate. Cookies and similar technologies: storing or accessing information on a user's device requires informed consent (to the UK GDPR standard) unless strictly necessary for a service the user requested, so analytics, advertising, and personalization cookies need a compliant banner: no pre-ticked boxes, no consent walls that nudge, reject as easy as accept, and no firing before consent; the DUAA introduces limited exceptions for low-risk purposes (first-party statistics, appearance preferences) to be detailed in secondary legislation, but behavioral advertising stays firmly in consent territory. Electronic marketing: email and SMS marketing to individuals requires prior consent (with the narrow 'soft opt-in' for existing customers being marketed similar products, with opt-out at every message); calls and faxes have their own rules; and 'legitimate interests' does not authorize electronic marketing under PECR, a chronic misunderstanding. Enforcement: historically capped at £500,000, PECR fines were the ICO's most active penalty stream (spam and nuisance-call operators, plus cookie-banner scrutiny of major sites); the DUAA raises PECR penalties to UK GDPR levels, £17.5 million or 4%, transforming the risk math for adtech and consent-management failures. Practical posture: treat the cookie layer as a PECR obligation with UK GDPR consent standards, audit what actually fires pre-consent (tag managers drift), and keep marketing-consent records per channel.

What has ICO enforcement actually looked like, and where is it heading?

The record: the two headline fines remain British Airways (£20 million, 2020, reduced from a proposed £183 million; security failures exposing ~400,000 customers' data) and Marriott (£18.4 million, 2020, reduced from £99 million; the Starwood reservation-system breach), both breach-security cases that also demonstrated the ICO's willingness to reduce proposed penalties substantially. Since then: TikTok £12.7 million (2023, children's data processed without proper consent); Clearview AI £7.5 million (2022, scraping; the enforcement survived jurisdictional appeal skirmishes); Advanced Computer Software £3.07 million (2025, the NHS-supply-chain ransomware case and the first major UK processor fine); 23andMe £2.31 million (2025, credential-stuffing security failures); plus a steady stream of PECR penalties against spam operators and data protection fee prosecutions. Style: fewer mega-fines than the EU's record, heavier use of reprimands (published), enforcement notices, and audits; consultation-first on novel questions (generative AI call-for-views series, adtech warnings that reshaped the market without a single fine). Direction of travel under the DUAA-restructured Information Commission: children's privacy (the Age Appropriate Design Code remains a global reference), adtech and cookie compliance with the new PECR fine ceiling behind it, AI training and transparency, and cyber-security failures in supply chains. For most organizations the realistic exposure is not the £17.5 million ceiling; it is the £3-20 million security case after a breach, the published reprimand that follows a mishandled DSAR stream, and, at the base of the pyramid, the unpaid fee prosecution, all cheaper to prevent than to litigate.

Regulatory Crosswalk

EU GDPRPECRISO/IEC 27701EU-UK adequacy

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.