United Kingdom
ComprehensiveUK GDPR + Data Protection Act 2018
Authority: Information Commissioner's Office (ICO) | Enforcement: Active | Enacted: May 2018
Overview
Post-Brexit, the UK retained the GDPR as the UK GDPR, supplemented by the Data Protection Act 2018. The ICO is one of the world's most active data protection regulators. The UK has EU adequacy status, facilitating data flows. The Data Protection and Digital Information Act 2024 introduced reforms to reduce compliance burdens while maintaining high standards.
14-Topic Coverage
Data Protection Authority
Fully AddressedThe ICO is an independent authority with powers to investigate, audit, fine, and issue enforcement notices. One of the most active DPAs globally with extensive guidance.
Consent Requirements
Fully AddressedSame as GDPR — six lawful bases including consent and legitimate interests. Consent must be freely given, specific, informed, and unambiguous.
Data Subject Rights
Fully AddressedFull suite of GDPR rights: access, rectification, erasure, restriction, portability, objection, and automated decision-making rights.
Cross-Border Transfer
Fully AddressedUK maintains its own adequacy decisions. EU adequacy for UK in place. International Data Transfer Agreement (IDTA) replaces EU SCCs. UK extension to EU-US DPF in place.
Breach Notification
Fully Addressed72-hour notification to ICO for breaches posing risk to individuals. Communication to affected individuals if high risk.
DPO Requirements
Fully AddressedMandatory for public authorities, large-scale systematic monitoring, and large-scale special category data processing. Same criteria as GDPR.
Children's Data
Fully AddressedAge of consent set at 13 (lower than GDPR default of 16). ICO Age Appropriate Design Code imposes obligations on online services likely to be accessed by children.
Penalties & Enforcement
Fully AddressedTwo-tier fines mirroring GDPR. ICO has issued significant fines including GBP 20M to British Airways and GBP 18.4M to Marriott (later reduced).
Sector-Specific Rules
Fully AddressedPECR governs electronic marketing and cookies. Financial Conduct Authority, NHS, and education sectors have additional data requirements.
Cookie/Tracking
Fully AddressedPECR requires consent for non-essential cookies. ICO actively enforces. Similar framework to EU ePrivacy Directive.
AI & Automated Decisions
Fully AddressedUK GDPR Article 22 applies. UK AI governance framework takes a sector-specific, principles-based approach rather than horizontal regulation.
Data Localisation
Not AddressedNo data localisation requirements. UK promotes free flow of data with appropriate safeguards for international transfers.
Significant Data Fiduciary
Partially AddressedNo direct equivalent. DPO and DPIA requirements based on processing scale and risk serve a similar function.
Government Data
Fully AddressedNational security exemption in DPA 2018. Law enforcement processing under Part 3. Intelligence services under Part 4 with separate regime.
Key Statistics
- Maximum Penalty
- GBP 17.5 million or 4% of global turnover
- Sections in Law
- 215
- Authority
- ICO
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate United Kingdom's regulations.
Book a Consultation