Regulation Finder/United Kingdom

United Kingdom

Comprehensive

UK GDPR + Data Protection Act 2018

Authority: Information Commissioner's Office (ICO) | Enforcement: Active | Enacted: May 2018

Overview

Post-Brexit, the UK retained the GDPR as the UK GDPR, supplemented by the Data Protection Act 2018. The ICO is one of the world's most active data protection regulators. The UK has EU adequacy status, facilitating data flows. The Data Protection and Digital Information Act 2024 introduced reforms to reduce compliance burdens while maintaining high standards.

14-Topic Coverage

Data Protection Authority

Fully Addressed

The ICO is an independent authority with powers to investigate, audit, fine, and issue enforcement notices. One of the most active DPAs globally with extensive guidance.

DPA 2018 Part 5

Data Subject Rights

Fully Addressed

Full suite of GDPR rights: access, rectification, erasure, restriction, portability, objection, and automated decision-making rights.

UK GDPR Articles 12-22

Cross-Border Transfer

Fully Addressed

UK maintains its own adequacy decisions. EU adequacy for UK in place. International Data Transfer Agreement (IDTA) replaces EU SCCs. UK extension to EU-US DPF in place.

UK GDPR Articles 44-49, IDTA

Breach Notification

Fully Addressed

72-hour notification to ICO for breaches posing risk to individuals. Communication to affected individuals if high risk.

UK GDPR Articles 33-34

DPO Requirements

Fully Addressed

Mandatory for public authorities, large-scale systematic monitoring, and large-scale special category data processing. Same criteria as GDPR.

UK GDPR Articles 37-39

Children's Data

Fully Addressed

Age of consent set at 13 (lower than GDPR default of 16). ICO Age Appropriate Design Code imposes obligations on online services likely to be accessed by children.

DPA 2018 Section 9, ICO AADC

Penalties & Enforcement

Fully Addressed

Two-tier fines mirroring GDPR. ICO has issued significant fines including GBP 20M to British Airways and GBP 18.4M to Marriott (later reduced).

UK GDPR Article 83, DPA 2018 Section 157

Sector-Specific Rules

Fully Addressed

PECR governs electronic marketing and cookies. Financial Conduct Authority, NHS, and education sectors have additional data requirements.

PECR 2003, FCA rules

AI & Automated Decisions

Fully Addressed

UK GDPR Article 22 applies. UK AI governance framework takes a sector-specific, principles-based approach rather than horizontal regulation.

UK GDPR Article 22, AI Regulation White Paper 2023

Data Localisation

Not Addressed

No data localisation requirements. UK promotes free flow of data with appropriate safeguards for international transfers.

UK GDPR Chapter V

Significant Data Fiduciary

Partially Addressed

No direct equivalent. DPO and DPIA requirements based on processing scale and risk serve a similar function.

UK GDPR Articles 35, 37

Government Data

Fully Addressed

National security exemption in DPA 2018. Law enforcement processing under Part 3. Intelligence services under Part 4 with separate regime.

DPA 2018 Parts 3-4, Schedule 2

Key Statistics

Maximum Penalty
GBP 17.5 million or 4% of global turnover
Sections in Law
215
Authority
ICO

Coverage Summary

Fully Addressed12/14
Partially Addressed1/14
Not Addressed1/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate United Kingdom's regulations.

Book a Consultation