The UK GDPR, and the ways it no longer matches the EU.
The UK kept the GDPR’s structure, then began editing it. This guide covers scope, the seven lawful bases, rights, ICO expectations, transfers after the 2031 adequacy renewal, and every change the Data (Use and Access) Act 2025 made.
Researched against ICO, GOV.UK and European Commission sources on . Written by Shambhu Kumar, Vedhacon.
Two instruments, read together
UK data protection law is not a single document. The UK GDPR carries the principles, lawful bases, rights and controller duties. The Data Protection Act 2018 supplies the detail the Regulation leaves to national law: exemptions, special category conditions, the law enforcement regime in Part 3 and the intelligence services regime in Part 4. The Privacy and Electronic Communications Regulations 2003 (PECR) govern cookies and direct marketing separately.
The Data (Use and Access) Act 2025 (DUAA) did not replace any of these. It amended all three in place. That matters practically: if you are reading an unconsolidated copy of the UK GDPR published before 2026, you are reading a superseded text.
Roles are unchanged from the EU model. A controller decides why and how personal data is processed; a processor acts on the controller’s documented instructions. The ICO’s enforcement against Capita and Advanced Computer Software, both acting wholly or partly as processors, is a reminder that security duties attach to processors directly, not only to the controller who engaged them.
What actually changed, and when
DUAA received Royal Assent on 19 June 2025. Its provisions were commenced in stages rather than all at once, so the compliance position moved through 2026.
| Change | Effect | In force |
|---|---|---|
| Recognised legitimate interests | New lawful basis for specified purposes; no legitimate interests assessment required | 5 February 2026 |
| Automated decision-making | Restrictions relaxed for non-special-category data, subject to safeguards | 5 February 2026 |
| Children’s data | Online services likely accessed by under-18s must consider their needs by design | 5 February 2026 |
| Cookie exemptions | Three new consent exemptions: statistics, appearance, emergencies | 5 February 2026 |
| PECR fine ceiling | Raised from £500,000 to UK GDPR levels | 5 February 2026 |
| New ICO powers | Interview notices, compelled independent reports, new criminal sanction for false statements | 5 February 2026 |
| Complaints handling | Controllers must accept and resolve complaints directly | 19 June 2026 |
| ICO restructuring | Corporation sole becomes the Information Commission, a body corporate | In progress through 2026 |
Subject access, scientific research and international transfer clarifications also form part of the Act. Confirm the precise commencement position for any provision you are relying on, since dates were set by separate commencement regulations.
Seven lawful bases, not six
This is the clearest divergence from the EU GDPR. The UK now has seven lawful bases. You must identify and document yours before processing starts, and you must name it in your privacy information.
- (a) Consent — freely given, specific, informed and unambiguous.
- (b) Contract — necessary for a contract with the person, or pre-contractual steps they asked for.
- (c) Legal obligation — necessary to comply with the law, not counting contractual obligations.
- (d) Vital interests — necessary to protect someone’s life.
- (e) Public task — a task in the public interest or official function with a clear basis in law.
- (ea) Recognised legitimate interest — new under DUAA. Covers safeguarding vulnerable people, responding to emergencies, preventing or investigating crime, national security, public security and defence, and disclosing data to a public body that requests it for its own public task. No legitimate interests assessment is required, but you must still tell people you are relying on it. Not available to public authorities performing their official tasks.
- (f) Legitimate interests — your interests or a third party’s, subject to a balancing test. Still requires an LIA. Not available to public authorities performing their official tasks.
Two points that generate most of the remediation work we see. First, necessity is objective. The ICO’s position is that processing must be a targeted and proportionate route to your purpose; “it is how we run our business” is not sufficient if a less intrusive route exists. Second, you cannot swap bases later. Retrospectively switching from consent to legitimate interests when someone withdraws consent is treated as inherently unfair. Decide once, document the reasoning, and keep it.
Your choice also determines which rights apply. Under legal obligation, the rights to erasure, portability and objection all fall away. Under contract, portability applies but objection does not. The absolute right to object to direct marketing survives every lawful basis.
Special category data under Article 9 still needs a second condition, drawn from the UK GDPR and Schedule 1 of the DPA 2018, and most of those conditions require an Appropriate Policy Document. Criminal offence data needs a condition too, unless you process under official authority.
Rights, and the subject access clock
The eight rights carry over: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights related to automated decision-making and profiling.
The headline operational change is to subject access. DUAA introduced a stop-the-clock rule: where you genuinely need more information from the requester to identify the data sought, you may pause the response deadline until they reply. It also confirmed in statute that you need only conduct a reasonable and proportionate search, which aligns the legislation with what the ICO had already been saying.
Neither change extends the underlying deadline of one month, extendable by a further two months for complex or numerous requests. Treat stop-the-clock as a narrow tool for genuine identification problems, not a general pause button; using it to buy time on a request you simply have not started is the kind of thing that turns a subject access complaint into a regulatory one.
Solely automated decisions became easier, not unregulated
Before DUAA, solely automated decisions with legal or similarly significant effects were permitted only in narrow circumstances. Since 5 February 2026 they may also rest on legitimate interests, provided no special category data is involved and three safeguards are in place: tell people how and when automated decision-making is used, let them contest the outcome, and give them a route to meaningful human intervention.
Where special category data is involved, the stricter pre-existing restrictions continue to apply.
Anyone deploying AI into recruitment, credit, pricing or fraud detection should treat the safeguards as the real obligation. The ICO published a Recruitment rewired update in March 2026 setting out its expectations for automated decision-making in recruitment, a statutory code of practice on AI and ADM is due, and draft ADM guidance has been out for consultation. The direction is more operational flexibility paired with closer scrutiny of how you evidence it.
The under-18 test is about who actually uses the service
Providers of information society services likely to be accessed by children must now consider, by design, how children are protected and supported, that children merit specific protection because they are less aware of the risks, and that their needs differ by age and stage of development.
The ICO has been explicit that scope turns on likely actual use, not stated audience. Declaring a service 18+ does not remove the obligation if under-18s are in fact likely to be using it. Organisations already conforming to the Age Appropriate Design Code are, in the ICO’s view, likely already meeting these requirements.
This is an area of live enforcement. In February 2026 the ICO fined Reddit £14.47m and Imgur/MediaLab £247,590 over children’s data handling, age assurance shortcomings and failure to carry out data protection impact assessments, following a review of 34 social media and video-sharing platforms.
Three new cookie exemptions, all narrow
Consent is still the default for storage and access technologies. DUAA added three exemptions, each limited by a sole purpose test:
- Statistics — collecting information solely about how your own online service is used. This permits some first-party analytics without consent. It does not cover third-party analytics providers that combine the data with other information they hold or reuse it for their own purposes, which excludes most common configurations.
- Appearance — adapting the service’s appearance or functions to a user’s preferences.
- Emergencies — determining a user’s location when they request emergency assistance.
Read sole purpose strictly. A tag that also feeds advertising or personalisation is outside all three.
The enforcement stakes rose at the same time: PECR maximum fines went from £500,000 to UK GDPR levels, up to £17.5m or 4% of global annual turnover. The ICO has been running a large-scale review of cookie compliance across the UK’s most-visited websites, has contacted 93 organisations about website cookies, and reprimanded Sky Betting and Gaming for sharing personal data with ad tech companies before users could accept or reject advertising cookies.
Adequacy runs to 2031, in both directions
EEA to UK. The UK’s original adequacy decisions of June 2021 were unusual in being time-limited, and were due to lapse in 2025. The European Commission held off renewing until it could assess DUAA. Following a favourable European Data Protection Board opinion on 20 October 2025 and member state approval, the Commission announced on 19 December 2025 that renewal was complete, adopting two decisions — one under the GDPR, one under the Law Enforcement Directive — extending adequacy to 27 December 2031. Transfers from the EEA into the UK therefore continue without supplementary safeguards.
This is the single most misreported fact about UK privacy law. A great deal of commentary written in 2025 still says adequacy expires that year. It does not.
UK to elsewhere. The UK operates its own adequacy regulations (“data bridges”), the International Data Transfer Agreement, and the UK Addendum to the EU standard contractual clauses. DUAA introduced a new adequacy test: the destination’s protection must be not materially lower than the UK’s. The EDPB noted that this test does not expressly reference government access, individual redress or an independent supervisory authority, and invited the Commission to monitor UK onward transfers. Expect continued scrutiny here rather than a settled position.
One structural risk worth recording on your risk register: DUAA lets the Secretary of State make changes to international transfers, automated decision-making and ICO governance through secondary regulations, which receive less parliamentary scrutiny. The EDPB flagged this as a divergence risk to be monitored. Adequacy is secure for now, but the mechanism that could erode it is faster than primary legislation.
72 hours, unchanged
Notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to people’s rights and freedoms. Where the risk is high, tell affected individuals without undue delay. Record every breach internally, including those you decide not to report, together with the reasoning.
Security remains the ICO’s most active enforcement area. The two largest recent fines both followed major cyber incidents: Capita, £14m, and Advanced Computer Software, £3.07m. Both organisations were acting as processors, at least in part.
You must now handle complaints yourself
Since 19 June 2026, controllers must provide a route for people to complain directly about how their personal data has been handled — for example an electronic complaint form — and must operate a process for dealing with those complaints. You must acknowledge a complaint within 30 days, make enquiries, and provide an outcome without undue delay.
This is a genuinely new operational obligation and an easy one to miss, because it looks administrative rather than legal. If your privacy notice currently points people straight to the ICO, it is out of date.
Fines, and the ICO’s widened toolkit
The ceiling for UK GDPR and DPA 2018 breaches is £17.5m or 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. PECR now carries the same ceiling. Fines sit alongside reprimands, enforcement notices and assessment notices.
DUAA also strengthened the ICO’s investigative powers. It can require an organisation to commission and pay for an independent investigative report, and it can issue interview notices compelling a named person to attend and answer questions. Declining to answer may be treated as an aggravating factor at the penalty stage, and knowingly or recklessly making a false statement under questioning is now a criminal offence.
Practically, this changes how you prepare for regulatory contact. Individual employees can be compelled to speak, so briefing and record accuracy matter more than they did.
Where the UK and EU regimes now differ
| Topic | EU GDPR | UK GDPR |
|---|---|---|
| Lawful bases | Six | Seven, adding recognised legitimate interest |
| Solely automated decisions | Permitted in narrow circumstances | Wider, on legitimate interests, where no special category data and safeguards are met |
| Subject access | No statutory stop-the-clock | Stop-the-clock plus reasonable and proportionate search |
| Analytics cookies | Consent required | Narrow first-party statistics exemption |
| Complaints | No general duty to operate a complaints process | Controller must accept and resolve complaints |
| Regulator | National supervisory authorities, EDPB | ICO, becoming the Information Commission |
| Maximum fine | €20m or 4% | £17.5m or 4% |
For most organisations already running an EU GDPR programme, the UK regime is a superset with easements, not a different system. The practical risk is not that UK rules are stricter, but that you apply a UK easement to EU processing where it does not exist. Keep the statistics cookie exemption, recognised legitimate interests and the relaxed ADM rules scoped to UK processing only.
UK GDPR, answered directly
Is the UK GDPR the same as the EU GDPR?
Did UK adequacy expire in 2025?
Do we still need an EU representative?
Can we drop our cookie banner now?
Does recognised legitimate interest replace legitimate interests?
Is the ICO still the regulator?
From DUAA gap analysis to evidence the ICO will accept
We map your existing programme against the amended UK regime, rescope lawful bases, rebuild cookie and ADM documentation, and stand up the complaints process the law now requires.
Primary references
- ICO, A guide to lawful basis, UK GDPR guidance and resources.
- GOV.UK, Data (Use and Access) Act 2025: data protection and privacy changes, published 27 June 2025.
- European Commission adequacy decisions for the United Kingdom, adopted 19 December 2025, valid to 27 December 2031.
- European Data Protection Board opinions on the draft UK adequacy extension decisions, 20 October 2025.
- ICO enforcement actions, 2025 to 2026.
This guide is general information, not legal advice. Verify any provision against the consolidated legislation and current ICO guidance before relying on it.