Jurisdiction Guides / Europe
United Kingdom Privacy & Data Protection Laws
Every regime below can apply to a business handling United Kingdom residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
The UK's post-Brexit version of GDPR, carrying over the same Article 3 extraterritoriality test: applies to organizations established in the UK, or non-UK organizations offering goods/services to UK residents or monitoring their behavior there. The Data (Use and Access) Act 2025 (Royal Assent June 19, 2025) amends rather than replaces that framework; its main data-protection provisions were commenced by regulations made January 29, 2026 and took effect February 5, 2026. Key changes: a new Article 6 lawful basis for 'recognised legitimate interests' (no balancing test for listed purposes), a codified list of processing treated as compatible with the original purpose, and a broadened statutory definition of 'research and statistical purposes' covering commercial as well as publicly funded scientific research. Separately, every organization processing personal data must have a formal data-protection complaints process in place by June 19, 2026 — this duty has no small-business carve-out. Enforced by the ICO (being reconstituted as the Information Commission under the DUAA).
Sector-Specific Law · 1
PECR is the UK's implementation of the ePrivacy Directive and it survived Brexit intact, so the cookie-consent and electronic-marketing rules continue to apply independently of the UK GDPR. It covers consent for cookies and similar device storage, direct marketing by call, text, email and fax, security of public electronic communications services, and customer privacy for traffic and location data. Two practical points. The ICO enforces PECR under its own penalty regime, and historically the large majority of its monetary penalties have been PECR marketing fines rather than data protection fines — so for a business doing outbound marketing, PECR is often the higher-probability enforcement exposure of the two. And the Data (Use and Access) Act 2025 raised PECR's maximum penalties to UK GDPR levels, which removes the long-standing gap that made PECR the cheaper regime to breach. Marked 'verified' on the framework; confirm current commencement of the specific DUAA penalty and cookie-exemption changes before relying on them.
Children & Minors Protections · 1
The UK runs two overlapping children's regimes with different regulators. The ICO's Age appropriate design code — the Children's Code, a statutory code under s. 123 DPA 2018 — sets fifteen standards, including data protection by default at the highest privacy setting, no profiling or nudge techniques by default, and data minimisation, and it applies to any information society service LIKELY TO BE ACCESSED by a person under 18. That 'likely to be accessed' test is much wider than 'aimed at children': a general-audience service with meaningful under-18 usage is in scope. Separately, the Online Safety Act's children's safety duties and highly effective age assurance requirements came into force July 25, 2025, enforced by Ofcom, obliging in-scope services to run children's risk assessments and, for certain content, to verify age robustly rather than by self-declaration. Compliance with one does not discharge the other.
Cross-Border Data Transfer · 1
The UK's structure mirrors Chapter V, but the instruments and the risk test are its own. Transfers rely on UK adequacy regulations, or on the ICO's International Data Transfer Agreement (or the UK Addendum bolted onto the EU SCCs), backed by a transfer risk assessment. The Data (Use and Access) Act 2025 changed the test rather than the mechanism: from February 5, 2026, new transfers must be assessed against a statutory 'data protection test' — whether the standard of protection in the destination is not materially lower than under UK law — which the exporter applies acting reasonably and proportionately. That is a deliberately less absolute standard than the EU's essential-equivalence test, and it is the clearest current point of divergence between the two regimes. Transfer mechanisms validly entered into before commencement remain effective; the ICO has signalled refreshed IDTA and Addendum templates during 2026, so template suites will need revisiting.
Data Security & Breach Notification · 1
The UK carried the GDPR breach regime over unchanged at Brexit: 72 hours to the ICO from awareness unless the breach is unlikely to result in a risk, and notification to affected individuals without undue delay where the risk to them is high. The Data (Use and Access) Act 2025 amended several parts of UK data protection law but did not shorten, lengthen, or remove this deadline. The practical divergence from the EU is jurisdictional rather than substantive: a breach touching both UK and EU residents is now two notifications to two regulators on the same clock, and the ICO runs its own reporting service and self-assessment tool.
Other Europe jurisdictions