WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

UK General Data Protection Regulation and Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025

UK GDPR / DUAA

United Kingdom · Jan 1, 2021 (post-Brexit retained-law version of the EU GDPR); DUAA 2025 data-protection provisions largely commenced Feb 5, 2026

The UK's post-Brexit version of GDPR, carrying over the same Article 3 extraterritoriality test: applies to organizations established in the UK, or non-UK organizations offering goods/services to UK residents or monitoring their behavior there. The Data (Use and Access) Act 2025 (Royal Assent June 19, 2025) amends rather than replaces that framework; its main data-protection provisions were commenced by regulations made January 29, 2026 and took effect February 5, 2026. Key changes: a new Article 6 lawful basis for 'recognised legitimate interests' (no balancing test for listed purposes), a codified list of processing treated as compatible with the original purpose, and a broadened statutory definition of 'research and statistical purposes' covering commercial as well as publicly funded scientific research. Separately, every organization processing personal data must have a formal data-protection complaints process in place by June 19, 2026 — this duty has no small-business carve-out. Enforced by the ICO (being reconstituted as the Information Commission under the DUAA).

UK GDPR (assimilated EU law) + Data Protection Act 2018 (c. 12), as amended by the Data (Use and Access) Act 2025 (c. 18)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.