UK Data Privacy Laws: UK GDPR, DPA 2018 & 2025 Reforms

The United Kingdom's data privacy framework is built on the UK GDPR and the Data Protection Act 2018, both enforced by the Information Commissioner's Office. The Data (Use and Access) Act 2025 amended both instruments, with core changes in force from 5 February 2026.
The United Kingdom operates one of the world's most developed data privacy regimes. Built on the Data Protection Act 2018 and the retained UK General Data Protection Regulation (UK GDPR), the framework provides strong rights for individuals and significant compliance obligations for organisations.
Since Brexit, the UK has maintained its own independent data protection regime, separate from the EU GDPR, enforced domestically by the Information Commissioner's Office (ICO). In 2025, the UK Parliament enacted the Data (Use and Access) Act 2025 (DUAA), the most significant overhaul of UK data law since the DPA 2018, introducing targeted reforms to how businesses, public bodies, and researchers handle personal information.
This guide covers the full UK data privacy framework as it stands in 2026: the legal foundations, the DUAA's specific reforms and phased commencement, the renewed EU adequacy decision, lawful bases, data subject rights, enforcement, and practical compliance steps for organisations.
This article presents general legal information about UK data protection law. It does not constitute legal advice. For guidance specific to your situation, consult a solicitor or data protection professional qualified to advise in England and Wales (or Scotland or Northern Ireland as applicable). Information verified as of 19 May 2026.
Quick Answer: What Are the UK's Data Privacy Laws?
The UK's data privacy framework rests on three interlocking instruments. The UK GDPR is the primary regulation, retained from EU law via the European Union (Withdrawal) Act 2018 and setting out core principles, lawful bases, individual rights, and accountability requirements. The Data Protection Act 2018 supplements the UK GDPR with domestic implementation provisions, exemptions, and separate regimes for law enforcement and intelligence services. The Data (Use and Access) Act 2025, which came into force in stages from August 2025, amends both earlier instruments with targeted reforms including new lawful-basis categories, modified automated decision-making rules, expanded cookie consent exemptions, and a restructured ICO. The ICO is the independent supervisory authority responsible for enforcing all three instruments and can impose fines up to GBP 17.5 million or 4% of global annual turnover. For cross-border flows, the EU renewed its UK adequacy decisions in December 2025, extending them to 27 December 2031.
The UK GDPR and Data Protection Act 2018
The foundational two-instrument structure has been in place since 1 January 2021, when the UK left the EU's data protection framework.

UK GDPR: Retained EU Law
When the UK left the European Union on 31 January 2020, Parliament incorporated the EU GDPR into domestic law through the European Union (Withdrawal) Act 2018. This retained version, known as the UK GDPR, preserves the same structure and principles as the EU regulation but operates as a standalone piece of UK legislation interpreted by UK courts.
The UK GDPR applies to any organisation that processes the personal data of individuals in the UK, regardless of where that organisation is based. This extraterritorial reach means a company in the United States, Canada, or anywhere else must comply with UK GDPR if it offers goods or services to UK residents or monitors their behaviour.
Data Protection Act 2018
The Data Protection Act 2018 received Royal Assent on 23 May 2018 and provides the detailed domestic implementation framework for the UK GDPR. It includes provisions that the UK GDPR delegates to member states, such as exemptions for journalism, research, and statistical purposes, and additional conditions for processing sensitive data.
The DPA 2018 also contains separate frameworks for law enforcement processing (Part 3, implementing the Law Enforcement Directive) and intelligence services processing (Part 4), each with their own distinct requirements.
The Seven Data Protection Principles
The UK GDPR establishes seven fundamental principles that underpin all data processing activities. These are legally binding requirements. Infringing them attracts the highest tier of fines.
Personal data must be:
- Processed lawfully, fairly, and transparently in relation to the data subject
- Collected for specified, explicit, and legitimate purposes and not further processed incompatibly with those purposes
- Adequate, relevant, and limited to what is necessary (data minimisation)
- Accurate and kept up to date, with inaccurate data corrected or erased without delay
- Kept in identifiable form no longer than necessary for the processing purpose
- Processed with appropriate security, protecting against unauthorised or unlawful processing and accidental loss, destruction, or damage
- Subject to accountability, requiring the controller to demonstrate compliance with all other principles
Lawful Bases for Processing Personal Data
Before processing any personal data, organisations must identify and document a lawful basis under Article 6 of the UK GDPR. There are six available bases.
The Six Lawful Bases
| Lawful Basis | Description | Common Use Cases |
|---|---|---|
| Consent | The individual has given clear, specific consent | Marketing emails, cookies, research participation |
| Contract | Processing is necessary to fulfil or enter into a contract | Employment records, customer order fulfilment |
| Legal Obligation | Processing is necessary to comply with the law | Tax reporting, anti-money laundering checks |
| Vital Interests | Processing is necessary to protect someone's life | Emergency medical treatment |
| Public Task | Processing is necessary for an official function in the public interest | Government services, regulatory functions |
| Legitimate Interests | Processing is necessary for your or a third party's legitimate interests, balanced against individual rights | Fraud prevention, network security |
Organisations must determine their lawful basis before processing begins and cannot change it retroactively. They must communicate it in privacy notices.
Special Category Data
Article 9 of the UK GDPR places additional restrictions on processing sensitive personal data, including racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric identification data, health data, and data concerning sex life or sexual orientation.
Processing special category data requires both a lawful basis under Article 6 and a separate condition under Article 9. DPA 2018 Schedule 1 provides 23 substantial public interest conditions that may supply that additional condition.
The Data (Use and Access) Act 2025: What It Changes
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and is the most significant reform to UK data protection since the DPA 2018. It amends the UK GDPR, the DPA 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR), and creates new frameworks for smart data portability and digital verification services.
The Act was the successor to the Data Protection and Digital Information (DPDI) Bill, which fell when the 2024 general election was called. The Labour government restarted the process and steered the DUAA to Royal Assent.

Recognised Legitimate Interests
The DUAA introduces a new category of "recognised legitimate interests" under Article 6(1)(f) of the UK GDPR. For these specified purposes, organisations do not need to conduct the third step of the usual legitimate interests assessment (the balancing test) because Parliament has already determined that the legitimate interest outweighs data subjects' rights in these contexts.
The five recognised legitimate interests are processing necessary for:
- National security, public security, or defence (including activities to safeguard state security)
- Preventing, detecting, investigating, or prosecuting criminal offences, or executing criminal penalties
- Safeguarding vulnerable individuals, particularly children
- Responding to emergencies under the Civil Contingencies Act 2004 that threaten life, health, or safety
- Assisting public bodies in performing their statutory tasks, where the sharing controller has received a lawful request from the public body
Organisations relying on a recognised legitimate interest must still satisfy the purpose-limitation and necessity tests; only the balancing test step is removed. Activities such as direct marketing and network security remain as codified "legitimate interests" but do not fall within the recognised category and still require a full three-part assessment. The ICO published guidance on recognised legitimate interests in early 2026.
Automated Decision-Making: Reformed Rules
The DUAA creates a more permissive framework for automated decision-making under the amended Article 22 of the UK GDPR. Under the original UK GDPR, solely automated decisions with legal or similarly significant effects were generally prohibited unless one of three narrow conditions applied (consent, contractual necessity, or authorised by law).
Under the DUAA amendments, organisations can make such decisions in broader circumstances, but must implement mandatory safeguards:
- Providing data subjects with meaningful information about significant decisions made about them
- Enabling individuals to make representations and contest decisions
- Ensuring human intervention is available upon request
- Reviewing challenged decisions with genuine human involvement
The ICO has announced plans to consult on updated automated decision-making and profiling guidance, with a statutory code of practice expected through 2026.
Subject Access Requests: Stop-the-Clock
The DUAA introduces a "stop-the-clock" mechanism for subject access requests (SARs). When an organisation requests further information from the data subject to locate the data or clarify the request, the one-calendar-month response period pauses until that information is received. This addresses a longstanding practical difficulty where organisations faced the same deadline regardless of whether the requester had provided necessary clarification.
Scientific Research Provisions
The DUAA clarifies that "scientific research" for UK GDPR purposes may include commercial research, a point previously uncertain. It also allows researchers to seek consent for broad areas of related research rather than a single, narrowly defined project, and sets out safeguards that must accompany research uses of personal data.
Complaints Process
Organisations must now provide an electronic mechanism for data subjects to make complaints. They must also inform individuals of the outcome of their complaint. A separate commencement order is expected to bring the complaints provisions into force approximately 12 months after Royal Assent (around mid-2026), giving organisations time to build compliant complaints-handling processes.
Children's Data Protection
New rules require online services likely to be accessed by children to consider how to protect and support children when designing those services. The ICO has also launched investigations into how social media and video-sharing platforms use UK children's personal information, with the Reddit and Imgur enforcement actions in 2026 marking the beginning of heightened enforcement in this area.
Smart Data and Digital Verification Services
Part 1 of the DUAA establishes a legislative framework for smart data schemes, enabling consumers to share their data with authorised third parties across sectors. Part 2 creates a statutory framework for digital verification services, including a trust register for certified providers, enabling streamlined identity verification. The digital identity provisions commenced on 1 December 2025.
The DUAA's Phased Commencement
The DUAA has been commenced in stages through separate statutory instruments. The key dates are:
| Stage | Date | What Commenced |
|---|---|---|
| Stage 1 | 20 August 2025 | Technical provisions clarifying the legal framework; new ICO statutory objectives; government reporting requirements on AI and copyright |
| Stage 2a | 5 September 2025 | Amendments to DPA 2018: legal professional privilege exemption (s. 79) and national security exemption (s. 88) for law enforcement processing (SI 2025/996) |
| Stage 2b | 30 September 2025 | Amendments to the Online Safety Act 2023: retention obligations for regulated services in child death investigations (s. 124) (SI 2025/982) |
| Stage 2c | 17 November 2025 | Amendments to DPA 2018: joint processing by intelligence services and competent authorities, and consequential amendments (ss. 89-90) (SI 2025/996) |
| Stage 3a | 1 December 2025 | Digital verification services framework; statutory trust register (Part 2, except ss. 45-48) (SI 2025/1213) |
| Stage 3b | 5 February 2026 | Most data protection amendments in Part 5 of the DUAA, including recognised legitimate interests, automated decision-making reforms, SAR stop-the-clock, PECR cookie changes, and scientific research provisions |
| Stage 3c | 6 February 2026 | New offences for creating or requesting purported non-consensual intimate images of adults, including AI-generated deepfakes, inserting ss. 66E-66H into the Sexual Offences Act 2003 (DUAA s. 138; SI 2026/31) |
| Stage 4 | Expected spring/summer 2026 | ICO governance transition to the Information Commission (once board members appointed); National Underground Asset Register; electronic births and deaths registration |
| Complaints | Expected mid-2026 (approximately 12 months post-Royal Assent) | Controller obligations to establish electronic complaints processes and notify outcomes |
The ICO's Transformation: Becoming the Information Commission
One of the most structurally significant changes in the DUAA is the abolition of the Information Commissioner's Office as a corporation sole and its replacement with a body corporate called the Information Commission.
The current ICO is a corporation sole, meaning legal authority is vested in the individual Information Commissioner (currently John Edwards, appointed January 2022). The new Information Commission will be led by a board comprising a Chair, a CEO, and seven non-executive members with shared governance responsibility.
Paul Arnold has been appointed as the first CEO of the Information Commission on an interim basis for up to two years. Recruitment for seven non-executive board members was underway as of early 2026. The transition to the Information Commission is expected in spring/summer 2026, once appointments are completed.
During the transition, the ICO continues to exercise all of its current powers. Nothing changes for organisations in terms of who they deal with until the governance transition formally takes effect.
The EU Adequacy Decision for the UK
After the UK left the EU's data protection framework, the European Commission needed to assess whether UK law continued to provide adequate protection before EU organisations could freely transfer personal data to the UK.
Original 2021 Adequacy Decisions and the 2025 Renewal
The Commission granted the UK adequacy in June 2021, adopting two decisions (one under the EU GDPR, one under the Law Enforcement Directive). The original decisions contained a four-year sunset, set to expire on 27 June 2025.
As that deadline approached, the Commission extended validity by six months while it assessed the impact of the Data (Use and Access) Act 2025 on UK data protection standards. Following that assessment, the Commission formally renewed both adequacy decisions on 19 December 2025, extending them until 27 December 2031.
This means organisations in EU and EEA member states can continue to transfer personal data to the UK without Standard Contractual Clauses or other Article 46 safeguards. The Commission confirmed that the DUAA's reforms did not lower UK data protection standards.
UK-to-EU Transfers
Data flowing from the UK to the EU/EEA does not require a separate adequacy decision. The UK has recognised EU/EEA member states as providing adequate protection under the UK's own adequacy regime.
Cookies and PECR: The New Consent Exemptions
The Privacy and Electronic Communications Regulations 2003 (PECR) govern cookies, electronic marketing, and communications metadata in the UK. The DUAA's Part 5 amendments to PECR, which came into force on 5 February 2026, made two major changes.
Expanded Cookie Consent Exemptions
Regulation 6(1) of PECR previously exempted only "strictly necessary" cookies from the requirement to obtain user consent. The DUAA adds new categories of cookies that may be set without prior consent, provided they are strictly necessary for one of the following purposes:
- Statistical or analytics purposes aimed at improving the service (aggregate, non-identifiable statistics only)
- Service functionality and user interface tailoring (personalisation and preference cookies)
- Software updates and user-experience improvement
- Fault and technical error detection
- Security and fraud detection
The analytics exemption carries conditions: the data must be used only for improving the service, it must not be used to profile individuals for other purposes, and the website must clearly explain its use of analytics cookies and provide a simple, free mechanism for users to object.
Elevated PECR Fines
The DUAA aligns PECR enforcement with the UK GDPR fining regime. The previous maximum PECR fine was GBP 500,000. Under the DUAA, the ICO can now impose PECR fines of up to GBP 17.5 million or 4% of global annual turnover, whichever is higher, for the most serious PECR breaches.
The ICO published draft updated cookies guidance for consultation in late 2025. Finalised guidance is expected in spring/summer 2026.
Cross-Border Data Transfers
Transferring personal data outside the UK requires compliance with Chapter V of the UK GDPR. The primary mechanisms are:
UK Adequacy Regulations
The UK Secretary of State can make adequacy regulations recognising that a third country provides adequate data protection. When in place, data flows freely without additional safeguards. The UK recognises all EU/EEA member states and countries previously recognised under EU GDPR adequacy decisions at the time of the UK's departure.
UK International Data Transfer Agreement (IDTA)
For transfers to countries without UK adequacy, organisations can use the UK International Data Transfer Agreement (IDTA), a UK-specific contractual framework that replaced the EU Standard Contractual Clauses on 21 March 2022. Organisations may also use the UK Addendum to the EU SCCs as an alternative.
The DUAA introduces a new standard for the Secretary of State's adequacy assessments: whether the third country provides a level of data protection "not materially lower" than the UK standard, replacing the previous "essentially equivalent" test. The ICO has signalled plans to update the IDTA and Addendum in 2026 to reflect DUAA changes.
UK Extension to the EU-US Data Privacy Framework
The UK established its own extension to the EU-US Data Privacy Framework, enabling transfers to US organisations that self-certify to the UK extension scheme.
Data Subject Rights Under the UK GDPR
The UK GDPR grants individuals eight statutory rights over their personal data.

The Eight Rights
| Right | What It Means | Response Deadline |
|---|---|---|
| Right to be informed | Organisations must provide clear, transparent privacy information at point of collection | At time of data collection |
| Right of access (SARs) | Individuals can request a copy of all personal data held about them | 1 calendar month (stop-the-clock applies under the DUAA) |
| Right to rectification | Individuals can request correction of inaccurate or incomplete data | 1 calendar month |
| Right to erasure | Individuals can request deletion in certain circumstances (purpose fulfilled, consent withdrawn, unlawful processing) | 1 calendar month |
| Right to restrict processing | Individuals can limit use of their data while accuracy or objections are assessed | 1 calendar month |
| Right to data portability | Individuals can receive data in machine-readable format and request transfer to another controller (consent or contract basis only) | 1 calendar month |
| Right to object | Individuals can object to legitimate interests or public task processing; absolute right to object to direct marketing | Without delay for direct marketing; 1 calendar month otherwise |
| Rights re automated decisions | Individuals have the right not to be subject to solely automated decisions with significant effects, with right to human review (amended by the DUAA) | 1 calendar month |
Responses are generally free. Organisations can charge a reasonable fee or refuse manifestly unfounded or excessive requests. The one-month deadline can be extended by a further two months for complex requests if the data subject is notified within the first month.
Breach Notification Requirements
Notifying the ICO
Under Article 33 of the UK GDPR, organisations must report a qualifying personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. This obligation applies when the breach is likely to result in a risk to the rights and freedoms of individuals.
Not every breach requires notification. Organisations must assess the likely risk and report only those breaches meeting the threshold. If reporting takes longer than 72 hours, reasons for the delay must be provided.
Notifying Affected Individuals
When a breach is likely to result in a high risk to the rights and freedoms of individuals, the organisation must also notify those individuals directly and without undue delay. The threshold for individual notification is higher than for ICO notification.
Phased reporting is permitted under Article 33(4). Where a full investigation cannot be completed within 72 hours, organisations may report initial information and follow up as the investigation progresses.
The Information Commissioner's Office: Powers and Enforcement
The ICO is the UK's independent supervisory authority for data protection and information rights. It has broad powers under the DPA 2018 to issue information notices, assessment notices, enforcement notices, and penalty notices.
Penalty Structure
| Tier | Maximum Fine | Applies To |
|---|---|---|
| Higher tier | GBP 17.5 million or 4% of global annual worldwide turnover (whichever is higher) | Breaches of data protection principles, lawful bases, data subject rights, and international transfer rules |
| Standard tier | GBP 8.7 million or 2% of global annual worldwide turnover (whichever is higher) | Failures by controllers and processors, certification bodies, and monitoring bodies |
| PECR (post-DUAA) | GBP 17.5 million or 4% of global annual turnover (whichever is higher) | Most serious PECR infringements |
Notable ICO Enforcement Actions
British Airways (2020): The ICO fined British Airways GBP 20 million for a data breach affecting over 400,000 customers. Attackers harvested payment card details from the BA website in 2018. The ICO found BA had failed to implement appropriate security measures under Articles 5(1)(f) and 32 of the UK GDPR.
Marriott International (2020): Marriott received a GBP 18.4 million fine after a cyber-attack on the Starwood Hotels system compromised approximately 339 million guest records worldwide.
TikTok (2023): The ICO issued a GBP 12.7 million penalty against TikTok for misusing children's personal data, processing the data of children under 13 without appropriate parental consent. TikTok's appeal hearing was scheduled for May 2026.
Clearview AI (2022, upheld 2025): The ICO fined Clearview AI GBP 7.5 million for unlawfully scraping images of UK residents to build a facial recognition database. The Upper Tribunal upheld the fine in October 2025, with Clearview granted permission to further appeal.
Reddit (2026): On 24 February 2026, the ICO fined Reddit GBP 14.47 million for unlawful processing of children's personal information, including failing to apply robust age assurance measures and failing to conduct a DPIA before January 2025. This was the ICO's largest children's privacy fine to date.
Imgur/MediaLab.AI (2026): The ICO fined MediaLab.AI (owner of Imgur) GBP 247,590 in February 2026 for processing the data of children under 13 without parental consent or a lawful basis.
X and xAI (Grok) investigation (2026): In February 2026, the ICO and Ofcom jointly announced investigations into X and xAI concerning the Grok AI chatbot, examining whether personal data was processed lawfully, fairly, and transparently, and whether appropriate safeguards were in place.
Data Protection Officers and DPIAs
When a DPO Is Required
Certain organisations must appoint a Data Protection Officer (DPO). Appointment is mandatory when:
- The organisation is a public authority or public body (except courts in their judicial capacity)
- Its core activities require regular and systematic monitoring of individuals on a large scale
- Its core activities involve processing special category data or criminal conviction data on a large scale
Voluntary DPO appointment is permitted; once appointed, the same statutory requirements apply regardless of whether appointment was mandatory.
Data Protection Impact Assessments (DPIAs)
A DPIA is required before processing likely to result in high risk to individuals' rights and freedoms. Mandatory contexts include processing involving new technology, large-scale profiling, systematic monitoring of public areas, and large-scale special category data processing. Where a DPIA identifies unresolvable high risk, the organisation must consult the ICO before proceeding.
How UK Data Privacy Law Compares to the EU GDPR
The UK and EU frameworks share the same foundations but are diverging as the DUAA takes effect.
| Area | UK GDPR (post-DUAA) | EU GDPR |
|---|---|---|
| Supervisory authority | ICO (transitioning to Information Commission) | Lead supervisory authority in country of establishment |
| Max fine | GBP 17.5m or 4% global turnover | EUR 20m or 4% global turnover |
| Recognised legitimate interests | Five public-interest categories exempt from balancing test | No equivalent; full LIA required for all legitimate interest claims |
| Automated decision-making | More permissive under DUAA, with mandatory safeguards | Article 22 prohibition with narrow exceptions |
| International transfer test | "Not materially lower" standard (DUAA) | "Essentially equivalent" standard |
| Cookie consent exemptions | Expanded to analytics, functionality, error detection (post-DUAA) | Strictly necessary only (under ePrivacy Directive) |
| SAR stop-the-clock | Yes, introduced by DUAA | No |
| PECR/ePrivacy max fine | GBP 17.5m or 4% (post-DUAA) | EUR 10m or 2% (proposed ePrivacy Regulation pending) |
Organisations that comply with the EU GDPR are generally well-positioned for UK GDPR compliance, but should review the DUAA-specific changes separately.
Recent Developments (2025-2026)
ICO children's enforcement intensifies (2026). The Reddit (GBP 14.47m) and Imgur (GBP 247,590) fines in February 2026, combined with ongoing investigations into Discord, Pinterest, and X, signal that age assurance requirements and children's DPIA obligations are under active enforcement.
ICO Grok/AI investigation (2026). The joint ICO-Ofcom investigation into X and xAI over the Grok chatbot's use of personal data is the first major UK regulatory action targeting AI-generated content and LLM-based personal data processing.
DUAA Part 5 in force from 5 February 2026. The main data protection amendments are now operative, requiring organisations to review legitimate interests assessments, automated decision-making policies, SAR processes, and cookie consent banners.
EU adequacy renewed to 2031 (19 December 2025). The European Commission formally renewed both UK adequacy decisions, extending free data flows from the EEA to the UK until 27 December 2031.
ICO cookie guidance in development. Draft guidance on the new PECR Regulation 6 cookie exemptions was published for consultation in late 2025. Finalised guidance is expected in spring/summer 2026.
Information Commission transition in progress. Board recruitment was underway in early 2026. The governance transition to the Information Commission is expected to complete in spring/summer 2026.
For related guidance, see our article on UK recording laws and the World Data Privacy Laws hub.
Practical Compliance Steps for Organisations
Organisations processing UK personal data should take the following steps to ensure compliance as of 2026:
- Map all processing activities and maintain a Record of Processing Activities (ROPA) under Article 30 of the UK GDPR
- Review legitimate interests assessments in light of the DUAA recognised legitimate interests and early ICO guidance; update documentation if relying on any of the five recognised categories
- Audit automated decision-making processes and implement the DUAA-mandated safeguards: information disclosure to data subjects, right to challenge, and human review mechanism
- Update SAR procedures to apply the DUAA stop-the-clock where appropriate when requesting clarification from data subjects
- Review cookie consent banners against the new PECR Regulation 6 exemptions; update privacy notices to reflect changes in analytics and functionality cookie treatment
- Check international transfer mechanisms: confirm adequacy status of destination countries, and review existing IDTAs and Addenda for any DUAA-driven updates signalled by the ICO
- Conduct DPIAs for any processing involving children, new technologies, AI systems, or large-scale profiling, and ensure documentation is current
- Implement breach response plans enabling ICO notification within 72 hours and individual notification for high-risk breaches
- Appoint a DPO if required under the three mandatory criteria, or designate a responsible data protection person and document the decision
- Prepare electronic complaints processes ahead of the DUAA complaints provisions commencing in mid-2026
This article provides general legal information, not legal advice. Data protection law is complex and subject to ongoing development through DUAA commencement orders and ICO guidance. Consult a data protection solicitor for advice tailored to your organisation's specific circumstances. UK law information verified as of 19 May 2026.
Related UK Data Privacy Guides
- How to Make a Subject Access Request (SAR)
- How to Complain to the ICO
- Data Breach Reporting: The 72-Hour Rule
- The Right to Erasure (Right to Be Forgotten)
- UK criminal record checks and data rights by nation (DBS, Disclosure Scotland, AccessNI)
This guide is part of our United Kingdom law guides.
Frequently Asked Questions
What is the difference between UK GDPR and EU GDPR?
The UK GDPR is the version of the EU GDPR incorporated into UK domestic law after Brexit through the European Union (Withdrawal) Act 2018. Both share the same core principles, rights framework, and penalty structure. Key differences have grown with the Data (Use and Access) Act 2025: the UK has introduced recognised legitimate interests (five public-interest categories exempt from the balancing test), a more permissive automated decision-making framework, expanded PECR cookie exemptions, a stop-the-clock mechanism for SARs, and a simplified adequacy test for international transfers. The UK GDPR is enforced by the ICO (transitioning to the Information Commission), with fines denominated in GBP up to GBP 17.5 million, while the EU GDPR is enforced by national supervisory authorities with fines in EUR up to EUR 20 million.
What is the Data (Use and Access) Act 2025 and when did it come into force?
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. It is the most significant reform to UK data protection law since the Data Protection Act 2018 and amends the UK GDPR, DPA 2018, and PECR. The Act was commenced in stages: technical provisions from 20 August 2025, digital identity and child safety provisions from 1 December 2025, and the main data protection amendments (recognised legitimate interests, automated decision-making, SAR stop-the-clock, and PECR cookie changes) from 5 February 2026. The ICO governance transition to the Information Commission and complaints provisions are expected in mid-to-late 2026.
What are recognised legitimate interests under the DUAA 2025?
Recognised legitimate interests are five specific public-interest processing purposes for which Parliament has determined the legitimate interest automatically outweighs data subjects' rights, removing the need for organisations to conduct the balancing test step of the usual legitimate interests assessment. The five categories are: national security, public security, or defence; preventing, detecting, investigating, or prosecuting crime; safeguarding vulnerable individuals including children; responding to emergencies under the Civil Contingencies Act 2004; and assisting public bodies in performing statutory tasks. Direct marketing and network security are not recognised legitimate interests; they remain codified legitimate interests that still require a full three-part assessment.
What are the penalties for violating UK data privacy laws?
The ICO enforces a two-tier penalty structure. The higher tier allows fines of up to GBP 17.5 million or 4% of total annual worldwide turnover, whichever is greater, for serious violations including breaches of data protection principles, processing without a lawful basis, and violating data subject rights. The standard tier allows fines of up to GBP 8.7 million or 2% of global turnover for less severe breaches. Following the DUAA, PECR infringements can also attract fines up to GBP 17.5 million or 4% of turnover, compared to the previous GBP 500,000 maximum.
How quickly must a data breach be reported to the ICO?
Under Article 33 of the UK GDPR, organisations must report a qualifying personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Not all breaches require notification; only those likely to result in a risk to individuals' rights and freedoms. Where a breach is likely to result in a high risk, the organisation must also notify affected individuals directly. Phased reporting is permitted: initial information can be provided within 72 hours with further details following as the investigation progresses. Failing to report when required can result in a fine of up to GBP 8.7 million or 2% of global turnover.
Can EU organisations still transfer personal data to the UK after Brexit?
Yes. The European Commission renewed its adequacy decisions for the UK on 19 December 2025, extending them until 27 December 2031. Both decisions cover transfers under the EU GDPR and under the Law Enforcement Directive. EU and EEA organisations can therefore continue to send personal data to the UK without Standard Contractual Clauses or other Article 46 safeguards. The Commission assessed that the Data (Use and Access) Act 2025 did not lower UK data protection standards.
What are the new cookie rules under the DUAA 2025?
The DUAA amended Regulation 6(1) of PECR to expand the categories of cookies that may be placed without prior user consent. In addition to strictly necessary cookies, websites can now use cookies without consent for: statistical or analytics purposes aimed at improving the service, service functionality and personalisation, software updates and user experience improvement, fault and technical error detection, and security or fraud detection. Analytics cookies used under this exemption must not be used for individual profiling and users must be informed and given a simple, free mechanism to object. PECR fines were also increased to match the UK GDPR maximum of GBP 17.5 million or 4% of turnover.
What is the Information Commission and when will it replace the ICO?
The Information Commission is the new data protection regulatory body that will replace the ICO under the Data (Use and Access) Act 2025. Unlike the ICO, which is a corporation sole with authority vested in the Information Commissioner personally, the Information Commission will be a body corporate governed by a board comprising a Chair, a CEO, and seven non-executive members. Paul Arnold has been appointed as the first CEO on an interim basis. Recruitment for non-executive board members was ongoing in early 2026, with the governance transition expected in spring/summer 2026 once appointments are completed.
Updates
Major refresh: added full coverage of the Data (Use and Access) Act 2025, the four-stage phased commencement, recognised legitimate interests, PECR/cookie consent reforms, the ICO-to-Information-Commission transition, EU adequacy renewal to December 2031, and 2025-2026 ICO enforcement actions including Reddit £14.47m fine.
Initial publication covering the UK GDPR and DPA 2018 framework, ICO powers, and early DUAA coverage.
Sources and References
- Data Protection Act 2018(legislation.gov.uk).gov
- Data (Use and Access) Act 2025(legislation.gov.uk).gov
- UK GDPR Guidance and Resources(ico.org.uk).gov
- A Guide to the Data Protection Principles(ico.org.uk).gov
- A Guide to Lawful Basis for Processing(ico.org.uk).gov
- Special Category Data Rules(ico.org.uk).gov
- Individual Rights Under UK GDPR(ico.org.uk).gov
- Personal Data Breaches: A Guide(ico.org.uk).gov
- Maximum Fine Under UK GDPR and DPA 2018(ico.org.uk).gov
- DUAA Data Protection and Privacy Changes(gov.uk).gov
- DUAA Plans for Commencement(gov.uk).gov
- DUAA Factsheet: UK GDPR and DPA(gov.uk).gov
- DUAA Factsheet: ICO Reforms(gov.uk).gov
- EU Renews UK Adequacy Decisions(ec.europa.eu).gov
- International Data Transfer Agreement and Guidance(ico.org.uk).gov
- Data Protection Officers Guidance(ico.org.uk).gov
- Data Protection Impact Assessments (DPIAs)(ico.org.uk).gov
- ICO Enforcement Action: TikTok(ico.org.uk).gov
- ICO Clearview AI Upper Tribunal Judgment(ico.org.uk).gov
- Reddit £14.47m Fine for Children Privacy Failures — ICO 2026(ico.org.uk).gov
- Data (Use and Access) Act 2025 (Commencement No. 1) Regulations 2025(legislation.gov.uk).gov
- Information Commission Non-Executive Member Appointments(apply-for-public-appointment.service.gov.uk).gov
- Data (Use and Access) Act 2025 (Commencement No. 2) Regulations 2025 (SI 2025/982)(legislation.gov.uk).gov
- Data (Use and Access) Act 2025 (Commencement No. 3 and Transitional and Saving Provisions) Regulations 2025 (SI 2025/996)(legislation.gov.uk).gov
- Data (Use and Access) Act 2025 (Commencement No. 4) Regulations 2025 (SI 2025/1213)(legislation.gov.uk).gov
- Data (Use and Access) Act 2025 (Commencement No. 5) Regulations 2026 (SI 2026/31)(legislation.gov.uk).gov