What Is UK General Data Protection Regulation + Data Protection Act 2018?
The UK's data protection framework has two interlocking parts: the UK GDPR (the retained-EU-law version of GDPR that has applied since 1 January 2021) and the Data Protection Act 2018 (DPA 2018), which supplements it with UK-specific provisions on immigration, national security, law enforcement processing (Part 3), and intelligence services (Part 4). In substance, UK GDPR broadly mirrors EU GDPR, but the text, regulator guidance, and UK-specific derogations control the details. The ICO is the supervisory authority, with enforcement powers up to £17.5 million or 4% of annual global turnover, whichever is higher. The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025. Most Part 5 data-protection and privacy provisions came into force on 5 February 2026, and current ICO guidance updated 19 June 2026 says all DUAA stages are in force. Organisations must provide a way to make data-protection complaints, acknowledge them within 30 days, take appropriate steps and keep the complainant informed, and provide an outcome without unjustifiable or excessive delay; this complaint route is separate from the one-month rights-request timeline. The European Commission's current adequacy page lists the UK's GDPR and law-enforcement adequacy decisions as renewed in December 2025, subject to their terms and future review.
At a glance
- Full name
- UK General Data Protection Regulation + Data Protection Act 2018
- Short code
- UK GDPR
- Jurisdiction
- United Kingdom
- Enacted
- 2018
- Last major update
- UK GDPR in force Jan 2021 post-Brexit; DUAA 2025 changes phased through 19 June 2026; EU adequacy renewed December 2025
- Regulator
- Information Commissioner's Office (ICO)
- Private right of action
- Yes
- Statutory citation
- Data Protection Act 2018 + UK GDPR
Scope, who UK GDPR covers
Protected data
Data subject rights
Right of access (Article 15), obtain confirmation of processing and a copy of personal data
Right to rectification (Article 16), correct inaccurate or incomplete data
Right to erasure / "right to be forgotten" (Article 17)
Right to restriction of processing (Article 18)
Right to data portability (Article 20), receive data in structured, machine-readable format
Right to object (Article 21), including to direct marketing and profiling
Rights relating to automated decision-making and profiling (Article 22)
Right to lodge a complaint with the ICO
Right to compensation for damage (Article 82)
Notable features
The UK GDPR includes UK-specific derogations, including provisions in the DPA 2018 for immigration, law-enforcement, and intelligence processing. The UK also retains its own adequacy-decision framework, separate from the EU framework; check the current ICO and government lists for the destination at issue.
Enforcement & penalties
Regulator: Information Commissioner's Office (ICO)
Penalties: Two-tier administrative fines: standard tier up to £8.7 million or 2% of annual worldwide turnover; higher tier up to £17.5 million or 4% of annual worldwide turnover, whichever is higher. The ICO issued Clearview AI a £7.5M penalty notice in 2022; the ICO's October 2025 Upper Tribunal update says the case was sent back to the First-tier Tribunal and that permission to appeal to the Court of Appeal was granted in December 2025, so the matter should not be described as finally resolved or overturned. Historical penalty amounts are case-specific and should be checked against the current ICO enforcement record.
Private right of action: Article 82 UK GDPR grants a right to compensation for material or non-material damage from a GDPR infringement. Under section 187 DPA 2018, an authorised representative body may exercise specified rights on a data subject’s behalf; this is not a blanket opt-out class-action right. The Supreme Court's 2021 Lloyd v Google judgment narrowed opt-out class actions, while direct individual claims remain fact-specific.
Relevance to data brokers
UK GDPR may apply to a data broker outside the UK when the Article 3 conditions are met, including offering goods or services to people in the UK or monitoring their behaviour. Article 17 provides an erasure right subject to conditions and exceptions; the controller’s legal basis and balancing analysis still matter. A broker relying on legitimate interests should be able to explain that basis and its assessment, but an individual request does not establish the outcome in advance.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
What is the difference between EU GDPR and UK GDPR?+
The UK GDPR is the UK-retained version of EU GDPR that has applied since 1 January 2021, following Brexit. Both use GDPR-style rights and legal bases, but the texts, amendments, regulator guidance, and court interpretation can diverge. The UK supplements UK GDPR with the Data Protection Act 2018, which adds UK-specific provisions for national security, law enforcement, and immigration.
How do I file a complaint with the ICO?+
Submit a complaint through the ICO’s current complaint route. The ICO recommends giving the organisation a chance to handle its data-protection complaint process first, but says you can complain to the ICO at any time; do not treat the organisation’s 30-day acknowledgment period as a universal precondition to contacting the ICO.
Can a data broker outside the UK be subject to UK GDPR?+
Potentially. Article 3 UK GDPR can apply to a controller or processor outside the UK when the statutory offering or monitoring conditions are met. Article 27 may also require a UK representative, subject to its conditions and exceptions; a data broker should assess that obligation rather than assuming it from a listing alone.
What is a Subject Access Request (SAR)?+
A SAR is a request under Article 15 UK GDPR asking a controller to confirm whether they process your personal data and provide a copy. Controllers must respond within one calendar month (extendable to three months for complex requests) and must provide the data free of charge in the first instance.
What changed under the Data (Use and Access) Act 2025?+
The DUAA received Royal Assent on 19 June 2025. Most Part 5 data-protection and privacy changes came into force on 5 February 2026, and ICO guidance updated 19 June 2026 says all stages are in force. Organisations must provide a way to make data-protection complaints, acknowledge them within 30 days, investigate and keep people informed, and respond without unjustifiable or excessive delay. The Act also changes areas such as cookies, recognised legitimate interests, automated decision-making, and research, so the provision-specific safeguards still matter.
Official sources & citations
Other international privacy regimes
UK GDPR sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
