UK General Data Protection Regulation
The UK GDPR is the data protection law that governs how organisations handle personal information about people in the United Kingdom. It is based on the EU's General Data Protection Regulation, which was written into UK law, and it works alongside the Data Protection Act 2018. It sets out rules and principles that organisations must follow when they collect and use personal data.
The UK GDPR is the retained and domesticated version of the EU General Data Protection Regulation, forming the primary data protection framework in the United Kingdom, and operating in conjunction with the Data Protection Act 2018. It regulates the processing of 'personal data', defined as any information relating to an identified or identifiable natural person (the 'data subject'), and is supervised and enforced in the UK by the Information Commissioner's Office (ICO). It is a distinct legal instrument from the EU GDPR; although the two share substantially similar text and structure, they are separate regimes and their interpretation, guidance, and enforcement should not be assumed to be identical. This entry addresses the identity and scope of the instrument only; it does not cover specific lawful bases, cross-border transfer mechanisms, retention obligations, data subject rights procedures, or enforcement penalties, each of which requires separate analysis.
Why it matters
The UK GDPR is the primary framework determining how organisations handling personal data about individuals in the United Kingdom must operate. Because it derives from the EU GDPR but exists as a separate, domesticated instrument working alongside the Data Protection Act 2018, organisations that operate across both the UK and the EU cannot assume a single compliance approach satisfies both regimes. Although the two share substantially similar text and structure, they are distinct legal frameworks, and their interpretation, supervisory guidance, and enforcement are set independently. Treating them as interchangeable is a common expert-level error that can lead to gaps in accountability documentation and misaligned governance decisions.
The practical significance lies in the scope of what the regulation captures. It regulates the processing of 'personal data', meaning any information relating to an identified or identifiable natural person. This broad definition means that a wide range of organisational activity falls within its remit, and determining whether particular information constitutes personal data is often a threshold question that shapes every downstream obligation. Getting this scoping wrong at the outset generally undermines the reliability of any later compliance analysis.
It is important to note the limits of this entry. Understanding that the UK GDPR is the governing instrument does not, on its own, resolve which lawful basis applies to a given activity, how retention should be structured, how data subject rights requests should be handled, or how cross-border transfers should be lawfully arranged. Each of those areas requires separate, context-specific analysis, and none is addressed here.
Who it's relevant to
Inside UK GDPR
Common questions
Answers to the questions practitioners most commonly ask about UK GDPR.