Skip to main content
Category: Privacy Regulations

UK General Data Protection Regulation

Also known as: UK GDPR, UK General Data Protection Regulation
Simply put

The UK GDPR is the data protection law that governs how organisations handle personal information about people in the United Kingdom. It is based on the EU's General Data Protection Regulation, which was written into UK law, and it works alongside the Data Protection Act 2018. It sets out rules and principles that organisations must follow when they collect and use personal data.

Formal definition

The UK GDPR is the retained and domesticated version of the EU General Data Protection Regulation, forming the primary data protection framework in the United Kingdom, and operating in conjunction with the Data Protection Act 2018. It regulates the processing of 'personal data', defined as any information relating to an identified or identifiable natural person (the 'data subject'), and is supervised and enforced in the UK by the Information Commissioner's Office (ICO). It is a distinct legal instrument from the EU GDPR; although the two share substantially similar text and structure, they are separate regimes and their interpretation, guidance, and enforcement should not be assumed to be identical. This entry addresses the identity and scope of the instrument only; it does not cover specific lawful bases, cross-border transfer mechanisms, retention obligations, data subject rights procedures, or enforcement penalties, each of which requires separate analysis.

Why it matters

The UK GDPR is the primary framework determining how organisations handling personal data about individuals in the United Kingdom must operate. Because it derives from the EU GDPR but exists as a separate, domesticated instrument working alongside the Data Protection Act 2018, organisations that operate across both the UK and the EU cannot assume a single compliance approach satisfies both regimes. Although the two share substantially similar text and structure, they are distinct legal frameworks, and their interpretation, supervisory guidance, and enforcement are set independently. Treating them as interchangeable is a common expert-level error that can lead to gaps in accountability documentation and misaligned governance decisions.

The practical significance lies in the scope of what the regulation captures. It regulates the processing of 'personal data', meaning any information relating to an identified or identifiable natural person. This broad definition means that a wide range of organisational activity falls within its remit, and determining whether particular information constitutes personal data is often a threshold question that shapes every downstream obligation. Getting this scoping wrong at the outset generally undermines the reliability of any later compliance analysis.

It is important to note the limits of this entry. Understanding that the UK GDPR is the governing instrument does not, on its own, resolve which lawful basis applies to a given activity, how retention should be structured, how data subject rights requests should be handled, or how cross-border transfers should be lawfully arranged. Each of those areas requires separate, context-specific analysis, and none is addressed here.

Who it's relevant to

Data protection officers and privacy leads
Those responsible for an organisation's data protection posture need to identify the UK GDPR as the governing instrument for processing personal data relating to individuals in the UK, and to recognise that it operates alongside the Data Protection Act 2018 rather than in isolation. Where an organisation also processes data subject to the EU GDPR, they should treat the two regimes as distinct and avoid assuming shared guidance or enforcement.
Compliance and legal professionals
Legal and compliance teams rely on correctly naming the applicable instrument before analysing specific obligations. Recognising the UK GDPR as a retained and domesticated framework, separate from the EU GDPR, is a prerequisite for accurate advice, though determining lawful bases, retention rules, and transfer mechanisms requires further analysis not covered here.
Information governance and data stewardship functions
Governance teams responsible for data ownership, cataloguing, and policy need to understand which regulatory framework scopes their personal data holdings. Because the UK GDPR captures any information relating to an identified or identifiable person, accurate scoping of what constitutes personal data underpins the reliability of governance records, though accountability under the framework generally requires demonstrable evidence rather than stated intent alone.
Organisations processing UK personal data
Any organisation collecting or using personal data about individuals in the United Kingdom falls within the remit of the UK GDPR and should identify it as the applicable framework, supervised and enforced by the Information Commissioner's Office. Organisations operating across the UK and EU should not assume a single approach satisfies both regimes.

Inside UK GDPR

Retained EU law origin
The UK GDPR is the version of the EU General Data Protection Regulation as it was retained and adapted into UK domestic law following the UK's departure from the EU. It closely mirrors the EU GDPR in structure and principles but operates as a distinct legal instrument under UK jurisdiction.
Relationship with the Data Protection Act
The UK GDPR generally operates alongside the UK's domestic data protection legislation, which supplements and gives effect to it, including provisions on exemptions, special categories, and the powers of the supervisory authority. The two should be read together rather than treated as a single instrument.
Supervisory authority
Enforcement and oversight in the UK context sit with the UK's national data protection supervisory authority, rather than an EU member state authority. This is a key divergence point from the EU GDPR, where the relevant supervisory authority is determined within the EU framework.
Core data protection principles
The UK GDPR generally carries over the core processing principles found in the EU GDPR, such as lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Accountability typically requires demonstrable evidence of compliance, not merely stated intent.
Controller and processor roles
The UK GDPR retains the distinction between a data controller, which determines the purposes and means of processing, and a data processor, which processes personal data on the controller's behalf. Obligations are allocated differently between these roles, with the controller generally bearing primary accountability.
Lawful bases for processing
The UK GDPR retains a defined set of lawful bases for processing personal data, of which consent is only one. Selecting an appropriate lawful basis is context-dependent and does not by itself guarantee overall compliance.
Data subject rights
The framework preserves individual rights over personal data, such as rights of access, rectification, erasure, restriction, portability, and objection, subject to the conditions and exemptions set out in UK law. This entry does not detail the specific conditions or time limits for each right.

Common questions

Answers to the questions practitioners most commonly ask about UK GDPR.

Is the UK GDPR identical to the EU GDPR?
No. Although the UK GDPR is derived from the EU GDPR and retains much of the same structure and terminology, it operates as a distinct legal instrument following the UK's departure from the EU. It sits alongside the Data Protection Act and is supervised by the UK's Information Commissioner's Office rather than EU supervisory authorities. The two regimes can diverge over time in interpretation, guidance, and legislative amendment, so they should not be treated as interchangeable. Cross-border transfer mechanics between the UK and EU are governed separately and are out of scope for this entry.
Does the UK GDPR still apply now that the UK has left the EU?
Yes. The UK's departure from the EU did not remove GDPR-style obligations; rather, the framework was retained in domestic law as the UK GDPR, working in conjunction with the Data Protection Act. Organisations processing personal data within scope remain subject to its requirements. The distinction to keep in mind is that compliance is now assessed under the UK regime and enforced by the UK's supervisory authority, not under the EU instrument.
Which supervisory authority enforces the UK GDPR?
The UK's Information Commissioner's Office generally acts as the supervisory authority for the UK GDPR. Organisations subject to the regime typically engage with the ICO for guidance, breach notification where required, and regulatory matters. Enforcement mechanics and any penalties are out of scope for this entry.
How does the UK GDPR relate to the Data Protection Act?
The UK GDPR does not operate in isolation. It is read together with the Data Protection Act, which provides supplementary provisions, exemptions, and detail on matters left to national implementation. When determining obligations under the UK regime, practitioners should generally consult both instruments rather than the UK GDPR alone.
Do controllers and processors have different obligations under the UK GDPR?
Yes. As in the EU regime from which it derives, the UK GDPR distinguishes between the controller, who determines the purposes and means of processing, and the processor, who acts on the controller's documented instructions. Each bears distinct accountability, and demonstrating compliance generally requires documented evidence rather than stated intent. The specific allocation of obligations should be assessed against the roles in each processing arrangement.
Does complying with the UK GDPR also satisfy EU GDPR obligations?
Not automatically. Because the two are separate instruments that may diverge, meeting UK GDPR requirements does not by itself guarantee compliance with the EU GDPR, and vice versa. Organisations operating across both jurisdictions typically need to assess their obligations under each regime independently. The mechanics of dual compliance and any transfer arrangements between the regimes are out of scope for this entry.

Common misconceptions

The UK GDPR and the EU GDPR are the same law, so compliance with one automatically means compliance with the other.
Although the UK GDPR is closely modelled on the EU GDPR, it is a separate legal instrument operating under UK jurisdiction with its own supervisory authority and domestic supplementing legislation. Organisations subject to both regimes should treat them as distinct and not assume that treatment, exemptions, or cross-border transfer arrangements are identical. This entry does not cover cross-border transfer mechanics.
Consent is required for all processing under the UK GDPR.
Consent is only one of several lawful bases available under the UK GDPR. Depending on context, another lawful basis may be more appropriate, and relying on consent where it is not freely given or is impractical can create additional risk. No single lawful basis guarantees compliance in isolation.
Pseudonymising or encrypting personal data takes it outside the scope of the UK GDPR.
Pseudonymisation is reversible and pseudonymised data generally remains personal data within scope of the UK GDPR. Encryption and similar controls are security measures and do not render data non-personal. Only genuinely irreversible anonymisation typically moves data outside most data protection obligations.

Best practices

Maintain separate compliance analysis for the UK GDPR and the EU GDPR where an organisation is subject to both, rather than assuming a single approach satisfies each regime.
Read the UK GDPR together with the UK's domestic data protection legislation to correctly apply exemptions, special category provisions, and supervisory authority powers.
Document and evidence the lawful basis selected for each processing activity, treating consent as one option among several rather than a default, and reassess where circumstances change.
Keep demonstrable evidence of accountability, such as records of processing decisions and policies, recognising that stated intent alone is insufficient under the framework.
Clearly define and record controller and processor roles for each processing arrangement so that obligations and primary accountability are correctly allocated.
Avoid treating pseudonymisation or encryption as removing data from scope, and confirm whether data is genuinely and irreversibly anonymised before excluding it from UK GDPR obligations.