Last updated: 27 September 2026
Quick answer: UK GDPR vs EU GDPR comes down to scope, regulator and direction of travel. The UK GDPR copied the EU text into UK law after Brexit, so principles, lawful bases, rights and the 72-hour breach rule are almost identical. The differences sit in supervision, transfers, fines in pounds, children’s consent age and UK-only reforms.
If you are a data protection officer covering both the UK and the EU, you are working with two regimes that share the same DNA but are no longer maintained by the same people. The EU regime is shaped by the European Data Protection Board (EDPB) and the Court of Justice of the EU. The UK regime is shaped by Parliament, the UK courts and the Information Commissioner’s Office (ICO).
This guide explains where the two regimes still match, where they differ today, what the Data (Use and Access) Act 2025 has changed, and how to run one privacy programme that satisfies both.
What is the difference between UK GDPR and EU GDPR?
The UK GDPR is the retained, amended version of the EU General Data Protection Regulation that applies in the UK, read together with the Data Protection Act 2018. The EU GDPR is Regulation (EU) 2016/679, which applies directly across the European Economic Area.
When the Brexit transition period ended on 31 December 2020, the UK kept the GDPR text but changed the parts that referred to EU institutions. References to the Commission became references to the Secretary of State, the supervisory authority became the ICO, and the EDPB and one-stop-shop mechanism fell away for UK processing.
The practical effect is that most of your day-to-day compliance work is the same under both regimes. The seven principles in Article 5, the six lawful bases in Article 6, special category conditions, data subject rights, records of processing, DPIAs, processor contracts and security obligations all carry the same article numbers and broadly the same wording.
In practice: if your GDPR programme is solid for the EU, you are most of the way to UK compliance. The gap is usually in UK-specific paperwork (the ICO fee, UK transfer tools, a UK representative) rather than in core principles.
UK GDPR vs EU GDPR: side-by-side comparison
The table below summarises the differences that matter most to DPOs as at September 2026.
| Topic | EU GDPR | UK GDPR (with DPA 2018) |
|---|---|---|
| Legal source | Regulation (EU) 2016/679, directly applicable | UK GDPR plus Data Protection Act 2018, amended by the Data (Use and Access) Act 2025 |
| Regulator | National supervisory authorities, coordinated by the EDPB, with a one-stop-shop for cross-border processing | The ICO (the Information Commission from 30 September 2026) only; no one-stop-shop |
| Maximum fines | EUR 20 million or 4% of worldwide turnover; EUR 10 million or 2% for lower tier | GBP 17.5 million or 4%; GBP 8.7 million or 2% for lower tier |
| Children’s consent for online services | 16 by default; member states may set 13 to 15 | 13 |
| Transfer tools | Commission adequacy decisions, EU SCCs, BCRs | UK adequacy regulations, the IDTA or UK Addendum to EU SCCs, BCRs |
| Local representative | Non-EU controllers need an EU representative (Article 27) | Non-UK controllers need a UK representative (Article 27) |
| Registration fee | No EU-wide fee | Data protection fee payable to the ICO unless exempt |
| Breach notification | 72 hours to the lead or local supervisory authority | 72 hours to the ICO |
Where do UK and EU GDPR still match?
They match on almost every core obligation. Both require a lawful basis for processing, transparency notices, data minimisation, accuracy, storage limitation and appropriate security.
- Accountability. Both require you to demonstrate compliance, including a record of processing activities (ROPA) under Article 30.
- Data subject rights. Access, rectification, erasure, restriction, portability and objection apply under both, with a one-month response period that can be extended in defined cases.
- Breach notification. Articles 33 and 34 still require notification to the regulator within 72 hours of becoming aware of a reportable breach, and notification to individuals where the risk is high.
- DPOs and DPIAs. The triggers for appointing a DPO and for carrying out a DPIA are the same in both texts.
How are international transfers different?
Transfers are where the two regimes diverge most in daily work. Each side decides for itself which countries are adequate and which contractual tools are acceptable.
EU to UK transfers
Personal data can flow freely from the EEA to the UK because the European Commission has found the UK adequate. According to the ICO’s guidance on receiving data from the EEA, the renewed adequacy decisions were adopted on 19 December 2025 and last until 27 December 2031.
UK to rest-of-world transfers
For restricted transfers out of the UK, you rely on UK adequacy regulations or an Article 46 safeguard. The ICO’s International Data Transfer Agreement and Addendum came into force on 21 March 2022. You can use the IDTA on its own, or attach the UK Addendum to the EU SCCs so one contract covers both regimes.
What has the Data (Use and Access) Act 2025 changed?
The Data (Use and Access) Act 2025 (DUAA) is the first significant UK reform of the retained GDPR. The ICO confirms it received Royal Assent on 19 June 2025 and that the provisions affecting data protection law and PECR are now in force. According to the government’s commencement plan, the majority of the data protection changes commenced on 5 February 2026.
The main data protection changes in the Act include:
- Recognised legitimate interests. A list of purposes, such as crime prevention and safeguarding, for which no balancing test is needed.
- Automated decision-making. A more permissive framework for solely automated decisions, with safeguards, except where special category data is involved.
- Subject access requests. Confirmation that controllers need only carry out reasonable and proportionate searches.
- Cookies and PECR. New consent exemptions for some low-risk cookies and PECR fines aligned with UK GDPR levels.
- Transfers. A new “not materially lower” test for adequacy and transfer safeguards.
- Complaints. A duty for controllers to have a process for handling data protection complaints.
The complaints duty applied from 19 June 2026: controllers must acknowledge a data protection complaint within 30 days and respond without undue delay. The Act also restructures the regulator, and from 30 September 2026 the ICO becomes the Information Commission, with the same regulatory functions. The EU GDPR has none of these changes, so UK and EU obligations now differ on substance, not just administration.
The EU side is not standing still either. The European Commission’s Digital Omnibus proposal of 19 November 2025 would amend parts of the GDPR, but at the time of writing it is still being negotiated, so nothing has changed yet for EU controllers. For a deeper look at the UK reforms, see our Data (Use and Access) Act 2025 compliance guide.
If you want to map one set of controls to GDPR, UK GDPR and 50+ other frameworks, you can start your 14-day free trial of Enactia’s AI-powered GRC platform.
Which regime applies to your organisation?
Many organisations are subject to both. Use this quick decision guide for each processing activity.
- Are you established in the UK? If yes, the UK GDPR applies to processing in the context of that establishment.
- Are you established in the EEA? If yes, the EU GDPR applies to processing in the context of that establishment.
- Do you target or monitor people in the UK from outside it? If yes, the UK GDPR applies under its territorial scope, and you likely need a UK representative.
- Do you target or monitor people in the EEA from outside it? If yes, the EU GDPR applies, and you likely need an EU representative.
- More than one yes? You have dual obligations. Map each activity in your ROPA to the regime or regimes that apply.
How should DPOs manage both regimes in one programme?
Build once on the common core, then add a thin layer of jurisdiction-specific controls.
Dual-compliance checklist
- Record in your ROPA which activities fall under the UK GDPR, the EU GDPR or both.
- Update privacy notices to name the correct regulator and transfer mechanism for each audience.
- Appoint an EU or UK representative where Article 27 requires one.
- Pay the ICO data protection fee if you process personal data in the UK and are not exempt.
- Use EU SCCs with the UK Addendum for vendors receiving both EU and UK data.
- Run one breach procedure with two notification branches: the ICO and the relevant EU authority.
- Review the DUAA changes now in force, and decide whether to adopt UK flexibilities or keep the stricter EU standard group-wide.
- Add a UK complaints-handling process that meets the DUAA duty in force since 19 June 2026.
- Keep one set of data subject request workflows, with regime-specific response templates.
Common mistake: relying on a UK flexibility, such as recognised legitimate interests, for a processing activity that also serves EU users. Where one system serves both markets, the EU standard often has to prevail.
Connected tooling helps here. A platform that cross-maps controls, like the Compliance Universe, lets you evidence a control once and show it against both regimes. For wider pitfalls, see our article on common mistakes in GDPR compliance.
Do breach and enforcement rules differ?
The breach rules are the same in substance, but you report to different regulators and face fines in different currencies. A breach affecting both UK and EU individuals may need two notifications within the same 72-hour window.
Under Article 83 of the EU GDPR, the higher tier of fines is EUR 20 million or 4% of worldwide annual turnover. The UK equivalents are GBP 17.5 million or 4%, and GBP 8.7 million or 2% for the lower tier, which covers failures to notify breaches. There is no one-stop-shop in the UK, so a UK establishment of an EU group deals with the ICO directly, even if an EU lead authority handles the EU side. An incident and data breach management workflow that tracks both clocks side by side reduces the risk of missing either.
Key takeaways
- The UK GDPR and EU GDPR share the same principles, rights, DPO and DPIA triggers and 72-hour breach rule.
- Differences today are mainly the regulator, fines in pounds, children’s consent at 13, transfer tools and the ICO fee.
- The EU renewed UK adequacy on 19 December 2025, valid until 27 December 2031.
- Most Data (Use and Access) Act 2025 changes have applied since 5 February 2026, with the complaints duty from 19 June 2026.
- Build one programme on the common core and add a thin jurisdiction-specific layer.
Frequently asked questions
Is UK GDPR the same as EU GDPR?
Not exactly. The UK GDPR started as a copy of the EU GDPR and keeps the same structure, principles and rights. However, it is supervised by the ICO, uses UK transfer tools and sets fines in pounds. The Data (Use and Access) Act 2025 adds further UK-only changes, and most of those have applied since February 2026.
Do I need to comply with both UK GDPR and EU GDPR?
You need to comply with both if you have establishments in both the UK and the EEA, or if you offer goods or services to, or monitor, people in both. Many international businesses fall into this group. Map each processing activity to the regime that applies and document the result in your ROPA.
Can personal data still flow freely from the EU to the UK?
Yes. The European Commission renewed its adequacy decisions for the UK on 19 December 2025, and they last until 27 December 2031. EEA organisations can therefore transfer personal data to the UK without additional safeguards such as SCCs, although the decisions can be reviewed if UK law changes significantly.
Do I need a UK representative and an EU representative?
If you are not established in the UK but target or monitor people there, Article 27 of the UK GDPR generally requires a UK representative. The mirror rule applies in the EU. Some exemptions exist for occasional, low-risk processing, and public authorities are exempt, so assess each case.
Which regulator do I report a breach to?
For UK processing, report to the ICO, which becomes the Information Commission on 30 September 2026. For EU processing, report to your lead supervisory authority under the one-stop-shop, or to the local authority if you have no EU main establishment. A breach affecting both groups of individuals may require both reports within 72 hours of becoming aware.
Conclusion: one core programme, two sets of rules
For DPOs, UK GDPR vs EU GDPR is less about two different laws and more about managing one shared foundation that is slowly splitting. Keep your core controls common, apply the UK reforms now in force, watch the EU Digital Omnibus, and document which regime applies to each activity. That keeps you audit-ready on both sides of the Channel.
If you would like to see how one platform can keep GDPR and UK GDPR mapped together, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
