The UK retained GDPR after leaving the EU, so the two regimes start from the same text - but they are now separate laws with separate regulators, separate transfer rules and separate futures. Any organisation processing personal data on both sides needs to satisfy both, and treating one as a subset of the other is where compliance gaps appear.
The framework
UK data protection rests on two instruments read together: UK GDPR - the retained regulation as amended - and the Data Protection Act 2018, which fills in national derogations, law-enforcement processing and exemptions. Alongside them sits PECR, the ePrivacy regulations governing cookies, electronic marketing and communications, which matters far more in practice than its low profile suggests.
The core obligations will be familiar: lawful basis, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Individual rights, records of processing, DPIAs for high-risk processing and 72-hour breach notification all carry over.
Where the UK diverges
- Two regulators, two registrations. The ICO supervises the UK; EU supervisory authorities supervise the EU. The one-stop-shop mechanism does not span both, so a UK organisation processing EU data may deal with several authorities directly.
- Representatives. A UK organisation without an EU establishment but targeting EU individuals generally needs an EU representative, and vice versa. This is quietly one of the most commonly missed obligations.
- Transfers. The UK operates its own adequacy decisions and its own transfer instruments - the International Data Transfer Agreement, or the UK Addendum bolted onto EU standard contractual clauses. Using unmodified EU SCCs for a UK export does not work.
- Fee, not just registration. UK controllers must generally pay an annual data protection fee to the ICO - a small, easily forgotten administrative duty with penalties attached.
- Divergence over time. The UK has legislated to reform aspects of its regime, and further change is expected. Do not assume the texts stay aligned; re-check anywhere your compliance argument depends on the wording rather than the principle.
Practical rule for organisations serving both: build to the stricter requirement, document once, and maintain two transfer mechanisms and two representative arrangements. The substantive controls rarely differ; the paperwork does.
Cover both regimes from one control set
GRC Copilot maps your controls and evidence across UK GDPR, EU GDPR and your security frameworks together, so overlapping obligations are satisfied once.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
What the ICO actually enforces
The ICO's public posture emphasises engagement and improvement over headline fines, particularly for public bodies - but enforcement is real and concentrated in recognisable areas:
- Security failures leading to breaches, especially where basic controls were absent - unpatched internet-facing systems, missing MFA, no monitoring. The pattern in penalty notices is remarkably consistent: the failure was known and unremediated.
- Electronic marketing under PECR - unsolicited calls, texts and emails. This produces a steady stream of monetary penalties, often against smaller organisations, and consent quality is the usual issue.
- Cookies and tracking, where the enforcement focus has been on consent that is not freely given - reject being harder than accept, or non-essential cookies set before any choice.
- Subject access request handling - late or incomplete responses are among the most frequent complaint categories, and the one most organisations underestimate operationally.
- Children's data, where the Age Appropriate Design Code sets expectations well above the baseline for any service likely to be accessed by children.
The operational obligations that trip people
- Subject access requests - one month, extendable in limited circumstances, covering data held anywhere including backups, email and messaging. Organisations without a search capability across their estate cannot meet this reliably, and the deadline does not care.
- Records of processing, kept current rather than written once.
- DPIAs for high-risk processing, completed before the processing starts - a retrospective DPIA is itself evidence of a failure.
- Processor contracts containing the required terms, with equivalent flow-down to sub-processors.
- Breach assessment within 72 hours, which means a triage process that can reach a decision quickly - and a record of breaches you decided not to report, with reasoning.
Frequently asked questions
Do we need both a UK and an EU representative?
If you have no establishment in a territory but target individuals there, you generally need a representative for it. Organisations established in both usually need neither.
Can we keep using EU SCCs for UK transfers?
Only with the UK Addendum attached, or by using the UK's own transfer agreement instead. Unmodified EU clauses do not cover a UK export.
Is a DPO mandatory?
Only in defined circumstances - public authorities, large-scale systematic monitoring, or large-scale special category processing. Many organisations appoint a privacy lead voluntarily, which is fine provided the role is not misrepresented as a statutory DPO.
How strict is cookie enforcement?
Stricter than most sites assume. Non-essential cookies require consent before being set, and refusing must be as easy as accepting.
Key takeaways
- UK GDPR and EU GDPR are separate laws with separate regulators and transfer instruments.
- EU SCCs need the UK Addendum; representatives are needed in territories where you have no establishment.
- PECR marketing and cookie consent generate more enforcement than the headline GDPR provisions.
- Subject access at scale requires a search capability, not a policy.