UK GDPR
Tier 1 In forceThe UK GDPR is the EU General Data Protection Regulation (Regulation (EU) 2016/679) as it was retained in UK domestic law at the end of the Brexit transition period and then textually amended ("onshored") by the 2019 EU Exit Regulations. It is not a free-standing code: it cannot be read alone and operates only in tandem with the Data Protection Act 2018 (instrument id dpa2018), which supplies the definitions, exemptions, criminal offences, enforcement powers and the regulator's constitution. The single most common error in UK privacy writing is to treat "UK GDPR" as a complete statute — the principles, lawful bases and rights live in the Regulation, but the operative detail (Schedules 2-4 exemptions, the s.155 penalty ceiling, the criminal offences) lives in the DPA 2018. Since 5 February 2026 it has been materially amended by the Data (Use and Access) Act 2025.
Identity
- Citation
- Regulation (EU) 2016/679 as retained and amended by the European Union (Withdrawal) Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419)
- Jurisdiction
- United Kingdom
- Type
- comprehensive
- Structure
- Retains the GDPR's 11 Chapters / 99 Articles structure, read with the DPA 2018 (7 Parts, 20 Schedules).
- Royal assent
- 27 April 2016
- Main commencement
- 1 January 2021
Applied as retained EU law from IP completion day (2020-12-31, 23:00 GMT). The 2019 EU Exit Regulations took effect at that point. Substantial amendments made by the Data (Use and Access) Act 2025 were commenced for the main data protection provisions on 5 February 2026 (SI 2026/82); the mandatory data-protection complaints procedure follows on 19 June 2026.
Amended by: Amended most significantly by the Data (Use and Access) Act 2025. Key changes now in force (from 5 February 2026): a new "recognised legitimate interests" lawful basis; a reworked automated decision-making regime replacing Article 22 with new Articles 22A-22D (moving from prohibition to a safeguards model); adjustments to research and scientific-processing consent; and revised international transfer tests. The mandatory data-protection complaints procedure commences 19 June 2026.
Reads together with
- Data Protection Act 2018
Indispensable companion. Supplies Part 2 (general processing supplementing the UK GDPR), the Schedules 2-4 exemptions and their trigger conditions, the s.155 penalty ceiling, the criminal offences (ss.170, 171, 173, 184, 132), s.198 director liability, and the Information Commissioner's constitution. The UK GDPR is legally incomplete without it.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
Lex specialis for electronic marketing, cookies and similar tracking. Where PECR applies to a processing activity it takes precedence over the general UK GDPR rules on that activity.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | None found — checked | The UK GDPR and DPA 2018 extend uniformly to England, Wales, Scotland and Northern Ireland; data protection is a reserved matter. No region is carved out. Some DPA 2018 provisions make minor Scotland-specific adjustments for devolved public authorities, but the substantive regime does not fork by region. |
| 2 | Commencement | Asymmetry found | Not fully in force in a static sense: the Data (Use and Access) Act 2025 amendments commence in phases. The main tranche commenced 5 February 2026 (SI 2026/82). The mandatory data-protection complaints procedure is set to commence 19 June 2026. Practitioners must check commencement status provision by provision rather than assume all DUAA changes are live. |
| 3 | Sunset / mandatory review | Asymmetry found | No sunset on the instrument itself. However, the EU adequacy decision covering UK-bound transfers carries a sunset clause (renewed 19 December 2025, running to 27 December 2031), which functions as a de facto external review point on UK divergence. |
| 4 | Criminal liability | Asymmetry found | The criminal track is not in the UK GDPR; it sits in the DPA 2018 (ss.170, 171, 173, 184, 132). All are fine-only — custody is NOT available for any UK data protection offence. This is a deliberate design choice distinguishing regulatory fines (civil monetary penalties) from the criminal offences, which are triable and carry unlimited fines but no imprisonment. |
| 5 | Civil liability | Asymmetry found | Article 82 UK GDPR and s.168 DPA 2018 give a private right of action independent of the ICO. Individuals may claim compensation for both material and non-material damage (distress). Claims are brought in the ordinary civil courts, not before the regulator. |
| 6 | Regulatory enforcement toolkit | None found — checked | The regulator's toolkit and ceiling sit in the DPA 2018 (information notices, assessment notices, enforcement notices, penalty notices) with the s.155 ceiling of the higher of £17.5m or 4% of global annual turnover. DUAA 2025 added new investigatory powers (compelling witnesses, technical reports) and reconstituted the ICO as the Information Commission. |
| 7 | Personal / director liability | Asymmetry found | Director/officer liability is carried by s.198 DPA 2018, under which offences committed with the consent, connivance or neglect of a director or similar officer expose that individual personally. This is a criminal route, separate from corporate regulatory fines. |
| 8 | Public vs private sector split | Asymmetry found | The DPA 2018 splits the regime by processing purpose: Part 2 (general/UK GDPR), Part 3 (law enforcement processing) and Part 4 (intelligence services). The UK GDPR itself governs general processing; law enforcement and intelligence processing fall under the separate Parts. |
| 9 | Legal-person coverage | None found — checked | Protects natural persons only. Personal data means data relating to an identified or identifiable living individual. Legal persons are not data subjects, consistent with the GDPR. |
| 10 | Exemptions — with conditions | Asymmetry found | The Regulation's Article 23 restriction power is exercised almost entirely through the DPA 2018, so the operative exemption regime lives in Schedules 2-4 of the companion Act rather than in the UK GDPR text itself (cross-refer dpa2018). Most are conditional prejudice or necessity tests applied case by case — crime and taxation, for instance, bites only to the extent that compliance would be likely to prejudice those purposes — with a smaller number of absolute carve-outs. A reader of the UK GDPR alone sees essentially no exemptions; that is the asymmetry. |
Exemptions
Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.
DPA 2018 Sch.2 Part 1 para 2 — Crime and taxation
Trigger
Not automatic. Applies only to the extent that applying the listed UK GDPR provisions would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of tax. It is a case-by-case prejudice test applied by the controller, not a blanket carve-out.
Disapplies
- listed transparency and subject-access provisions
The prejudice test — not the mere existence of the exemption — is the answer a practitioner needs.
Interactions and conflicts
The cross-instrument texture that profiling an Act in isolation misses — including where the real answer to a question about this Act is found in a different one.
| Instrument | Relationship | Note |
|---|---|---|
| Data Protection Act 2018 | Reads with | The DPA 2018 prevails on any point of operative detail it supplies (exemptions, offences, penalty ceiling, regulator powers). The UK GDPR supplies the principles, lawful bases and rights. |
| PECR 2003 | Lex specialis | PECR prevails over the general UK GDPR rules for electronic marketing and cookies; where PECR sets a specific consent rule, that rule governs that activity. |
Live issues
Sources
- Primary Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) legislation.gov.uk
- Regulator European Commission renews UK data adequacy decisions European Commission / eucrim
- Secondary UK: Commencement of the data protection provisions in the Data (Use and Access) Act DLA Piper Privacy Matters
Never independently verified — seeded from the prototype.