Data Protection Atlas

United Kingdom

Tier 1 Comprehensive law Europe

A single unified regime: the UK GDPR (the onshored Regulation (EU) 2016/679) read together with the Data Protection Act 2018 as one Keeling-schedule-style whole, with PECR 2003 as lex specialis for direct marketing and cookies. Data protection is a reserved matter, so there is no devolved substantive law — the one narrow exception is a single exemption that cannot apply in Scotland. The Data (Use and Access) Act 2025 is the largest amendment to date and is still commencing in phases.

At a glance

Principal law
Data Protection Act 2018 + UK GDPR
Regulator
Information Commissioner's Office (ICO)
Maximum penalty
Higher of £17.5m or 4% of global annual turnover
Criminal offences
Yes — five, all fine-only (ss.170, 171, 173, 184, 132)
Breach notification
72 hours to the ICO where the risk threshold is met
Sub-national variation
None (Pattern 4) — one narrow exemption excluded in Scotland

Structure

Structural pattern
Pattern 4 — fully unified
Sub-jurisdictions
None — no sub-national axis
ISO code
GB

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Regulators

  • Information Commissioner's Office ICO

    Supervisory authority for the UK GDPR, DPA 2018 and PECR, and prosecutor of the DPA's criminal offences. Being restructured into an Information Commission (a board replacing the corporation-sole Commissioner) by the DUAA 2025.

  • Investigatory Powers Commissioner's Office IPCO

    Shares oversight of intelligence-services processing, which sits under Part 4 of the DPA 2018 rather than the UK GDPR.

Transfers and adequacy

EU member
No
EEA member
No
Holds EU adequacy
Yes
Granted
19 December 2025
Expires
27 December 2031
Review
Sunset clause: lapses 2031-12-27 unless renewed. Joint Commission/EDPB review scheduled after four years, with continuous Commission monitoring of UK legislative developments.

Renewed decisions adopted 19 December 2025 — Implementing Decision (EU) 2025/2574 under the GDPR, with a parallel decision under the Law Enforcement Directive — replacing the original 28 June 2021 decisions after a six-month bridging extension (Implementing Decision (EU) 2025/1226, 27 June to 27 December 2025). Both strands expire 27 December 2031. The UK remains the only adequacy partner subject to a sunset clause.

Instruments

In scope, not yet profiled

Instrument Note
UK GDPR (retained Regulation (EU) 2016/679) Tier 1 scoped. Inseparable from the DPA 2018 in practice — profiled next so the two can be cross-referenced section by section rather than summarised together.
Privacy and Electronic Communications Regulations 2003 (PECR) Tier 1 scoped. Lex specialis for direct marketing and cookies; amended alongside the DUAA 2025, with fines raised to UK GDPR levels.

Procedures

How the concepts differ here

The governance concepts are written from a GDPR-family default. These are the recorded departures for this jurisdiction, including those inherited from its legal family. An absent entry means nobody has checked, not that the position matches the default.

Concept How it differs Position here Scope
Choosing and documenting a lawful basis Additional requirement Adds "recognised legitimate interests" — a defined list of purposes for which no balancing test is required. This jurisdiction
Automated decisions, profiling and AI Works differently Reformed to permit more solely automated significant decisions, with safeguards, rather than prohibiting them subject to three gateways. This jurisdiction
Rectification in practice Additional requirement Destroying or concealing records to defeat a request is a criminal offence, not only a regulatory failure. This jurisdiction

Sources

Last verified 25 July 2026 by Owen S