United Kingdom
Tier 1 Comprehensive law EuropeA single unified regime: the UK GDPR (the onshored Regulation (EU) 2016/679) read together with the Data Protection Act 2018 as one Keeling-schedule-style whole, with PECR 2003 as lex specialis for direct marketing and cookies. Data protection is a reserved matter, so there is no devolved substantive law — the one narrow exception is a single exemption that cannot apply in Scotland. The Data (Use and Access) Act 2025 is the largest amendment to date and is still commencing in phases.
At a glance
- Principal law
- Data Protection Act 2018 + UK GDPR
- Regulator
- Information Commissioner's Office (ICO)
- Maximum penalty
- Higher of £17.5m or 4% of global annual turnover
- Criminal offences
- Yes — five, all fine-only (ss.170, 171, 173, 184, 132)
- Breach notification
- 72 hours to the ICO where the risk threshold is met
- Sub-national variation
- None (Pattern 4) — one narrow exemption excluded in Scotland
Structure
- Structural pattern
- Pattern 4 — fully unified
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- GB
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Regulators
- Information Commissioner's Office ICO
Supervisory authority for the UK GDPR, DPA 2018 and PECR, and prosecutor of the DPA's criminal offences. Being restructured into an Information Commission (a board replacing the corporation-sole Commissioner) by the DUAA 2025.
- Investigatory Powers Commissioner's Office IPCO
Shares oversight of intelligence-services processing, which sits under Part 4 of the DPA 2018 rather than the UK GDPR.
Transfers and adequacy
- EU member
- No
- EEA member
- No
- Holds EU adequacy
- Yes
- Granted
- 19 December 2025
- Expires
- 27 December 2031
- Review
- Sunset clause: lapses 2031-12-27 unless renewed. Joint Commission/EDPB review scheduled after four years, with continuous Commission monitoring of UK legislative developments.
Renewed decisions adopted 19 December 2025 — Implementing Decision (EU) 2025/2574 under the GDPR, with a parallel decision under the Law Enforcement Directive — replacing the original 28 June 2021 decisions after a six-month bridging extension (Implementing Decision (EU) 2025/1226, 27 June to 27 December 2025). Both strands expire 27 December 2031. The UK remains the only adequacy partner subject to a sunset clause.
Instruments
DPA 2018
Data Protection Act 2018, c. 12
PECR
SI 2003/2426
UK GDPR
Regulation (EU) 2016/679 as retained and amended by the European Union (Withdrawal) Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419)
In scope, not yet profiled
| Instrument | Note |
|---|---|
| UK GDPR (retained Regulation (EU) 2016/679) | Tier 1 scoped. Inseparable from the DPA 2018 in practice — profiled next so the two can be cross-referenced section by section rather than summarised together. |
| Privacy and Electronic Communications Regulations 2003 (PECR) | Tier 1 scoped. Lex specialis for direct marketing and cookies; amended alongside the DUAA 2025, with fines raised to UK GDPR levels. |
Procedures
Personal data breach notification (UK)
UK deltas to the GDPR breach archetype. The two-threshold architecture (risk to the ICO under Art 33; high risk to individuals under Art 34) is inherited unchanged from the UK GDPR. What differs: the recipient is the ICO and its reporting channel; a specific criminal offence under s.173 DPA 2018; the separate PECR reg 5A 24-hour regime for public electronic communications service providers; and DUAA 2025 changes, with commencement status as at 2026-07-26.
Subject access requests — United Kingdom
The UK deltas from the GDPR-family SAR archetype, post-DUAA 2025. Three steps change, one procedural step is added that the archetype does not have, and one criminal backstop applies that a generic SAR guide never mentions.
How the concepts differ here
The governance concepts are written from a GDPR-family default. These are the recorded departures for this jurisdiction, including those inherited from its legal family. An absent entry means nobody has checked, not that the position matches the default.
| Concept | How it differs | Position here | Scope |
|---|---|---|---|
| Choosing and documenting a lawful basis | Additional requirement | Adds "recognised legitimate interests" — a defined list of purposes for which no balancing test is required. | This jurisdiction |
| Automated decisions, profiling and AI | Works differently | Reformed to permit more solely automated significant decisions, with safeguards, rather than prohibiting them subject to three gateways. | This jurisdiction |
| Rectification in practice | Additional requirement | Destroying or concealing records to defeat a request is a criminal offence, not only a regulatory failure. | This jurisdiction |
Sources
- Primary Data Protection Act 2018 (c. 12) legislation.gov.uk
- Regulator Information Commissioner's Office ICO
Last verified 25 July 2026 by Owen S