After the UK left the EU, the GDPR was retained in domestic law as the UK GDPR and must be read together with the Data Protection Act 2018, which supplies exemptions, conditions for special-category processing and the framework for the ICO.
For most organisations the practical obligations mirror the EU regime: the same principles, the same lawful bases, the same rights, the same accountability posture. The differences show up in transfer mechanisms, exemptions, regulator practice and the fact that an organisation operating on both sides may be subject to both regimes at once.
The Privacy and Electronic Communications Regulations (PECR) sit alongside the UK GDPR and govern electronic marketing, cookies and similar technologies. Many UK enforcement actions concern PECR rather than the UK GDPR itself.
Who and what it applies to
- Territorial scope
- Processing in the context of a UK establishment, and processing by organisations outside the UK that offer goods or services to, or monitor the behaviour of, people in the UK.
- Dual application
- An organisation serving both UK and EU/EEA markets is commonly subject to both the UK GDPR and the EU GDPR, and may need representatives in each.
- PECR
- Electronic marketing, cookies and similar technologies are governed by PECR, which has its own consent standard and its own penalties.
Core principles
- Lawfulness, fairness and transparency.
- Purpose limitation.
- Data minimisation.
- Accuracy.
- Storage limitation.
- Integrity and confidentiality.
- Accountability — demonstrable, documented compliance.
Individual rights
Information
Privacy information at collection, or within a reasonable period where data is obtained from another source.
Access
A copy of personal data with supplementary information; UK exemptions may narrow what must be disclosed.
Rectification
Correction of inaccurate or incomplete data.
Erasure
Deletion where a specified ground applies and no exemption prevents it.
Restriction
Temporary limitation of processing while a dispute is resolved.
Portability
Machine-readable copy of data provided by the individual where processing is automated and based on consent or contract.
Objection
Objection to legitimate-interests and public-task processing; an absolute right in respect of direct marketing.
Automated decisions
Safeguards against solely automated decisions with legal or similarly significant effects.
Organisational obligations
Records and accountability
Records of processing activities, policies proportionate to risk, and evidence that controls operate.
Transparency
Privacy information that reflects real processing, including any profiling or AI-assisted decisions.
DPIAs
Required for high-risk processing; the ICO publishes a list of processing types that always require one.
Contracts
Written processor terms equivalent to Article 28 of the EU regime.
Breach reporting
Report reportable personal data breaches to the ICO without undue delay and within 72 hours where feasible; tell individuals where the risk to them is high.
PECR compliance
Consent for non-essential cookies and most electronic marketing, with a valid soft opt-in route for existing customers in limited circumstances.
Cross-border considerations
- Restricted transfers out of the UK require UK adequacy regulations, an appropriate safeguard, or an exception.
- The UK's safeguard tools include the International Data Transfer Agreement (IDTA) and the UK Addendum to the EU Standard Contractual Clauses.
- A transfer risk assessment is expected where a safeguard rather than adequacy is relied on.
Enforcement overview
- The ICO investigates complaints, issues assessment and enforcement notices, and can impose monetary penalties.
- The UK GDPR's higher fine tier is the greater of GBP 17.5 million or 4% of total worldwide annual turnover.
- PECR carries a separate maximum penalty and is the basis for much of the ICO's marketing enforcement.
- The ICO also uses reprimands, audits and published outcomes, which carry reputational weight even without a fine.
Implementation checklist
- 1Confirm whether you are subject to the UK regime, the EU regime, or both, and appoint representatives where needed.
- 2Keep a UK-specific record of processing and transfer inventory.
- 3Review cookie banners and marketing consent against PECR, not only the UK GDPR.
- 4Use the IDTA or UK Addendum for restricted transfers and keep the risk assessment with the contract.
- 5Track the ICO's high-risk processing list when deciding whether a DPIA is mandatory.
- 6Document exemptions relied on when responding to access requests.
Frequently asked questions
Is the UK GDPR the same as the EU GDPR?
It is structurally very similar but not identical. Exemptions, transfer instruments, regulator guidance and the applicable fine currency differ, and an organisation can be subject to both regimes simultaneously.
Do cookie rules come from the UK GDPR?
Consent for non-essential cookies comes from PECR; the UK GDPR then governs any personal data processed as a result.
Official sources
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.