Post-Brexit, the UK operates its own data protection law — UK GDPR — which is separate from EU GDPR. For EU-based SaaS companies with UK customers or UK users, the question of whether UK GDPR applies is common and important. The short answer: if you process personal data of people in the UK, UK GDPR very likely applies to you — and you have specific obligations as a result.
UK GDPR's Territorial Scope
UK GDPR uses the same territorial scope model as EU GDPR (Article 3). It applies to:
- Organisations established in the UK — regardless of where the processing occurs
- Organisations not established in the UK but offering goods or services to individuals in the UK (the "targeting criterion")
- Organisations not established in the UK but monitoring the behaviour of individuals in the UK
For EU SaaS companies: If your product is offered to UK users or customers — whether or not you have a UK office — UK GDPR applies to your processing of their personal data.
Indicators that you are "offering" to UK users:
- Your website is accessible in the UK and you accept UK customers
- You use UK pricing (GBP)
- You have UK-specific marketing or sales activities
- You have a significant UK user base
- Customer support is provided in UK English
UK GDPR vs EU GDPR: Are They the Same?
UK GDPR is based on EU GDPR — it was directly incorporated into UK law by the Data Protection Act 2018. The substantive requirements are largely identical:
- Same lawful bases (consent, contract, legitimate interest, legal obligation, vital interests, public interest)
- Same data subject rights (access, erasure, portability, objection, etc.)
- Same principles (data minimisation, purpose limitation, storage limitation, etc.)
- Same breach notification timelines (72 hours to the ICO)
- Same DPO appointment requirements
Key differences:
- The supervisory authority is the ICO (Information Commissioner's Office), not an EU DPA
- UK GDPR has its own transfer mechanism for transfers from the UK to third countries
- UK GDPR is subject to UK legislative amendments — the government has signalled possible future divergence
- The EU-UK adequacy decision enables free data flow between EU and UK — but it is subject to review
If you are already EU GDPR compliant, UK GDPR compliance requires relatively minor additions — primarily addressing the UK-specific supervisory authority and transfer mechanisms.
What You Need to Do for UK GDPR Compliance
1. Appoint a UK Representative
If you are not established in the UK (no UK office, no UK employees) but process UK residents' data, you must appoint a UK GDPR representative. This is analogous to the EU GDPR Article 27 representative requirement.
The UK representative:
- Is established in the UK
- Acts as a point of contact with the ICO and UK data subjects
- Can be a third-party service provider (there are UK representative service companies)
Exceptions: Occasional processing, processing unlikely to result in risk to individuals, processing by public authorities.
For most EU SaaS companies with a meaningful UK user base, appointing a UK representative is required.
2. UK Privacy Notice
Your existing EU GDPR-compliant privacy notice needs UK-specific additions:
- Reference to the ICO as the supervisory authority for UK users
- UK-specific contact for data subject rights requests
- Reference to the UK GDPR as the applicable framework for UK users
The simplest approach: a "UK Users" section at the bottom of your privacy notice, or a separate UK privacy page linked from the main notice.
3. UK Transfer Mechanisms
Transfers from the UK to third countries (including the EU) are governed by UK GDPR Chapter V. The key mechanisms:
EU adequacy decision for UK: The UK has an adequacy decision from the EU, meaning EU personal data can be transferred to the UK freely. This covers transfers from EU → UK.
UK→EU transfers: UK GDPR has its own adequacy decision for EU/EEA countries — the UK considers EU countries adequate, so transfers from UK → EU do not require additional mechanisms.
UK → US transfers: The UK has its own International Data Transfer Agreement (IDTA) and UK Addendum to EU SCCs. The EU-US DPF does not automatically cover UK → US transfers — a separate UK-US data bridge arrangement covers DPF-certified companies.
For most EU SaaS companies processing UK user data in EU infrastructure: EU-UK adequacy means the data flow is covered. If you transfer UK data to the US or other third countries, UK transfer mechanisms are required.
4. ICO Registration
Some organisations must register with the ICO as a data controller. This applies to controllers established in the UK. For EU companies without a UK establishment, registration is typically not required — but appointing a UK representative means your representative has an ICO presence.
Enforcement Risk for EU Companies
The ICO can enforce UK GDPR against non-UK established controllers. Post-Brexit enforcement against EU companies has been limited in practice due to jurisdictional challenges, but this does not mean the risk is zero:
- UK individuals have the right to complain to the ICO about any controller processing their data
- ICO investigations can result in fines of up to £17.5 million or 4% of global annual turnover
- ICO enforcement activity against international companies has been increasing