UK GDPR and EU GDPR were identical at the point of Brexit — UK GDPR was simply EU GDPR retained in UK law. Since then, the UK has begun exercising its legislative independence. Some divergence has occurred; more is planned. For companies operating under both frameworks, tracking these differences matters because compliance with one does not guarantee compliance with the other.
What Remains the Same
The vast majority of the substantive law remains aligned:
Principles: Lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, accountability — identical in both frameworks.
Lawful bases: Same six bases — consent, contract, legal obligation, vital interests, public task, legitimate interests. Same conditions and interpretation.
Data subject rights: Access, rectification, erasure, restriction, portability, objection, automated decision rights — broadly equivalent, with minor variations in timescales (UK GDPR uses calendar month for access requests; EU GDPR also uses one month, effectively the same).
DPO requirements: Same obligation — mandatory for public authorities, systematic monitoring at scale, large-scale special category processing.
Breach notification: 72 hours to supervisory authority; notification to individuals for high-risk breaches — same framework.
Accountability: Records of processing activities, DPIAs, data protection by design — same requirements.
Where UK GDPR Has Diverged
1. International Data Transfers
This is the most significant area of substantive divergence.
EU: Uses adequacy decisions, Standard Contractual Clauses (EU SCCs 2021), and Binding Corporate Rules.
UK: Uses:
- UK adequacy regulations (the UK's own adequacy list)
- International Data Transfer Agreement (IDTA) — the UK's own SCC equivalent
- UK Addendum to EU SCCs — allows companies to use EU SCCs for UK transfers by adding a UK addendum
- Binding Corporate Rules (same concept, ICO-approved)
The IDTA is a different legal instrument from the EU SCCs. Companies cannot use EU 2021 SCCs for UK transfers without the UK addendum. If you have executed EU SCCs for EU → third country transfers, you need a separate UK instrument for UK → third country transfers.
EU-UK data flows: Both sides have mutual adequacy — the EU has recognised the UK as adequate, and the UK has recognised EU/EEA countries as adequate. No transfer mechanism is needed for EU ↔ UK data flows.
UK-US data bridge: The UK has a bilateral arrangement with the US analogous to the EU-US DPF. US companies can certify under the UK Extension to the Data Privacy Framework. This is separate from the EU DPF certification.
2. ICO as Supervisory Authority
The UK supervisory authority is the Information Commissioner's Office (ICO), not the EDPB or national EU DPAs. Enforcement, guidance, and interpretations come from the ICO.
The ICO:
- Publishes its own guidance — which sometimes differs from EDPB positions
- Has its own enforcement approach and priorities
- Cannot participate in the EU one-stop-shop mechanism
- Has a separate complaints handling process
For companies with both EU and UK establishments, the one-stop-shop mechanism applies to EU processing (lead EU DPA coordinates), but UK processing falls under ICO jurisdiction separately.
3. DPDI Act (Data Protection and Digital Information Act)
The UK government proposed the DPDI Act to amend UK GDPR. As of 2026, portions of this legislation are in effect. Key changes:
Legitimate interest: The DPDI Act narrowed the circumstances where a balancing test is required — for certain listed business purposes, legitimate interest can be relied on without a full balancing assessment.
Cookie consent: Changes to cookie consent rules — reduced consent requirements for certain analytical cookies.
Research exemption: Broader research exemptions than EU GDPR.
Data Protection Officers: The DPO requirement has been modified — UK GDPR now requires a "Senior Responsible Individual" in some cases instead of a formal DPO.
AI and automated decisions: The DPDI Act updated Article 22 provisions for automated decision-making.
The extent and timing of DPDI Act implementation matters — check the current state of UK law before relying on any EU GDPR interpretation for UK compliance.
4. Fines
The fine levels under UK GDPR are set in GBP:
- Standard maximum: £17.5 million or 4% of global annual turnover
- Lower tier: £8.7 million or 2% of global annual turnover
These levels are broadly equivalent to EU GDPR's €20 million / €10 million tiers, depending on exchange rates.
Practical Implications for Dual-Framework Companies
Separate transfer documentation: Maintain UK IDTA/addendum documents for UK → third country transfers, alongside EU SCC documentation for EU → third country transfers.
Separate privacy notice provisions: Address both ICO and relevant EU DPA in your privacy notice. The ICO should be identified for UK users; the relevant EU DPA for EU users.
Monitor DPDI divergence: UK GDPR is actively evolving. Set a calendar reminder to review UK-specific compliance every 6 months.
Separate breach reporting: UK breaches go to ICO. EU breaches go to the relevant national DPA. If a breach affects both UK and EU individuals, both notifications are required.