facebook-pixel

GDPR After Brexit: What Changed for UK Businesses in 2026

L
Lunyb Security Team
··10 min read

When the United Kingdom formally left the European Union, one of the biggest questions facing British businesses was simple: what happens to data protection law? GDPR had only been in force since May 2018, and companies had spent millions preparing for it. Would Brexit tear that framework apart, or would UK law continue to mirror Brussels?

The answer, several years on, is more nuanced than most people expected. GDPR did not disappear from the UK — it was domesticated, renamed, and is now slowly evolving on a separate track. This article explains exactly what changed, what stayed the same, and what UK organisations need to do differently in 2026.

The Short Answer: GDPR Still Applies, But It's Now "UK GDPR"

After Brexit, the EU General Data Protection Regulation stopped applying directly to the United Kingdom. In its place, the government retained the same rules under domestic law and renamed them the UK GDPR. This new instrument sits alongside the amended Data Protection Act 2018 and is enforced by the Information Commissioner's Office (ICO).

In practical terms, if your organisation was compliant with EU GDPR on 31 December 2020, you were compliant with UK GDPR on 1 January 2021. The core principles — lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability — were carried over word for word.

Two Regulations, Not One

The critical shift is that UK businesses now potentially deal with two parallel regimes:

  • UK GDPR — applies when you process the personal data of individuals in the UK, or when your organisation is established in the UK.
  • EU GDPR — still applies when you offer goods or services to individuals in the European Economic Area (EEA), or monitor their behaviour there.

Many British companies now fall under both. A London-based e-commerce shop that ships to customers in Dublin, Berlin and Manchester is subject to UK GDPR for its British customers and EU GDPR for its Irish and German ones.

Key Differences Between UK GDPR and EU GDPR

While the two regulations remain heavily aligned, meaningful differences have emerged — and more are on the way. Here is a snapshot of where they currently diverge.

AreaUK GDPREU GDPR
RegulatorInformation Commissioner's Office (ICO)National DPAs coordinated via EDPB
Maximum fine£17.5 million or 4% of global turnover€20 million or 4% of global turnover
Representative requiredUK representative for non-UK controllers targeting UKEU representative for non-EU controllers targeting EU
International transfersUK IDTA or UK Addendum to EU SCCsEU Standard Contractual Clauses (SCCs)
Adequacy decisionsIssued by UK Secretary of StateIssued by European Commission
Age of consent (child)1316 (but Member States can lower to 13)
One-stop-shop mechanismNo longer available to UK firmsAvailable for EU-established firms

Data Transfers: The Biggest Practical Headache

Before Brexit, personal data flowed freely between the UK and the EEA because both operated under the same regulation. After Brexit, the UK legally became a "third country" from the EU's perspective, meaning transfers required a lawful mechanism.

The EU Adequacy Decision for the UK

In June 2021, the European Commission granted the UK an adequacy decision, confirming that UK data protection standards were essentially equivalent to those in the EU. This meant EEA-to-UK transfers could continue without additional safeguards such as Standard Contractual Clauses.

The decision is not permanent, however. It includes a four-year sunset clause and is subject to review. If the UK diverges too significantly from EU standards — a real possibility given ongoing reform proposals — the adequacy decision could be revoked or narrowed. That would force thousands of businesses to renegotiate transfer arrangements, add SCCs to contracts and conduct transfer impact assessments.

UK-to-Overseas Transfers

For transfers going the other way — out of the UK to countries outside the EEA — the UK has developed its own tools:

  1. International Data Transfer Agreement (IDTA) — the UK equivalent of the EU SCCs.
  2. UK Addendum to the EU SCCs — allows organisations already using EU SCCs to bolt on UK coverage.
  3. UK adequacy regulations — the UK has recognised most of the EU's adequate countries plus, notably, the US under the UK Extension to the EU-US Data Privacy Framework.

If your organisation still relies on legacy EU SCCs signed before 2022 for UK-outbound transfers, those are no longer valid. You need to have re-papered them by now.

The Role of the ICO After Brexit

The Information Commissioner's Office is now the sole UK data protection regulator. Before Brexit, UK-based multinationals could benefit from the EU's "one-stop-shop" mechanism — dealing primarily with the ICO as their lead authority for pan-European issues. After Brexit, that privilege ended.

A UK company operating across the EU may now need to engage with multiple Member State regulators, appoint an EU representative under Article 27 of the EU GDPR, and follow enforcement action from bodies such as Ireland's Data Protection Commission or France's CNIL.

ICO's Post-Brexit Approach

The ICO has publicly stated it wants to be more pragmatic and outcomes-focused than some of its European counterparts. In recent years it has:

  • Issued clearer, more business-friendly guidance on cookies, AI and children's data.
  • Focused enforcement on egregious breaches rather than technical infringements.
  • Reduced some proposed fines significantly after representations (for example, the well-publicised reduction of the Marriott and British Airways penalties).
  • Launched a regulatory sandbox for innovative technologies.

This softer tone is welcome for businesses but has drawn criticism from privacy advocates who argue enforcement should be tougher.

UK-Specific Reforms: The Data Use and Access Act

The UK government has spent years debating how far it should diverge from EU rules. Successive proposals — the Data Protection and Digital Information Bill, and later the Data (Use and Access) Act — have attempted to trim what ministers describe as "unnecessary burdens" while maintaining adequacy.

Key changes now in force or on the horizon include:

  1. Legitimate interests clarifications — a defined list of "recognised legitimate interests" (such as fraud prevention, network security, safeguarding) that do not require a full balancing test.
  2. Simplified record-keeping — reduced Article 30 documentation obligations for smaller organisations processing low-risk data.
  3. Reforms to Subject Access Requests — clearer thresholds for refusing "vexatious or excessive" requests, and clarified time-stop rules.
  4. Automated decision-making — a more permissive framework for solely automated decisions, provided safeguards are in place.
  5. Cookies and PECR — moves to allow certain analytics cookies without consent, and higher fines for nuisance marketing (up to UK GDPR levels).
  6. Smart data and digital verification services — new statutory frameworks unrelated to EU law.

Each incremental reform increases the risk that the EU will re-examine the UK's adequacy status when it next comes up for review.

What UK Businesses Need to Do Differently

If your compliance programme was built for EU GDPR in 2018 and never updated, it is out of date. Here is a practical checklist for 2026.

1. Update Your Privacy Notices

References to the "General Data Protection Regulation (EU) 2016/679" should be replaced or supplemented with "UK GDPR" language. If you serve both UK and EU customers, your notice should reference both regimes and identify the relevant regulator (ICO for UK data subjects, and the relevant EU authority for EEA ones).

2. Review Your Transfer Mechanisms

Audit every outbound data flow. Are you still relying on the old 2010 EU SCCs? Have you replaced them with either the IDTA or the UK Addendum? Have you completed a Transfer Risk Assessment (TRA) for each transfer to a non-adequate country?

3. Appoint Representatives Where Needed

If you are established in the UK but offer goods or services to individuals in the EEA, you likely need an EU representative under Article 27 of the EU GDPR. Conversely, EU-based companies targeting the UK need a UK representative. Failing to appoint one is a common — and easily discovered — compliance gap.

4. Refresh Your Records of Processing

Your Article 30 records (Records of Processing Activities) should identify which processing falls under UK GDPR, EU GDPR, or both. This matters when responding to regulatory queries or breach notifications.

5. Rethink Breach Notification Workflows

A breach affecting both UK and EU data subjects may need to be reported to the ICO and one or more EU regulators within 72 hours. Your incident response plan should identify who notifies whom, in which language, and using which portal.

6. Watch Your Marketing Stack

Cookies, tracking pixels, URL shorteners and email tools all process personal data. Choose vendors that give you transparency over where data is stored and how it is transferred. Privacy-focused link management platforms like Lunyb can help marketers track campaign performance without adopting the invasive tracking patterns that attract ICO scrutiny — a point worth exploring in our honest review of Lunyb and our wider 2026 buyer's guide to URL shorteners.

Enforcement Trends: What the ICO Is Actually Fining

Since Brexit, ICO enforcement has focused on a few recurring themes:

  • Nuisance marketing — unsolicited calls, texts and emails under PECR remain the single most common cause of fines.
  • Poor security — companies suffering ransomware attacks because they failed to patch known vulnerabilities or enforce MFA.
  • Children's data — enforcement of the Age Appropriate Design Code, especially against social platforms.
  • Public sector failures — reprimands (rather than fines) issued to councils, NHS trusts and government departments for large-scale disclosures.
  • AI and profiling — early enforcement against facial recognition and opaque scoring systems.

A telling shift: the ICO now uses reprimands and enforcement notices far more than large fines. This is less headline-grabbing but often more painful — a reprimand becomes public, damages trust, and can trigger civil claims.

The Future: Divergence or Alignment?

The UK stands at a fork in the road. On one path, it continues gradual, targeted reform while preserving EU adequacy — the pragmatic choice that most large businesses prefer. On the other, it pursues a more radical rewrite of data protection, potentially unlocking innovation but risking the loss of frictionless data flows with Europe.

Most observers expect the middle course to prevail. UK GDPR is likely to remain recognisable to anyone familiar with the EU regime for the foreseeable future, but with growing pockets of difference around AI, research, public interest processing and legitimate interests.

For businesses, the key message is that GDPR compliance is no longer a one-time project. It requires ongoing monitoring of two regulatory regimes, quarterly reviews of transfer mechanisms, and a willingness to update policies as UK and EU rules gently drift apart.

Frequently Asked Questions

Does GDPR still apply in the UK after Brexit?

Yes. The EU GDPR was retained in UK law and renamed the UK GDPR. It works alongside the amended Data Protection Act 2018 and is enforced by the Information Commissioner's Office. The core principles, rights and obligations are almost identical to those under the EU regime.

Do I need to comply with both UK GDPR and EU GDPR?

You do if your organisation processes personal data of individuals in both jurisdictions. A UK business selling to EU customers must comply with UK GDPR for its domestic customers and EU GDPR for its EEA customers. In many cases this means dual privacy notices, dual representatives and dual regulator relationships.

Is the UK still considered "adequate" by the EU?

Yes, at present. The European Commission granted the UK an adequacy decision in June 2021, allowing personal data to flow from the EEA to the UK without additional safeguards. The decision is subject to periodic review, and further UK reforms could put it at risk.

What happens if I'm still using old EU Standard Contractual Clauses?The pre-2021 EU SCCs are no longer valid for either EU or UK outbound transfers. You must have replaced them — either with the new 2021 EU SCCs (for EU-origin transfers), the UK IDTA, or the UK Addendum to the EU SCCs (for UK-origin transfers). If you have not repapered by now, you have a compliance gap that regulators will notice.

What are the maximum fines under UK GDPR?

The UK GDPR retains the two-tier fine structure but converts the amounts into sterling. The higher tier is up to £17.5 million or 4% of total worldwide annual turnover, whichever is greater. The lower tier is up to £8.7 million or 2% of turnover. In addition, PECR fines for nuisance marketing have been brought into line with these thresholds under recent reforms.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles