GDPR After Brexit: What Changed for UK Businesses and Data Protection
When the United Kingdom formally left the European Union on 31 January 2020, and the transition period ended on 31 December 2020, one of the most pressing questions for businesses was what would happen to data protection law. The General Data Protection Regulation (GDPR) had reshaped how organisations across Europe handled personal data, and its future in the UK was uncertain. Several years on, the picture is clearer, but complexity remains. This guide explains what changed with GDPR after Brexit, what stayed the same, and what UK organisations need to do to remain compliant in 2026 and beyond.
What Is GDPR After Brexit?
GDPR after Brexit refers to two parallel legal frameworks: the EU GDPR, which continues to apply to organisations processing data of individuals in the European Economic Area (EEA), and the UK GDPR, a domesticated version of the regulation that governs data processing within the United Kingdom. Both regimes share the same core principles, but they are now legally distinct and can diverge over time.
The UK GDPR came into force on 1 January 2021, alongside the amended Data Protection Act 2018. Together, they form the foundation of UK data protection law. The Information Commissioner's Office (ICO) remains the UK's independent regulator, while the European Data Protection Board (EDPB) oversees the EU regime.
The Key Changes at a Glance
While the substance of the rules remained largely intact after Brexit, the structural and jurisdictional changes are significant. Below is a summary of the most important differences.
| Area | Before Brexit (EU GDPR) | After Brexit (UK GDPR) |
|---|---|---|
| Governing law | EU GDPR directly applicable | UK GDPR + Data Protection Act 2018 |
| Regulator | ICO as part of EDPB one-stop-shop | ICO acts independently; no one-stop-shop |
| Maximum fines | €20m or 4% global turnover | £17.5m or 4% global turnover |
| EU-UK data transfers | Free flow within EEA | Permitted under adequacy decision (June 2021) |
| Representative requirement | Non-EU firms need EU rep | Non-UK firms may need UK rep; UK firms may need EU rep |
| International transfers | EU Standard Contractual Clauses | UK International Data Transfer Agreement (IDTA) or Addendum |
The UK GDPR: A Domesticated Version of EU Law
The UK GDPR is essentially a copy-paste of the EU GDPR into UK law, with technical amendments to make it function domestically. References to "the Union" became references to "the United Kingdom", and the ICO absorbed the functions previously shared with EU counterparts.
What Stayed the Same
The core obligations remain identical. UK organisations must still:
- Process personal data lawfully, fairly and transparently
- Collect data for specified, explicit and legitimate purposes
- Ensure data is accurate, adequate and kept up to date
- Store data no longer than necessary
- Protect data with appropriate security measures
- Respect data subject rights, including access, rectification and erasure
- Report qualifying breaches to the ICO within 72 hours
- Appoint a Data Protection Officer (DPO) where required
- Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing
What Changed in Practice
The most tangible changes concern jurisdiction and cross-border operations. UK-only businesses that never dealt with EU customers saw little practical difference. But any organisation with EU-facing operations now navigates two overlapping regimes. Fines are calculated in pounds sterling rather than euros, and the ICO no longer participates in the EU's cooperation and consistency mechanisms, meaning it cannot issue binding decisions across the EEA.
The EU Adequacy Decision: Why It Matters
On 28 June 2021, the European Commission adopted an adequacy decision for the UK, confirming that UK data protection law provides a level of protection "essentially equivalent" to the EU GDPR. This decision means personal data can continue to flow freely from the EEA to the UK without additional safeguards such as Standard Contractual Clauses.
The adequacy decision was a huge relief for businesses, but it is not permanent. It includes a sunset clause and is subject to review. The current decision is valid until 27 June 2025, at which point it will be reassessed. If the UK diverges too significantly from EU standards, particularly around surveillance or onward transfers, the decision could be suspended or revoked, forcing organisations to implement contractual safeguards overnight.
International Data Transfers From the UK
For transfers out of the UK to third countries, the rules mirror but do not perfectly match the EU regime. The UK recognises its own list of adequate jurisdictions, which currently includes the EEA, plus countries the EU had already deemed adequate before Brexit (such as Japan, New Zealand and Switzerland).
The International Data Transfer Agreement (IDTA)
Where no adequacy exists, UK organisations must use the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. These replaced the old EU SCCs for UK-originating transfers from 21 March 2022, with a transition period that ended in March 2024. Any transfer agreement still relying on the legacy EU SCCs after that date is non-compliant.
Transfer Risk Assessments
Following the Schrems II ruling from the Court of Justice of the European Union, exporters must also carry out a Transfer Risk Assessment (TRA) to evaluate whether the destination country's laws provide adequate protection, particularly against government access. The ICO has published its own TRA tool, which takes a slightly less stringent approach than the EDPB's methodology.
Representatives: Who Needs One Now?
Article 27 of both regimes requires organisations without an establishment in the relevant territory to appoint a local representative if they offer goods or services to, or monitor the behaviour of, individuals there.
- UK businesses targeting EU customers: may need to appoint an EU-based representative
- EU businesses targeting UK customers: may need to appoint a UK-based representative
- US or other third-country businesses: may need both a UK and an EU representative
Small-scale, occasional processing that does not involve special category data may qualify for an exemption, but the threshold is narrow and organisations should not assume they qualify without a formal assessment.
UK Divergence: The Data (Use and Access) Act and Reform Plans
Since Brexit, successive UK governments have signalled a desire to "reform" data protection law to reduce compliance burdens and support innovation. The Data Protection and Digital Information Bill fell in 2024 when the general election was called, but the incoming government introduced the Data (Use and Access) Act, which brings targeted reforms without fully overhauling the framework.
Notable Proposed and Enacted Changes
- Clarification of legitimate interests as a lawful basis, including a list of recognised legitimate interests
- Reforms to Subject Access Request handling, including clearer thresholds for "manifestly unfounded or excessive" requests
- Changes to cookie rules, allowing certain low-risk cookies without consent
- Reforms to automated decision-making rules
- A new Information Commission replacing the ICO's current structure
Each divergence carries a trade-off: greater flexibility for UK businesses, but heightened risk to the EU adequacy decision. Organisations must watch this closely, because losing adequacy would impose significant new costs on any UK business handling EU data.
Enforcement Under the ICO
The ICO's enforcement approach post-Brexit has remained broadly consistent with pre-Brexit patterns, though it has been criticised for being less aggressive than some EU counterparts. Notable UK GDPR fines in recent years include actions against major retailers, telecoms firms and public bodies for security breaches and unlawful marketing.
The ICO's regulatory toolkit includes:
- Information notices and assessment notices
- Enforcement notices requiring specific action
- Monetary penalty notices up to £17.5m or 4% of global turnover
- Reprimands and public statements
- Prosecution for certain criminal offences under the DPA 2018
Practical Steps for UK Businesses in 2026
Whether you are a small e-commerce shop or a multinational, the practical compliance checklist has evolved. Here is what UK organisations should prioritise now.
1. Map Your Data Flows
Understand where personal data comes from, where it goes, and which regime applies. Any data flowing between the UK and the EEA, or onward to third countries, requires a documented lawful basis and appropriate transfer mechanism.
2. Update Contracts and Privacy Notices
Contracts drafted before Brexit may still reference EU GDPR alone or use outdated EU SCCs. Review and update these to reflect the UK GDPR, the IDTA where relevant, and dual references where both regimes apply. Privacy notices should identify the correct regulator (ICO) and clarify international transfer arrangements.
3. Appoint Representatives Where Needed
If you sell to EU customers from the UK, or vice versa, check whether an Article 27 representative is required and appoint one in writing. The representative's details must appear in your privacy notice.
4. Review Third-Party Tools and Links
Marketing tools, analytics platforms and even URL shorteners can process personal data such as IP addresses. Choose providers that are transparent about their processing locations and offer compliant transfer mechanisms. For instance, when sharing shortened links in campaigns, using a privacy-respecting service like Lunyb can help minimise unnecessary data collection compared with less transparent alternatives. For a broader look at options, see our 2026 buyer's guide to URL shorteners.
5. Refresh Your Breach Response Plan
A single incident affecting both UK and EU data subjects may require notifications to the ICO and one or more EU supervisory authorities within 72 hours. Your incident response plan should reflect this dual-notification reality, with named contacts and pre-drafted templates for each regulator.
6. Monitor the Adequacy Review
Assign someone in your organisation to track the EU Commission's adequacy review and any UK legislative reforms. If adequacy were revoked, you would need SCCs, IDTAs and Transfer Impact Assessments in place quickly to keep data flowing.
Common Misconceptions About GDPR After Brexit
Several myths persist among UK businesses, some of which can lead to expensive mistakes.
"GDPR Doesn't Apply to UK Businesses Anymore"
False. The UK GDPR applies to virtually all UK organisations processing personal data, and the EU GDPR still applies to any UK business offering goods or services to individuals in the EEA.
"Small Businesses Are Exempt"
Also false. There is no general small-business exemption. Some obligations (such as record-keeping) are lighter for organisations under 250 employees, but core principles apply to everyone.
"We Only Need to Worry About the ICO"
Not if you have EU customers. You could face parallel investigations from the ICO and an EU supervisory authority for the same incident, with separate fines under each regime.
The Road Ahead
The story of GDPR after Brexit is one of pragmatic continuity punctuated by growing divergence. UK organisations that treated Brexit as an opportunity to audit their data practices are in a strong position. Those that ignored the changes now face an increasingly complex landscape, particularly as the 2025 adequacy review approaches and UK reforms take effect.
The best strategy is to treat UK GDPR and EU GDPR as a single, high-standard baseline. Meeting the stricter of the two requirements in any given area keeps you compliant with both and protects you from regulatory shocks. Data protection is no longer just a legal box-ticking exercise: it is a trust signal, a competitive differentiator, and increasingly, a boardroom concern.
Frequently Asked Questions
Does the EU GDPR still apply to UK businesses?
Yes, if your UK business offers goods or services to individuals located in the EEA, or monitors their behaviour, the EU GDPR applies extraterritorially under its Article 3(2). You may also need to appoint an EU representative.
What is the difference between UK GDPR and EU GDPR fines?
The maximum penalties are functionally equivalent but denominated differently. UK GDPR caps fines at £17.5 million or 4% of annual global turnover, whichever is higher, while EU GDPR uses €20 million or 4% of global turnover. A serious cross-border breach could result in separate fines under both regimes.
Is the EU adequacy decision for the UK permanent?
No. The current adequacy decision is subject to periodic review and includes a sunset clause. It is currently valid until 27 June 2025, after which the European Commission must decide whether to renew it based on the state of UK data protection law at that time.
Do UK businesses still need to comply with cookie rules?
Yes. The Privacy and Electronic Communications Regulations (PECR) continue to govern cookies and electronic marketing in the UK, and they operate alongside the UK GDPR. Reforms under the Data (Use and Access) Act may relax certain low-risk cookie requirements, but consent remains the default for non-essential cookies.
What is the UK IDTA and when do I need to use it?
The International Data Transfer Agreement (IDTA) is the ICO's standard contract for transferring personal data from the UK to countries without a UK adequacy determination. You need it (or the UK Addendum to the EU SCCs) whenever you send personal data outside the UK to a non-adequate country, such as the United States, without relying on another safeguard.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you powerful rights over your personal data, from access and correction to data portability and breach notification. This 2026 guide explains each right in plain English and shows you exactly how to enforce them.
Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches scheme requires organisations to report eligible breaches to the OAIC and affected individuals. This 2026 guide covers who's covered, notification timelines, penalties up to AUD $50 million, and how to prepare.
GDPR in Ireland: Your Privacy Rights Explained
A plain-English guide to GDPR privacy rights in Ireland. Learn your eight core rights, how to file a Subject Access Request, and how to complain to the Irish Data Protection Commission when a company mishandles your personal data.
Data Protection Act 2018 Ireland: A Complete Guide for Businesses
Ireland's Data Protection Act 2018 sits alongside the GDPR to govern how personal data is handled. This complete guide covers scope, data subject rights, DPC enforcement powers, penalties up to €20 million, and a practical compliance checklist for Irish businesses.