facebook-pixel

GDPR After Brexit: What Changed for UK Businesses and Data Protection

L
Lunyb Security Team
··11 min read

When the United Kingdom formally left the European Union on 31 January 2020 and completed the transition period on 31 December 2020, one of the most pressing questions for businesses was: what happens to data protection law? The General Data Protection Regulation (GDPR) had reshaped how organisations across Europe handle personal data since May 2018, and its future in Britain was uncertain. Several years on, we now have a clearer picture of what changed, what stayed the same, and what UK organisations need to do to remain compliant.

This guide explains the current state of GDPR after Brexit, the emergence of the UK GDPR, the adequacy decision from the European Commission, and practical steps businesses should take when transferring data between the UK and the EU.

What Is GDPR After Brexit?

GDPR after Brexit refers to the parallel data protection regimes now operating in the UK and the EU. The EU GDPR no longer applies directly in the UK, but its provisions have been retained in domestic law as the "UK GDPR," which works alongside the Data Protection Act 2018 (DPA 2018).

In practical terms, UK organisations still follow rules that look almost identical to the EU version. The core principles, individual rights, lawful bases for processing, breach reporting obligations, and enforcement structures were all preserved. What changed is the legal source of those rules and how they interact with the EU across borders.

Two Regimes, One Framework

Since 1 January 2021, UK businesses have had to navigate two overlapping frameworks:

  • UK GDPR — the retained version of the EU regulation, applied to processing that takes place in the UK.
  • EU GDPR — still applicable when a UK business offers goods or services to individuals in the EU or monitors their behaviour.

This dual reality means many organisations must comply with both regimes simultaneously, even though the substantive requirements are nearly identical.

The Legal Framework: UK GDPR and the DPA 2018

The UK GDPR was created through the European Union (Withdrawal) Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. These instruments "copied and pasted" the EU GDPR into UK domestic law, making necessary adjustments to references to EU institutions, member states, and mechanisms that no longer applied.

Alongside the UK GDPR, the Data Protection Act 2018 continues to fill in the details: it covers areas such as processing by law enforcement authorities, intelligence services, national security exemptions, and specific derogations that member states were allowed to make under the original EU GDPR.

Key Institutions Involved

  • Information Commissioner's Office (ICO) — the UK's independent regulator for data protection.
  • European Data Protection Board (EDPB) — the ICO no longer sits on this body but still engages informally.
  • Department for Science, Innovation and Technology (DSIT) — leads UK government policy on data protection reform.

What Actually Changed After Brexit?

While the rules feel familiar, several significant changes affect how UK businesses operate day-to-day. Here are the most important shifts:

  1. Loss of the one-stop-shop mechanism. UK-based organisations can no longer use the ICO as their lead supervisory authority for EU-wide processing. They must now deal separately with EU regulators for activities in each member state.
  2. EU representatives required. UK organisations offering goods or services in the EU (or monitoring EU residents) must appoint a representative established in an EU member state under Article 27 of the EU GDPR.
  3. UK representatives required. Conversely, EU organisations targeting UK residents must appoint a UK-based representative.
  4. Data transfers require new safeguards. Personal data flows between the UK and third countries are now governed by UK rules, not EU rules.
  5. Divergence risk. Over time, UK and EU data protection law can drift apart as each jurisdiction makes its own reforms.

The Adequacy Decision: Why It Matters

The single most important development post-Brexit was the European Commission's adequacy decision, adopted on 28 June 2021. Adequacy means the EU considers the UK's data protection standards "essentially equivalent" to its own, allowing personal data to flow freely from the EU to the UK without additional safeguards such as Standard Contractual Clauses (SCCs).

Without this decision, transferring customer records, employee data, or marketing lists from the EU to the UK would have required extensive contractual and technical measures — a significant burden on cross-border trade and cooperation.

The Adequacy Sunset Clause

Uniquely, the UK adequacy decision included a "sunset clause," meaning it automatically expired after four years. The original decision was set to lapse on 27 June 2025 unless renewed. In late 2024 and 2025, the European Commission reviewed UK data protection developments and extended the adequacy finding, though renewal is not guaranteed indefinitely.

Any future divergence — for example, weaker onward transfer rules or reduced regulatory independence — could jeopardise the UK's adequacy status. Businesses should monitor developments closely because losing adequacy would fundamentally change how EU-to-UK data flows are managed.

UK-to-EU and International Data Transfers

The UK Government has separately determined that the EEA offers adequate protection, so UK-to-EU transfers are unrestricted. Transfers to other countries ("restricted transfers") require appropriate safeguards under Article 46 of the UK GDPR.

Available Transfer Mechanisms

MechanismDescriptionTypical Use Case
UK Adequacy RegulationsCountries the UK deems adequate (includes EEA, Japan, South Korea, etc.)Free flow of data without further safeguards
International Data Transfer Agreement (IDTA)UK-specific contract replacing the old EU SCCsTransfers to non-adequate countries
UK Addendum to EU SCCsBolts onto the EU 2021 SCCs to make them work under UK lawMultinationals using a single global contract
Binding Corporate Rules (BCRs)Intra-group data transfer rules approved by the ICOLarge multinationals with consistent global policies
UK–US Data BridgeExtension of the EU–US Data Privacy Framework for UK dataTransfers to certified US organisations

Transfer Risk Assessments

Following the influential Schrems II judgment (which technically pre-dates the split but continues to inform UK guidance), organisations must carry out a Transfer Risk Assessment (TRA) before relying on the IDTA or Addendum. The ICO has published its own TRA tool, which differs from the EDPB approach and is generally considered more pragmatic.

Rights of Individuals: Largely Unchanged

The rights afforded to data subjects under the UK GDPR mirror those in the EU version. UK residents can still:

  • Request access to their personal data (subject access request)
  • Have inaccurate data corrected
  • Ask for data to be erased in certain circumstances ("right to be forgotten")
  • Restrict or object to processing
  • Receive their data in a portable format
  • Not be subject to solely automated decision-making that has legal or similarly significant effects

Response deadlines (one month, extendable to three), fees (generally free), and identity verification rules all remain the same.

Enforcement and Penalties

The ICO retains its enforcement powers, and the maximum fines under the UK GDPR are set at £17.5 million or 4% of global annual turnover, whichever is higher — closely mirroring the EU threshold of €20 million or 4%.

UK organisations that also fall under the EU GDPR can be fined by both regulators for the same underlying failure, so the practical exposure has actually increased for cross-border businesses.

Recent Enforcement Trends

Since Brexit, the ICO has issued significant fines against UK-based organisations for issues such as inadequate security controls, unlawful marketing, and failures to respond to subject access requests. The regulator has also embraced reprimands and enforcement notices as alternatives to headline-grabbing fines, particularly for public sector bodies.

Data Protection Reform: The UK's Own Path

The UK Government has repeatedly signalled its intent to reform data protection law to reduce compliance burdens while maintaining high standards. The Data Protection and Digital Information Bill went through multiple iterations before falling with the 2024 general election, but reform remains on the policy agenda under the current government through the Data (Use and Access) Bill.

Proposed changes have included:

  • Simplifying record-keeping obligations for small businesses
  • Reforming rules around cookies and consent for low-risk analytics
  • Clarifying legitimate interests as a lawful basis for common processing activities
  • Restructuring the ICO into a body with a board and chief executive
  • Streamlining Data Subject Access Request (DSAR) rules to allow refusal of "vexatious" requests

Any reform must strike a careful balance: too much divergence from EU standards risks the loss of adequacy, which would harm UK plc far more than compliance simplifications would help.

Practical Steps for UK Businesses

If your organisation processes personal data — and virtually every business does — here is a practical post-Brexit checklist:

  1. Map your data flows. Understand where personal data comes from, where it is stored, and where it goes. Pay special attention to any transfers involving the EU, the US, or other third countries.
  2. Update privacy notices. Reference the UK GDPR and DPA 2018 rather than the EU GDPR where appropriate, and specify the ICO as your supervisory authority.
  3. Appoint representatives. If you offer services to EU residents, appoint an Article 27 representative in an EU member state. If you are an EU organisation targeting UK residents, appoint a UK representative.
  4. Review your contracts. Update controller-processor agreements and international transfer contracts to include the IDTA or UK Addendum where needed.
  5. Refresh internal policies. Train staff on the UK-specific framework, particularly if they handle DSARs or international transfers.
  6. Monitor legal developments. Stay informed about reform proposals, adequacy renewal, and ICO guidance updates.

Security Practices That Support Compliance

Data protection law demands "appropriate technical and organisational measures" — a deliberately flexible standard. Practical security measures that support UK GDPR compliance include:

  • Encryption of data at rest and in transit
  • Multi-factor authentication for administrative access
  • Regular vulnerability scanning and penetration testing
  • Minimising the personal data collected and shortening retention periods
  • Using privacy-respecting tools when sharing links, files, and analytics data

For example, when sharing links in marketing campaigns or internal communications, choosing a link management service that respects data minimisation and offers transparent analytics can reduce risk. Tools like Lunyb provide URL shortening with a privacy-conscious approach — you can read our honest review of Lunyb for more detail. For a broader comparison of shortening platforms, our 2026 buyer's guide to URL shorteners explains what to look for in a compliant provider, and if you are considering enterprise-grade options, see our Rebrandly review for 2026.

The Bottom Line

GDPR after Brexit is a story of continuity with important structural changes. The rules protecting personal data in the UK remain robust, largely mirroring the EU regime. What has changed is the legal machinery: parallel regimes, adequacy dependencies, transfer paperwork, and representative appointments now all form part of the compliance landscape.

For most organisations, the practical compliance burden is manageable but requires ongoing attention. The biggest risk is complacency — assuming that because the substantive rules feel familiar, no action is needed. Businesses that treat UK data protection as a living compliance function, monitor regulatory developments, and invest in privacy-by-design practices will be well-placed regardless of how the UK–EU relationship evolves in the years ahead.

Frequently Asked Questions

Does the EU GDPR still apply to UK businesses?

Yes, but only when a UK business offers goods or services to individuals in the EU or monitors their behaviour. In those cases, the EU GDPR applies extraterritorially alongside the UK GDPR. Organisations in that position typically need to appoint an EU representative and comply with both frameworks.

What is the difference between UK GDPR and EU GDPR?

Substantively, they are nearly identical — the UK GDPR is essentially a copy of the EU GDPR retained in UK law. The differences lie in enforcement authority (the ICO rather than an EU regulator), maximum fines expressed in pounds sterling, references to UK institutions, and the loss of the one-stop-shop mechanism. Small divergences are also emerging as UK reform proposals progress.

Do I still need an EU representative after Brexit?

If you are a UK-based organisation processing personal data of individuals in the EU (for example, selling to EU customers or tracking EU visitors to your website), then yes — Article 27 of the EU GDPR requires you to appoint a representative established in an EU member state, unless a limited exemption applies.

Is the UK still considered adequate by the EU?

Yes, as of the current date. The European Commission granted the UK an adequacy decision in June 2021 and reviewed and extended it in 2025. This allows EU-to-UK data flows without additional safeguards. However, adequacy is not permanent and could be reviewed or withdrawn if UK data protection standards are seen to diverge significantly from EU norms.

What are the maximum fines under UK GDPR?

The Information Commissioner's Office can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier breaches can attract fines of up to £8.7 million or 2% of turnover. These thresholds are broadly aligned with the EU GDPR penalty structure.

How does Brexit affect international data transfers from the UK?

The UK operates its own list of "adequate" countries and its own transfer tools, notably the International Data Transfer Agreement (IDTA) and the UK Addendum to the EU SCCs. Transfers to countries without a UK adequacy decision require one of these mechanisms, plus a Transfer Risk Assessment to ensure the destination country provides essentially equivalent protection.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles