facebook-pixel

GDPR After Brexit: What Changed for UK Businesses and Data Protection

L
Lunyb Security Team
··9 min read

When the United Kingdom formally left the European Union on 31 January 2020, one of the most pressing questions for businesses was what would happen to data protection law. The General Data Protection Regulation (GDPR) had only been in force since May 2018, yet it had already reshaped how organisations across Europe handled personal data. Nearly six years on from the transition period ending, the landscape has evolved in ways both subtle and significant.

This guide explains exactly what changed with GDPR after Brexit, how the UK GDPR now differs from its EU counterpart, and what British organisations need to do to remain compliant when handling personal data at home and across borders.

What Is GDPR After Brexit? A Quick Definition

GDPR after Brexit refers to the UK's domestic version of the General Data Protection Regulation, known as the UK GDPR, which came into force on 1 January 2021. It sits alongside the amended Data Protection Act 2018 and largely mirrors the EU GDPR, but it is a separate legal instrument enforced by the Information Commissioner's Office (ICO) rather than European authorities.

In practical terms, UK organisations still need to comply with strict data protection principles, honour data subject rights, and report breaches within 72 hours. However, the legal framework, oversight body, and international transfer mechanisms have all shifted in important ways.

The Two Regulations: UK GDPR vs EU GDPR

Since the end of the Brexit transition period on 31 December 2020, two parallel regulations govern British businesses depending on where their data subjects are located.

UK GDPR

The UK GDPR applies to the processing of personal data by controllers and processors established in the UK, regardless of whether the processing takes place in the UK. It also applies to organisations outside the UK that offer goods or services to, or monitor the behaviour of, individuals in the UK.

EU GDPR

The EU GDPR continues to apply to any UK business that offers goods or services to individuals in the European Economic Area (EEA), or monitors their behaviour. This means many British companies now face a dual compliance burden.

Side-by-Side Comparison

FeatureUK GDPREU GDPR
RegulatorInformation Commissioner's Office (ICO)National data protection authorities across EEA
Maximum fine£17.5 million or 4% of global turnover€20 million or 4% of global turnover
Territorial scopeUK data subjectsEEA data subjects
Legal basisData Protection Act 2018 (as amended)Regulation (EU) 2016/679
Representative requiredUK representative if based abroadEU representative if based outside EEA
Age of consent13 years16 years (member states can lower to 13)

The Adequacy Decision: A Critical Lifeline

Perhaps the most consequential development in GDPR after Brexit was the European Commission's adequacy decision, adopted on 28 June 2021. This decision recognises the UK as providing an essentially equivalent level of data protection to the EU, allowing personal data to flow freely from the EEA to the UK without additional safeguards.

Without this decision, every transfer of personal data from the EU to the UK would have required Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another legal mechanism. The administrative burden would have been enormous, particularly for small and medium-sized enterprises.

The Sunset Clause

Uniquely, the UK adequacy decision includes a sunset clause. It was originally set to expire on 27 June 2025, though the European Commission has indicated it may be renewed. This creates ongoing uncertainty for UK businesses, as any divergence from EU standards could jeopardise the decision when it comes up for renewal.

International Data Transfers From the UK

The UK has largely followed the EU's approach to international transfers, recognising the same list of adequate countries. However, it has begun to develop its own mechanisms and add new territories to its adequacy list.

UK Adequacy Regulations

The Secretary of State can now make its own adequacy regulations, and the UK has recognised additional jurisdictions independently of the EU. This includes the UK Extension to the EU-US Data Privacy Framework, which permits transfers to certified US organisations.

International Data Transfer Agreement (IDTA)

In March 2022, the ICO introduced the International Data Transfer Agreement and the UK Addendum to the EU SCCs. These replace the old EU SCCs for UK transfers. Organisations had until 21 March 2024 to update legacy contracts.

Transfer Risk Assessments

Following the Schrems II judgment, UK exporters must also conduct a Transfer Risk Assessment (TRA) before relying on transfer tools. The ICO has published its own TRA tool, which takes a slightly different approach from the European Data Protection Board's guidance, focusing more on the risk to data subjects.

Key Changes for UK Businesses

Beyond the headline legal shifts, there are several practical changes that organisations need to have addressed by now.

  1. Appointing an EU representative: If you offer goods or services to people in the EEA or monitor their behaviour, and you have no establishment in the EU, you must appoint a representative under Article 27 of the EU GDPR.
  2. Appointing a UK representative: Conversely, non-UK organisations processing UK residents' data need a UK representative.
  3. Updating privacy notices: Privacy policies should reference the UK GDPR, name the ICO as the supervisory authority for UK data subjects, and disclose international transfer mechanisms.
  4. Reviewing lead supervisory authority arrangements: The one-stop-shop mechanism no longer applies to UK organisations, meaning you may deal with multiple EU regulators as well as the ICO.
  5. Updating contracts: Data processing agreements and international transfer contracts must reflect the new dual regime.

The Data (Use and Access) Act 2025

The most significant domestic development in UK data protection is the Data (Use and Access) Act 2025, which received Royal Assent in June 2025. It represents the government's ambition to make UK data protection law more flexible and business-friendly while preserving the adequacy decision.

What the Act Changes

The Act introduces reforms across several areas:

  • Legitimate interests: A new list of "recognised legitimate interests" that do not require the traditional balancing test.
  • Automated decision-making: Relaxed rules for solely automated decisions, provided safeguards are in place.
  • Cookies and PECR: Fewer scenarios requiring cookie consent, particularly for analytics and improving services.
  • Subject access requests: Clearer rules on "stop the clock" provisions when clarification is needed.
  • Complaints: New requirements for controllers to have complaint-handling processes and acknowledge complaints within 30 days.
  • ICO reform: The ICO becomes the Information Commission, with a governance structure closer to other UK regulators.

While the reforms are relatively modest, the direction of travel matters. Any perceived weakening of protections could threaten the EU adequacy decision when it comes up for review.

Enforcement and Fines Under the UK GDPR

The ICO has continued to enforce data protection law robustly since Brexit. Notable fines include those levied against Clearview AI, TikTok for children's data violations, and various public bodies for security failings.

The maximum fines mirror the EU regime in real terms: £17.5 million or 4% of global annual turnover for the most serious infringements, and £8.7 million or 2% for lesser breaches. The ICO has, however, taken a somewhat more collaborative approach than some EU regulators, often issuing reprimands or improvement notices before resorting to monetary penalties.

Practical Compliance Checklist for UK Organisations

If you are a UK business handling personal data, use this checklist to sense-check your compliance posture:

  1. Confirm which regulation applies to each data flow (UK GDPR, EU GDPR, or both).
  2. Maintain a Record of Processing Activities (ROPA) under Article 30.
  3. Ensure your privacy notice reflects both UK and EU obligations if relevant.
  4. Review all international data transfers and put IDTAs or UK Addendums in place.
  5. Conduct Transfer Risk Assessments for restricted transfers.
  6. Appoint EU and UK representatives where required.
  7. Update your Data Protection Impact Assessment (DPIA) templates.
  8. Train staff on the differences between the two regimes.
  9. Establish a clear breach notification workflow that considers both the ICO and any EU supervisory authorities.
  10. Monitor developments around the adequacy decision renewal.

What About Marketing, Tracking Links, and Analytics?

Marketing activities remain heavily regulated under the Privacy and Electronic Communications Regulations (PECR), which sit alongside the UK GDPR. Tracking cookies, email marketing, and behavioural analytics all continue to require appropriate legal bases and, in many cases, consent.

For businesses that rely on shortened URLs for campaign tracking, choosing a privacy-respecting provider matters. Tools like Lunyb allow marketers to create trackable short links without excessive data collection, which helps with data minimisation obligations under Article 5. If you are evaluating options, our 2026 buyer's guide to URL shorteners covers the compliance considerations in detail.

The Future of GDPR in the UK

Looking ahead, the biggest question is whether the UK will continue to align closely with EU data protection law or diverge more significantly. The Data (Use and Access) Act 2025 represents a careful attempt to modernise without breaking the adequacy relationship, but political pressure to reduce regulatory burdens could push future reforms further.

For businesses, the pragmatic answer is to build compliance programmes to the higher of the two standards. If you can meet EU GDPR requirements, you will almost certainly meet UK GDPR requirements. This approach also insulates you from future divergence and simplifies operations across borders.

Frequently Asked Questions

Does GDPR still apply in the UK after Brexit?

Yes. The EU GDPR was retained in UK law as the "UK GDPR" from 1 January 2021. It works alongside the amended Data Protection Act 2018 and is enforced by the Information Commissioner's Office. UK organisations must also comply with the EU GDPR if they process data of individuals in the EEA.

What is the main difference between UK GDPR and EU GDPR?

The core principles, rights, and obligations are almost identical. The main differences lie in enforcement (ICO versus EEA regulators), maximum fines (denominated in pounds rather than euros), international transfer mechanisms (IDTA rather than EU SCCs), and the age of consent for online services (13 in the UK, 16 in the EU by default).

Do I need both a UK and EU representative?

Possibly. If your organisation is based in the UK and offers services to individuals in the EEA without an EU establishment, you need an Article 27 EU representative. If you are based outside the UK and process UK residents' data, you need a UK representative. Businesses with global operations often need both.

Will the EU adequacy decision for the UK be renewed?

The European Commission has signalled willingness to renew the adequacy decision, but renewal depends on the UK maintaining essentially equivalent standards of protection. The Data (Use and Access) Act 2025 has been drafted with this in mind, but any significant divergence from EU norms could put the decision at risk in future reviews.

What should I do about data transfers from the EU to the UK?

Because of the adequacy decision, no additional safeguards are currently required for personal data transfers from the EEA to the UK. However, you should monitor the status of the decision and be prepared to implement Standard Contractual Clauses or another mechanism should the situation change.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles