facebook-pixel

UK Data Protection Act vs GDPR Explained: Key Differences for 2026

L
Lunyb Security Team
··10 min read

Since Brexit reshaped the UK's relationship with EU law, businesses have grappled with a confusing question: which data protection rules actually apply? The short answer is that both the UK Data Protection Act 2018 (DPA 2018) and the UK GDPR apply domestically, while the EU GDPR still applies if you process data of individuals in the European Economic Area. This guide breaks down the differences, overlaps, and practical compliance steps for UK organisations in 2026.

What Is the UK Data Protection Act 2018?

The UK Data Protection Act 2018 is the primary piece of legislation that governs how personal data is processed in the United Kingdom. It replaced the older Data Protection Act 1998 and works alongside the UK GDPR to form the country's data protection framework.

The DPA 2018 does three main things:

  1. It supplements the UK GDPR by filling in the gaps that member states were allowed to legislate on (such as age of consent for information society services).
  2. It applies GDPR-style standards to areas outside the scope of EU law, including law enforcement processing and intelligence services (Parts 3 and 4 of the Act).
  3. It grants powers to the Information Commissioner's Office (ICO) and creates criminal offences for certain misuses of data.

What Is the UK GDPR?

The UK GDPR is the retained version of the EU General Data Protection Regulation, incorporated into UK law by the European Union (Withdrawal) Act 2018 and amended by subsequent regulations. It came into force on 1 January 2021 when the Brexit transition period ended.

Functionally, the UK GDPR is almost identical to the EU GDPR. It uses the same core principles, the same lawful bases for processing, and the same rights for data subjects. The differences are largely structural: references to "member states" have been changed to "the United Kingdom," and the supervisory authority is the ICO rather than a European data protection board.

UK Data Protection Act vs GDPR: The Core Relationship

The most important point to understand is that the DPA 2018 and the UK GDPR are not competing regimes. They work together as a single, integrated framework. Think of the UK GDPR as the main rulebook and the DPA 2018 as the UK-specific instruction manual that tells you how to apply it in a British context.

Here is how the two instruments interact:

AspectUK GDPRData Protection Act 2018
ScopeGeneral processing of personal dataSupplements UK GDPR + covers law enforcement and intelligence services
Legal formRetained EU regulationUK Act of Parliament
Data subject rightsDefines the eight core rightsProvides exemptions and limitations
Enforcement bodyICOICO
Maximum fine£17.5m or 4% of global turnoverSame, mirrors UK GDPR
Age of consent (children)Not specifiedSet at 13 years

UK GDPR vs EU GDPR: What Actually Changed After Brexit?

For most UK businesses, day-to-day compliance feels identical to pre-Brexit. But there are meaningful differences worth understanding.

1. Two Regimes May Apply Simultaneously

If your organisation is based in the UK but offers goods or services to individuals in the EEA, or monitors their behaviour, you must comply with both the UK GDPR and the EU GDPR. This is known as the "dual compliance" requirement.

2. Representatives

UK controllers without an EU establishment that process EEA residents' data must appoint an EU representative under Article 27 of the EU GDPR. Conversely, EU-based controllers processing UK residents' data may need a UK representative.

3. International Data Transfers

The UK now issues its own adequacy decisions. In June 2021, the EU granted the UK adequacy status, meaning data can flow freely from the EEA to the UK. This decision was renewed in 2025. For transfers from the UK to other countries, the ICO has issued the UK International Data Transfer Agreement (IDTA) and a UK addendum to the EU Standard Contractual Clauses.

4. Regulatory Divergence

The UK government has signalled a willingness to diverge from EU rules through the Data (Use and Access) Act 2025, which introduces reforms around cookies, legitimate interests, and automated decision-making. However, any significant divergence risks the UK's adequacy status, so changes have been measured.

The Seven Data Protection Principles

Both the UK GDPR and the DPA 2018 are built on seven core principles. Any organisation processing personal data must comply with all of them.

  1. Lawfulness, fairness and transparency — process data lawfully, fairly, and in a way individuals understand.
  2. Purpose limitation — collect data for specified, explicit, and legitimate purposes.
  3. Data minimisation — collect only what is necessary.
  4. Accuracy — keep data accurate and up to date.
  5. Storage limitation — keep data only as long as necessary.
  6. Integrity and confidentiality — process data securely.
  7. Accountability — demonstrate compliance with the above.

Rights of Data Subjects Under Both Regimes

The eight rights afforded to individuals are identical under the UK GDPR and DPA 2018, though the DPA carves out specific exemptions (such as for national security or crime prevention).

  • The right to be informed
  • The right of access (subject access requests)
  • The right to rectification
  • The right to erasure ("right to be forgotten")
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights related to automated decision-making and profiling

Key Differences: Where the DPA 2018 Goes Beyond the UK GDPR

Law Enforcement Processing (Part 3)

The UK GDPR does not cover personal data processed by "competent authorities" for law enforcement purposes. Part 3 of the DPA 2018 fills this gap by implementing the EU Law Enforcement Directive into UK law.

Intelligence Services Processing (Part 4)

Processing by MI5, MI6, and GCHQ is entirely outside the UK GDPR. Part 4 of the DPA 2018 sets bespoke rules for these services, based on modernised Council of Europe Convention 108 principles.

Criminal Offences

The DPA 2018 creates specific criminal offences that the UK GDPR does not, including:

  • Unlawfully obtaining or disclosing personal data (section 170)
  • Re-identifying de-identified personal data (section 171)
  • Altering data to prevent disclosure following a subject access request (section 173)

Exemptions

Schedules 2 to 4 of the DPA 2018 list exemptions from certain UK GDPR provisions, covering areas such as journalism, research, legal privilege, and immigration.

Fines and Enforcement

The ICO enforces both the UK GDPR and the DPA 2018. Maximum fines are tiered:

  • Standard maximum: £8.7 million or 2% of worldwide annual turnover, whichever is higher.
  • Higher maximum: £17.5 million or 4% of worldwide annual turnover, whichever is higher.

Recent enforcement actions have targeted issues such as inadequate security measures, non-compliant cookie banners, and mishandling of subject access requests. The ICO has increasingly used reprimands and enforcement notices alongside monetary penalties.

Practical Compliance Checklist for UK Businesses

Whether you run a small e-commerce site or a multinational, the following checklist helps you stay compliant with both the UK GDPR and the DPA 2018.

  1. Map your data. Document what personal data you collect, why, and where it flows.
  2. Identify lawful bases. Assign a lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) to every processing activity.
  3. Update privacy notices. Make them clear, layered, and specific to each processing purpose.
  4. Review consent mechanisms. Ensure cookies, marketing opt-ins, and other consents meet UK GDPR standards.
  5. Implement security controls. Encryption, access controls, and secure link handling all matter. If you share links containing tracking parameters, tools like Lunyb can help you shorten and manage URLs without exposing unnecessary data.
  6. Handle subject access requests. Have a documented process to respond within one calendar month.
  7. Prepare for breaches. Notify the ICO within 72 hours of becoming aware of a notifiable breach.
  8. Appoint a DPO if required. Public authorities and organisations undertaking large-scale monitoring or processing of special category data must appoint a Data Protection Officer.
  9. Review international transfers. Use the UK IDTA or Addendum to SCCs where necessary.
  10. Train your staff. Human error remains the leading cause of breaches.

Common Misconceptions

"Brexit means GDPR no longer applies in the UK"

False. The UK GDPR is retained UK law and remains in full force. If you process EEA residents' data, the EU GDPR also applies.

"The DPA 2018 replaced the GDPR"

False. The DPA 2018 was passed to work alongside the (then EU, now UK) GDPR. It never replaced it.

"Small businesses are exempt"

False. There is no small business exemption. However, obligations are proportionate — a five-person company is not expected to have the same compliance apparatus as a bank.

"Consent is always required"

False. Consent is only one of six lawful bases. For many business activities, legitimate interests or contractual necessity is more appropriate.

How Link Management Fits Into Data Protection

Modern data protection is not just about big databases — it extends to seemingly minor tools like URL shorteners, analytics platforms, and marketing pixels. When you share a shortened link, the redirect service may log IP addresses, timestamps, referrers, and user agents. That log is personal data under the UK GDPR.

Choosing a privacy-respecting shortener matters. Our review of Lunyb covers how the service handles link analytics with minimal data retention, and our 2026 buyer's guide compares the compliance postures of major providers. If you're weighing the enterprise option, our Rebrandly review examines its data handling in detail.

Looking Ahead: The Data (Use and Access) Act 2025

The UK's data protection framework continues to evolve. The Data (Use and Access) Act 2025 introduces reforms aimed at reducing compliance burden while maintaining EU adequacy. Key changes include:

  • A more flexible approach to cookies, allowing certain low-risk cookies without explicit consent.
  • A statutory list of legitimate interests for common commercial activities.
  • Reforms to subject access request handling, including clearer rules on "vexatious or excessive" requests.
  • Modernised rules for scientific research and AI training.

UK businesses should monitor ICO guidance closely as these provisions come into force through 2026.

Frequently Asked Questions

Is the UK Data Protection Act the same as GDPR?

No, but they work together. The UK GDPR is the main data protection regulation, while the Data Protection Act 2018 supplements it with UK-specific rules, exemptions, and provisions for law enforcement and intelligence services processing.

Does the EU GDPR still apply to UK businesses?

Yes, if a UK business offers goods or services to individuals in the EEA or monitors their behaviour, the EU GDPR applies alongside the UK GDPR. Such businesses may also need to appoint an EU representative.

What is the maximum fine under the UK GDPR and DPA 2018?

The maximum fine is £17.5 million or 4% of worldwide annual turnover, whichever is higher. A lower tier of £8.7 million or 2% of turnover applies to less serious infringements.

Who enforces data protection law in the UK?

The Information Commissioner's Office (ICO) is the independent supervisory authority. It can investigate complaints, issue enforcement notices, impose fines, and prosecute certain criminal offences under the DPA 2018.

Do I need to register with the ICO?

Most organisations that process personal data must pay a data protection fee to the ICO unless an exemption applies. Fees range from £40 to £2,900 per year depending on organisation size and turnover.

Conclusion

The UK Data Protection Act 2018 and the UK GDPR are not rivals — they are two halves of the same framework. The UK GDPR provides the core rules for general processing, while the DPA 2018 fills in national-specific detail, covers law enforcement and intelligence processing, and creates additional criminal offences. For most UK organisations, compliance means following a single integrated set of obligations, but businesses trading across the Channel must also consider the EU GDPR. As the Data (Use and Access) Act 2025 reshapes some of the rules, staying informed and building strong data governance foundations remains the best route to sustainable compliance.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles