UK Data Protection Act vs GDPR Explained: Key Differences in 2026
Since Brexit, UK businesses have been navigating a slightly more complex data protection landscape. The UK Data Protection Act 2018 (DPA 2018), the UK GDPR and the EU GDPR all sit alongside one another, each with their own scope. Understanding how they interact is essential for any organisation that collects, stores or processes personal data in Britain.
This guide breaks down what each law does, where they overlap, and what you need to do to stay compliant in 2026.
What Is the UK Data Protection Act 2018?
The UK Data Protection Act 2018 is the primary piece of British legislation governing how personal data must be handled. It supplements the UK GDPR and sets out the specific rules, exemptions and enforcement powers that apply within the United Kingdom.
The DPA 2018 came into force on 25 May 2018, the same day the EU GDPR became enforceable. It replaced the older Data Protection Act 1998 and was designed to bring UK law into full alignment with the European framework. After Brexit, the DPA 2018 was amended to work alongside the UK GDPR — a retained version of the EU regulation.
Key Components of the DPA 2018
- Part 1: Preliminary definitions and scope.
- Part 2: General processing rules that sit alongside the UK GDPR.
- Part 3: Law enforcement processing (police, prosecutors, courts).
- Part 4: Intelligence services processing.
- Parts 5–7: Powers of the Information Commissioner's Office (ICO), enforcement, offences and appeals.
What Is the GDPR?
The General Data Protection Regulation (GDPR) is a European Union law that harmonises data protection rules across all EU member states. It came into effect on 25 May 2018 and remains one of the world's most influential privacy frameworks.
Following Brexit, the UK created its own version — the UK GDPR — which is almost identical in wording to the EU GDPR but operates as domestic British law. Both regulations share the same seven core principles:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality (security)
- Accountability
UK Data Protection Act vs GDPR: The Core Difference
The simplest way to think about it: the UK GDPR sets out the broad rules, while the DPA 2018 fills in the UK-specific detail. They are not competing laws — they work together.
The EU GDPR, meanwhile, still applies to any UK business that offers goods or services to individuals in the EU, or that monitors the behaviour of people located in the EU.
Side-by-Side Comparison
| Feature | UK GDPR | DPA 2018 | EU GDPR |
|---|---|---|---|
| Jurisdiction | United Kingdom | United Kingdom | European Union (EEA) |
| Type of law | Retained EU regulation | Domestic UK Act | EU regulation |
| Regulator | ICO | ICO | Local EU DPAs (e.g. CNIL, DPC) |
| Maximum fine | £17.5m or 4% global turnover | £17.5m or 4% global turnover | €20m or 4% global turnover |
| Covers law enforcement data | No | Yes (Part 3) | Separate directive (LED) |
| Age of consent (children) | 13 | 13 | 16 (member states may lower to 13) |
| International transfers | UK adequacy decisions | Supports UK GDPR rules | EU adequacy decisions |
Key Differences Between the DPA 2018 and the GDPR
1. Scope of Application
The GDPR (both EU and UK versions) applies to general processing of personal data by businesses, public bodies and organisations. The DPA 2018 goes further by covering areas the GDPR does not — most notably law enforcement processing and intelligence services processing. If you're a police force or a security agency in Britain, the DPA 2018 is your primary framework.
2. Exemptions and Derogations
The DPA 2018 provides specific UK exemptions that the GDPR itself leaves to member states. These include exemptions for:
- Journalism, academic, artistic and literary purposes
- Research and statistical processing
- Immigration control
- Legal professional privilege
- National security and defence
3. Age of Consent for Online Services
Under the EU GDPR, children need parental consent to use information society services until they turn 16, though member states can lower this to 13. The UK, via the DPA 2018, has set this age at 13 — the lowest allowed threshold.
4. International Data Transfers
Post-Brexit, the UK maintains its own list of "adequate" countries for international data transfers. The EU has granted the UK an adequacy decision (renewed in 2025), meaning data can still flow freely between the EU and UK. However, transfers to third countries like the US now involve UK-specific tools such as the International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses.
5. Enforcement and the ICO
The Information Commissioner's Office (ICO) enforces both the UK GDPR and the DPA 2018. Unlike EU businesses, which may deal with multiple supervisory authorities, UK organisations have a single regulator — which simplifies compliance somewhat.
What Both Frameworks Require
Despite their differences, the DPA 2018 and the GDPR share the same foundation. Any organisation handling personal data must:
- Identify a lawful basis for every processing activity (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
- Provide clear privacy notices to data subjects explaining what data is collected, why, and how long it's kept.
- Respect data subject rights, including access, rectification, erasure, restriction, portability and objection.
- Report data breaches to the ICO within 72 hours when they pose a risk to individuals.
- Implement appropriate security, including encryption, access controls and staff training.
- Maintain a Record of Processing Activities (ROPA) if you have 250+ employees or engage in higher-risk processing.
- Appoint a Data Protection Officer (DPO) if you're a public authority or engage in large-scale monitoring or processing of special category data.
Practical Compliance Steps for UK Businesses
Step 1: Map Your Data
Know exactly what personal data you hold, where it's stored, who has access, and why. This is the foundation of everything else.
Step 2: Review Your Lawful Bases
Consent isn't always the best basis. For most business operations, "legitimate interests" or "contract" is more appropriate — and less fragile.
Step 3: Update Privacy Notices
Ensure your privacy policy references the UK GDPR and the DPA 2018 (not just the EU GDPR) and lists the ICO as the relevant supervisory authority.
Step 4: Audit Your Vendors
Every third-party tool that touches personal data — from email marketing platforms to link shorteners — is a processor. Ensure you have a data processing agreement (DPA) in place. For link tracking specifically, privacy-first tools like Lunyb minimise the amount of personal data collected compared to some legacy shorteners. You can read more in our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.
Step 5: Prepare for Data Subject Requests
You have one calendar month to respond to a Subject Access Request (SAR). Build a documented process now rather than scrambling when one arrives.
Step 6: Train Your Staff
Most data breaches are human — misdirected emails, weak passwords, lost devices. Annual training, backed by clear internal policies, is essential.
The Future: The Data (Use and Access) Act 2025
The UK government has passed the Data (Use and Access) Act 2025 (formerly the Data Protection and Digital Information Bill), which amends parts of both the UK GDPR and the DPA 2018. Key changes include:
- Simplified rules for legitimate interests, including a recognised list of "pre-approved" purposes
- Reduced requirements for ROPAs for smaller organisations
- Reforms to cookie rules, allowing certain low-risk cookies without consent
- A restructured ICO, renamed the Information Commission
- Clearer rules on automated decision-making
These reforms don't dramatically diverge from EU standards — which is deliberate, to protect the UK's adequacy status — but they do add flexibility for British businesses.
Penalties for Non-Compliance
The ICO can issue fines up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier breaches (such as failing to keep proper records) can attract fines up to £8.7 million or 2% of turnover.
Beyond fines, non-compliance carries reputational damage, potential class-action-style group claims under Section 187 of the DPA 2018, and enforcement notices that can force operational changes.
Which Law Applies to Your Business?
Here's a quick decision framework:
- UK-only business, UK customers only: UK GDPR + DPA 2018 apply.
- UK business selling to EU customers: UK GDPR + DPA 2018 + EU GDPR all apply. You may need an EU representative.
- EU business selling into the UK: EU GDPR + UK GDPR apply. You may need a UK representative.
- Global business with UK operations: All three frameworks likely apply, plus any local laws in other jurisdictions.
Frequently Asked Questions
Is the UK GDPR the same as the EU GDPR?
They are almost identical in wording but operate as separate legal instruments. The UK GDPR is retained British law enforced by the ICO, while the EU GDPR is European law enforced by national data protection authorities across the EEA. Post-Brexit divergence is minor so far, though the Data (Use and Access) Act 2025 introduces some UK-specific reforms.
Do I need to comply with both the DPA 2018 and the UK GDPR?
Yes. The two work together. The UK GDPR sets the main framework, and the DPA 2018 supplements it with UK-specific rules, exemptions and enforcement mechanisms. Compliance with one requires compliance with the other.
What happens if the UK loses its EU adequacy decision?
If the EU withdrew the UK's adequacy status, personal data transfers from the EU to the UK would require additional safeguards such as Standard Contractual Clauses or Binding Corporate Rules. This would significantly increase compliance costs for cross-border businesses. The 2025 adequacy renewal is valid until 2031, subject to review.
Does the DPA 2018 apply to small businesses?
Yes. There's no blanket exemption based on size. However, some obligations — such as maintaining a full Record of Processing Activities or appointing a DPO — only apply to larger organisations or those engaged in higher-risk processing. Small businesses still need lawful bases, privacy notices, security measures and breach reporting.
How long do I have to report a data breach?
You must report a notifiable breach to the ICO within 72 hours of becoming aware of it. If the breach poses a high risk to individuals' rights and freedoms, you must also inform the affected data subjects without undue delay. Not every breach is notifiable — only those likely to result in risk.
Final Thoughts
The UK Data Protection Act 2018 and the UK GDPR are two sides of the same coin. Together with the EU GDPR (where relevant), they form the backbone of British data protection law. For most businesses, the practical compliance work is the same: know your data, be transparent, secure it properly, respect people's rights, and document everything.
With reforms like the Data (Use and Access) Act 2025 coming into force, UK data protection is becoming slightly more flexible without abandoning its European foundations. Staying informed — and building privacy into your operations from the ground up — remains the surest path to compliance.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.