facebook-pixel

UK Data Protection Act vs GDPR Explained: Key Differences in 2026

L
Lunyb Security Team
··9 min read

Since Brexit, UK businesses have been navigating a slightly more complex data protection landscape. The UK Data Protection Act 2018 (DPA 2018), the UK GDPR and the EU GDPR all sit alongside one another, each with their own scope. Understanding how they interact is essential for any organisation that collects, stores or processes personal data in Britain.

This guide breaks down what each law does, where they overlap, and what you need to do to stay compliant in 2026.

What Is the UK Data Protection Act 2018?

The UK Data Protection Act 2018 is the primary piece of British legislation governing how personal data must be handled. It supplements the UK GDPR and sets out the specific rules, exemptions and enforcement powers that apply within the United Kingdom.

The DPA 2018 came into force on 25 May 2018, the same day the EU GDPR became enforceable. It replaced the older Data Protection Act 1998 and was designed to bring UK law into full alignment with the European framework. After Brexit, the DPA 2018 was amended to work alongside the UK GDPR — a retained version of the EU regulation.

Key Components of the DPA 2018

  • Part 1: Preliminary definitions and scope.
  • Part 2: General processing rules that sit alongside the UK GDPR.
  • Part 3: Law enforcement processing (police, prosecutors, courts).
  • Part 4: Intelligence services processing.
  • Parts 5–7: Powers of the Information Commissioner's Office (ICO), enforcement, offences and appeals.

What Is the GDPR?

The General Data Protection Regulation (GDPR) is a European Union law that harmonises data protection rules across all EU member states. It came into effect on 25 May 2018 and remains one of the world's most influential privacy frameworks.

Following Brexit, the UK created its own version — the UK GDPR — which is almost identical in wording to the EU GDPR but operates as domestic British law. Both regulations share the same seven core principles:

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality (security)
  7. Accountability

UK Data Protection Act vs GDPR: The Core Difference

The simplest way to think about it: the UK GDPR sets out the broad rules, while the DPA 2018 fills in the UK-specific detail. They are not competing laws — they work together.

The EU GDPR, meanwhile, still applies to any UK business that offers goods or services to individuals in the EU, or that monitors the behaviour of people located in the EU.

Side-by-Side Comparison

Feature UK GDPR DPA 2018 EU GDPR
Jurisdiction United Kingdom United Kingdom European Union (EEA)
Type of law Retained EU regulation Domestic UK Act EU regulation
Regulator ICO ICO Local EU DPAs (e.g. CNIL, DPC)
Maximum fine £17.5m or 4% global turnover £17.5m or 4% global turnover €20m or 4% global turnover
Covers law enforcement data No Yes (Part 3) Separate directive (LED)
Age of consent (children) 13 13 16 (member states may lower to 13)
International transfers UK adequacy decisions Supports UK GDPR rules EU adequacy decisions

Key Differences Between the DPA 2018 and the GDPR

1. Scope of Application

The GDPR (both EU and UK versions) applies to general processing of personal data by businesses, public bodies and organisations. The DPA 2018 goes further by covering areas the GDPR does not — most notably law enforcement processing and intelligence services processing. If you're a police force or a security agency in Britain, the DPA 2018 is your primary framework.

2. Exemptions and Derogations

The DPA 2018 provides specific UK exemptions that the GDPR itself leaves to member states. These include exemptions for:

  • Journalism, academic, artistic and literary purposes
  • Research and statistical processing
  • Immigration control
  • Legal professional privilege
  • National security and defence

3. Age of Consent for Online Services

Under the EU GDPR, children need parental consent to use information society services until they turn 16, though member states can lower this to 13. The UK, via the DPA 2018, has set this age at 13 — the lowest allowed threshold.

4. International Data Transfers

Post-Brexit, the UK maintains its own list of "adequate" countries for international data transfers. The EU has granted the UK an adequacy decision (renewed in 2025), meaning data can still flow freely between the EU and UK. However, transfers to third countries like the US now involve UK-specific tools such as the International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses.

5. Enforcement and the ICO

The Information Commissioner's Office (ICO) enforces both the UK GDPR and the DPA 2018. Unlike EU businesses, which may deal with multiple supervisory authorities, UK organisations have a single regulator — which simplifies compliance somewhat.

What Both Frameworks Require

Despite their differences, the DPA 2018 and the GDPR share the same foundation. Any organisation handling personal data must:

  1. Identify a lawful basis for every processing activity (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
  2. Provide clear privacy notices to data subjects explaining what data is collected, why, and how long it's kept.
  3. Respect data subject rights, including access, rectification, erasure, restriction, portability and objection.
  4. Report data breaches to the ICO within 72 hours when they pose a risk to individuals.
  5. Implement appropriate security, including encryption, access controls and staff training.
  6. Maintain a Record of Processing Activities (ROPA) if you have 250+ employees or engage in higher-risk processing.
  7. Appoint a Data Protection Officer (DPO) if you're a public authority or engage in large-scale monitoring or processing of special category data.

Practical Compliance Steps for UK Businesses

Step 1: Map Your Data

Know exactly what personal data you hold, where it's stored, who has access, and why. This is the foundation of everything else.

Step 2: Review Your Lawful Bases

Consent isn't always the best basis. For most business operations, "legitimate interests" or "contract" is more appropriate — and less fragile.

Step 3: Update Privacy Notices

Ensure your privacy policy references the UK GDPR and the DPA 2018 (not just the EU GDPR) and lists the ICO as the relevant supervisory authority.

Step 4: Audit Your Vendors

Every third-party tool that touches personal data — from email marketing platforms to link shorteners — is a processor. Ensure you have a data processing agreement (DPA) in place. For link tracking specifically, privacy-first tools like Lunyb minimise the amount of personal data collected compared to some legacy shorteners. You can read more in our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.

Step 5: Prepare for Data Subject Requests

You have one calendar month to respond to a Subject Access Request (SAR). Build a documented process now rather than scrambling when one arrives.

Step 6: Train Your Staff

Most data breaches are human — misdirected emails, weak passwords, lost devices. Annual training, backed by clear internal policies, is essential.

The Future: The Data (Use and Access) Act 2025

The UK government has passed the Data (Use and Access) Act 2025 (formerly the Data Protection and Digital Information Bill), which amends parts of both the UK GDPR and the DPA 2018. Key changes include:

  • Simplified rules for legitimate interests, including a recognised list of "pre-approved" purposes
  • Reduced requirements for ROPAs for smaller organisations
  • Reforms to cookie rules, allowing certain low-risk cookies without consent
  • A restructured ICO, renamed the Information Commission
  • Clearer rules on automated decision-making

These reforms don't dramatically diverge from EU standards — which is deliberate, to protect the UK's adequacy status — but they do add flexibility for British businesses.

Penalties for Non-Compliance

The ICO can issue fines up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier breaches (such as failing to keep proper records) can attract fines up to £8.7 million or 2% of turnover.

Beyond fines, non-compliance carries reputational damage, potential class-action-style group claims under Section 187 of the DPA 2018, and enforcement notices that can force operational changes.

Which Law Applies to Your Business?

Here's a quick decision framework:

  • UK-only business, UK customers only: UK GDPR + DPA 2018 apply.
  • UK business selling to EU customers: UK GDPR + DPA 2018 + EU GDPR all apply. You may need an EU representative.
  • EU business selling into the UK: EU GDPR + UK GDPR apply. You may need a UK representative.
  • Global business with UK operations: All three frameworks likely apply, plus any local laws in other jurisdictions.

Frequently Asked Questions

Is the UK GDPR the same as the EU GDPR?

They are almost identical in wording but operate as separate legal instruments. The UK GDPR is retained British law enforced by the ICO, while the EU GDPR is European law enforced by national data protection authorities across the EEA. Post-Brexit divergence is minor so far, though the Data (Use and Access) Act 2025 introduces some UK-specific reforms.

Do I need to comply with both the DPA 2018 and the UK GDPR?

Yes. The two work together. The UK GDPR sets the main framework, and the DPA 2018 supplements it with UK-specific rules, exemptions and enforcement mechanisms. Compliance with one requires compliance with the other.

What happens if the UK loses its EU adequacy decision?

If the EU withdrew the UK's adequacy status, personal data transfers from the EU to the UK would require additional safeguards such as Standard Contractual Clauses or Binding Corporate Rules. This would significantly increase compliance costs for cross-border businesses. The 2025 adequacy renewal is valid until 2031, subject to review.

Does the DPA 2018 apply to small businesses?

Yes. There's no blanket exemption based on size. However, some obligations — such as maintaining a full Record of Processing Activities or appointing a DPO — only apply to larger organisations or those engaged in higher-risk processing. Small businesses still need lawful bases, privacy notices, security measures and breach reporting.

How long do I have to report a data breach?

You must report a notifiable breach to the ICO within 72 hours of becoming aware of it. If the breach poses a high risk to individuals' rights and freedoms, you must also inform the affected data subjects without undue delay. Not every breach is notifiable — only those likely to result in risk.

Final Thoughts

The UK Data Protection Act 2018 and the UK GDPR are two sides of the same coin. Together with the EU GDPR (where relevant), they form the backbone of British data protection law. For most businesses, the practical compliance work is the same: know your data, be transparent, secure it properly, respect people's rights, and document everything.

With reforms like the Data (Use and Access) Act 2025 coming into force, UK data protection is becoming slightly more flexible without abandoning its European foundations. Staying informed — and building privacy into your operations from the ground up — remains the surest path to compliance.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles