facebook-pixel

UK Data Protection Act vs GDPR Explained: A 2026 Compliance Guide

L
Lunyb Security Team
··10 min read

Since Brexit, UK organisations have been navigating two overlapping data protection regimes: the UK Data Protection Act 2018 (DPA 2018) and the UK GDPR, alongside the still-relevant EU GDPR for anyone handling European data. Understanding how these frameworks differ (and where they mirror each other) is essential for lawful marketing, HR practices, analytics, and even something as simple as running a link tracker.

This guide breaks down the UK Data Protection Act vs GDPR debate in plain English, explains how the two work together, and outlines the practical compliance steps every UK business should take in 2026.

Quick Definition: What Are the DPA 2018 and UK GDPR?

The Data Protection Act 2018 is the UK's primary domestic data protection statute. The UK GDPR is the retained version of the EU General Data Protection Regulation, transposed into UK law after Brexit. Together, they form the UK's core data protection framework, enforced by the Information Commissioner's Office (ICO).

Put simply: the UK GDPR sets out the high-level principles and rights, while the DPA 2018 fills in the UK-specific detail, exemptions, and enforcement mechanisms.

A Short History: How the UK Got Two Data Laws

Before 2018, the UK relied on the Data Protection Act 1998. When the EU GDPR came into force in May 2018, the UK passed the DPA 2018 to supplement it and cover areas the GDPR left to member states, such as law enforcement processing and intelligence services.

After Brexit, the EU GDPR no longer applied directly in the UK. Parliament used the European Union (Withdrawal) Act 2018 to retain a domestic version, now known as the UK GDPR. The DPA 2018 was amended in parallel to keep everything consistent.

The Three-Layer UK Framework

  1. UK GDPR — general processing rules and data subject rights.
  2. DPA 2018 Part 2 — general processing supplements (exemptions, age of consent for information society services, etc.).
  3. DPA 2018 Parts 3 and 4 — rules for law enforcement and intelligence services.

UK Data Protection Act vs GDPR: Side-by-Side Comparison

The following table highlights the core differences and overlaps between the DPA 2018 and the UK GDPR.

FeatureUK GDPRData Protection Act 2018
Type of lawRetained EU regulation (now UK statute)UK Act of Parliament
ScopeGeneral processing of personal dataGeneral processing + law enforcement + intelligence services
Core principlesDefines the 7 data protection principlesApplies UK GDPR principles and adds sector-specific rules
Data subject rightsAccess, rectification, erasure, portability, objection, etc.Mirrors UK GDPR rights, adds exemptions
Age of consent (online services)Baseline 16Lowered to 13 in the UK
Maximum fine£17.5m or 4% of global turnoverSame fines applied under UK GDPR framework
RegulatorInformation Commissioner's Office (ICO)Information Commissioner's Office (ICO)
International transfersGoverned by Chapter V and UK adequacy decisionsSupports UK GDPR transfer rules

The Seven Data Protection Principles

Both the UK GDPR and DPA 2018 revolve around seven core principles. These are the foundation of any compliance programme.

  1. Lawfulness, fairness and transparency — process data on a lawful basis and tell people what you're doing.
  2. Purpose limitation — collect data for specified, explicit purposes.
  3. Data minimisation — only collect what you actually need.
  4. Accuracy — keep personal data accurate and up to date.
  5. Storage limitation — don't keep data longer than necessary.
  6. Integrity and confidentiality — secure data against unauthorised access or loss.
  7. Accountability — be able to demonstrate compliance with all of the above.

Key Differences Between the DPA 2018 and UK GDPR

Although they work together, there are important distinctions worth understanding.

1. Scope of Processing Covered

The UK GDPR applies to most general processing by businesses, charities and public bodies. The DPA 2018 goes further — Part 3 governs processing by police and criminal justice bodies, and Part 4 covers intelligence services. If you're a private-sector business, most of your compliance work will sit under the UK GDPR and DPA 2018 Part 2.

2. National Exemptions

The DPA 2018 sets out numerous UK-specific exemptions that modify how the UK GDPR applies. Examples include:

  • Journalism, academic, artistic and literary expression
  • Crime prevention and taxation
  • Research, statistics and archiving in the public interest
  • Legal professional privilege
  • Confidential references

3. Age of Consent for Online Services

The EU GDPR set the default age of consent at 16, allowing member states to lower it to 13. The DPA 2018 uses that flexibility to set the UK threshold at 13, meaning children aged 13 and over can consent to information society services (like social media) without parental approval.

4. Criminal Offences

The DPA 2018 creates several criminal offences that don't sit in the UK GDPR itself, including knowingly or recklessly obtaining or disclosing personal data without consent, and re-identifying de-identified data.

5. International Data Transfers

Post-Brexit, the UK issues its own adequacy decisions. The EU currently recognises the UK as adequate, so data can flow both ways — but that adequacy is reviewed periodically and could change.

UK GDPR vs EU GDPR: A Common Point of Confusion

Many businesses ask whether the UK GDPR is the same as the EU GDPR. In practice, they are 95% identical, but there are meaningful differences:

AspectUK GDPREU GDPR
RegulatorICO onlyLead supervisory authority in the EU
Maximum fine£17.5m / 4% global turnover€20m / 4% global turnover
RepresentativesNon-UK controllers targeting UK must appoint a UK repNon-EU controllers targeting EU must appoint an EU rep
Adequacy decisionsIssued by UK governmentIssued by European Commission
Enforcement cooperationIndependent of EDPBCoordinated via EDPB one-stop-shop

If your business targets both UK and EU customers, you need to comply with both regimes — and potentially appoint representatives in both jurisdictions.

Who Needs to Comply?

You must comply with the UK GDPR and DPA 2018 if:

  • You are established in the UK and process personal data
  • You are outside the UK but offer goods or services to people in the UK
  • You are outside the UK but monitor the behaviour of people in the UK (e.g., through analytics, tracking pixels, or advertising cookies)

This scope catches almost every online business with UK customers, including SaaS providers, ecommerce shops, publishers, and even smaller operators using link tracking or email marketing tools.

Penalties and Enforcement

The ICO can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious breaches. Lower-tier infringements can result in fines of up to £8.7m or 2% of turnover.

But fines aren't the only risk. The ICO can also:

  • Issue enforcement notices requiring you to change practices
  • Issue reprimands (increasingly common in recent years)
  • Ban specific processing activities
  • Compel data subject access request (DSAR) compliance

Individuals also have the right to claim compensation for material and non-material damage, which has fuelled a growing volume of civil claims following data breaches.

Practical Compliance Steps for UK Businesses

Here's a practical checklist that aligns with both the DPA 2018 and UK GDPR.

  1. Map your data. Document what personal data you collect, why, where it's stored, and who has access.
  2. Establish lawful bases. For every processing activity, identify a lawful basis (consent, contract, legitimate interests, legal obligation, vital interests, or public task).
  3. Update privacy notices. Ensure they reflect UK GDPR requirements including retention periods, transfers, and rights.
  4. Implement security measures. Use encryption, access controls, secure hosting, and modern authentication.
  5. Manage data subject rights. Have a documented process for handling DSARs within one month.
  6. Sign data processing agreements. Every processor (analytics, email, hosting) needs a written contract.
  7. Assess international transfers. Use the UK's International Data Transfer Agreement (IDTA) or Addendum where needed.
  8. Train your team. Regular training is one of the ICO's expectations under the accountability principle.
  9. Prepare for breaches. You have 72 hours to report notifiable breaches to the ICO.
  10. Document everything. Accountability means being able to prove you did the work.

Data Protection in Everyday Marketing Tools

Marketers often overlook that even simple tools like link shorteners, email platforms and analytics dashboards process personal data. Click data tied to IP addresses, device fingerprints, or user identifiers falls squarely within the UK GDPR.

When choosing a link management tool, look for providers that minimise data collection, offer clear privacy documentation, and process data in appropriate jurisdictions. Privacy-focused shorteners like Lunyb can be a sensible choice for UK marketers who want branded links without shipping excessive click data to third parties — you can read more in our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.

For teams evaluating enterprise-grade alternatives, our Rebrandly review also covers how larger platforms handle data protection and processor obligations.

Special Categories of Data

Both the UK GDPR and DPA 2018 impose stricter rules on "special category" personal data, which includes:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data
  • Health data
  • Data concerning sex life or sexual orientation

To process these, you need both a UK GDPR Article 6 lawful basis and an Article 9 condition, which is often supplemented by a Schedule 1 condition under the DPA 2018.

The Data (Use and Access) Act and Future Reform

The UK government has been consulting on data protection reform for several years. The Data (Use and Access) Act 2025 introduced targeted reforms, including changes to cookie rules, automated decision-making, and research provisions. However, the core UK GDPR and DPA 2018 architecture remains intact.

For most businesses, the fundamentals of compliance haven't changed — lawful basis, transparency, security, and accountability remain non-negotiable.

Common Compliance Mistakes to Avoid

  • Assuming consent is always required. Legitimate interests or contract may be more appropriate.
  • Ignoring processor contracts. Every SaaS tool you use needs a data processing agreement.
  • Overlooking retention. Keeping data "just in case" breaches the storage limitation principle.
  • Weak DSAR processes. Missing the one-month deadline is a common ICO complaint.
  • Cookie banner theatre. Pre-ticked boxes and cookie walls are not valid consent.

FAQ

Is the UK GDPR the same as the EU GDPR?

They are very similar but not identical. The UK GDPR is the retained UK version of the EU GDPR, enforced by the ICO. Fines are in pounds, transfers are governed by UK adequacy decisions, and non-UK controllers targeting UK customers must appoint a UK representative rather than an EU one.

Do I need to comply with both the DPA 2018 and the UK GDPR?

Yes. The two work together. The UK GDPR sets out the main obligations, and the DPA 2018 provides UK-specific detail, exemptions, and criminal offences. Compliance means addressing both.

What's the maximum fine under UK data protection law?

The ICO can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious infringements such as breaching the core data protection principles or ignoring data subject rights.

Does the UK GDPR apply to businesses outside the UK?

Yes, if they offer goods or services to people in the UK or monitor their behaviour. Non-UK businesses that fall within scope generally need to appoint a UK representative under Article 27.

How long do I have to report a data breach?

You must report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it. If the breach poses a high risk to individuals, you also need to notify affected data subjects without undue delay.

Do link shorteners and analytics tools fall under UK GDPR?

Yes. If a tool processes IP addresses, device identifiers, or click behaviour tied to individuals, that's personal data. You need a lawful basis, transparent privacy information, and a data processing agreement with the provider.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles