facebook-pixel

UK Data Protection Act vs GDPR Explained: Key Differences in 2026

L
Lunyb Security Team
··10 min read

Since Brexit, businesses operating in the United Kingdom have had to navigate two closely related but distinct data protection regimes: the UK Data Protection Act 2018 (DPA 2018) and the EU General Data Protection Regulation (GDPR). While the two frameworks share a common heritage and much of their substance, there are important legal, territorial, and operational differences that every data controller, marketer, and IT decision-maker should understand.

This guide breaks down the UK Data Protection Act vs GDPR debate in plain English, explaining what each law covers, how they interact, and what UK organisations need to do to stay compliant in 2026.

What Is the UK Data Protection Act 2018?

The UK Data Protection Act 2018 is the United Kingdom's principal data protection statute. It sets out how personal data must be collected, stored, processed, and shared by organisations operating in the UK, and it works alongside the UK GDPR to form the country's post-Brexit data protection framework.

The DPA 2018 replaced the older Data Protection Act 1998 and originally came into force to supplement the EU GDPR while the UK was still an EU member state. It covers areas that the GDPR left to individual member states, such as:

  • Law enforcement processing (Part 3)
  • Intelligence services processing (Part 4)
  • National security exemptions
  • Age thresholds for children's consent (set at 13 in the UK)
  • Special categories of data and criminal offence data rules

What Is the GDPR?

The General Data Protection Regulation (EU) 2016/679 is a European Union regulation that came into effect on 25 May 2018. It harmonises data protection law across all EU member states and applies extraterritorially to any organisation, anywhere in the world, that offers goods or services to EU residents or monitors their behaviour.

After Brexit, the EU GDPR was retained in UK law as the UK GDPR, which is a near-identical version tailored for domestic use. The EU GDPR still applies directly to UK businesses that process the personal data of individuals located in the EU.

Two GDPRs, One Framework

It's important to distinguish between:

  • EU GDPR — the original regulation, enforced by EU data protection authorities.
  • UK GDPR — the retained UK version, enforced by the Information Commissioner's Office (ICO).

The DPA 2018 sits alongside the UK GDPR and provides the operational detail the regulation refers to.

UK Data Protection Act vs GDPR: The Core Differences

At a high level, the DPA 2018 and the EU GDPR are around 95% aligned. The real differences appear in territorial scope, enforcement, national derogations, and a handful of specific rules. The table below summarises the key contrasts.

Feature UK Data Protection Act 2018 (+ UK GDPR) EU GDPR
Territorial scope United Kingdom European Economic Area (EEA) + extraterritorial reach
Regulator Information Commissioner's Office (ICO) National DPAs (e.g. CNIL, DPC) coordinated by the EDPB
Maximum fine £17.5 million or 4% of global turnover €20 million or 4% of global turnover
Children's consent age 13 years old 16 years old (member states can lower to 13)
Law enforcement processing Covered in Part 3 of DPA 2018 Covered by separate Law Enforcement Directive
Intelligence services Covered in Part 4 of DPA 2018 Outside GDPR scope
International transfers UK adequacy decisions + UK IDTA / UK Addendum to SCCs EU adequacy decisions + Standard Contractual Clauses (SCCs)
Representative requirement UK representative for non-UK controllers targeting UK EU representative for non-EU controllers targeting EU

How the Two Laws Work Together

For most UK-based organisations, the DPA 2018 and UK GDPR are read as a single package. The UK GDPR sets the principles, rights, and obligations; the DPA 2018 fills in the national detail, exemptions, and enforcement mechanisms.

A UK business that also serves EU customers has to comply with both regimes:

  1. The UK GDPR + DPA 2018 for personal data of individuals in the UK.
  2. The EU GDPR for personal data of individuals in the EU/EEA.

In practice, most compliance programmes are designed to meet whichever standard is stricter on a given issue, which usually means a single unified policy works for both.

Key Principles Shared by the DPA 2018 and GDPR

Both the DPA 2018 and the GDPR are built on seven data protection principles. Any organisation processing personal data must be able to demonstrate compliance with all of them.

  1. Lawfulness, fairness and transparency — Have a valid legal basis and be open about processing.
  2. Purpose limitation — Collect data for specified, explicit, and legitimate purposes.
  3. Data minimisation — Only collect what you actually need.
  4. Accuracy — Keep personal data up to date.
  5. Storage limitation — Don't keep data longer than necessary.
  6. Integrity and confidentiality — Protect data with appropriate security.
  7. Accountability — Be able to prove compliance with the above.

Individual Rights Under Both Regimes

The rights of data subjects are almost identical under the UK DPA/UK GDPR and the EU GDPR. UK residents and EU residents both benefit from:

  • The right to be informed
  • The right of access (subject access requests)
  • The right to rectification
  • The right to erasure ("right to be forgotten")
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights related to automated decision-making and profiling

The DPA 2018 does introduce some UK-specific exemptions — for example, around journalism, national security, and immigration — that allow controllers to refuse or limit certain requests in defined circumstances.

International Data Transfers After Brexit

One of the biggest practical differences between the UK and EU regimes lies in how international data transfers are handled.

UK Transfers

The UK operates its own list of "adequate" jurisdictions and provides two main transfer tools:

  • The UK International Data Transfer Agreement (IDTA)
  • The UK Addendum to the EU Standard Contractual Clauses

EU Transfers

The EU uses its own adequacy decisions, Standard Contractual Clauses (SCCs), and Binding Corporate Rules. Notably, the EU currently considers the UK an "adequate" jurisdiction, meaning personal data can flow freely from the EU to the UK — but this adequacy decision is reviewed periodically.

If you share short links, analytics, or customer data across borders — for instance using a link management tool — always check where that provider stores and processes data. Privacy-focused platforms like Lunyb are useful here because they minimise the personal data attached to shortened URLs, reducing your cross-border transfer footprint. You can read our honest review of Lunyb for more detail.

Enforcement and Penalties

Enforcement is where the two regimes clearly diverge in practice, even if the rules on paper look similar.

ICO (United Kingdom)

The Information Commissioner's Office enforces the DPA 2018 and UK GDPR. Maximum fines are:

  • Standard maximum: £8.7 million or 2% of global annual turnover
  • Higher maximum: £17.5 million or 4% of global annual turnover

The ICO tends to favour engagement, guidance, and reprimands before moving to financial penalties, though large fines have been issued in high-profile breach cases.

EU Data Protection Authorities

Under the EU GDPR, each member state has its own supervisory authority. Fines can reach €20 million or 4% of global turnover, and enforcement across the EU has generally been more aggressive, particularly by authorities in Ireland, France, and Italy.

Which Law Applies to Your Business?

Working out which regime you fall under isn't always obvious. Use this quick decision guide:

  1. Are you established in the UK? → UK GDPR + DPA 2018 apply.
  2. Do you offer goods or services to people in the UK, or monitor their behaviour? → UK GDPR + DPA 2018 apply, even if you're based abroad.
  3. Are you established in the EU/EEA? → EU GDPR applies.
  4. Do you offer goods or services to people in the EU/EEA, or monitor their behaviour? → EU GDPR applies, even if you're based in the UK or elsewhere.

Many UK SMEs will find that both regimes apply if they have any EU customers, website visitors targeted by EU-facing marketing, or EU-based employees.

Practical Compliance Checklist for UK Businesses

Whether you fall under the DPA 2018, EU GDPR, or both, the operational steps are broadly the same. Here's a compliance checklist tailored for UK organisations in 2026:

  1. Map your data — Know what personal data you hold, where it comes from, and where it goes.
  2. Identify legal bases — Assign a lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) to every processing activity.
  3. Update privacy notices — Ensure they reflect both the UK GDPR and, where relevant, the EU GDPR.
  4. Review third-party processors — Sign data processing agreements (DPAs) with all vendors, including analytics, email, and link management tools.
  5. Handle international transfers correctly — Use the UK IDTA, UK Addendum, or EU SCCs as appropriate.
  6. Prepare for data subject requests — Have processes to respond within one month.
  7. Implement security controls — Encryption, access management, secure backups, and staff training.
  8. Report breaches within 72 hours — Both regimes require notification to the relevant regulator.
  9. Appoint a DPO if required — Mandatory for public authorities and large-scale processors of sensitive data.
  10. Document everything — Accountability requires evidence, not just intent.

Common Misconceptions

"Brexit Means GDPR Doesn't Apply Anymore"

False. The UK GDPR is essentially the EU GDPR retained in UK law. And if you serve EU customers, the EU GDPR still applies to you directly.

"The DPA 2018 Replaced the GDPR in the UK"

Also false. The DPA 2018 supplements the UK GDPR — it doesn't replace it. They work together.

"Small Businesses Are Exempt"

Neither regime has a general small-business exemption. Some record-keeping obligations are lighter for organisations under 250 employees, but the core rules still apply.

How URL Shorteners and Link Tools Fit In

If your business uses link shorteners for marketing, analytics, or customer communication, remember that click data, IP addresses, and device information can qualify as personal data. Choosing a provider that offers strong privacy defaults, transparent data handling, and UK/EU-friendly hosting can materially reduce your compliance burden.

For a broader look at how different providers stack up on privacy and features, see our 2026 buyer's guide to the best URL shorteners and our detailed Rebrandly review.

FAQ: UK Data Protection Act vs GDPR

1. Is the UK GDPR the same as the EU GDPR?

They are almost identical in substance but legally distinct. The UK GDPR is the retained version of the EU regulation, adapted for UK law and enforced by the ICO. The EU GDPR is enforced by member state authorities and applies to organisations targeting the EU.

2. Does the Data Protection Act 2018 replace the GDPR in the UK?

No. The DPA 2018 works alongside the UK GDPR, providing national detail, exemptions, and rules for areas like law enforcement and intelligence services processing that the GDPR does not cover.

3. What is the maximum fine under the UK Data Protection Act 2018?

The maximum fine is £17.5 million or 4% of a company's global annual turnover, whichever is higher. Lesser breaches carry a maximum of £8.7 million or 2% of turnover.

4. Do I need to comply with both UK and EU GDPR?

If your organisation processes personal data of individuals in both the UK and the EU/EEA, then yes. Most businesses design a single compliance programme that meets the stricter of the two standards on each issue.

5. What age is a child considered able to consent under UK data protection law?

Under the UK GDPR and DPA 2018, children aged 13 and over can provide their own consent for online services. Under the EU GDPR, the default age is 16, though member states may lower it to 13.

Final Thoughts

The UK Data Protection Act 2018 and the GDPR are not competing frameworks — they're two overlapping layers of the same broader system. For most UK businesses in 2026, compliance is less about choosing between them and more about building a mature, well-documented data protection programme that respects the rights of individuals, wherever they live.

Get the fundamentals right — clear legal bases, minimised data collection, strong security, transparent notices, and reliable vendor management — and you'll be well positioned to meet the requirements of both the UK and EU regimes without duplicating effort.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles