UK Data Protection Act vs GDPR Explained: A Complete 2026 Guide
Since Brexit, businesses operating in the United Kingdom have faced a subtle but important question: which data protection law actually applies to them? The answer is rarely a simple choice between the UK Data Protection Act 2018 and the EU General Data Protection Regulation — in many cases, both apply simultaneously. This guide explains the relationship between these frameworks, highlights the practical differences, and sets out what UK organisations need to do to remain compliant in 2026.
What Is the UK Data Protection Act 2018?
The UK Data Protection Act 2018 (DPA 2018) is the United Kingdom's primary domestic data protection statute. It supplements the UK GDPR and covers areas that the GDPR left to individual member states, such as law enforcement processing, intelligence services, and specific exemptions relating to journalism, research, and national security.
The DPA 2018 originally implemented the EU GDPR into UK law before Brexit. After the UK left the European Union, the GDPR was retained in domestic legislation as the "UK GDPR", and the DPA 2018 was amended to work alongside it. Together, these two instruments form the backbone of UK data protection.
Key Components of the DPA 2018
- Part 2: Supplements the UK GDPR for general processing.
- Part 3: Governs processing by law enforcement bodies (the Law Enforcement Directive).
- Part 4: Covers processing by intelligence services (MI5, MI6, GCHQ).
- Schedules: Detail specific exemptions, lawful bases, and conditions for processing special category data.
What Is the GDPR?
The General Data Protection Regulation (EU) 2016/679 is a European Union regulation that took effect on 25 May 2018. It harmonises data protection law across all EU member states and applies extraterritorially to any organisation processing the personal data of EU residents, regardless of where that organisation is based.
The GDPR introduced sweeping changes to how personal data must be collected, stored, and processed. It elevated individual rights, established a strict accountability model, and empowered supervisory authorities to impose substantial fines. Following Brexit, the EU GDPR no longer directly applies to purely domestic UK activity, but it still applies to any UK organisation offering goods or services to individuals in the EU or monitoring their behaviour.
UK GDPR vs EU GDPR: The Critical Distinction
Before comparing the DPA 2018 to the GDPR, it is essential to understand that "UK GDPR" and "EU GDPR" are now two separate legal instruments, although they remain almost identical in substance.
- UK GDPR: The retained version of the GDPR, incorporated into UK law and enforced by the Information Commissioner's Office (ICO).
- EU GDPR: The original EU regulation, enforced by data protection authorities across the 27 EU member states plus the European Data Protection Board.
A UK-based e-commerce site selling to customers in Germany, for example, must comply with both frameworks. If it also handles employee data in Britain, the DPA 2018 layers on additional national-specific rules.
Key Differences Between the DPA 2018 and GDPR
While the DPA 2018 and UK GDPR are designed to work in tandem, they serve different purposes. The table below summarises the most significant contrasts.
| Aspect | DPA 2018 | UK GDPR / EU GDPR |
|---|---|---|
| Legal type | Act of the UK Parliament | Regulation (retained EU law in UK) |
| Primary role | Supplements GDPR; covers gaps | Sets the core data protection framework |
| Territorial scope | UK only | UK GDPR: UK; EU GDPR: EU/EEA + extraterritorial |
| Regulator | Information Commissioner's Office (ICO) | ICO (UK GDPR); national DPAs (EU GDPR) |
| Maximum fine | £17.5 million or 4% of global turnover | €20 million or 4% of global turnover |
| Law enforcement processing | Yes (Part 3) | Not covered directly |
| Intelligence services | Yes (Part 4) | Not covered |
| Age of consent for online services | 13 | 16 (EU default; member states can lower to 13) |
| National security exemptions | Broader | Limited |
1. Age of Consent for Digital Services
One of the most cited differences is the age at which a child can consent to online services without parental approval. The UK, through the DPA 2018, set this at 13. The EU GDPR defaults to 16 but permits member states to lower the threshold to as low as 13. Businesses offering services to children across borders must design consent flows carefully.
2. Exemptions and Derogations
The DPA 2018 exercises many of the derogations left open by the GDPR. These include exemptions for journalism, academic research, statutory functions, and immigration control. The immigration exemption in particular has been controversial and was partially struck down by the Court of Appeal in 2021 before being redrafted.
3. Enforcement and Fines
Both frameworks share a two-tier fine structure. Lower-tier infringements can attract fines of up to £8.7 million or 2% of global turnover (UK), or €10 million / 2% (EU). Higher-tier breaches — such as violating data subject rights or international transfer rules — can reach £17.5 million or 4% of turnover (UK), matching the EU's €20 million ceiling.
4. International Data Transfers
Post-Brexit, transfers of personal data between the UK and EU rely on an EU adequacy decision granted in June 2021 and renewed in 2025. Transfers to third countries must use approved safeguards such as the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or Binding Corporate Rules.
What Do UK Organisations Actually Need to Comply With?
For most UK-based businesses, the practical compliance stack looks like this:
- UK GDPR — the primary rulebook for processing personal data in the UK.
- DPA 2018 — fills in the gaps, particularly for special categories, criminal data, exemptions, and public bodies.
- Privacy and Electronic Communications Regulations (PECR) — governs cookies, marketing emails, and electronic communications.
- EU GDPR — applies if the organisation targets or monitors individuals in the EU.
Core Compliance Obligations
- Identify a lawful basis for every processing activity (consent, contract, legal obligation, vital interests, public task, legitimate interests).
- Maintain a Record of Processing Activities (ROPA) under Article 30.
- Provide clear, layered privacy notices at the point of data collection.
- Honour data subject rights within one month: access, rectification, erasure, restriction, portability, and objection.
- Report qualifying personal data breaches to the ICO within 72 hours.
- Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing.
- Appoint a Data Protection Officer where required (public authorities, large-scale monitoring, or large-scale processing of special categories).
The Data (Use and Access) Act 2025: What Is Changing?
In 2025, the UK enacted the Data (Use and Access) Act, which introduced targeted reforms to the UK GDPR and DPA 2018. The reforms aim to reduce compliance burdens while preserving the EU adequacy decision. Key changes include:
- A revised approach to legitimate interests, including a list of "recognised legitimate interests" that do not require a balancing test.
- Streamlined rules for scientific research and reuse of data.
- Reforms to automated decision-making rules, expanding permissible uses outside special category data.
- A new Information Commission replacing the ICO with a board-led governance model.
- Changes to cookie rules under PECR, permitting certain low-risk cookies without consent.
Despite these reforms, the fundamentals of the UK GDPR remain intact, and organisations already compliant with the previous framework will not need to overhaul their programmes.
Practical Impact on Websites and Link Sharing
Any UK organisation that operates a website, sends marketing emails, or shares tracked links must consider how personal data flows through those channels. Even something as simple as a shortened URL can capture IP addresses, referrers, device metadata, and location signals — all of which are personal data under both the DPA 2018 and UK GDPR.
Choosing tools that respect privacy by design is therefore a compliance decision, not just a technical one. Privacy-focused link management platforms such as Lunyb allow UK businesses to shorten and track links without imposing aggressive fingerprinting or third-party tracking on end users. For more context, see our honest review of Lunyb and our broader 2026 URL shortener buyer's guide.
Common Compliance Mistakes to Avoid
- Treating consent as a default lawful basis. Legitimate interests or contract may be more appropriate and less fragile.
- Ignoring PECR. Cookies and marketing emails have separate consent rules that sit on top of the UK GDPR.
- Assuming Brexit ended EU GDPR obligations. If you have EU customers, you almost certainly still need to comply with the EU GDPR and may need an EU representative under Article 27.
- Neglecting vendor due diligence. Article 28 requires written data processing agreements with every processor, including analytics providers, hosting companies, and link tracking services.
- Missing the 72-hour breach notification window. Have an incident response plan drafted before you need it.
How to Build a Compliance Roadmap
- Map your data. Document what personal data you hold, where it lives, and who has access.
- Assess your lawful bases. For each processing activity, identify and document the appropriate Article 6 (and Article 9, if applicable) basis.
- Update policies. Refresh privacy notices, cookie banners, retention schedules, and internal data handling policies.
- Train staff. Human error is the leading cause of breaches. Annual training with role-specific modules is essential.
- Review vendors. Confirm every processor has a signed Data Processing Agreement and adequate security measures.
- Test rights procedures. Run a mock subject access request to ensure you can respond within one month.
- Prepare for breaches. Draft an incident response playbook covering detection, containment, notification, and post-incident review.
FAQ
Is the UK still subject to GDPR after Brexit?
Yes. The UK retained the GDPR in domestic law as the UK GDPR. Additionally, any UK organisation offering goods or services to individuals in the EU, or monitoring their behaviour, must also comply with the EU GDPR.
What is the difference between the DPA 2018 and the UK GDPR?
The UK GDPR sets the core rules for personal data processing, while the DPA 2018 supplements it by covering areas the GDPR leaves to national law — such as law enforcement processing, intelligence services, exemptions, and the age of digital consent.
What are the maximum fines under the DPA 2018?
The DPA 2018 and UK GDPR share a two-tier structure. The higher tier reaches £17.5 million or 4% of worldwide annual turnover, whichever is greater. The lower tier is £8.7 million or 2% of global turnover.
Do small businesses in the UK need to comply?
Yes. Both the UK GDPR and DPA 2018 apply regardless of business size. However, smaller organisations may benefit from lighter obligations, such as exemptions from maintaining a full Record of Processing Activities under certain conditions, and reduced fees payable to the ICO.
How did the Data (Use and Access) Act 2025 change things?
The 2025 Act introduced targeted reforms including recognised legitimate interests, updates to automated decision-making rules, changes to cookie consent under PECR, and the creation of a new Information Commission. It did not fundamentally alter the UK GDPR framework, and the EU adequacy decision remains in place.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued some of its largest data protection fines to date in 2026, targeting healthcare providers, retailers, councils and marketers. This guide breaks down each major penalty and explains how UK organisations can avoid becoming the next headline.
PIPEDA vs GDPR: Canadian Privacy Law Explained
PIPEDA and GDPR both protect personal data, but they differ sharply in scope, consent rules, penalties, and enforcement. This guide breaks down the key differences and shows Canadian businesses how to build one privacy program that satisfies both laws.
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives people in Ireland powerful rights over their personal data, from access and erasure to complaints against major tech firms. This guide explains those rights, how to enforce them through the DPC, and practical steps to protect your privacy every day.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a layered privacy landscape spanning PIPEDA, Quebec's Law 25, and provincial laws. This guide breaks down consent, breach response, cross-border transfers, and practical safeguards every organization needs in 2026.