UK Data Protection Act vs GDPR Explained: Key Differences in 2026
Since Brexit, UK businesses have had to navigate two closely related but legally distinct data protection frameworks: the UK Data Protection Act 2018 (DPA 2018) and the General Data Protection Regulation (GDPR). Although they share the same DNA, they diverge in scope, enforcement authority, and certain operational rules. This guide breaks down the UK Data Protection Act vs GDPR in plain English, so you can understand what applies to your organisation and how to stay compliant in 2026.
What Is the UK Data Protection Act 2018?
The UK Data Protection Act 2018 is the primary piece of UK legislation governing how personal data is processed. It came into force on 25 May 2018 to sit alongside the EU GDPR, filling in national derogations (areas where the EU allowed member states to set their own rules) and covering domains outside GDPR's scope, such as law enforcement processing and national security.
The DPA 2018 has four main parts relevant to most organisations:
- Part 2 – General processing, which supplements the UK GDPR.
- Part 3 – Law enforcement processing.
- Part 4 – Intelligence services processing.
- Part 5 – The Information Commissioner's role and enforcement powers.
After Brexit, the UK also created the UK GDPR, a domesticated version of the EU GDPR retained in UK law. The DPA 2018 and UK GDPR now work together as the country's core data protection framework.
What Is the GDPR?
The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's flagship data protection law, enforceable since 25 May 2018. It sets a harmonised standard for how personal data must be collected, stored, processed, and shared across all 27 EU member states, plus the EEA countries of Norway, Iceland, and Liechtenstein.
The GDPR is built on seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. These principles remain identical in both the EU GDPR and the UK GDPR.
UK Data Protection Act vs GDPR: The Core Difference
The simplest way to think about it: the UK GDPR sets out the main rules, while the DPA 2018 tailors those rules for the UK context and extends them into areas GDPR does not cover. The EU GDPR, meanwhile, is a separate law enforced by EU supervisory authorities and can still apply to UK businesses that offer goods or services to EU residents.
Here is a side-by-side comparison of the three overlapping instruments:
| Feature | EU GDPR | UK GDPR | UK Data Protection Act 2018 |
|---|---|---|---|
| Jurisdiction | EU / EEA | United Kingdom | United Kingdom |
| Regulator | National DPAs (e.g. CNIL, DPC) | Information Commissioner's Office (ICO) | Information Commissioner's Office (ICO) |
| Maximum fine | €20 million or 4% global turnover | £17.5 million or 4% global turnover | Aligned with UK GDPR |
| Age of consent (children) | 16 (member states may lower to 13) | 13 | 13 (set by DPA 2018) |
| Covers law enforcement? | No (separate LED directive) | No | Yes (Part 3) |
| Covers intelligence services? | No | No | Yes (Part 4) |
Key Similarities Between the DPA 2018 and GDPR
Because the UK GDPR was copied and pasted from the EU GDPR at the point of Brexit, the two share far more in common than they differ. Understanding the shared foundations helps you avoid duplicating compliance work.
1. Same Core Principles
Both regimes require organisations to process personal data lawfully, fairly, and transparently, and to hold themselves accountable. The six lawful bases for processing – consent, contract, legal obligation, vital interests, public task, and legitimate interests – are identical.
2. Same Individual Rights
Data subjects have the same eight rights under both frameworks: the right to be informed, access, rectification, erasure, restrict processing, data portability, object, and rights related to automated decision-making.
3. Similar Breach Notification Rules
Both require notifiable personal data breaches to be reported to the relevant regulator within 72 hours of the controller becoming aware of them.
4. Similar Documentation Duties
Records of processing activities (ROPAs), data protection impact assessments (DPIAs), and appointing a Data Protection Officer where required apply under both.
Key Differences Between the UK DPA and EU GDPR
While the frameworks are aligned, several practical differences matter if you operate across the UK and EU.
1. Regulator and Enforcement
UK organisations are supervised by the Information Commissioner's Office (ICO). Businesses operating in the EU may face several supervisory authorities and must identify a lead supervisor under the one-stop-shop mechanism – something the UK no longer participates in.
2. Fines Denominated Differently
EU GDPR fines are capped at €20 million or 4% of global annual turnover, whichever is higher. UK GDPR mirrors this but converts the ceiling to £17.5 million.
3. Children's Consent Age
The UK sets the age at which a child can consent to information society services at 13. EU member states set their own age between 13 and 16 – for example, Germany uses 16 while Ireland uses 16 and Spain uses 14.
4. International Data Transfers
After Brexit, the EU adopted an adequacy decision for the UK in June 2021, allowing personal data to flow freely from the EEA to the UK. That decision is subject to review and could be revoked if UK data protection standards diverge too far. Transfers from the UK to third countries follow the UK's own adequacy list, which currently mirrors the EU's but is maintained independently.
5. National Security and Immigration Exemptions
The DPA 2018 includes broader exemptions for immigration control and national security than the EU GDPR permits – a point of friction that has been challenged in UK courts.
6. Representative Requirements
Non-UK organisations targeting UK residents must appoint a UK representative under the UK GDPR. Non-EU organisations targeting EU residents must appoint an EU representative under the EU GDPR. Many businesses now need both.
Which Law Applies to Your Business?
The territorial scope test determines which regime applies. It is entirely possible – and common – for a single organisation to be subject to both the UK GDPR and the EU GDPR simultaneously.
- UK GDPR + DPA 2018 applies if you are established in the UK, or if you offer goods/services to or monitor the behaviour of individuals in the UK.
- EU GDPR applies if you are established in the EU/EEA, or if you offer goods/services to or monitor individuals in the EU/EEA.
- Both apply if you operate across both jurisdictions – for example, a UK ecommerce store shipping to Ireland and France.
Practical Compliance Steps for UK Businesses in 2026
Meeting your obligations under the UK Data Protection Act and UK GDPR does not need to be overwhelming. Focus on the fundamentals first.
1. Map Your Data
Document what personal data you collect, why, where it is stored, who has access, and when it is deleted. This forms your Record of Processing Activities.
2. Update Privacy Notices
Ensure your privacy policy references the UK GDPR and DPA 2018, names the ICO as the supervisory authority, and provides a UK postal address for data subject requests.
3. Review Lawful Bases
For every processing activity, confirm which of the six lawful bases you rely on. If you rely on consent, ensure it is freely given, specific, informed, and unambiguous.
4. Secure Your Links and Analytics
Shortened URLs, tracking pixels, and referral links often collect IP addresses and device information, which count as personal data. Choose privacy-respecting tools – for example, Lunyb is a URL shortener that offers analytics without excessive third-party tracking, which supports data minimisation duties. See our honest Lunyb review or compare options in our 2026 buyer's guide to URL shorteners.
5. Handle International Transfers Properly
Use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses for transfers outside the UK's adequacy list.
6. Train Staff and Log Breaches
Human error causes the majority of reportable breaches. Regular training and a clear internal incident response process are essential.
Enforcement Trends and Penalties
The ICO has taken a more measured approach than several EU regulators, often favouring reprimands and enforcement notices over headline fines. However, significant penalties have still been issued – British Airways (£20m), Marriott (£18.4m), and TikTok (£12.7m for children's data violations) are recent examples.
Common causes of enforcement action include:
- Inadequate security controls leading to data breaches.
- Unlawful marketing communications under PECR (which sits alongside the DPA 2018).
- Failure to respond to subject access requests within one month.
- Improper use of children's data.
- Excessive or unclear cookie tracking.
The Data (Use and Access) Act and Future Reform
In 2025, the UK passed the Data (Use and Access) Act, which amends parts of the UK GDPR and DPA 2018. Key changes include streamlined rules for scientific research, adjustments to automated decision-making, and reforms to the ICO's governance (renaming it the Information Commission). These changes are being phased in throughout 2026, so organisations should monitor ICO guidance closely to avoid falling behind.
The reforms aim to reduce compliance burden without breaking the EU adequacy decision – a delicate balancing act that will shape UK data protection for the rest of the decade.
Summary: UK DPA vs GDPR at a Glance
- The UK GDPR is the main rulebook; the DPA 2018 tailors and extends it.
- The EU GDPR is a separate law that can still apply to UK organisations serving EU customers.
- Core principles, individual rights, and breach rules are nearly identical.
- Differences include the regulator, fine currency, child consent age, and national security exemptions.
- Many UK businesses must comply with both frameworks in parallel.
Frequently Asked Questions
Is the UK still under GDPR after Brexit?
Yes. The UK retained GDPR in domestic law as the UK GDPR, which works alongside the Data Protection Act 2018. The EU GDPR no longer applies directly in the UK but can still reach UK businesses that target EU customers.
What is the difference between the DPA 2018 and the UK GDPR?
The UK GDPR sets out the main data protection rules, while the DPA 2018 fills in national details (like the child consent age of 13), governs law enforcement and intelligence processing, and grants the ICO its enforcement powers. The two are designed to be read together.
Do I need to comply with both the UK GDPR and EU GDPR?
If your organisation offers goods or services to, or monitors the behaviour of, individuals in both the UK and the EU/EEA, then yes – both apply. You may also need to appoint separate UK and EU representatives if you have no establishment in either territory.
What are the maximum fines under the UK Data Protection Act?
The maximum fine under the UK GDPR and DPA 2018 is £17.5 million or 4% of global annual turnover, whichever is higher. Lower-tier infringements are capped at £8.7 million or 2% of turnover.
Does the UK Data Protection Act cover cookies?
Cookies are primarily regulated by the Privacy and Electronic Communications Regulations (PECR), which sit alongside the DPA 2018 and UK GDPR. Cookie consent standards, however, are drawn from the UK GDPR definition of consent, so the three regimes work together.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR share common ground but differ in scope, consent rules, breach timelines, and penalties. This guide breaks down the key differences and shows Singapore businesses how to build a single, unified compliance strategy that satisfies both regimes.
PIPEDA vs GDPR: Canadian Privacy Law Explained for 2026
PIPEDA and GDPR both protect personal data, but they differ significantly in consent rules, fines, and individual rights. This guide compares the two frameworks and explains what Canadian businesses need to know in 2026.
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes how platforms handle content, age checks, and encrypted messages — with real consequences for your privacy. Here's what the law actually requires in 2026, how it affects your data, and the practical steps you can take to stay in control.
GDPR in Ireland: Your Privacy Rights Explained
A clear, practical guide to your GDPR rights in Ireland—covering the eight core rights, how to exercise them, how to complain to the Data Protection Commission, and what businesses must do to comply.