facebook-pixel

UK Data Protection Act vs GDPR Explained: A 2026 Compliance Guide

L
Lunyb Security Team
··10 min read

Since Brexit, UK organisations have had to navigate two closely related but distinct privacy frameworks: the UK Data Protection Act 2018 (DPA 2018) and the EU General Data Protection Regulation (GDPR). Although they share the same DNA, the differences matter — especially if you handle data belonging to UK residents, EU citizens, or both. This guide breaks down how these laws compare in 2026, what has changed, and what businesses actually need to do to stay compliant.

What Is the UK Data Protection Act 2018?

The UK Data Protection Act 2018 is the primary piece of legislation governing how personal data is processed in the United Kingdom. It works alongside the UK GDPR — a domesticated version of the EU regulation that was retained in UK law after Brexit.

The DPA 2018 does three main things:

  1. It supplements and tailors the UK GDPR for domestic use.
  2. It applies data protection standards to areas outside EU competence, such as immigration and national security.
  3. It implements the Law Enforcement Directive for police and criminal justice processing.

The Act is enforced by the Information Commissioner's Office (ICO), which acts as the UK's independent data protection regulator.

What Is the GDPR?

The General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's comprehensive data privacy law, in force since May 2018. It applies directly across all EU/EEA member states and governs how organisations collect, store, share, and secure personal data belonging to individuals in the EU.

The GDPR introduced landmark principles that reshaped global privacy expectations, including lawful basis for processing, data subject rights, breach notification within 72 hours, and mandatory Data Protection Officers (DPOs) for certain organisations.

UK Data Protection Act vs GDPR: The Core Differences

At first glance, the DPA 2018 and the EU GDPR look almost identical — because the UK GDPR was deliberately copy-pasted from the EU version at the point of Brexit. However, several practical differences have emerged, and they are widening as UK legislation evolves.

1. Jurisdiction and Territorial Scope

The EU GDPR applies to organisations established in the EU/EEA, and to non-EU organisations that offer goods or services to, or monitor the behaviour of, individuals in the EU.

The UK DPA 2018 / UK GDPR applies to organisations established in the UK and to those outside the UK that target UK residents. A business selling to customers in both London and Paris typically has to comply with both regimes.

2. Regulatory Authority

Under the EU GDPR, enforcement is handled by national supervisory authorities (such as the CNIL in France or Ireland's DPC), coordinated via the European Data Protection Board (EDPB).

Under the DPA 2018, the sole regulator is the ICO. UK organisations no longer benefit from the EU's "one-stop shop" mechanism, meaning a UK company operating across Europe may need to deal with multiple regulators.

3. Maximum Fines

Both regimes impose severe financial penalties, but the currencies and caps differ slightly.

AspectUK DPA 2018 / UK GDPREU GDPR
Maximum fine (higher tier)£17.5 million or 4% of global turnover€20 million or 4% of global turnover
Maximum fine (lower tier)£8.7 million or 2% of global turnover€10 million or 2% of global turnover
RegulatorICONational DPAs + EDPB
AppealsFirst-tier Tribunal (UK)National courts / CJEU

4. International Data Transfers

The EU has granted the UK an adequacy decision, meaning data can flow freely from the EU to the UK. This decision is subject to periodic review and was reaffirmed in 2025 with an extension into the late 2020s.

For transfers out of the UK to third countries, the UK uses its own International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs). These are separate documents from the EU's SCCs.

5. Data Protection Officers (DPOs)

Both regimes require certain organisations to appoint a DPO. However, upcoming UK reforms under the Data (Use and Access) Act — building on earlier Data Protection and Digital Information Bill proposals — may replace the DPO with a more flexible "Senior Responsible Individual" role for UK-only organisations. EU-facing businesses will still need a traditional DPO under EU GDPR rules.

6. Age of Consent for Children

The GDPR sets the default digital age of consent at 16, but allows member states to lower it to 13. The UK sets this age at 13, whereas countries like Germany maintain 16. If your service targets minors, you need to apply the correct threshold per jurisdiction.

7. National Security and Immigration Exemptions

The DPA 2018 includes specific exemptions relating to immigration control and national security that are not mirrored in the EU GDPR. Some of these exemptions have been challenged in UK courts, leading to partial revisions in recent years.

What They Have in Common

Despite the divergence, the core principles remain shared. Both the UK DPA 2018 and the EU GDPR require organisations to:

  • Process personal data lawfully, fairly, and transparently.
  • Collect data for specified, explicit, and legitimate purposes.
  • Ensure data is accurate, minimised, and stored no longer than necessary.
  • Maintain appropriate security using technical and organisational measures.
  • Uphold data subject rights — access, rectification, erasure, portability, objection, and restriction.
  • Report personal data breaches within 72 hours where they pose a risk to individuals.
  • Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing.

Data Subject Rights Under Both Regimes

Individuals — referred to as "data subjects" — have effectively the same eight rights under both regimes:

  1. Right to be informed — clear privacy notices.
  2. Right of access — subject access requests (SARs).
  3. Right to rectification — correcting inaccurate data.
  4. Right to erasure — the "right to be forgotten".
  5. Right to restrict processing.
  6. Right to data portability.
  7. Right to object — particularly to direct marketing.
  8. Rights related to automated decision-making and profiling.

The UK is exploring reforms that would make SARs easier for businesses to refuse if they are "vexatious or excessive", a slightly looser standard than the EU's "manifestly unfounded" test.

Practical Compliance: What UK Businesses Should Do

If your organisation processes personal data of UK residents, EU residents, or both, follow this compliance workflow:

  1. Map your data. Document what personal data you collect, where it comes from, where it is stored, who accesses it, and where it goes.
  2. Identify your lawful bases. Every processing activity needs one of the six lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests).
  3. Update privacy notices. Ensure they meet Articles 13 and 14 requirements, referencing both UK GDPR and EU GDPR where applicable.
  4. Review transfers. Use the IDTA or UK Addendum for transfers out of the UK, and SCCs for transfers out of the EU.
  5. Appoint responsible roles. A DPO if required, plus a UK/EU representative if you are based outside those jurisdictions but target them.
  6. Test breach response. Run tabletop exercises to ensure you can notify the ICO within 72 hours.
  7. Train staff. The vast majority of ICO fines involve human error or poor internal procedures.

Common Compliance Pitfalls

The ICO's public enforcement records highlight recurring mistakes UK businesses make:

  • Sending marketing emails without valid consent under PECR (Privacy and Electronic Communications Regulations), which sits alongside the DPA 2018.
  • Sharing personal data via unsecured links — a surprisingly frequent cause of breaches. When distributing links containing sensitive tokens or personal identifiers, use a reputable link platform with HTTPS, access controls, and analytics. A privacy-focused shortener like Lunyb can help teams manage link expiry and reduce exposure of long, sensitive URLs.
  • Ignoring subject access requests or missing the one-month deadline.
  • Failing to conduct DPIAs before launching new tracking, AI, or profiling systems.
  • Poor cookie consent implementations that pre-tick boxes or bury reject options.

UK Reform: The Data (Use and Access) Act

The UK has been steadily reforming its data protection landscape. The Data (Use and Access) Act 2025 introduces targeted changes rather than a wholesale rewrite. Key adjustments include:

  • Streamlined rules for legitimate interests, with a list of "recognised" legitimate interests that do not require a balancing test.
  • Clarified rules on automated decision-making, particularly for AI systems.
  • Reformed cookie rules, allowing certain low-risk cookies (like analytics) without explicit consent.
  • A refreshed ICO governance structure, renaming it the Information Commission with a board and chair.

Critically, these reforms are designed to preserve the UK's EU adequacy status — so divergence is intentionally modest.

Do You Need to Comply With Both?

Many UK organisations must comply with both regimes simultaneously. You fall under the EU GDPR in addition to the UK DPA 2018 if you:

  • Have an establishment (office, subsidiary) in the EU/EEA.
  • Offer goods or services to individuals located in the EU/EEA (even for free).
  • Monitor the behaviour of individuals in the EU/EEA (e.g. via analytics or advertising cookies).

In those cases, you'll also need to appoint an EU representative under Article 27 of the EU GDPR if you don't have an EU establishment. Similarly, EU-based businesses selling to UK customers need a UK representative.

Enforcement Trends in 2026

Both the ICO and EU regulators have been increasingly active. Notable trends include:

  • Higher fines for adtech and cookie violations, particularly around consent-or-pay models.
  • Sharp focus on AI training data and generative AI compliance.
  • Aggressive scrutiny of data broker practices and profiling.
  • Rising regulatory action over employee monitoring tools.
  • Stronger cross-border cooperation between the ICO and EU authorities on major cases.

Organisations that share links, tracking pixels, or user analytics data across borders should re-examine their tooling. Choosing platforms that respect privacy by default — for example, a shortener that avoids unnecessary tracking — reduces both risk and paperwork. You can compare options in our 2026 URL shortener buyer's guide or read our honest review of Lunyb.

Quick Reference: DPA 2018 vs EU GDPR

FeatureUK DPA 2018 / UK GDPREU GDPR
Territorial focusUK residentsEU/EEA residents
RegulatorICONational DPAs + EDPB
One-stop shopNoYes
Age of digital consent1316 (default, can be lowered)
Max fine£17.5m / 4%€20m / 4%
Transfer mechanismIDTA / UK AddendumSCCs / BCRs
National security exemptionsBroaderMore limited
Recent reformsData (Use and Access) Act 2025Ongoing at member-state level

FAQ

Is the UK still under GDPR after Brexit?

Yes, but under the UK GDPR, which is a retained, domesticated version of the EU regulation. It sits alongside the Data Protection Act 2018. UK organisations must comply with UK GDPR, and separately with EU GDPR if they process data of individuals in the EU/EEA.

What is the main difference between the DPA 2018 and the GDPR?

The DPA 2018 is UK-specific legislation that supplements the UK GDPR, tailoring it for domestic law and covering areas outside EU competence (such as immigration and law enforcement). The EU GDPR is directly applicable across the EU/EEA. The core principles are almost identical, but jurisdiction, regulators, fine currencies, and some exemptions differ.

Do I need to comply with both the UK and EU GDPR?

You need to comply with both if you operate in, or target customers in, both the UK and the EU/EEA. Most international companies fall into this category and maintain parallel documentation, representative appointments, and transfer safeguards.

What are the fines under the UK Data Protection Act?

The maximum fine under the UK GDPR / DPA 2018 is £17.5 million or 4% of annual global turnover, whichever is higher. Lower-tier infringements are capped at £8.7 million or 2% of turnover.

Will UK data protection law diverge further from the EU?

Some divergence is happening through the Data (Use and Access) Act 2025 and related reforms, but the UK government has been careful to preserve its EU adequacy decision. Expect continued alignment on core principles, with pragmatic differences on areas like cookies, legitimate interests, and DPO requirements.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles