UK Data Protection Act vs GDPR Explained: Key Differences in 2026
If you handle personal data in the United Kingdom, you have almost certainly heard of both the Data Protection Act 2018 and the General Data Protection Regulation (GDPR). At first glance, they look like two names for the same rulebook. In practice, they work together as a layered framework, and since Brexit the picture has become more nuanced with the introduction of the UK GDPR alongside the EU version.
This guide breaks down the UK Data Protection Act vs GDPR debate in plain English, covering scope, enforcement, individual rights, penalties, and what organisations need to do in 2026 to stay compliant.
What Is the GDPR?
The General Data Protection Regulation (GDPR) is a European Union law that came into force on 25 May 2018. It sets out how organisations must collect, process, store, and share personal data belonging to individuals in the EU and European Economic Area (EEA).
GDPR is built around seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Any organisation, anywhere in the world, that offers goods or services to people in the EU or monitors their behaviour is caught by the regulation.
Key Features of EU GDPR
- Applies extraterritorially to any organisation processing EU residents' data
- Fines of up to €20 million or 4% of global annual turnover, whichever is higher
- Mandatory 72-hour breach notification to supervisory authorities
- Data subject rights including access, rectification, erasure, and portability
- Requirement to appoint a Data Protection Officer (DPO) in certain cases
What Is the UK Data Protection Act 2018?
The Data Protection Act 2018 (DPA 2018) is the UK's domestic data protection law. It replaced the older Data Protection Act 1998 and was designed to sit alongside the EU GDPR, filling in national-level details that the regulation left to individual member states.
Before Brexit, the DPA 2018 supplemented EU GDPR. After the UK left the EU on 31 January 2020, the government retained GDPR in domestic law as the "UK GDPR" through the European Union (Withdrawal) Act 2018. Today, the DPA 2018 and UK GDPR together form the primary data protection framework in Britain.
What the DPA 2018 Covers
The Act is structured into several parts, each addressing a specific area:
- Part 2: General processing, which supplements the UK GDPR
- Part 3: Law enforcement processing (implementing the EU Law Enforcement Directive)
- Part 4: Intelligence services processing
- Part 5: Powers and duties of the Information Commissioner's Office (ICO)
- Part 6: Enforcement, including criminal offences and penalties
UK GDPR vs EU GDPR: What Changed After Brexit?
The UK GDPR is essentially a copy of the EU GDPR that was brought into UK law after Brexit, with technical amendments so it works in a domestic context. The core principles, rights, and obligations are almost identical, but there are important structural and jurisdictional differences.
Main Post-Brexit Changes
- The Information Commissioner's Office (ICO) is now the sole UK supervisory authority, rather than the lead authority in a one-stop-shop mechanism
- References to EU institutions and law were replaced with UK equivalents
- The UK is now a "third country" from an EU perspective, requiring adequacy decisions or safeguards for data transfers
- Fines under UK GDPR are capped at £17.5 million or 4% of global turnover, whichever is higher
UK Data Protection Act vs GDPR: A Side-by-Side Comparison
The cleanest way to see the relationship between these laws is to compare them directly. The table below highlights the practical differences most organisations need to understand.
| Feature | EU GDPR | UK GDPR | DPA 2018 |
|---|---|---|---|
| Jurisdiction | EU/EEA and organisations targeting EU residents | UK and organisations targeting UK residents | UK-specific supplement |
| Supervisory Authority | National DPAs (e.g. CNIL, BfDI) | Information Commissioner's Office (ICO) | ICO |
| Maximum Fine | €20 million or 4% global turnover | £17.5 million or 4% global turnover | Same as UK GDPR for related offences |
| Breach Notification | Within 72 hours to relevant DPA | Within 72 hours to ICO | Aligns with UK GDPR |
| Age of Consent (Children) | 16 (member states can lower to 13) | 13 | Set at 13 by DPA 2018 |
| Criminal Offences | Left to member states | Covered by DPA 2018 | Defines specific offences, e.g. unlawful obtaining of data |
| National Security Exemptions | Not covered | Not covered directly | Detailed in Parts 3 and 4 |
How the DPA 2018 and UK GDPR Work Together
Think of the UK GDPR as the main engine and the DPA 2018 as the chassis and wiring that make it run in a British context. The UK GDPR sets out the high-level rules for general processing of personal data, while the DPA 2018 provides essential national detail.
Specific Roles of the DPA 2018
- Filling derogations: The UK GDPR permits member states (and now the UK) to set their own rules in certain areas. The DPA 2018 uses these to define, for example, exemptions for journalism, research, and health data.
- Regulating areas outside UK GDPR scope: Law enforcement and intelligence agency processing fall under separate regimes within the DPA 2018.
- Setting the children's age of consent: The DPA 2018 sets this at 13 for information society services, lower than the EU default of 16.
- Creating criminal offences: Things like knowingly or recklessly obtaining personal data without consent are criminal offences under the DPA 2018, not the UK GDPR.
- Providing the ICO's powers: The Act defines the ICO's investigative, corrective, and enforcement powers.
Individual Rights Under Both Frameworks
One area where the DPA 2018 and UK GDPR are very closely aligned with the EU GDPR is data subject rights. Individuals in the UK enjoy essentially the same protections as those in the EU.
The Eight Core Data Subject Rights
- Right to be informed about how data is used
- Right of access to personal data (subject access request)
- Right to rectification of inaccurate or incomplete data
- Right to erasure (the "right to be forgotten")
- Right to restrict processing in certain circumstances
- Right to data portability in a machine-readable format
- Right to object to processing, including for direct marketing
- Rights related to automated decision-making and profiling
Organisations typically have one calendar month to respond to a subject access request, and cannot charge a fee except in limited cases such as manifestly unfounded or excessive requests.
International Data Transfers: The Adequacy Question
Since Brexit, transferring personal data between the UK and the EU has required careful attention. In June 2021, the European Commission granted the UK an adequacy decision, meaning EU-to-UK data flows can continue without additional safeguards. This decision is due for review in 2025, so organisations should keep an eye on updates from the European Commission and the ICO.
For transfers from the UK to other countries, the UK operates its own adequacy regime under the DPA 2018 and UK GDPR. The UK has recognised the EEA, Gibraltar, and countries with EU adequacy decisions, and has separately signed data bridges such as the UK-US Data Bridge.
Practical Tools for International Transfers
- UK International Data Transfer Agreement (IDTA)
- UK Addendum to the EU Standard Contractual Clauses
- Binding Corporate Rules for multinational groups
- Transfer risk assessments where required
Enforcement and Penalties
The Information Commissioner's Office is the UK's independent regulator for data protection. It has significant enforcement powers under the DPA 2018, including issuing information notices, assessment notices, enforcement notices, and monetary penalties.
Tiers of Fines Under UK GDPR
| Tier | Maximum Fine | Type of Infringement |
|---|---|---|
| Standard maximum | £8.7 million or 2% global turnover | Administrative failings, such as record-keeping and breach notification |
| Higher maximum | £17.5 million or 4% global turnover | Breaches of core principles, individual rights, or transfer rules |
The ICO has issued several high-profile fines since 2018, including multi-million pound penalties against airlines, hotel groups, and technology companies for security failings and improper data handling.
Practical Compliance Steps for UK Organisations in 2026
If you are a business or public body processing personal data in the UK, compliance means addressing both the UK GDPR and the DPA 2018 together. Here is a practical roadmap.
- Map your data: Know what personal data you hold, why you have it, where it is stored, and who has access.
- Identify your lawful basis: Every processing activity needs a lawful basis under Article 6 of the UK GDPR (and Article 9 for special category data).
- Update privacy notices: Make sure notices are clear, accessible, and explain data subject rights.
- Review contracts: Data processing agreements with vendors must meet UK GDPR requirements.
- Prepare for breaches: Have an incident response plan that meets the 72-hour notification window.
- Consider a DPO: Required for public authorities and organisations engaged in large-scale monitoring or processing of special category data.
- Handle international transfers carefully: Use the IDTA or UK Addendum where required.
- Secure your links and communications: If you share URLs to customer portals, files, or forms, use a privacy-conscious link management service. Tools like Lunyb allow you to shorten, brand, and track links without exposing unnecessary user data. You can read our honest review of Lunyb or compare it in our 2026 buyer's guide.
Looking Ahead: The Data (Use and Access) Act
UK data protection law is not standing still. The Data (Use and Access) Act, which received Royal Assent in 2025, introduces targeted reforms to the DPA 2018 and UK GDPR. Changes include simplified rules for research, adjustments to automated decision-making provisions, and reforms to the ICO's governance structure.
The core framework of UK GDPR plus DPA 2018 remains intact, but organisations should watch for ICO guidance in 2026 as the new provisions take effect. For businesses that also operate in the EU, maintaining compliance with the stricter of the two regimes remains the pragmatic approach.
Frequently Asked Questions
Is the UK still under GDPR after Brexit?
Yes, but under the UK GDPR rather than the EU GDPR. The UK GDPR is a domesticated version of the EU regulation, retained in UK law after Brexit and read alongside the Data Protection Act 2018. Organisations that also process EU residents' data must still comply with the EU GDPR separately.
What is the main difference between the DPA 2018 and UK GDPR?
The UK GDPR sets out the general principles, rights, and obligations for processing personal data. The DPA 2018 supplements it by adding UK-specific detail, covering areas outside UK GDPR scope (like law enforcement and intelligence services), and creating criminal offences and enforcement powers for the ICO.
Do I need to comply with both EU GDPR and UK GDPR?
If your organisation is established in the UK but offers goods or services to individuals in the EU (or monitors their behaviour), you need to comply with both. You may also need to appoint an EU representative under Article 27 of the EU GDPR, and a UK representative if you are based outside the UK but process UK residents' data.
What are the fines under the UK Data Protection Act?
The maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious infringements. Lower-tier fines are capped at £8.7 million or 2% of turnover. The DPA 2018 also creates criminal offences with separate penalties, including unlimited fines in some cases.
Does the UK GDPR apply to small businesses?
Yes. UK GDPR applies to any organisation processing personal data, regardless of size, though some obligations (like appointing a DPO or keeping detailed processing records) are scaled based on risk and scale. Small businesses still need lawful bases, transparent privacy notices, security measures, and breach response plans.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.