facebook-pixel

UK Data Protection Act vs GDPR Explained: Key Differences in 2026

L
Lunyb Security Team
··10 min read

Since Brexit, UK organisations have had to navigate two closely related but distinct data protection regimes: the UK Data Protection Act 2018 (DPA 2018) and the EU General Data Protection Regulation (GDPR). Although they share the same DNA, subtle differences in scope, enforcement, and derogations can trip up businesses that assume compliance with one automatically satisfies the other.

This guide explains the UK Data Protection Act vs GDPR in plain English, highlights where the two diverge, and outlines what UK-based controllers and processors need to do in 2026 to stay compliant.

What Is the UK Data Protection Act 2018?

The UK Data Protection Act 2018 is the domestic law that governs how personal data is processed in the United Kingdom. It sits alongside the UK GDPR, which is the retained EU regulation as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.

The DPA 2018 does three main things:

  1. Supplements the UK GDPR with UK-specific provisions and exemptions.
  2. Applies data protection rules to law enforcement and intelligence services processing (Parts 3 and 4).
  3. Establishes the Information Commissioner's Office (ICO) as the UK's supervisory authority.

The Relationship Between the DPA 2018 and the UK GDPR

Many people say "Data Protection Act" when they actually mean the combined framework of the UK GDPR + DPA 2018. In practice, the two must be read together: the UK GDPR sets the core principles and rights, while the DPA 2018 fills in the gaps for areas the UK is allowed to legislate on nationally.

What Is the EU GDPR?

The EU General Data Protection Regulation (Regulation (EU) 2016/679) is the European Union's flagship data protection law. It came into force on 25 May 2018 and applies directly across all EU and EEA member states.

The EU GDPR governs the processing of personal data of individuals in the EU/EEA, regardless of where the controller or processor is based. This extraterritorial reach means many UK businesses selling to EU customers must comply with both the UK and EU regimes simultaneously.

UK Data Protection Act vs GDPR: Are They the Same?

Not quite. When the UK left the EU on 31 January 2020 and completed the transition period on 31 December 2020, the EU GDPR ceased to apply directly. It was "copied" into UK law as the UK GDPR, then modified by the DPA 2018 and the 2019 exit regulations.

Since then, the UK and EU have started to diverge — slowly. Key differences already exist, and the UK government has signalled further reform through the Data (Use and Access) Act and related initiatives.

Quick Comparison Table

Feature UK GDPR + DPA 2018 EU GDPR
Territorial scope Processing in the UK, plus UK residents targeted from abroad Processing in the EU/EEA, plus EU residents targeted from abroad
Supervisory authority Information Commissioner's Office (ICO) National DPAs (e.g. CNIL, Datatilsynet) + EDPB
Maximum fines £17.5 million or 4% of global annual turnover €20 million or 4% of global annual turnover
Age of consent for online services 13 16 (member states may lower to 13)
Representative required UK representative for non-UK controllers targeting UK EU representative under Article 27
International transfers UK adequacy decisions, IDTA, UK Addendum to SCCs EU adequacy decisions, EU SCCs
Law enforcement processing Covered by Part 3 of DPA 2018 Covered by the Law Enforcement Directive (separate)

Key Differences Between the UK and EU Regimes

1. Enforcement and Regulators

Under the EU GDPR, cross-border cases are handled through the "one-stop-shop" mechanism, coordinated by the European Data Protection Board (EDPB). The ICO no longer sits on the EDPB. UK organisations that process EU data must now deal with a lead EU supervisory authority separately from the ICO.

2. Fines and Currency

Both regimes cap fines at 4% of global annual turnover, but the currency and absolute figures differ: £17.5 million under UK law versus €20 million under EU law. Practically, a single incident affecting UK and EU data subjects could attract two separate penalties.

3. Age of Consent for Information Society Services

The UK sets the age at which a child can consent to online services at 13, in line with the US COPPA age threshold. The EU default is 16, although member states can lower it to 13. This matters for social platforms, gaming sites, and ed-tech providers operating across borders.

4. International Data Transfers

Transferring personal data outside the UK requires a valid mechanism under the UK GDPR: a UK adequacy decision, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses (SCCs). The EU has its own adequacy list, which does not always match the UK's. For example, the UK has recognised certain jurisdictions the EU has not (and vice versa).

5. National Security and Immigration Exemptions

The DPA 2018 contains broader exemptions for national security, defence, and — controversially — immigration control. Some of these have been challenged in court. The EU GDPR permits national derogations but the specific UK carve-outs do not exist in identical form across EU member states.

6. Law Enforcement and Intelligence Services

Part 3 of the DPA 2018 implements the EU Law Enforcement Directive for UK police and prosecutors. Part 4 governs the intelligence services (MI5, MI6, GCHQ) with its own tailored regime. The EU GDPR itself does not cover these areas — they are handled by the separate Law Enforcement Directive.

What Stays the Same

Despite the divergences, the core substance of both laws remains remarkably similar. If you are already compliant with one, you are 90% of the way to compliance with the other.

Shared Principles

Both regimes require personal data to be:

  • Processed lawfully, fairly, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Kept in identifiable form no longer than necessary
  • Processed with appropriate security

Shared Rights for Data Subjects

Individuals under both regimes enjoy the same eight rights: to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights related to automated decision-making and profiling.

Shared Obligations

  • Appointing a Data Protection Officer (DPO) where required
  • Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Maintaining Records of Processing Activities (ROPA)
  • Notifying breaches within 72 hours
  • Building privacy by design and by default into systems

Who Needs to Comply With Both?

Many UK organisations must comply with both the UK and EU regimes at once. You likely fall into this category if you:

  1. Offer goods or services to individuals located in the EU/EEA (paid or free).
  2. Monitor the behaviour of individuals in the EU/EEA (e.g. website analytics, ad tracking).
  3. Have an establishment (office, branch, subsidiary) in an EU member state.
  4. Process personal data on behalf of a controller subject to EU GDPR.

In these scenarios, you should appoint an EU representative under Article 27 of the EU GDPR, in addition to complying with the UK regime.

Practical Compliance Checklist for UK Businesses

Step 1: Map Your Data

Understand what personal data you hold, where it came from, why you have it, and who you share it with. Focus especially on flows between the UK and EU.

Step 2: Identify Applicable Regimes

Decide whether you are subject to only UK law, only EU law, or both. Document this reasoning — regulators expect to see it.

Step 3: Review Privacy Notices

Your privacy notice should identify the correct legal basis, name the ICO (and any lead EU authority), and reflect UK-specific rights. If you serve EU customers, provide equivalent information under Articles 13–14 of the EU GDPR.

Step 4: Update International Transfer Documents

Replace legacy EU SCCs with the UK IDTA or the UK Addendum for transfers out of the UK. For transfers out of the EU, use the 2021 EU SCCs. Complete a Transfer Risk Assessment (TRA) for each destination.

Step 5: Appoint Representatives

Non-UK controllers targeting the UK need a UK representative. Non-EU controllers targeting the EU need an EU representative. A UK-based business selling into the EU typically needs the latter.

Step 6: Train and Document

Keep staff training, ROPAs, DPIAs, and breach response plans current. The ICO's Accountability Framework is a useful benchmark.

How This Affects Links, Tracking, and Analytics

Personal data protection does not stop at your CRM. Any URL that captures identifiers — session IDs, UTM tags tied to a person, IP addresses via analytics — is in scope. UK organisations using link tracking should:

  • Disclose tracking in their privacy notice and cookie banner.
  • Rely on a valid legal basis (usually consent for non-essential tracking under PECR).
  • Assess whether the link-shortening or analytics provider transfers data outside the UK.
  • Use providers that minimise data collection and offer clear data processing terms.

Privacy-conscious link platforms like Lunyb aim to keep tracking data minimal and transparent, which helps reduce the compliance surface for marketing teams. If you are evaluating link tools, our 2026 URL shortener buyer's guide compares options with data protection in mind, and our honest Lunyb review covers the platform in detail.

The Direction of Travel: UK Reform in 2026

The UK is actively reforming its data protection framework. The Data (Use and Access) Act, along with ongoing ICO guidance updates, aims to reduce compliance burdens for low-risk processing while preserving the EU adequacy decision granted in June 2021 (renewed in 2025).

Key trends to watch:

  • Simplified rules for cookie consent and low-risk analytics.
  • Clearer rules for legitimate interests, especially for direct marketing.
  • Reforms to subject access request handling and vexatious requests.
  • New frameworks for AI and automated decision-making.

If divergence goes too far, the EU could revoke UK adequacy — which would force UK businesses to rely on SCCs for every EU-to-UK data flow. That risk is a strong incentive for the UK to keep its regime broadly aligned.

Common Misconceptions

"GDPR no longer applies in the UK."

False. The UK GDPR is essentially the same regulation, just re-badged and slightly modified. The EU GDPR also still applies extraterritorially to UK businesses serving EU customers.

"The DPA 2018 replaced GDPR in the UK."

Also false. The DPA 2018 complements the UK GDPR; it does not replace it.

"Small businesses are exempt."

There is no general small-business exemption. Some record-keeping obligations are lighter for organisations under 250 employees, but the core rules apply to everyone processing personal data.

Frequently Asked Questions

Is the UK GDPR the same as the EU GDPR?

They are substantially the same but not identical. The UK GDPR is the retained version of the EU GDPR, tailored by the DPA 2018 and the 2019 exit regulations. Differences include fine currency, child consent age, international transfer mechanisms, and certain national exemptions.

Do I need to comply with both the UK and EU GDPR?

If your organisation processes personal data of individuals located in both the UK and the EU/EEA — for example, by selling to customers in both regions — then yes, both regimes apply and you should document compliance with each.

What is the maximum fine under the UK Data Protection Act?

The highest tier of fine under the UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher. The ICO also has powers to issue enforcement notices, reprimands, and audit orders.

Do I still need EU Standard Contractual Clauses for UK data transfers?

For transfers of personal data from the UK to a country without a UK adequacy decision, you should use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. The pre-2021 EU SCCs are no longer valid on their own.

Who enforces data protection law in the UK?

The Information Commissioner's Office (ICO) is the independent supervisory authority responsible for enforcing the UK GDPR and DPA 2018. It handles complaints, investigates breaches, issues fines, and publishes guidance.

Final Thoughts

The UK Data Protection Act 2018 and the GDPR are two sides of the same coin — closely aligned, but with meaningful practical differences that matter if you operate across borders. For most UK organisations in 2026, compliance is about maintaining strong fundamentals (lawful bases, transparency, security, accountability) while keeping an eye on divergence between the UK and EU regimes.

Treat the two frameworks as a combined obligation, document your decisions, and revisit your data flows at least annually. That approach will keep you on the right side of both the ICO and EU regulators, whatever changes the next few years bring.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles