facebook-pixel

UK Data Protection Act vs GDPR Explained: Key Differences in 2026

L
Lunyb Security Team
··10 min read

Since Brexit, UK organisations have had to navigate two closely related but legally distinct privacy regimes: the UK Data Protection Act 2018 (DPA 2018), which incorporates the UK GDPR, and the EU General Data Protection Regulation (EU GDPR). On the surface the two look almost identical, which is precisely why so many compliance teams get caught out by the small but important differences.

This guide explains how the UK Data Protection Act and the GDPR relate to one another, where they diverge, and what UK and international businesses need to do to stay compliant in 2026.

What Is the UK Data Protection Act 2018?

The UK Data Protection Act 2018 is the primary piece of UK legislation governing how personal data is processed. It sits alongside the UK GDPR, together forming the UK's post-Brexit data protection framework, and is enforced by the Information Commissioner's Office (ICO).

The DPA 2018 does three main things:

  1. It supplements and tailors the UK GDPR for domestic use (Part 2).
  2. It applies data protection rules to law enforcement processing (Part 3).
  3. It applies specific rules to intelligence services processing (Part 4).

In other words, the DPA 2018 is not a stand-alone replacement for the GDPR. It is the national statute that works together with the UK GDPR, filling in gaps that the UK Parliament is allowed to customise, such as the age of consent for information society services (set at 13 in the UK) and exemptions for journalism, research, and immigration.

What Is the UK GDPR?

When the UK left the EU, the EU GDPR was retained in domestic law and renamed the "UK GDPR" via the European Union (Withdrawal) Act 2018. It mirrors the EU GDPR almost word for word, with technical amendments to remove references to EU institutions and replace them with UK equivalents (for example, the ICO replaces the European Data Protection Board as the lead supervisor).

What Is the EU GDPR?

The EU General Data Protection Regulation (Regulation 2016/679) is the European Union's unified data protection law. It applies directly across all 27 EU member states and governs how organisations collect, store, use, and share personal data belonging to individuals in the EU.

The EU GDPR applies to:

  • Any organisation established in the EU, regardless of where processing takes place.
  • Organisations outside the EU that offer goods or services to EU residents.
  • Organisations outside the EU that monitor the behaviour of EU residents.

Enforcement is handled by the national supervisory authority in each member state, coordinated through the European Data Protection Board (EDPB).

UK Data Protection Act vs GDPR: Side-by-Side Comparison

The simplest way to see the differences is in a direct comparison. The table below summarises the core structural and legal distinctions.

Area UK DPA 2018 + UK GDPR EU GDPR
Legal basis UK Act of Parliament + retained EU regulation Directly applicable EU regulation
Supervisory authority Information Commissioner's Office (ICO) National authority in each EU member state (e.g. CNIL, Garante)
Territorial scope Processing related to the UK Processing related to the EU/EEA
Maximum fine £17.5 million or 4% of global annual turnover €20 million or 4% of global annual turnover
Age of digital consent 13 years 16 years (member states may lower to 13)
International transfers UK adequacy decisions, UK IDTA, UK Addendum to EU SCCs EU adequacy decisions, EU SCCs, BCRs
Representative requirement UK representative required for non-UK controllers targeting UK EU representative required for non-EU controllers targeting EU
Law enforcement processing Covered under DPA 2018 Part 3 Covered under separate Law Enforcement Directive (EU) 2016/680

Where the Two Regimes Agree

Despite being separate laws, the UK and EU regimes still share the vast majority of their requirements. If you are compliant with one, you are approximately 90% of the way to compliance with the other.

Shared Core Principles

Both regimes are built on the same seven data protection principles:

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality (security)
  7. Accountability

Shared Individual Rights

Data subjects enjoy the same eight rights under both laws, including the right of access, rectification, erasure, restriction, data portability, and the right to object to processing or automated decision-making.

Shared Obligations

Both regimes require organisations to:

  • Maintain records of processing activities (ROPAs).
  • Carry out Data Protection Impact Assessments (DPIAs) for high-risk processing.
  • Appoint a Data Protection Officer (DPO) in certain circumstances.
  • Report personal data breaches within 72 hours.
  • Implement privacy by design and by default.

Where the Two Regimes Diverge

The devil, as always, is in the detail. Several practical differences matter a great deal for compliance teams.

1. International Data Transfers

This is the single biggest area of divergence. The UK and the EU now operate separate adequacy regimes. The European Commission granted the UK adequacy in 2021 (renewed in 2025), which allows personal data to flow freely from the EU to the UK. For transfers from the UK to third countries, the UK uses its own International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, rather than the EU SCCs directly.

The UK has also issued its own adequacy regulations for countries such as the Republic of Korea, and is pursuing a wider list than the EU in some cases.

2. Supervisory Authority and Representatives

Organisations outside the UK that target UK residents must appoint a UK representative under Article 27 of the UK GDPR. Separately, organisations outside the EU that target EU residents must appoint an EU representative. If you serve both markets, you need both.

3. Fines and Enforcement

Maximum fines are set in different currencies: £17.5 million in the UK and €20 million in the EU. In practice both can also reach 4% of global annual turnover, whichever is higher. The ICO has historically taken a slightly more pragmatic, guidance-led approach than some EU regulators, though enforcement activity has stepped up considerably since 2023.

4. UK-Specific Exemptions

The DPA 2018 contains a long list of exemptions in Schedules 2–4. These include specific carve-outs for immigration control, journalism, academic research, and certain regulatory functions. Some of these exemptions have been controversial and challenged in UK courts.

5. Age of Digital Consent

In the UK, children can consent to information society services from age 13. In the EU, the default is 16, although member states may lower it (several, including Spain and Denmark, have chosen 13 or 14).

6. The Data (Use and Access) Act 2025

In 2025 the UK passed the Data (Use and Access) Act, which amends the DPA 2018 and UK GDPR in several ways. Key changes include a reformed approach to cookies and similar technologies, clearer rules for legitimate interests in areas such as fraud prevention and direct marketing, and streamlined requirements for automated decision-making. UK and EU rules continue to drift further apart as a result.

Who Needs to Comply with Which?

Many organisations wrongly assume they only need to pick one framework. In reality, scope depends on where your data subjects are, not where your business is based.

Your Situation UK DPA/UK GDPR? EU GDPR?
UK business serving only UK customers Yes No
UK business serving UK and EU customers Yes Yes
EU business serving UK and EU customers Yes Yes
US business targeting UK residents only Yes (with UK representative) No
US business targeting EU residents only No Yes (with EU representative)

Practical Compliance Checklist for 2026

Whether you fall under the UK regime, the EU regime, or both, the practical steps are broadly the same. Use the checklist below as a starting point.

  1. Map your data. Identify what personal data you collect, where it comes from, where it is stored, and who has access.
  2. Document your lawful basis. For every processing activity, record which Article 6 (and if relevant, Article 9) basis applies.
  3. Update privacy notices. Make sure they reflect both UK and EU requirements if you serve both markets.
  4. Review international transfers. Use the UK IDTA or UK Addendum for UK transfers and the EU SCCs for EU transfers, backed by a transfer risk assessment.
  5. Appoint representatives. Non-UK organisations need an Article 27 UK representative; non-EU organisations need an Article 27 EU representative.
  6. Train staff. Everyone handling personal data should understand their obligations, especially around breach reporting (72 hours).
  7. Review marketing links and tracking. Shortened URLs, UTM parameters and tracking pixels can all constitute personal data. Use privacy-respecting tools such as Lunyb for link shortening when you need analytics without unnecessary data collection.
  8. Audit cookies and consent. The 2025 UK reforms change what you can set without consent, but EU rules under the ePrivacy Directive remain strict.

Common Misconceptions

"Brexit means we don't need to worry about GDPR"

Incorrect. The UK retained the GDPR as the UK GDPR, and any UK business targeting EU customers must also comply with the EU GDPR.

"The DPA 2018 replaced the GDPR in the UK"

Also incorrect. The DPA 2018 supplements the UK GDPR; it does not replace it. The two must be read together.

"ICO fines are smaller than EU fines, so UK compliance is cheaper"

In headline terms the caps are similar (£17.5m vs €20m). More importantly, reputational damage and civil claims from affected individuals often cost more than the regulatory fine itself.

"We can keep using EU SCCs for UK transfers"

Only if accompanied by the UK Addendum. Standalone EU SCCs are not valid for transfers originating in the UK.

Looking Ahead: UK and EU Divergence

Since 2023, the UK has made clear its intention to diverge from the EU model where it believes doing so will encourage innovation and reduce burdens on business. The Data (Use and Access) Act 2025 is the most significant step so far, but further reform is expected throughout 2026, particularly around AI governance, automated decision-making, and research exemptions.

The risk for UK businesses is that divergence could, in time, threaten the EU's adequacy decision. If adequacy were ever revoked, data flows from the EU to the UK would require SCCs or other safeguards, significantly increasing compliance costs. For now, however, adequacy remains in place and the two regimes continue to be more similar than different.

If you are responsible for marketing or communications and want to think more broadly about privacy-aware tooling, our guides on the best URL shorteners of 2026 and how Lunyb handles user data may be useful starting points.

Frequently Asked Questions

Is the UK GDPR the same as the EU GDPR?

Almost, but not quite. The UK GDPR is the retained EU GDPR with technical amendments to make it work in UK law. The substance is nearly identical, but the enforcement authority, representative requirements, international transfer mechanisms, and some national derogations differ.

Do UK businesses still need to comply with the EU GDPR?

Yes, if they offer goods or services to individuals in the EU, or monitor the behaviour of individuals in the EU. In that case they must comply with both the UK regime and the EU GDPR, and usually appoint an EU representative under Article 27.

What is the difference between the DPA 2018 and the UK GDPR?

The UK GDPR sets out the main data protection rules. The Data Protection Act 2018 is a UK Act of Parliament that supplements the UK GDPR with national detail, covers law enforcement and intelligence services processing, and provides a range of exemptions.

What is the maximum fine under the UK Data Protection Act?

The maximum fine under the UK GDPR, enforced through the DPA 2018, is £17.5 million or 4% of annual global turnover, whichever is higher. Lower-tier infringements are capped at £8.7 million or 2% of global turnover.

Does the UK still have EU adequacy in 2026?

Yes. The European Commission's adequacy decision for the UK was renewed in 2025 and remains in force. It is kept under review and could be reconsidered if UK data protection standards diverge significantly from the EU in the future.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles