UK Data Protection Act vs GDPR Explained: Key Differences for 2026
Since Brexit, UK businesses have had to navigate two overlapping privacy regimes: the UK Data Protection Act 2018 (DPA 2018) and the General Data Protection Regulation (GDPR). Although they share the same DNA, there are meaningful differences in scope, enforcement and how they interact with the newer UK GDPR. This guide explains how the two frameworks compare, what UK organisations need to do to stay compliant in 2026, and where common pitfalls lie.
What Is the UK Data Protection Act 2018?
The UK Data Protection Act 2018 is the primary piece of UK legislation governing how personal data is processed within the United Kingdom. It replaced the Data Protection Act 1998 and was designed to sit alongside the EU GDPR when the UK was still a member state.
The DPA 2018 is split into several parts, each covering a specific processing context:
- Part 2 – General processing, supplementing and tailoring the UK GDPR.
- Part 3 – Law enforcement processing (transposing the EU Law Enforcement Directive).
- Part 4 – Processing by the intelligence services.
- Parts 5 and 6 – The Information Commissioner's Office (ICO) and enforcement powers.
Crucially, the DPA 2018 adds UK-specific exemptions, defines the age of consent for information society services (13 in the UK) and provides the legal framework that empowers the ICO to investigate and fine organisations.
What Is the GDPR (and the UK GDPR)?
The General Data Protection Regulation is an EU-wide regulation that came into force on 25 May 2018. It harmonises data protection rules across the European Economic Area (EEA) and introduced a strict rights-based framework for individuals, with significant fines for non-compliance.
After Brexit, the EU GDPR was retained in UK law as the UK GDPR via the European Union (Withdrawal) Act 2018. From 1 January 2021, UK organisations have had to comply with:
- The UK GDPR – a near-identical copy of the EU GDPR, tailored for the UK.
- The DPA 2018 – which supplements the UK GDPR and provides the enforcement regime.
- The EU GDPR – if they offer goods or services to, or monitor the behaviour of, individuals in the EEA.
So in practice, UK businesses don't choose between the DPA 2018 and GDPR – they usually have to comply with both at once.
UK Data Protection Act vs GDPR: The Core Relationship
The simplest way to think about it: the UK GDPR is the main rulebook, and the DPA 2018 is the UK's implementation and enforcement layer. The two work together rather than compete.
Here's a quick summary of how they interact:
| Aspect | UK GDPR | DPA 2018 |
|---|---|---|
| Primary purpose | Sets core data protection principles and rights | Implements, supplements and enforces UK GDPR in UK law |
| Scope | General processing of personal data | General, law enforcement and intelligence services processing |
| Lawful bases | Six lawful bases (consent, contract, legal obligation, etc.) | Adds UK-specific conditions for special category and criminal data |
| Age of consent | Default: 16 | Lowered to 13 for UK information society services |
| Regulator | Enforced in UK by the ICO | Grants the ICO its investigatory and enforcement powers |
| Maximum fines | £17.5m or 4% global turnover | Mirrors UK GDPR fines; also criminal offences |
Key Differences Between the DPA 2018 and the EU GDPR
While the UK GDPR and EU GDPR are substantively very similar, the DPA 2018 introduces several UK-specific elements worth highlighting.
1. Territorial Scope and International Transfers
The EU GDPR applies when EEA residents' data is processed, regardless of where the organisation is based. The UK GDPR applies when UK residents' data is processed. UK businesses serving EU customers must comply with both regimes and may need to appoint an EU representative under Article 27 of the EU GDPR.
Transfers of personal data from the UK to third countries now follow a UK-specific adequacy regime. The UK has issued its own adequacy regulations, and uses the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
2. Exemptions and Derogations
The DPA 2018 includes exemptions not expressly spelled out in the EU GDPR, such as:
- Immigration exemption – allowing certain restrictions on data subject rights for immigration control purposes.
- Journalism, academic, artistic and literary purposes – broader than many EU implementations.
- Research and statistics – with specific safeguards under Schedule 2.
- National security and defence – processing by intelligence services under Part 4.
3. Criminal Offences
Unlike the EU GDPR, which focuses on administrative fines, the DPA 2018 creates several criminal offences, including:
- Unlawfully obtaining or disclosing personal data (Section 170).
- Re-identifying de-identified personal data (Section 171).
- Altering records to prevent disclosure to a data subject (Section 173).
These can result in unlimited fines in England and Wales, and in some cases personal liability for directors.
4. Children's Data
The EU GDPR sets the default age of digital consent at 16, allowing member states to lower it to 13. The DPA 2018 chose the lower bound of 13, meaning UK children aged 13+ can consent to information society services without parental approval. The ICO's Age Appropriate Design Code adds further obligations for services likely to be accessed by children.
Where the Two Frameworks Fully Overlap
Despite the differences, the vast majority of day-to-day compliance obligations are identical under the UK GDPR and EU GDPR. Both require:
- A lawful basis for every processing activity.
- Transparent privacy notices written in plain language.
- Honouring data subject rights (access, rectification, erasure, portability, objection).
- Data protection by design and by default.
- Records of processing activities (ROPA) for most organisations.
- Data Protection Impact Assessments (DPIAs) for high-risk processing.
- Breach notification to the regulator within 72 hours where feasible.
- Appropriate technical and organisational security measures.
If your organisation already has a mature GDPR programme, the gap to UK compliance is usually small – but it is not zero.
Who Needs to Comply?
Any organisation that processes the personal data of individuals in the UK is in scope of the UK GDPR and the DPA 2018. This includes:
- UK-established businesses of any size, including sole traders.
- Non-UK businesses that offer goods or services to UK residents.
- Non-UK businesses that monitor the behaviour of UK residents (for example via analytics, advertising cookies or location tracking).
- Public authorities and not-for-profits.
There is no small-business exemption. A one-person consultancy that keeps a client email list is just as much a data controller as a FTSE 100 bank – though the required measures are proportionate to risk.
Penalties and Enforcement
The ICO enforces both the UK GDPR and the DPA 2018. In serious cases, the maximum administrative fine is the higher of:
- £8.7 million or 2% of global annual turnover – for lower-tier breaches (e.g. record-keeping failures).
- £17.5 million or 4% of global annual turnover – for higher-tier breaches (e.g. breaching the data protection principles or data subject rights).
Beyond fines, the ICO can issue enforcement notices, assessment notices, reprimands and bans on processing. Individuals can also bring civil claims for compensation, including for non-material damage such as distress.
Notable Recent Enforcement Trends
The ICO's approach in 2024–2026 has emphasised:
- Cookies and online tracking consent (particularly on high-traffic UK websites).
- AI and automated decision-making transparency.
- Children's data under the Age Appropriate Design Code.
- Data broker and ad-tech supply chains.
- Public-sector breaches involving sensitive data.
Practical Compliance Checklist for UK Businesses
Whether you are a startup or an established enterprise, the following checklist translates the DPA 2018 and UK GDPR into concrete actions.
- Map your data. Document what personal data you hold, where it comes from, who you share it with, and your lawful basis.
- Update privacy notices. Make sure they reference the UK GDPR, DPA 2018 and the ICO as the regulator – not just the EU GDPR.
- Review your cookie banners. Non-essential cookies and trackers require clear, affirmative consent under PECR and the UK GDPR.
- Appoint a DPO if required. Mandatory for public authorities and organisations whose core activities involve large-scale monitoring or special category data.
- Document DPIAs for high-risk processing such as profiling, biometric data or large-scale CCTV.
- Check international transfers. Ensure the UK IDTA or Addendum is in place for transfers to countries without UK adequacy.
- Train your staff annually on handling personal data, phishing and breach escalation.
- Test incident response. You must notify the ICO within 72 hours of becoming aware of a notifiable breach.
Marketing, Links and Privacy: A Practical Angle
UK marketers often forget that even seemingly innocuous tools – email trackers, pixel-based analytics, redirect links – can process personal data such as IP addresses and device identifiers. That brings them squarely within scope of the UK GDPR and the DPA 2018.
When you share marketing links, choose tools that are transparent about what they collect and that avoid intrusive fingerprinting. For example, a privacy-respecting URL shortener like Lunyb lets you create short links and track aggregate click metrics without building invasive profiles of individual users. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares the leading providers on privacy and features, and our honest review of Lunyb walks through its approach in detail.
If you're specifically comparing enterprise tools, you may also find our Rebrandly review for 2026 useful when assessing contractual terms and data-processing agreements.
How the Future Might Look: The DUAA and Reform
The Data (Use and Access) Act and related reforms are gradually updating parts of the UK framework, with aims to reduce compliance friction for low-risk processing, modernise the ICO's governance and clarify rules on automated decision-making and research. The core principles of the UK GDPR and DPA 2018 are expected to remain intact, so organisations that invest in solid compliance today will not see that work wasted.
Businesses should monitor:
- Changes to legitimate interests and "recognised legitimate interests".
- New rules on cookies and similar technologies.
- Updated international transfer mechanisms and adequacy decisions.
- ICO guidance on AI and large language models.
Frequently Asked Questions
Is the UK still subject to the GDPR after Brexit?
Yes, but in a modified form. The EU GDPR no longer applies directly in the UK, but it has been retained as the UK GDPR, which sits alongside the Data Protection Act 2018. UK organisations that offer goods or services to EEA residents, or monitor their behaviour, must also continue to comply with the EU GDPR.
What is the main difference between the DPA 2018 and the UK GDPR?
The UK GDPR sets out the core data protection principles, rights and obligations, while the DPA 2018 is the UK statute that implements them, adds UK-specific exemptions (such as for immigration, journalism and research), creates criminal offences for data misuse, and grants enforcement powers to the ICO.
Can an organisation be fined under both the DPA 2018 and the UK GDPR?
In practice, the ICO issues fines under the combined framework rather than stacking them. The maximum administrative penalty is £17.5 million or 4% of global annual turnover, whichever is higher. However, individuals within an organisation can also face separate criminal prosecution under sections 170–173 of the DPA 2018.
Does the DPA 2018 apply to small businesses and sole traders?
Yes. There is no size-based exemption. Any organisation or individual acting as a data controller or processor in the UK must comply, including sole traders, charities and clubs. Obligations are, however, risk-based: a small business processing low volumes of low-risk data will not need the same controls as a multinational.
Do I need to register with the ICO?
Most organisations that process personal data electronically must pay a data protection fee to the ICO each year, unless they qualify for an exemption. The fee ranges from £40 to £2,900 depending on size and turnover. Failing to pay when required is itself a breach that can lead to fines.
Final Thoughts
The UK Data Protection Act 2018 and the GDPR are not rival frameworks – they are two layers of the same system. The UK GDPR provides the principles and rights, the DPA 2018 provides the national implementation and enforcement, and the EU GDPR continues to apply whenever UK organisations touch EEA personal data.
For most UK businesses, the practical takeaway is simple: build one strong, well-documented privacy programme that respects the UK GDPR principles, honours data subject rights, uses privacy-respecting tools, and keeps clear records. Do that, and you will comfortably satisfy both the DPA 2018 and the GDPR – whichever direction UK reform takes next.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives everyone in Ireland powerful rights over their personal data, from access and erasure to portability and objection. This guide explains each right in plain English, how to enforce it through the Data Protection Commission, and practical steps to protect your privacy online.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 reshapes how online platforms, advertisers, and intermediaries handle harmful content. This complete guide covers scope, obligations, penalties, and practical compliance steps for businesses and users in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to data privacy for Canadian businesses — covering PIPEDA, Quebec Law 25, consent, breach response, vendor management, and CPPA preparation. Learn exactly what to implement to stay compliant and build customer trust.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Canadian privacy law has changed dramatically with Bill C-27, Quebec's Law 25, and expanded provincial rules. This 2026 guide explains your rights, business obligations, and practical steps to protect personal information in the digital age.