Home › Law library › UK GDPR / DPA 2018
GB
UK GDPR / DPA 2018
UK General Data Protection Regulation and Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025)
Sourced. Last verified 9 October 2026
United Kingdom Privacy
- Status
- In force since 1 Jan 2021 (retained from EU GDPR); DUAA 2025 data protection changes fully in force by 19 June 2026.
- Who it applies to
- Organisations processing personal data in the context of a UK establishment, and non-UK organisations offering goods/services to, or monitoring the behaviour of, people in the UK.
- Size thresholds
- None — applies regardless of size.
- Regulator
- Information Commissioner's Office (ICO)
- Breach or incident reporting
- Report notifiable breaches to the ICO within 72 hours of becoming aware, where feasible. Tell affected individuals without undue delay if high risk. PECR breaches by telecoms providers: 72 hours (since 20 Aug 2025).
- Deadline to answer personal data requests
- 1 month, extendable by 2 months for complex requests; clock can pause while you seek clarification (new Art 12A, for requests from 5 Feb 2026). Searches need only be reasonable and proportionate.
- Data protection officer
- DPO mandatory for public authorities and where core activities involve large-scale systematic monitoring or large-scale special-category/criminal data (same tests as EU GDPR).
- Local representative
- Non-UK organisations with no UK establishment that target or monitor people in the UK must appoint a UK representative in writing, unless processing is occasional and low-risk or they are a public authority.
- Sending data abroad
- Transfers need UK adequacy regulations (data bridges), or the IDTA / UK Addendum to EU SCCs, or BCRs. Since 5 Feb 2026 the adequacy test is whether protection is 'not materially lower'; existing TRAs remain usable.
- Cookies and consent
- PECR: consent needed for non-essential cookies, but since 5 Feb 2026 low-risk statistical/analytics and functionality cookies can be set without consent if users get clear info and an opt-out. Ad/tracking cookies still need consent.
- Maximum penalty
- Up to £17.5 million or 4% of worldwide annual turnover, whichever is higher (lower tier £8.7m or 2%). PECR fines raised to the same level from 5 Feb 2026.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Map processing and choose a lawful basis; consider the new 'recognised legitimate interests' list.
- Offer an easy (e.g. online) complaints route; acknowledge complaints within 30 days (from 19 Jun 2026).
- Answer DSARs within one month using reasonable and proportionate searches.
- Review cookie banners: drop consent only for exempt analytics/functionality cookies.
- Add safeguards (info, human review, challenge) to significant automated decisions.
- Report notifiable breaches to the ICO within 72 hours.
- Use IDTA/UK Addendum for restricted transfers outside the UK.
Recent changes
DUAA 2025 (Royal Assent 19 Jun 2025): reasonable/proportionate DSAR searches (in force on Royal Assent); cookie exemptions, recognised legitimate interests, ADM reform, new transfer test, PECR fines (5 Feb 2026); mandatory complaints handling (19 Jun 2026).
Sources
- Primary source: https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/
- Second source: https://bratby.law/data-use-and-access-act-2025-commencement/
- Regulator: Information Commissioner's Office (ICO)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].