UK GDPR After Brexit – Differences That Matter for Websites

UK GDPR After Brexit – Differences That Matter for Websites

The United Kingdom left the EU’s regulatory orbit on 31 December 2020, but its data protection law did not disappear – it split into a parallel version called UK GDPR, sitting alongside the retained Data Protection Act 2018. For any website that serves UK visitors, collects their data, or processes payments from UK customers, understanding where UK GDPR now diverges from EU GDPR is not academic. It affects your privacy policy wording, your international transfer mechanism, your supervisory authority contact details, and in some cases your cookie banner logic.

Why UK GDPR exists as a separate regime

When the Brexit transition period ended, the EU General Data Protection Regulation was copied almost word-for-word into UK domestic law via the European Union (Withdrawal) Act 2018. That copy became “UK GDPR.” It started as a near-identical twin of EU Regulation 2016/679, enforced by the Information Commissioner’s Office (ICO) instead of a national EU data protection authority.

Since then, the two frameworks have started to drift. The UK government passed the Data (Use and Digital Access) Act 2025, receiving royal assent in June 2025, which amends UK GDPR in ways that have no EU equivalent – changes to the legal basis for certain automated decision-making, adjustments to subject access request timelines in specific contexts, and a new framework for “recognised legitimate interests” that lets organisations skip the balancing test for a defined list of purposes, including fraud prevention and safeguarding. A website compliance program built purely on EU GDPR templates will miss these UK-specific provisions.

The adequacy decision and why it’s not permanent

Data can currently flow from the EEA to the UK without extra safeguards because the European Commission granted the UK an adequacy decision in June 2021. That decision was extended in June 2025 for a further six years, running to December 2031, after the Commission concluded UK data protection standards still align closely enough with EU GDPR.

This is not a settled state, though. Adequacy decisions get reviewed periodically, and any future UK domestic reform that meaningfully lowers protection standards could put the next renewal at risk. Sites transferring data in the other direction – UK to EEA – don’t need a transfer mechanism at all right now, since the UK government issued its own adequacy regulations recognising the EEA. Sites transferring UK personal data to the US, India, or other non-adequate countries still need a valid mechanism, and this is where the practical differences start to bite.

The transfer mechanism split: SCCs vs. the IDTA

EU GDPR uses the European Commission’s Standard Contractual Clauses, updated in June 2021. The UK does not use those clauses directly. Instead, the ICO issued its own International Data Transfer Agreement (IDTA), effective 21 March 2022, plus a UK Addendum that can be bolted onto the EU SCCs for organisations that prefer one contract covering both regimes.

A common mistake is assuming the EU SCCs alone cover a UK transfer. They don’t, unless the UK Addendum is attached. A website relying on a US-based email marketing tool, for example, needs to check whether its data processing agreement references the IDTA or the Addendum specifically for UK-originating personal data, not just the EU version. Many vendor-supplied DPAs from 2021 and earlier only reference the EU clauses because they were drafted before the ICO’s mechanism existed. For a deeper look at how these transfer instruments actually function in practice, see the piece on Standard Contractual Clauses for International Data Transfers.

Supervisory authority and enforcement differences

EU GDPR complaints go to the relevant national data protection authority – CNIL in France, the Datenschutzbehörde in Austria, and so on, or via the one-stop-shop mechanism for cross-border cases. UK GDPR complaints go exclusively to the ICO, based in Wilmslow. A privacy policy that lists a French or German DPA as the contact for UK data subjects is simply wrong and needs the ICO’s details instead, including its current maximum fine structure: up to £17.5 million or 4% of global annual turnover, whichever is higher – numerically close to the EU’s €20 million / 4% cap, but expressed in a different currency and set by a different statute.

Where the substance still matches

Despite the drift, most operational requirements remain aligned. Lawful bases for processing, the six data subject rights (access, rectification, erasure, restriction, portability, objection), the 72-hour breach notification window, and the requirement to maintain records of processing activities under Article 30 all carry over from EU GDPR into UK GDPR largely unchanged. A site already documenting its processing activities properly under EU rules is most of the way toward UK compliance too – the ROPA practices described in Records of Processing Activities – ROPA in Practice apply equally on either side of the Channel.

Common mistakes practitioners make

A GRC lead reviewing a multi-market site often assumes “EU GDPR compliant” and “UK GDPR compliant” are interchangeable labels. Three patterns show up repeatedly: privacy policies that reference only “the GDPR” without specifying which one applies to which visitor segment; DPO appointment letters that name an EU representative under Article 27 but skip the separate UK representative requirement, which is a distinct obligation triggered by processing UK residents’ data from outside the UK; and cookie consent tools configured with EU consent strings that never actually get served to UK-geolocated traffic, leaving those visitors with a banner that looks present but isn’t legally bound to UK PECR (Privacy and Electronic Communications Regulations) rules, which still apply in parallel with UK GDPR for cookies specifically.

The DPO question deserves its own scrutiny, since UK GDPR’s thresholds for mandatory appointment mirror the EU’s but get assessed against a UK-only footprint. The considerations are laid out in DPO Responsibilities for Mid-Sized Businesses Online.

Practical steps for a website operating across both markets

An experienced practitioner first checks whether the site’s privacy policy has separate sections – or at least separate contact blocks – for EU and UK visitors, since a single merged clause tends to get one of the two jurisdictions wrong. Next comes verifying the transfer mechanism paperwork actually references the IDTA or Addendum, not just EU SCCs, for any UK-to-third-country flow. Third, confirm the ICO registration is current; UK data controllers processing personal data generally must pay the annual data protection fee to the ICO, currently £40 to £2,900 depending on organisation size and turnover, separate from any EU registration obligations.

Cookie banners deserve a technical check, not just a visual one – confirming that UK-geolocated sessions actually receive a PECR-compliant consent flow rather than inheriting EU-only defaults by accident.

Frequently asked questions

Does a small UK-only website still need to worry about EU GDPR at all?
Only if it targets or monitors EU residents – offering goods, services, or tracking behaviour aimed at people in the EU. A UK business selling exclusively to UK customers, with no EU marketing or currency options, generally falls under UK GDPR alone.

Is the UK Addendum a replacement for the EU SCCs?
No. The Addendum modifies and attaches to the EU SCCs; it’s not a standalone document. Organisations can alternatively use the ICO’s full IDTA on its own without referencing the EU clauses.

Will UK GDPR keep diverging from EU GDPR over time?
Likely yes, gradually. The Data (Use and Digital Access) Act 2025 is the first major domestic reform since the copy-paste in 2018, and the UK government has signalled further updates are possible, provided they don’t jeopardise the EU adequacy decision renewal due by December 2031.

Treat UK GDPR and EU GDPR as related but distinct compliance obligations rather than one label with two names – the moment a site serves both audiences, its privacy documentation, transfer contracts, and consent tooling need to reflect that split explicitly, not just in spirit.