GDPR

Knowledge Base | GDPR | What is UK GDPR?

What is UK GDPR?

UK GDPR is the United Kingdom General Data Protection Regulation. It governs how personal data is collected, used, stored and shared, and gives individuals rights over their information. It became a separate domestic regime on 1 January 2021, following the Brexit transition period. It operates alongside the Data Protection Act 2018 and is enforced by the Information Commissioner’s Office, the ICO.

It generally applies to processing connected with a UK establishment. Organisations outside the UK can also fall within its scope when they offer goods or services to people in the UK or monitor their behaviour there. Organisations must establish a lawful basis, explain their processing, protect personal data, respect individuals’ rights and demonstrate compliance.

The Data (Use and Access) Act 2025 amendments changed parts of UK GDPR without replacing it. All the Act’s data protection provisions were in force by 19 June 2026. UK and EU GDPR remain separate regimes, and an organisation may need to comply with both.