The UK GDPR is the United Kingdom General Data Protection Regulation, effective from 1 January 2021. It covers the key principles, rights, and obligations for processing personal data in the United Kingdom, and sits alongside the Data Protection Act 2018. It applies to any organisation offering goods or services to individuals in the UK, or monitoring the behaviour of individuals in the UK.
Who Does It Apply To?
The UK GDPR applies to UK businesses and organisations, and to international businesses and organisations that collect and process the personal data of UK citizens.
Personal Data
Personal data is any information or identifier that enables an individual to be identified, directly or in combination with other data, for example, name, location data, ID number, or online identifiers including IP address and cookie identifiers.
Principles
The UK GDPR’s principles are the same seven principles as the EU GDPR:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality (security)
- Accountability
Key Areas of Change in the UK GDPR

A few areas have changed since Brexit, affecting data transfer between the UK and the EEA:
International Data Transfers
If your UK business transfers personal data to or from other countries, including the EEA, the transfer needs to be covered by one of:
- An adequacy regulation: a decision made by the UK government about transferring personal data to a given third country or international organisation.
- An appropriate safeguard: an adequacy decision, continued use of the EU’s Standard Contractual Clauses, or binding corporate rules.
- An exception: for example, valid consent from the individual, a contract requiring the transfer, protecting someone’s vital interests, or a one-off transfer justified by a compelling legitimate interest.
EU Representatives
If you’re a UK-based controller or processor with no offices in the EEA, but you offer goods or services to (or monitor) individuals in the EEA, you may need to appoint a European representative, located in the EEA, able to represent you regarding your EU GDPR obligations. This isn’t required if your processing is occasional, low risk, and doesn’t involve large-scale special category or criminal offence data.
EU Regulatory Oversight
UK organisations whose processing includes cross-border processing, or who target EEA/EU individuals, may need to comply with additional oversight requirements; see the ICO’s guidance on EU regulatory oversight for details.
Other Minor Updates

If you process personal data and are subject to the EU GDPR, review your privacy policy for any changes to international transfers and representative requirements, check your data subject rights processes still hold regardless of where the individual resides, review your records of processing activities if you transfer data internationally, and confirm your Data Protection Officer arrangements (one DPO can cover both the EEA and UK, or you can appoint one for each).
Conclusion
The UK GDPR is very similar to the EU GDPR, with one major difference: the framework is now controlled by the UK government rather than the EU. Only a few changes have been made, around international data transfers, EU representatives, EU regulatory oversight, and some minor updates. The UK GDPR now sits alongside the Data Protection Act 2018 as the UK’s personal data processing law.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.