GDPR UK FAQs

Our GDPR UK FAQs explain the legal requirements, individual rights, enforcement, and compliance expectations for organisations handling personal data.

What is GDPR UK?

UK GDPR (General Data Protection Regulation) is the UK’s main data protection law that gives individual rights over their data and controls how organisations collect, use, store, and protect personal data.

UK GDPR sits alongside the Data Protection Act 2018 and is based on the original EU GDPR but tailored for UK law after Brexit.

When was the GDPR introduced in the UK?

GDPR was introduced in the UK on 25 May 2018, alongside the Data Protection Act 2018.

Following Brexit, it became UK GDPR from 1 January 2021, but the core rules remained largely the same.

Is there a difference between UK and EU GDPR?

Yes, there is a difference between UK GDPR and EU GDPR, though they are currently almost the same in practice.

  • EU GDPR applies in the European Union.
  • UK GDPR applies in the UK and works alongside the Data Protection Act 2018.

The key difference is who regulates and enforces the law:

  • In the EU, this is done by EU supervisory authorities.
  • In the UK, it is enforced by the Information Commissioner’s Office.

Over time, the UK can choose to diverge from EU GDPR, but at present, the rules and rights remain largely the same.

Which act of parliament works together with UK GDPR?

The Act of Parliament that works alongside UK GDPR is the Data Protection Act 2018.

Together, UK GDPR and the Data Protection Act 2018 form the UK’s full legal framework for data protection.

Who is the supervisory authority for GDPR in the UK?

The supervisory authority for GDPR in the UK is the Information Commissioner’s Office (ICO).

The ICO is responsible for enforcing UK GDPR, handling complaints, and issuing guidance and fines where data protection law is breached.

How does UK GDPR define personal data?

Under UK GDPR, personal data means any information that relates to an identified or identifiable living individual.

This includes obvious identifiers like name, address, email, and phone number, as well as online identifiers, location data, ID numbers, and any information that can directly or indirectly identify someone.

Does the UK GDPR only apply to electronically stored data?

No, UK GDPR does not only apply to electronically stored data.

UK GDPR covers both digital data and certain paper records, as long as the paper records form part of a structured filing system (for example, organised employee files or customer records). This is set out under UK GDPR, alongside the Data Protection Act 2018.

Who must comply with the UK GDPR?

Everyone who processes personal data in the UK must comply with UK GDPR. This includes:

  • Employers and businesses of all sizes
  • Public sector bodies and local authorities
  • Charities and not-for-profit organisations
  • Sole traders and freelancers
  • Overseas organisations that offer goods or services to people in the UK or monitor their behaviour.

If an organisation collects, stores, uses, shares, or deletes personal data, it is legally required to follow UK GDPR, alongside the Data Protection Act 2018.

For information about how to ensure compliance, please read our article GDPR audit checklist – is your organisation compliant?

Can an individual be held responsible under UK GDPR?

Yes, an individual can be held responsible under UK GDPR, depending on their role.

If someone is a sole trader, they are personally legally responsible for compliance. Employees can also face internal disciplinary action, and in serious cases (such as deliberate misuse of data), they can face criminal charges under the Data Protection Act 2018.

Regulatory fines are usually issued to the organisation by the Information Commissioner’s Office, but individuals are not automatically immune from legal consequences.

What does UK GDPR require by law?

UK GDPR, enforced alongside the Data Protection Act 2018, legally requires organisations to:

  • Process personal data lawfully, fairly, and transparently
  • Collect data only for specified, legitimate purposes
  • Limit data to what is necessary (data minimisation)
  • Keep data accurate and up to date
  • Store data securely and only for as long as needed
  • Respect individuals’ rights, including access, rectification, erasure, and objection
  • Report serious data breaches to the regulator within 72 hours
  • Demonstrate compliance through records, policies, and, where required, data protection impact assessments.

How many principles make up the UK GDPR?

The seven UK GDPR principles are:

  1. Lawfulness, fairness and transparency – use data legally and openly
  2. Purpose limitation – only use data for specific, stated purposes
  3. Data minimisation – only collect what is necessary
  4. Accuracy – keep data correct and up to date
  5. Storage limitation – keep data only as long as needed
  6. Integrity and confidentiality – keep data secure
  7. Accountability – be able to prove compliance

What are individuals’ rights under UK GDPR?

Under UK GDPR, individuals have the right to:

  • Be informed about how their data is used
  • Access their personal data
  • Rectify inaccurate data
  • Erase their data (the “right to be forgotten”)
  • Restrict how their data is used
  • Data portability (receive and reuse their data)
  • Object to certain types of processing
  • Not be subject to solely automated decisions that have legal or significant effects

These rights give people strong control over how their personal data is handled.

What is considered UK GDPR compliant consent?

UK GDPR-compliant consent must be:

  • Freely given – no pressure or unfair consequences for refusing
  • Specific – clear what the person is agreeing to
  • Informed – they understand how their data will be used
  • Unambiguous – given by a clear positive action (no pre-ticked boxes)
  • Easy to withdraw – people must be able to change their mind at any time

Silence, inactivity, or bundled consent is not valid. These rules apply under UK GDPR alongside the Data Protection Act 2018.

What is the difference between a data controller and a data processor?

A data controller decides why and how personal data is processed. They determine the purpose, the lawful basis, and what the data will be used for.

A data processor processes personal data only on the controller’s instructions. They do not decide the purpose and must follow the terms set by the controller.

What level of security is required under the UK GDPR?

Under UK GDPR, organisations must put in place “appropriate technical and organisational measures” to secure personal data. There is no single fixed standard; security must be proportionate to the risk.

This means the level of security should reflect:

  • The sensitivity of the data
  • The likely risk to individuals if it were breached
  • The size and resources of the organisation

Measures can include access controls, encryption, staff training, secure storage, and regular security testing, alongside duties in the Data Protection Act 2018.

How long should I keep employee records under UK GDPR?

Under UK GDPR and the Data Protection Act 2018, you must keep employee records only for as long as they are needed for a lawful purpose—there’s no single fixed time limit.

Common UK benchmarks used in practice include:

  • Personnel files: up to 6 years after employment ends (to cover contract and tribunal claims)
  • Payroll, tax and NI records: 6 years (HMRC requirements)
  • Recruitment records (unsuccessful candidates): 6–12 months
  • Health and safety records: often 3–40 years, depending on the exposure and regulations

Once records are no longer needed, they must be securely deleted or destroyed.

Is GDPR training mandatory UK?

GDPR training is not explicitly named as mandatory in UK law, but in practice it is effectively required.

Under UK GDPR and the Data Protection Act 2018, organisations must ensure staff understand how to handle personal data lawfully and securely. Without appropriate training, it is very difficult to demonstrate compliance with the accountability principle.

Is ISO 27001 GDPR compliant in the UK?

No, ISO/IEC 27001 is not automatically GDPR compliant, but it strongly supports UK GDPR compliance.

ISO 27001 focuses on information security management, which aligns closely with UK GDPR’s security and accountability requirements under UK GDPR. However, UK GDPR also covers lawful processing, individual rights, consent, and data retention, which go beyond ISO 27001.

Do organisations need to pay a data protection fee to the ICO?

Yes, most organisations need to pay a data protection fee to the ICO.

In the UK, most controllers of personal data must pay an annual fee to the Information Commissioner’s Office, unless they are specifically exempt (for example, certain small household or domestic settings).

The fee bands range from around £40 to £2,900 depending on the size and turnover of the organisation. Failure to pay the fee when required is a common cause of ICO enforcement action and fines.

What is the fine for a GDPR breach in the UK?

In the UK, fines for breaching UK GDPR can be up to £17.5 million or 4% of global annual turnover (whichever is higher) for the most serious infringements.

Lower-level breaches can still attract fines of up to £8.7 million or 2% of turnover. Fines are issued by the Information Commissioner’s Office (ICO) based on the severity, intent, and impact of the breach.

How have the rules for Subject Access Requests (SARs) changed?

Under the Data (Use and Access) Act 2025, the rules for Subject Access Requests (SARs) have changed to give organisations more time and clarity when they need additional information from the requester.

The key change is the introduction of the “stop-the-clock” rule:

  • If an organisation cannot locate, verify or find the personal data requested without asking the requester for clarification or more information, it can pause the 30-day deadline until the requester responds.
  • The SAR timeframe resumes once the clarification or additional information has been received.

This means organisations are not automatically penalised for delays caused by waiting for a requester to help narrow or clarify their request, as long as they act promptly once they have what they need.

What is the Recognised Legitimate Interests basis?

The Recognised Legitimate Interests (RLI) basis is a lawful basis for processing personal data introduced by the Data (Use and Access) Act 2025.

It allows organisations to process personal data without carrying out a Legitimate Interests Assessment (LIA) for certain pre-approved activities, such as:

  • crime prevention and detection,
  • safeguarding individuals,
  • responding to emergencies, and
  • protecting public security.

These activities are deemed legitimate by law, meaning organisations no longer need to balance their interests against the individual’s rights for those specific purposes.

RLI does not remove other data protection duties. Organisations must still be transparent, minimise data use, keep data secure, and respect individuals’ rights.

What is the “not materially lower” standard for international data transfers?

The “not materially lower” standard is the UK test for international data transfers introduced by the Data (Use and Access) Act 2025.

It means that when transferring personal data to a country without a UK adequacy decision, the level of protection must not be materially lower than UK standards. Exact equivalence is no longer required, but organisations must still put appropriate safeguards in place and document their assessment.

Can organisations use AI to make automated decisions about customers?

Under the Data (Use and Access) Act 2025, organisations can use AI to make automated decisions about customers using non-sensitive personal data, provided that:

  • there is a valid lawful basis (such as legitimate interests),
  • the decision has a clear purpose, and
  • individuals are given a way to challenge the decision or request human review.

Automated decisions that involve special category data or have significant legal or similarly serious effects remain more tightly restricted and require stronger safeguards.

What are the new cookie consent rules for 2026?

In the UK, cookie rules are set by Privacy and Electronic Communications Regulations (PECR) and enforced by the ICO.

From 2026, the Data (Use and Access) Act 2025 allows non-intrusive cookies (such as basic analytics and user preferences) to be used without opt-in consent, provided users are clearly informed and can opt out.

Can my employer read my emails under UK GDPR?

Yes, your employer can read your work emails in some circumstances, but only if it is lawful, necessary, and proportionate under UK GDPR and the Data Protection Act 2018.

They must:

  • Have a clear business reason (such as security, misconduct, or legal compliance)
  • Inform staff through monitoring or IT policies
  • Avoid excessive or intrusive monitoring
  • Respect your right to privacy, especially where emails are marked personal

Routine or secret monitoring without a valid reason is likely to be unlawful and could be investigated by the Information Commissioner’s Office.