Our GDPR UK FAQs explain the legal requirements, individual rights, enforcement, and compliance expectations for organisations handling personal data.
UK GDPR (General Data Protection Regulation) is the UK’s main data protection law that gives individual rights over their data and controls how organisations collect, use, store, and protect personal data.
UK GDPR sits alongside the Data Protection Act 2018 and is based on the original EU GDPR but tailored for UK law after Brexit.
GDPR was introduced in the UK on 25 May 2018, alongside the Data Protection Act 2018.
Following Brexit, it became UK GDPR from 1 January 2021, but the core rules remained largely the same.
Yes, there is a difference between UK GDPR and EU GDPR, though they are currently almost the same in practice.
The key difference is who regulates and enforces the law:
Over time, the UK can choose to diverge from EU GDPR, but at present, the rules and rights remain largely the same.
The Act of Parliament that works alongside UK GDPR is the Data Protection Act 2018.
Together, UK GDPR and the Data Protection Act 2018 form the UK’s full legal framework for data protection.
The supervisory authority for GDPR in the UK is the Information Commissioner’s Office (ICO).
The ICO is responsible for enforcing UK GDPR, handling complaints, and issuing guidance and fines where data protection law is breached.
Under UK GDPR, personal data means any information that relates to an identified or identifiable living individual.
This includes obvious identifiers like name, address, email, and phone number, as well as online identifiers, location data, ID numbers, and any information that can directly or indirectly identify someone.
No, UK GDPR does not only apply to electronically stored data.
UK GDPR covers both digital data and certain paper records, as long as the paper records form part of a structured filing system (for example, organised employee files or customer records). This is set out under UK GDPR, alongside the Data Protection Act 2018.
Everyone who processes personal data in the UK must comply with UK GDPR. This includes:
If an organisation collects, stores, uses, shares, or deletes personal data, it is legally required to follow UK GDPR, alongside the Data Protection Act 2018.
For information about how to ensure compliance, please read our article GDPR audit checklist – is your organisation compliant?
Yes, an individual can be held responsible under UK GDPR, depending on their role.
If someone is a sole trader, they are personally legally responsible for compliance. Employees can also face internal disciplinary action, and in serious cases (such as deliberate misuse of data), they can face criminal charges under the Data Protection Act 2018.
Regulatory fines are usually issued to the organisation by the Information Commissioner’s Office, but individuals are not automatically immune from legal consequences.
UK GDPR, enforced alongside the Data Protection Act 2018, legally requires organisations to:
The seven UK GDPR principles are:
Under UK GDPR, individuals have the right to:
These rights give people strong control over how their personal data is handled.
UK GDPR-compliant consent must be:
Silence, inactivity, or bundled consent is not valid. These rules apply under UK GDPR alongside the Data Protection Act 2018.
A data controller decides why and how personal data is processed. They determine the purpose, the lawful basis, and what the data will be used for.
A data processor processes personal data only on the controller’s instructions. They do not decide the purpose and must follow the terms set by the controller.
Under UK GDPR, organisations must put in place “appropriate technical and organisational measures” to secure personal data. There is no single fixed standard; security must be proportionate to the risk.
This means the level of security should reflect:
Measures can include access controls, encryption, staff training, secure storage, and regular security testing, alongside duties in the Data Protection Act 2018.
Under UK GDPR and the Data Protection Act 2018, you must keep employee records only for as long as they are needed for a lawful purpose—there’s no single fixed time limit.
Common UK benchmarks used in practice include:
Once records are no longer needed, they must be securely deleted or destroyed.
GDPR training is not explicitly named as mandatory in UK law, but in practice it is effectively required.
Under UK GDPR and the Data Protection Act 2018, organisations must ensure staff understand how to handle personal data lawfully and securely. Without appropriate training, it is very difficult to demonstrate compliance with the accountability principle.
No, ISO/IEC 27001 is not automatically GDPR compliant, but it strongly supports UK GDPR compliance.
ISO 27001 focuses on information security management, which aligns closely with UK GDPR’s security and accountability requirements under UK GDPR. However, UK GDPR also covers lawful processing, individual rights, consent, and data retention, which go beyond ISO 27001.
Yes, most organisations need to pay a data protection fee to the ICO.
In the UK, most controllers of personal data must pay an annual fee to the Information Commissioner’s Office, unless they are specifically exempt (for example, certain small household or domestic settings).
The fee bands range from around £40 to £2,900 depending on the size and turnover of the organisation. Failure to pay the fee when required is a common cause of ICO enforcement action and fines.
In the UK, fines for breaching UK GDPR can be up to £17.5 million or 4% of global annual turnover (whichever is higher) for the most serious infringements.
Lower-level breaches can still attract fines of up to £8.7 million or 2% of turnover. Fines are issued by the Information Commissioner’s Office (ICO) based on the severity, intent, and impact of the breach.
Under the Data (Use and Access) Act 2025, the rules for Subject Access Requests (SARs) have changed to give organisations more time and clarity when they need additional information from the requester.
The key change is the introduction of the “stop-the-clock” rule:
This means organisations are not automatically penalised for delays caused by waiting for a requester to help narrow or clarify their request, as long as they act promptly once they have what they need.
The Recognised Legitimate Interests (RLI) basis is a lawful basis for processing personal data introduced by the Data (Use and Access) Act 2025.
It allows organisations to process personal data without carrying out a Legitimate Interests Assessment (LIA) for certain pre-approved activities, such as:
These activities are deemed legitimate by law, meaning organisations no longer need to balance their interests against the individual’s rights for those specific purposes.
RLI does not remove other data protection duties. Organisations must still be transparent, minimise data use, keep data secure, and respect individuals’ rights.
The “not materially lower” standard is the UK test for international data transfers introduced by the Data (Use and Access) Act 2025.
It means that when transferring personal data to a country without a UK adequacy decision, the level of protection must not be materially lower than UK standards. Exact equivalence is no longer required, but organisations must still put appropriate safeguards in place and document their assessment.
Under the Data (Use and Access) Act 2025, organisations can use AI to make automated decisions about customers using non-sensitive personal data, provided that:
Automated decisions that involve special category data or have significant legal or similarly serious effects remain more tightly restricted and require stronger safeguards.
In the UK, cookie rules are set by Privacy and Electronic Communications Regulations (PECR) and enforced by the ICO.
From 2026, the Data (Use and Access) Act 2025 allows non-intrusive cookies (such as basic analytics and user preferences) to be used without opt-in consent, provided users are clearly informed and can opt out.
Yes, your employer can read your work emails in some circumstances, but only if it is lawful, necessary, and proportionate under UK GDPR and the Data Protection Act 2018.
They must:
Routine or secret monitoring without a valid reason is likely to be unlawful and could be investigated by the Information Commissioner’s Office.