GDPR for United Kingdom
GDPR compliance for UK companies — UK GDPR post-Brexit, ICO enforcement, and what's different from EU GDPR.
Data Protection Authority
Information Commissioner's Office (ICO)
Key Requirements
- →UK GDPR is a separate framework from EU GDPR since Brexit (Jan 2021)
- →ICO breach notification deadline: 72 hours
- →UK-EU adequacy decision in place — transfers to EU remain unrestricted
- →UK adequacy decisions cover: EU/EEA, EEA-listed countries
The United Kingdom retained GDPR in domestic law after Brexit as UK GDPR, administered by the ICO. For UK companies, the practical requirements are nearly identical to EU GDPR: lawful basis for all processing, privacy notices at collection, 72-hour breach reporting to the ICO, and Data Subject Access Request responses within one month.
The key post-Brexit complexity is international data transfers. UK companies transferring data to the EU can still do so freely under the UK-EU adequacy decision. Transfers to other countries require an appropriate safeguard — UK Standard Contractual Clauses (the IDTA, International Data Transfer Agreement) or a transfer impact assessment.
ICO enforcement has increased significantly since 2021. Notable fines have hit British Airways, Marriott, and numerous SMBs for failures in technical security measures, inadequate consent mechanisms, and failure to respond to DSARs within the one-month window. The ICO's public enforcement register is a useful resource to understand current priorities.
For UK-based SaaS companies with EU customers, you're operating under both UK GDPR and EU GDPR simultaneously. You need a UK privacy policy and an EU privacy policy, a UK DPA representative contact and an EU Article 27 representative, and your sub-processor list must be current and accurate under both frameworks.
The UK's Data Protection and Digital Information (DPDI) Bill is the next evolution of UK GDPR — it will simplify some consent requirements and adjust legitimate interest balancing tests. Keep an eye on ICO guidance as it comes into force.
Check your GDPR compliance now
Free 5-minute self-assessment — score your GDPR controls across lawful basis, data subject rights, security, and breach notification.
Run free GDPR compliance check →