Skip to main content
LiveUK

UK GDPR

UK General Data Protection Regulation, with the Data Protection Act 2018

The UK’s data protection law after Brexit — the substance of GDPR, governed by the ICO, with its own rules for transfers and children’s data.

Overview

What is UK GDPR?

The UK GDPR is the United Kingdom’s data protection regime. When the Brexit transition period ended on 31 December 2020, the EU GDPR was “retained” into domestic law and tailored for the UK. In practice the law sits in two instruments that you read together: the UK GDPR itself, and the Data Protection Act 2018 (DPA 2018), which fills in the UK-specific detail the regulation leaves to member states.

Substantively, it is GDPR. The seven data-protection principles, the six lawful bases, the transparency duties, the individual rights (access, rectification, erasure, portability, restriction, objection and rights around automated decisions), the accountability obligations, the 72-hour breach-notification duty and the requirement for appropriate security all carry across almost unchanged. If you already understand GDPR, you understand most of UK GDPR.

What changes is the machinery around it. The regulator is the Information Commissioner’s Office (ICO), not an EU authority. Restricted transfers out of the UK use UK-specific tools — the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — supported by a transfer risk assessment. Most organisations must pay the ICO’s annual data protection fee and appear on its register. And the UK has its own statutory code for children’s data, the ICO Age Appropriate Design Code (the “Children’s Code”). The regime also continues to evolve — most recently through the UK’s data-protection reform agenda (the Data (Use and Access) Act 2025).

Data flows in both directions matter. Transfers from the EU into the UK rely on the European Commission’s adequacy decision for the UK, which was renewed in December 2025 and now runs until December 2031, subject to ongoing review. Transfers from the UK to other countries need a UK-recognised safeguard. If you serve people in both the EU and the UK — as most online businesses do — you are typically subject to UK GDPR and EU GDPR at the same time. In practice the underlying controls overlap heavily; it is the UK-specific requirements that you must not miss.

Applicability

Who must comply?

  • Any organisation established in the UK that processes personal data, whether as a controller (you decide why and how) or a processor (you act on a controller’s instructions).
  • Organisations outside the UK that offer goods or services to people in the UK, or monitor their behaviour — the extra-territorial reach mirrors EU GDPR. Such organisations may also need to appoint a UK representative.
  • Online services likely to be accessed by under-18s, which are additionally bound by the ICO Children’s Code regardless of where the provider is based.
  • Most UK controllers, which must pay the ICO data protection fee and hold a current ICO registration number unless a narrow exemption applies.
  • There is no general small-business exemption from the core duties — a sole trader handling UK personal data is in scope, though some record-keeping obligations scale with size, risk and the nature of the processing.

Obligations

What you must maintain

A lawful basis and clear purposes

A documented Article 6 basis for every processing activity (and an Article 9/10 condition for special-category or criminal-offence data), used for the purposes you told people about.

Transparent, UK-accurate privacy information

A complete Article 13/14 privacy notice that names UK GDPR / the DPA 2018, the ICO as your supervisory authority, and your UK transfer mechanisms — not a copy that still points at an EU authority.

An ICO registration and fee

Payment of the ICO data protection fee and a current registration number, typically shown in your privacy notice or footer.

A Record of Processing Activities (RoPA)

Your Article 30 register of what you process, why, the lawful basis, recipients, transfers and retention.

A working rights process

A way to recognise and answer data subject requests (Articles 15–22) within the statutory one-month window, with evidence of how each was handled.

UK transfer safeguards

An IDTA or UK Addendum (not EU-only SCCs) plus a transfer risk assessment for any restricted transfer of personal data out of the UK.

Children’s Code conformance

For services likely accessed by children: high-privacy defaults, data minimisation, age-appropriate application, no nudge techniques, and no profiling without a compelling, documented reason.

Breach detection and notification

A process to detect, record and — where the risk threshold is met — notify the ICO within 72 hours and affected individuals without undue delay (Articles 33/34).

Appropriate security and accurate corporate identity

Article 32 technical and organisational measures, and accurate registered-entity details (company name, number and registered office) as presented to data subjects.

Coverage

How Audulate covers UK GDPR

Automated scan

Automated checks — the GDPR rule set, plus UK-specific rules

When UK GDPR is your active framework, Audulate runs its full library of deterministic website, security, forms and transparency checks, and adds a set of UK-only rules that don’t exist in the EU scan.

  • ICO surfacing: confirms your privacy information references the ICO as supervisory authority and that an ICO registration number is present and in a valid format.
  • UK international transfers: checks that a UK-recognised mechanism (IDTA or UK Addendum) is disclosed, and flags reliance on superseded mechanisms such as the EU-US Privacy Shield or an EU-only SCC reference.
  • Children’s Code: tests for age-appropriate design on child-directed services — including a technical age-gate verification (submitting an under-age value to confirm it is actually enforced) and detection of profiling or behavioural-advertising trackers that the Code restricts even where consent is claimed.
  • Companies House verification: cross-checks the company number and registered office you present against the public register, so your stated corporate identity is accurate.
  • The complete GDPR baseline applied under UK GDPR: cookies and consent, trackers firing before consent, privacy-policy completeness and freshness, third-party and transfer disclosure, form and PII handling, TLS and security headers, and the full set of data-subject-rights disclosures.
AI-assessed

AI-assessed checks

Where a deterministic rule can only check that words are present, AI reads the actual content and judges whether it genuinely reflects the UK regime — then independently verifies high-severity findings to keep false positives down.

  • UK-specificity of your privacy policy: whether it has truly been adapted for the UK (naming UK GDPR / DPA 2018, the ICO, and UK transfer tools) rather than left as a generic or EU-only notice.
  • Children’s Code policy adequacy: whether a child-facing service’s policy actually addresses data collected from children, parental responsibility, and the Code’s expectations — not just a token line.
  • The full GDPR AI layer: privacy-policy completeness and plain-language quality, cookie-banner quality and dark-pattern detection, legitimate-interest adequacy, special-category basis, DSR-process clarity and processor enumeration.
Attested

Organisational controls (attested) and the operating toolkit

The duties that live off your website are tracked as structured, evidenced controls in-app — Audulate gives you the surface, the audit trail and the export, while you remain accountable for the decisions.

  • Processor governance: signed Article 28 DPAs and periodic vendor reviews, with sub-processor and transfer tracking.
  • Accountability records: the Article 30 RoPA, DPIAs for high-risk processing (Article 35), and consent records.
  • Operational duties: a breach register, staff data-protection training, and a DPO appointment where one is required.
  • Security and transfers: documented Article 32 technical and organisational measures, an appointed UK representative where needed, and executed UK transfer safeguards (IDTA / UK Addendum plus the transfer risk assessment).

Everything rolls into a single 0–100 compliance score across your website, code and cloud, with audit-ready evidence you can export at any time.

UK GDPR module suite

The full UK GDPR stack,
cross-linked.

10 purpose-built modules — cookie consent, DSR, RoPA, DPIA, breach, vendors, notices, DPO — each with a live product UI and shared evidence.

Your live compliance score across all GDPR articles. See exactly where you stand, what's passing, what's failing, and what to fix next.

  • Overall compliance score (0–100)
  • Per-article status breakdown
  • Risk severity heatmap
94

94 / 100 — Excellent

✓ 47 passing✗ 2 failing⚠ 4 warnings
Art. 5Lawfulness & minimisationPASS
Art. 7Consent mechanismFAIL
Art. 13Privacy noticeWARN
Art. 30Record of processingPASS
Art. 33Breach notificationPASS
Art. 35DPIA requiredWARN

Get started

Up and running in 3 steps

1

Run a free scan

Add your website URL — your first scan is free and runs in minutes.

2

Review your findings

See every gap with severity, plain-English explanation and fix guidance.

3

Fix & evidence

Resolve issues, track them over time, and export audit-ready reports.

FAQ

UK GDPR questions

What is the difference between UK GDPR and EU GDPR?

The substance is nearly identical — the same principles, lawful bases, individual rights and accountability duties. The differences are institutional and procedural: the ICO is the regulator, restricted transfers out of the UK use the IDTA or UK Addendum rather than EU SCCs, most UK controllers must pay the ICO fee, and the ICO Children’s Code applies to services children are likely to use. If you serve both the EU and the UK, you are usually subject to both regimes at once.

Do I need an ICO registration number, and what does Audulate check?

Most UK controllers must pay the ICO’s annual data protection fee and hold a registration. Audulate checks that a registration number is present on your site and that it is in the valid ICO format — and surfaces the ICO as your supervisory authority in your privacy information.

How do I transfer data out of the UK lawfully?

A restricted transfer needs a UK-recognised safeguard — most commonly the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs — backed by a transfer risk assessment. Audulate flags whether a UK mechanism is disclosed and catches reliance on outdated mechanisms such as Privacy Shield; you maintain the executed agreements and assessment as an attested control.

What is the Children’s Code and how does Audulate help?

The Children’s Code (the ICO Age Appropriate Design Code) sets standards for online services likely to be accessed by under-18s — high-privacy defaults, data minimisation, and tight limits on profiling. Audulate tests whether an age gate is actually enforced, detects profiling and behavioural-advertising trackers on child-directed services, and uses AI to assess whether your policy adequately addresses children’s data.

What are the penalties under UK GDPR?

The ICO can issue fines up to £17.5 million or 4% of total annual worldwide turnover, whichever is higher, for the most serious infringements, alongside enforcement notices and other corrective measures. Most ICO action, however, starts with engagement and remediation rather than a headline penalty.

Is the UK still “adequate” for EU data transfers?

Yes. In December 2025 the European Commission renewed its adequacy decision for the UK, so personal data can continue to flow freely from the EEA to the UK; the decision runs until December 2031, subject to review. It is still sensible to keep your transfer documentation in order — Audulate’s vendor and transfer tracking is built for that.

Do I still need PECR if I comply with UK GDPR?

Yes. PECR (cookies and electronic marketing) is a separate set of rules that sits alongside UK GDPR, and it is where most cookie-consent and marketing-opt-in obligations actually live. Audulate covers PECR as its own live framework — see the PECR page.

Related:GDPR PECR

This page is informational and not legal advice. Coverage describes Audulate’s current capabilities; your compliance obligations depend on your specific circumstances.

Get started today

Your compliance changes
every time you ship.

Audulate keeps up. Free to start.

2 free scans / monthNo credit card5-minute setup