Brexit made things complicated. If you have EU clients or process EU citizens' personal data, "UK GDPR-compliant" isn't enough. The EU operates under its own legislation — GDPR (EU 2016/679) — with its own supervisory authorities and its own enforcement record.
The good news: UK GDPR and EU GDPR are 90% identical. The bad news: the 10% that differs can cost you separate fines, in two jurisdictions.
In this guide I'll clarify: what UK kept from GDPR, what changed, how data transfer works after Brexit, and what you actually need to do if your business processes personal data of clients in both jurisdictions.
1. Context: how we ended up with two laws
Before 1 January 2021, GDPR (EU Regulation 2016/679) applied directly in the UK as well. With Brexit becoming effective, the UK "withdrew" the European GDPR and retained it as domestic legislation as UK GDPR, supplemented by the Data Protection Act 2018.
The two work together:
- UK GDPR — the locally adopted version of the European GDPR. Same principles, same rights.
- UK Data Protection Act 2018 — UK-specific adaptations: derogations for law enforcement, national security, journalistic purposes.
The UK supervisory authority is the Information Commissioner's Office (ICO). In the EU it's the relevant national authority (CNIL in France, BfDI in Germany, etc.). The two no longer cooperate automatically as before — each can investigate independently.
2. What GDPR and UK DPA have in common
If you're already EU GDPR compliant, you have almost everything you need for the UK:
- The same 7 principles: lawfulness, transparency, purpose limitation, minimisation, accuracy, storage limitation, security, accountability.
- The same data subject rights: access, rectification, erasure, restriction, portability, objection, automated decisions.
- Identical deadlines: 72 hours for breach notification, 30 days for subject access requests.
- The same lawful bases for processing: consent, contract, legal obligation, vital interest, public task, legitimate interest.
- The same roles: Controller, Processor, DPO (Data Protection Officer).
Your GDPR documentation (Record of Processing, DPIA, retention policies) largely applies to the UK as well. You just need to update it with references to UK DPA and ICO where you mention the authority.
3. The differences that matter in practice
| Topic | EU GDPR | UK GDPR + DPA 2018 |
|---|---|---|
| Supervisory authority | Member state authority (CNIL, BfDI, etc.) | ICO (Information Commissioner's Office) |
| Age of consent for online services | 16 years (or lower, decided by each state) | 13 years (more permissive) |
| Local representative | Required if no EU establishment processing EU data | Required separately in UK if no UK establishment |
| Transfer to third countries | EU Commission adequacy decision | Separate ICO decision (partially different list) |
| Immigration exemptions | Limited | UK DPA allows restrictions for "immigration control" |
| Breach notification | To EU member state authority in 72h | To ICO in 72h (different authority!) |
| Additional rights | Standard GDPR rights | DPA adds specific rights for justice-system data |
The 3 most painful practical differences:
Separate representatives
If your UK business processes personal data of EU citizens without an EU establishment, you must appoint an EU Representative under Art. 27 EU GDPR. Similarly, an EU firm without UK establishment needs a separate UK representative.
This representative must have a physical seat in the relevant jurisdiction, respond to data subject requests, and be a point of contact for the supervisory authority.
Double breach notifications
If a breach affects both EU and UK citizens, you must notify both authorities separately — the ICO and the relevant EU regulator — within 72 hours. Each can investigate independently.
Cookie consent — different rules
UK Privacy and Electronic Communications Regulations (PECR) add specific requirements for non-essential cookies, beyond GDPR. The ICO has published recent stricter guidance on cookie banners — many EU sites that think they're OK for UK are NOT OK.
4. EU ↔ UK data transfer after Brexit
This is the area with the most confusion. In short: transfer is legal, but must be documented correctly.
From EU to UK
The European Commission issued an adequacy decision in June 2021 for the UK. This means the EU recognises the UK as having an "adequate" level of data protection. Transfer is allowed without additional measures.
The decision is reviewed periodically. The next critical review is in 2025-2026 — if UK significantly changes its laws, the decision can be withdrawn.
From UK to EU
The UK issued its own adequacy decisions for all EU and EEA member states. Transfer is allowed without additional measures.
From EU / UK to US, India, other countries
Here it gets more complicated. The UK list of adequate countries differs slightly from the EU one. For the US, both EU and UK use the Data Privacy Framework, but company registrations must be made separately.
You use AWS or Google Cloud with EU-based servers. But you have a US sub-processor. For UK clients, you need to verify that processing contracts explicitly reference UK Standard Contractual Clauses (UK SCCs) and/or International Data Transfer Agreement (IDTA), not just EU SCCs.
5. Fines — ICO vs EU regulators
| Category | EU GDPR | UK GDPR / ICO |
|---|---|---|
| Maximum fine | €20 million or 4% global turnover | £17.5 million or 4% global turnover |
| "Tier 2" fine (less serious breaches) | €10 million or 2% | £8.7 million or 2% |
| Investigation frequency | Reactive (after complaints) | Proactive (ICO runs thematic audits) |
| Average resolution time | 6-18 months | 3-12 months (faster) |
The ICO has a reputation for being more proactively active: running thematic audits on specific sectors (e.g. online retail, fintech) and issuing detailed guidance. EU regulators respond more to specific complaints.
A few recent examples:
- British Airways — £20M fine for a breach exposing data of 400,000 clients (negotiated down from £183M initially proposed by the ICO)
- Marriott International — £18.4M for a breach affecting 339M client records
- Capita — under recent ICO investigation for a 2023 breach
6. What you need to do if you have clients in both
Concrete checklist for a UK firm with clients in both UK and EU:
- Update the Record of Processing — explicitly add both "UK Data Protection Act 2018", "UK GDPR" and "EU GDPR" in the applicable legislation for relevant categories.
- Appoint an EU Representative (if no establishment there). Typical costs: £80-200/month from a specialist provider.
- Update the Privacy Policy — separate sections for EU and UK citizens, with their authorities (ICO, CNIL etc.) mentioned.
- Update processor contracts — add UK SCCs / IDTA and EU SCCs for relevant transfers.
- Cookie banner — ensure it complies with PECR (UK) requirements plus ePrivacy (EU). Usually need services like CookieYes, OneTrust.
- Breach procedure — update to include notification to ICO AND relevant EU regulators when applicable.
- DPO or equivalent — verify if your EU data processing requires a separate DPO under EU GDPR.
- Periodic audit — recommended: semi-annual for sensitive data (financial, medical), annual for the rest.
Many firms treat the two jurisdictions identically ("a single unified policy"). It's a valid strategy if the policy covers the stricter version of both — but you need to check the two requirement sets point by point.
7. Practical examples by industry
UK online store delivering to EU
You process: name, address, email, phone, order history. Required: bilingual privacy policy (EN/relevant EU language), PECR-compliant cookie banner, contract with courier covering data transfer, optional EU Representative if EU sales exceed 5% of total.
Accounting firm with EU clients
You process: clients' financial data (controller) and their employees' (sub-processor). Required: separate Data Processing Agreements (DPA) with each EU client distinct from UK ones, EU SCCs for sub-processor transfers to non-UK/EU countries, annual compliance audit, DPO recommended.
B2B SaaS with global users
You process: contact data, platform content, logs. The most complicated case: requires both UK Representative + EU Representative (separately if establishment only in one), multi-lingual Data Processing Agreement, UK SCCs + EU SCCs in parallel, detailed register of international transfers.
Marketing agency with EU campaigns
You process data through Meta Ads, Google Ads, email marketing. Critical: consent for direct marketing per PECR (stricter than GDPR on email), clearly communicated profiling, simple opt-out honoured within 30 days max.