UK GDPR is the main law governing how organisations in the UK collect, use, store and share personal data. It is the UK’s own version of the EU’s General Data Protection Regulation, kept on the statute book after Brexit and read together with the Data Protection Act 2018. The Information Commissioner’s Office (ICO) is the regulator that enforces it.
How UK GDPR works
Personal data is any information that identifies a living person directly or indirectly: a name, an email address, a phone number, an IP address, or a cookie identifier tied to a device. If your business handles any of it, UK GDPR applies. That covers almost any business with a website or a mailing list.
The law rests on seven principles. Data must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what you need; kept accurate; kept no longer than necessary; kept secure; and you must be able to show you comply. Every use of personal data needs one of six lawful bases, and marketers mostly rely on two of them: consent and legitimate interests.
People have rights over their data, including access, correction, erasure and an absolute right to object to direct marketing. A business that decides why and how data is used is the controller. A supplier that handles data on its instructions, such as your email platform or CRM provider, is a processor, and the two need a written contract. Serious breaches must be reported to the ICO within 72 hours.
Where the UK and EU versions now differ
For the first few years after Brexit the two texts were almost identical. The Data (Use and Access) Act 2025 started to move them apart. The changes that matter most for marketers are:
- a list of “recognised legitimate interests”, such as crime prevention and safeguarding, that no longer need a balancing test, and wording in the law itself confirming that direct marketing can be a legitimate interest;
- more room for automated decision-making, except where special category data is involved;
- a clearer limit on subject access requests, so that a business need only make reasonable and proportionate searches;
- changes to PECR, the separate rules on cookies and electronic marketing, which allow some low-risk analytics cookies without consent where users are told and can object, extend the email soft opt-in to charities, and raise PECR fines to UK GDPR levels.
The Act’s provisions are being brought into force in stages, so check the ICO’s guidance for which are live at the time of writing (October 2026). The EU GDPR still applies in full to a UK business that sells to people in the EU or monitors their behaviour, which can mean working to two standards at once.
Why it matters
The ICO can fine up to £17.5 million or 4% of annual worldwide turnover, whichever is higher, for the most serious breaches. Small businesses rarely face that, and the ICO usually starts with a reprimand or an order to put things right. The everyday risks look different: a complaint from someone who received emails they never agreed to, a subject access request you cannot answer within a month, or a breach caused by a shared spreadsheet of customer details.
For marketing, UK GDPR shapes what you can measure. Analytics tags and advertising pixels collect personal data, so your cookie banner, the consent choices behind it and your privacy notice decide how much data your ad platforms receive. A business that gets this right has cleaner data it can defend. One that ignores it builds its reporting on tracking it may later have to switch off.
Common mistakes
- Treating it as an EU rule that left with Brexit. The UK kept the law. For UK businesses, the main changes were the name and the fact that the ICO is the only regulator.
- Relying on consent for everything. Consent must be freely given and as easy to withdraw as to give. For many routine uses, contract or legitimate interests is the better basis.
- Copying another site’s privacy policy. A privacy notice must describe what your site actually collects and who receives it. A template that names tools you do not use, and misses the ones you do, is wrong on day one.
- Forgetting the data protection fee. Most organisations that process personal data must pay an annual fee to the ICO unless an exemption applies.
- Losing track of suppliers. Every tool that receives customer data, from the form plugin to the CRM, needs a contract and a place in your records.
How to act on it
Start with an inventory. List every place personal data enters your business: contact forms, booking tools, ad platforms, your email list, call recordings and analytics. Note the lawful basis for each, who else receives the data, and how long you keep it. That one document makes your privacy notice, cookie set-up and subject access responses far easier.
Then check the marketing layer, because that is where small businesses most often slip. Analytics and advertising tags should wait for consent where they need it, every marketing email needs a working unsubscribe link, and you should be able to show when and how each subscriber joined. A digital marketing strategy can map your channels against these rules, so that measurement is planned around consent rather than patched afterwards.
