Legal and Compliance

UK GDPR

Also called United Kingdom General Data Protection Regulation, UK General Data Protection Regulation

The UK's main data protection law: its retained version of the EU GDPR, read with the Data Protection Act 2018 and enforced by the ICO.

Quick facts: UK GDPR

Category
Legal and Compliance
Also called
United Kingdom General Data Protection Regulation, UK General Data Protection Regulation
Level
Intermediate
Affects
Cookie consent, analytics and ad tracking, email marketing, contact forms, CRM data, privacy notices
Where to see it
ICO guidance and self-assessment tools, your consent management platform, a record of processing, privacy notice, supplier contracts
In this article4
  1. How UK GDPR works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

UK GDPR is the main law governing how organisations in the UK collect, use, store and share personal data. It is the UK’s own version of the EU’s General Data Protection Regulation, kept on the statute book after Brexit and read together with the Data Protection Act 2018. The Information Commissioner’s Office (ICO) is the regulator that enforces it.

How UK GDPR works

Personal data is any information that identifies a living person directly or indirectly: a name, an email address, a phone number, an IP address, or a cookie identifier tied to a device. If your business handles any of it, UK GDPR applies. That covers almost any business with a website or a mailing list.

The law rests on seven principles. Data must be processed lawfully, fairly and transparently; collected for specified purposes; limited to what you need; kept accurate; kept no longer than necessary; kept secure; and you must be able to show you comply. Every use of personal data needs one of six lawful bases, and marketers mostly rely on two of them: consent and legitimate interests.

People have rights over their data, including access, correction, erasure and an absolute right to object to direct marketing. A business that decides why and how data is used is the controller. A supplier that handles data on its instructions, such as your email platform or CRM provider, is a processor, and the two need a written contract. Serious breaches must be reported to the ICO within 72 hours.

Where the UK and EU versions now differ

For the first few years after Brexit the two texts were almost identical. The Data (Use and Access) Act 2025 started to move them apart. The changes that matter most for marketers are:

  • a list of “recognised legitimate interests”, such as crime prevention and safeguarding, that no longer need a balancing test, and wording in the law itself confirming that direct marketing can be a legitimate interest;
  • more room for automated decision-making, except where special category data is involved;
  • a clearer limit on subject access requests, so that a business need only make reasonable and proportionate searches;
  • changes to PECR, the separate rules on cookies and electronic marketing, which allow some low-risk analytics cookies without consent where users are told and can object, extend the email soft opt-in to charities, and raise PECR fines to UK GDPR levels.

The Act’s provisions are being brought into force in stages, so check the ICO’s guidance for which are live at the time of writing (October 2026). The EU GDPR still applies in full to a UK business that sells to people in the EU or monitors their behaviour, which can mean working to two standards at once.

Why it matters

The ICO can fine up to £17.5 million or 4% of annual worldwide turnover, whichever is higher, for the most serious breaches. Small businesses rarely face that, and the ICO usually starts with a reprimand or an order to put things right. The everyday risks look different: a complaint from someone who received emails they never agreed to, a subject access request you cannot answer within a month, or a breach caused by a shared spreadsheet of customer details.

For marketing, UK GDPR shapes what you can measure. Analytics tags and advertising pixels collect personal data, so your cookie banner, the consent choices behind it and your privacy notice decide how much data your ad platforms receive. A business that gets this right has cleaner data it can defend. One that ignores it builds its reporting on tracking it may later have to switch off.

Common mistakes

  • Treating it as an EU rule that left with Brexit. The UK kept the law. For UK businesses, the main changes were the name and the fact that the ICO is the only regulator.
  • Relying on consent for everything. Consent must be freely given and as easy to withdraw as to give. For many routine uses, contract or legitimate interests is the better basis.
  • Copying another site’s privacy policy. A privacy notice must describe what your site actually collects and who receives it. A template that names tools you do not use, and misses the ones you do, is wrong on day one.
  • Forgetting the data protection fee. Most organisations that process personal data must pay an annual fee to the ICO unless an exemption applies.
  • Losing track of suppliers. Every tool that receives customer data, from the form plugin to the CRM, needs a contract and a place in your records.

How to act on it

Start with an inventory. List every place personal data enters your business: contact forms, booking tools, ad platforms, your email list, call recordings and analytics. Note the lawful basis for each, who else receives the data, and how long you keep it. That one document makes your privacy notice, cookie set-up and subject access responses far easier.

Then check the marketing layer, because that is where small businesses most often slip. Analytics and advertising tags should wait for consent where they need it, every marketing email needs a working unsubscribe link, and you should be able to show when and how each subscriber joined. A digital marketing strategy can map your channels against these rules, so that measurement is planned around consent rather than patched afterwards.

Do and do not

Do

  • Keep an inventory of what personal data you collect, why, and who receives it
  • Choose and record a lawful basis for each use
  • Make tracking tags wait for consent where the rules require it

Do not

  • Assume Brexit removed data protection duties
  • Copy a privacy policy from another website
  • Rely on consent where another lawful basis fits better

Questions people ask about this

Is UK GDPR the same as EU GDPR?

It started as a near copy, adapted to work in UK law from 1 January 2021. Since the Data (Use and Access) Act 2025 the two have begun to differ, mainly on legitimate interests, automated decisions, subject access requests and the cookie rules in PECR. The core principles, lawful bases and rights are still the same.

Does UK GDPR apply to small businesses and sole traders?

Yes. There is no exemption based on size: if you handle personal data about customers, enquirers or staff, the law applies. Some record-keeping duties are lighter for organisations with fewer than 250 employees, but a business that markets to people regularly rarely falls outside them entirely. The ICO publishes guidance written specifically for small organisations.

Do I need consent to send marketing emails?

For emails to individuals, PECR generally requires consent, unless the soft opt-in applies to existing customers who bought or negotiated to buy something similar and were given a chance to opt out. Emails to corporate addresses do not need consent under PECR, but UK GDPR still applies to named people, and every message needs a clear way to opt out. See the opt-in entry for how sign-up methods differ.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.