Artifact GuideEU

EU GDPR vs UK GDPR

The EU GDPR and UK GDPR still share a common structure, but they are separate legal regimes with different territorial tests, regulators, transfer tools, and post-2025 UK amendments.

Use one operational evidence set where the facts are the same, then record separate EU and UK conclusions for scope, exemptions, automated decisions, complaints, breaches, and international transfers.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
13

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The EU GDPR and are separate laws. Their principles, controller and processor roles, lawful bases, core rights, records, DPIAs, security, and 72-hour breach framework remain closely aligned, so much of the same factual evidence can support both. Do not assume that one legal conclusion covers both: the UK GDPR is read with the Data Protection Act 2018 and has been amended by the Data (Use and Access) Act 2025, while EU enforcement, cross-border supervision, automated-decision rules, exemptions, and transfer mechanisms follow EU law.

Side-by-side comparison

EU GDPR vs UK GDPR: separate conclusions, reusable evidence

Compare each regime on the same facts, then apply its own territorial test, domestic qualifications, regulator route, automated-decision rule, and transfer mechanism.

Review all sources
First framework
EU GDPR

The EU column is based on the GDPR text and EU-focused guidance for lawful basis, rights, accountability records, DPIAs, security, breach response, transfers, and enforcement.

Second framework
UK GDPR

The UK column reflects the current , Data Protection Act 2018, post-2025 amendments, ICO procedures, and UK transfer tools.

Comparison row 1

Scope boundary

EU GDPR

EU GDPR applies to processing of personal data by controllers and processors, including processing in the context of an EU establishment and non-EU offering or monitoring of people in the Union.

UK GDPR

applies to processing in the context of a UK establishment and to certain processing by a controller or processor outside the UK that offers goods or services to, or monitors the behaviour of, people in the UK.

Operational implication

Test each territory separately. A service aimed at people in both the EU and UK may fall under both regimes and may need an EU representative, a UK representative, or both when the respective non-establishment conditions are met.

Comparison row 2

Covered actors

EU GDPR

EU GDPR evidence should identify controllers, processors, joint controllers, processor instructions, Article 28 contracts, Article 30 records, DPO involvement where applicable, and the owner responsible for each processing activity.

UK GDPR

The retains controller, joint-controller, processor, representative, and data-protection-officer roles. The Data Protection Act 2018 adds domestic conditions and exemptions that may affect how those duties apply.

Operational implication

One data map and one processor contract can supply common facts, but record whether each clause satisfies EU Article 28, UK Article 28, or both, and check any applicable domestic qualification.

Comparison row 3

Trigger

EU GDPR

EU GDPR work should identify the Article 6 lawful basis, provide transparent information, support rights under Articles 15 to 22, and keep logs showing how requests were received, verified, answered, or refused.

UK GDPR

The retains rights to information, access, rectification, erasure, restriction, portability, objection, and safeguards for significant automated decisions, subject to the UK text and Data Protection Act 2018 exemptions. The usual UK response period is one month, with extensions and permitted refusals depending on the rule and facts.

Operational implication

One intake tool can serve both regimes, but it must record the governing jurisdiction, identity checks, deadline, extension, exemption, search scope, response, and regulator escalation separately.

Comparison row 4

Core obligations

EU GDPR

EU GDPR work should tie Article 32 security measures to the processing risk, run a DPIA where processing is likely to create high risk, retain residual-risk and consultation decisions, and record personal-data-breach assessments.

UK GDPR

likewise requires risk-based security, DPIAs for processing likely to create high risk, and breach assessment. A controller must notify the ICO within 72 hours where a personal-data breach is likely to risk people's rights and freedoms, and notify affected people without undue delay where high risk is likely.

Operational implication

Security controls may be shared, but a breach affecting both territories needs separate threshold decisions, regulator filings, communications, and records for the EU and UK.

Comparison row 5

Evidence record

EU GDPR

EU GDPR evidence can include the scope memo, lawful-basis analysis, rights log, RoPA, processor contract, DPIA, Article 32 security record, breach assessment, transfer file, and supervisory-authority correspondence.

UK GDPR

UK evidence can use the same factual records, but should also capture the UK territorial conclusion, Data Protection Act condition or exemption, amended automated-decision assessment, ICO filing, and UK transfer instrument where relevant.

Operational implication

Keep shared facts in one controlled record and attach separate legal conclusions. Reuse does not remove the need to identify which version of the law, exemption, regulator, and transfer mechanism applies.

Comparison row 6

International transfers

EU GDPR

EU GDPR Chapter V permits transfers on the basis of an adequacy decision, appropriate safeguards such as EU SCCs, or a narrowly applicable derogation. The European Commission renewed the United Kingdom's EU GDPR adequacy decision on 19 December 2025.

UK GDPR

UK restricted transfers use the transfer rules. Where no UK adequacy regulation applies, an exporter may use the UK IDTA or the UK Addendum to the EU SCCs and must complete the required transfer assessment; EU SCCs alone are not valid for a UK restricted transfer.

Operational implication

Map each transfer direction. EU-to-UK, UK-to-EU, EU-to-other-country, and UK-to-other-country flows can require different legal instruments and assessments even when the same vendor and dataset are involved.

Comparison row 7

Enforcement

EU GDPR

EU GDPR supervisory authorities have corrective powers and administrative fines. The GDPR text sets EU fine tiers of up to EUR 10,000,000 or 2 percent of worldwide annual turnover, and up to EUR 20,000,000 or 4 percent, depending on the infringement.

UK GDPR

The Information Commissioner enforces the and Data Protection Act 2018. The UK regime has its own complaint, investigation, notice, appeal, remedy, and penalty provisions; EU supervisory-authority procedures and the EU one-stop-shop do not govern UK enforcement.

Operational implication

Send incidents, complaints, and regulator correspondence through the correct channel. A matter spanning both regimes may require parallel handling by the ICO and one or more EU supervisory authorities.

Comparison row 8

Overlap and reuse

EU GDPR

EU and UK teams can often reuse the same operational artifacts, but each artifact still needs a separate legal label. A RoPA, DPIA, transfer file, or breach log can travel across workstreams only if the supporting source is clear.

UK GDPR

UK teams can reuse those artifacts where they describe the same processing, but must account for the amended UK automated-decision rules, Data Protection Act conditions and exemptions, ICO procedures, and UK transfer instruments.

Operational implication

Reuse the document, not the legal conclusion. Label the jurisdiction, current legal text, exemption, regulator, transfer direction, and approval owner on each decision.

Comparison row 9

Practical decision rule

EU GDPR

EU GDPR applies to processing of personal data by controllers and processors, including processing in the context of an EU establishment and non-EU offering or monitoring of people in the Union.

UK GDPR

Apply the UK territorial test independently, then check the amended , Data Protection Act 2018, ICO route, and UK transfer tool for the activity.

Operational implication

Maintain one factual inventory where possible, but approve separate EU and UK legal conclusions. Escalate when territorial reach, a domestic exemption, special-category data, significant automated decisions, or an international transfer changes the outcome.

Practical decision rule

How should teams decide whether one evidence pack is enough?

  • Use one shared evidence pack only when each item has a source label for every jurisdiction it supports.
  • For EU GDPR, label scope, lawful basis, rights, RoPA, DPIA, security, breach, transfer, and enforcement evidence from the cited EU sources.
  • For , label the territorial test, Data Protection Act condition or exemption, amended automated-decision rule, ICO procedure, and UK transfer instrument.
  • Use the same underlying evidence only where it describes the same processing and remains current; record a separate legal approval for each regime.
Section 1

How to use this comparison

First decide which regime applies. The EU GDPR covers processing in the context of an EU establishment and certain offering or monitoring directed at people in the Union. The uses a parallel test for a UK establishment and certain offering or monitoring directed at people in the United Kingdom. One activity can fall under both tests.

Then run the same factual inventory for each regime: controller and processor roles, purpose, lawful basis, special-category conditions, notice, rights, records, DPIA, security, breach response, and transfer destination. Apply the jurisdiction's own exemptions, regulator route, transfer instrument, and amended rules before signing off.

  • Record an EU scope conclusion and a UK scope conclusion separately; establishment, targeting, and representative duties depend on the facts in each territory.
  • Check the together with the Data Protection Act 2018 because the Act supplies national rules, exemptions, enforcement provisions, and special processing conditions.
  • Keep separate evidence labels when the same RoPA, DPIA, transfer file, contract, or security record is reused across jurisdictions.
  • For a UK restricted transfer, select a UK mechanism. EU standard contractual clauses alone are not a valid UK transfer tool; the UK International Data Transfer Agreement or the UK Addendum to the EU clauses may be used where their conditions are met.
Section 2

Evidence records to keep separate

The most useful output is not a generic statement that the regimes are similar. It is a labelled evidence pack showing which source supports each conclusion.

For EU GDPR, keep the Article 6 lawful-basis analysis, privacy notice basis, rights workflow, RoPA, processor terms, DPIA or no-DPIA rationale, Article 32 security measures, breach assessment, transfer mechanism, and supervisory-authority response history as distinct records.

  • Record the processing purpose, data categories, data subjects, recipients, transfers, erasure timing, and security measures in the RoPA.
  • Keep consent evidence only where consent is actually the chosen lawful basis; otherwise record the selected Article 6 basis and why it fits.
  • Keep DPIA scoping, risk assessment, mitigation decisions, residual risk approvals, and consultation decisions together.
  • For transfers, keep the adequacy, SCC, transfer impact assessment, supplementary-measures, and importer-notification evidence separate from general vendor due diligence.
Section 3

Where the regimes now diverge

The Data (Use and Access) Act 2025 amended, but did not replace, the and Data Protection Act 2018. All of its data-protection provisions are now in force. The amended UK rules add recognised legitimate interests, change purpose-compatibility and international-transfer wording, and replace the former Article 22 restriction with Articles 22A to 22D.

For significant decisions based solely on automated processing, the amended generally permits a wider range of lawful bases if the controller provides information, allows representations, enables human intervention, and allows the person to contest the decision. Significant solely automated decisions involving special-category data remain restricted to explicit consent or substantial public interest with a basis in domestic law and suitable safeguards. The EU GDPR continues to apply its own Article 22 rule.

  • Do not carry an EU Article 22 conclusion into the UK without rechecking the amended UK Articles 22A to 22D.
  • Check Data Protection Act 2018 schedules and exemptions before assuming that an EU right or condition produces the same UK result.
  • Route UK complaints and breach notifications to the ICO; EU cross-border processing follows the competent EU supervisory-authority and cooperation rules.
  • Treat regulator guidance as explanatory material, not as a substitute for the current legislation.
Section 4

Accountability checks before relying on one evidence pack

A shared privacy evidence pack is useful only if it preserves the source for each claim. EU GDPR accountability evidence should show the controller decision, processor instructions, lawful basis, rights handling, Article 30 records, security measures, DPIA outcome, breach assessment, and transfer mechanism.

Where a record is reused for work, label the UK rule that supports the conclusion. A shared data map can describe the same system, but the EU and UK scope test, lawful-basis analysis, exemption, transfer tool, automated-decision assessment, and regulator filing should remain visible.

  • Name the controller, joint controller, or processor role for each processing activity.
  • Attach the Article 6 lawful basis and the evidence that supports it.
  • Show how data-subject rights requests are received, identified, routed, answered, and logged.
  • Keep Article 32 security measures and breach assessments tied to the specific processing activity.
  • For transfers, record the exporter, importer, destination, adequacy status, safeguard, transfer assessment, supplementary measures, and jurisdiction-specific contract.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Grounds UK domestic conditions, exemptions, regulator powers, remedies, and enforcement.
ico.org.uk
Referenced sections
  • Confirms that the 2025 Act received Royal Assent on 19 June 2025 and that all provisions affecting data-protection law and the Privacy and Electronic Communications Regulations are now in force.
eur-lex.europa.eu
Referenced sections
  • Grounds the EU GDPR evidence categories used in the decision rule.
"demonstrate compliance"
Related guides

Explore more topics

Does the EU GDPR apply outside the EU under Article 3?
A GDPR Article 3 territorial-scope FAQ covering EU establishment, non-EU targeting, monitoring in the EU, public-international-law cases, and Article 27 representatives.
EU GDPR Applicability Test for Products, Vendors, and Data Flows
A concrete GDPR scope test for personal data, controller and processor roles, EU establishment, EU targeting or monitoring, special-category and child data, transfers, vendors, and evidence.
EU GDPR Article 30 RoPA Intake Workflow
This GDPR Article 30 RoPA intake workflow helps capture controller and processor fields, owners, transfers, retention, security measures, and evidence before a processing activity goes live.
EU GDPR Article 6 Legal Bases FAQ
FAQ on the six Article 6 GDPR lawful bases, consent caveats, legitimate interests, public-task and legal-obligation limits, and Article 9 special-category data.
EU GDPR Automated Decision-Making and Profiling: Article 22 Scope, Safeguards, and Evidence
GDPR guide to profiling and Article 22 decisions: scope, transparency, lawful basis, DPIA triggers, safeguards, human intervention, challenge rights, and evidence.
EU GDPR Breach Notification 72 Hours: Article 33 and 34 workflow
Official source EU GDPR breach notification workflow covering awareness, 72-hour supervisory authority notices, processor escalation, high-risk data-subject communication, delay reasons, and evidence logs.
EU GDPR Breach Notification Workflow: 72-hour clock, risk assessment, and records
A concrete EU GDPR breach notification workflow for detecting and triaging incidents, starting the awareness clock, assessing risk, notifying authorities or data subjects, and keeping Article 33 records.
EU GDPR Checklist: scope, lawful basis, DSARs, DPIA, RoPA, transfers
This GDPR checklist helps review scope, lawful basis, notices, DSAR handling, DPIAs, RoPA, processor contracts, SCC transfers, breach notification, retention, security, and evidence.
EU GDPR Children and Special-Category Data Guide
GDPR guide to children's consent and special-category data: Article 8 national age variation, Article 9 conditions, transparency, DPIA triggers, safeguards, and evidence.
EU GDPR Compliance Checklist: scope, rights, DPIA, RoPA, transfers
Practical EU GDPR compliance guide for mapping scope, lawful basis, notices, data-subject rights, DPIAs, RoPA, processor terms, breaches, transfers, retention, security, and penalties.
EU GDPR Controller, Processor, and Joint Controller Roles
Classify GDPR controllers, processors, and joint controllers from actual decision-making, then document Article 26 allocation, Article 28 terms, instructions, and vendor evidence.
EU GDPR Data Subject Rights and DSAR Workflow
GDPR rights-request workflow for intake, identity checks, request scope, the one-month response clock, extensions, refusals, processor coordination, and evidence.
EU GDPR deadlines and compliance calendar
EU GDPR calendar for calculating rights-request deadlines, breach notification, DPIA and prior-consultation gates, transfer reviews, and retention checks.
EU GDPR DPIA and Prior Consultation Workflow
Screen high-risk processing, run a GDPR Article 35 DPIA, record mitigation, and identify when Article 36 prior consultation is required.
EU GDPR DPIA and risk management under Articles 35 and 36
EU GDPR DPIA guide covering Article 35 triggers and contents, CNIL and DPC PIA methods, residual risk, mitigation records, and prior consultation limits.
EU GDPR DSAR Exceptions: refusal, extensions, identity checks
FAQ on when EU GDPR controllers may extend, charge for, narrow, redact, or refuse a data subject access request under Articles 12 and 15.
EU GDPR DSAR Workflow: Intake, Clock, Rights, and Evidence
Run a GDPR DSAR workflow for intake, identity checks, rights scoping, one-month response timing, extensions, refusals, processor handoffs, and evidence records.
EU GDPR FAQ: scope, lawful basis, rights, DPIA, breaches, transfers
Direct EU GDPR FAQ answers on scope, controller and processor roles, lawful basis, data subject rights, DPIAs, breach notification, international transfers, and Article 83 fine tiers.
EU GDPR International Transfers and SCCs: Chapter V evidence guide
GDPR Chapter V guide to adequacy decisions, SCCs, transfer assessments, supplementary measures, Article 49 derogations, and EU-US DPF checks.
EU GDPR Lawful Basis and Consent Guide
Focused GDPR guide to Article 6 lawful bases, consent conditions, legitimate interests, special category data, withdrawal, and evidence records.
EU GDPR Lawful Basis and LIA Workflow for Article 6(1)(f)
Assess GDPR legitimate interests with a purpose, necessity, balancing, Article 21 objection, and evidence-record workflow based on Article 6(1)(f).
EU GDPR Lead Supervisory Authority and One-Stop-Shop
How GDPR main establishment, cross-border processing, Article 56 lead authority competence, and Article 60 cooperation fit together.
EU GDPR LIA Template for Article 6(1)(f)
This EU GDPR legitimate interests assessment template helps document Article 6(1)(f) purpose, necessity, balancing, safeguards, objection rights, and evidence.
EU GDPR penalties and fines: Article 83 tiers and evidence
EU GDPR penalties guide covering Article 83 fine ceilings, the EDPB calculation method, CJEU conditions, Article 58 powers, and evidence.
EU GDPR Processor Contracts and Vendor Management | Article 28 Evidence Guide
EU GDPR Article 28 guide for processor contracts, sub-processor controls, controller-processor role boundaries, vendor evidence, and SCC transfer clauses where applicable.
EU GDPR Record of Processing Activities Template: Article 30 RoPA Fields
Build a GDPR Article 30 record of processing activities with separate controller and processor fields for purposes, data categories, recipients, transfers, erasure time limits, and security measures.
EU GDPR Requirements: scope, rights, security, DPIA, RoPA, and transfers
Overview of core EU GDPR requirements covering scope, principles, lawful basis, notices, data-subject rights, processors, RoPA, security, breaches, DPIAs, and international transfers.
EU GDPR Retention and Erasure Schedule
Build an EU GDPR retention and erasure schedule with purpose-based periods, expiry actions, Article 17 decisions, recipient notices, and deletion evidence.
EU GDPR SCC Transfer Impact Assessment FAQ
FAQ on when SCC transfer impact assessments are needed, what Clause 14 records, and when supplementary safeguards or transfer suspension are required.
EU GDPR Transfer TIA and SCC Workflow
A GDPR workflow for checking adequacy, selecting SCC modules, documenting transfer impact assessments, and recording supplementary measures for third-country transfers.
EU GDPR Transparency Notices: Articles 12, 13 and 14
GDPR privacy-notice guide for Articles 12, 13, and 14: direct collection, other data sources, purposes, lawful bases, recipients, transfers, retention, rights, and timing.
EU GDPR vs Brazil LGPD: scope, legal bases, rights, incidents, and transfers
Compare EU GDPR and Brazil LGPD scope, actors, legal bases, rights timing, security incidents, international transfers, evidence, regulators, and penalties.
EU GDPR vs California CCPA: scope, rights, opt-outs, and evidence
Compare EU GDPR and California CCPA scope, roles, consumer rights, response times, sale and sharing opt-outs, risk assessments, contracts, transfers, and enforcement.
EU GDPR vs ePrivacy Directive: personal data, cookies, consent, and communications
Compare the EU GDPR and ePrivacy Directive for personal data processing, consent and lawful basis, cookies and terminal access, electronic communications, and parallel compliance.
GDPR processor vs controller: role boundaries and evidence
Decide whether a party is a GDPR controller, processor, or joint controller using purpose-and-means tests, Article 28 terms, Article 26 arrangements, and Article 30 records.
GDPR vs EU AI Act: privacy controls for AI systems
Map the GDPR work that remains necessary when an AI system processes personal data, including lawful basis, notices, DPIAs, Article 22, rights, security, records, and transfers.
GDPR vs EU Data Act: personal data, connected products, and access rights
Compare GDPR privacy duties with EU Data Act rights and duties for connected-product data, third-party access, data holders, users, contracts, cloud switching, and enforcement.
When does the EU GDPR require a DPIA?
Answer the EU GDPR DPIA threshold question with Article 35 triggers, high-risk criteria, supervisory-authority list checks, and DPIA content requirements.
When does the GDPR 72-hour breach notification clock start?
GDPR breach-awareness FAQ covering the Article 33 clock, processor escalation, delayed or phased notifications, risk assessment, and records to keep.