---
title: "UK GDPR Timeline and Implementation Guide"
canonical_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation"
source_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation"
author: "Sorena AI"
description: "UK GDPR guide to scope, lawful bases, rights, accountability, breaches, children, automated decisions, transfers, and 2025-2026 amendments."
published_at: "2026-02-21"
updated_at: "2026-07-16"
keywords:
  - "UK GDPR"
  - "ICO guidance"
  - "data subject rights"
  - "breach notification"
  - "UK transfers"
  - "Data Protection Act 2018"
  - "International transfers"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# UK GDPR Timeline and Implementation Guide

UK GDPR guide to scope, lawful bases, rights, accountability, breaches, children, automated decisions, transfers, and 2025-2026 amendments.

![UK GDPR compliance artifact preview](https://cdn.sorena.io/cdn-cgi/image/format=auto/cheatsheets/prod/sorena-ai-uk-gdpr-timeline-small.jpg?v=cheatsheets%2Fprod)

*UK GDPR* *Free Resource*

## UK GDPR Timeline and Implementation Guide

UK GDPR is the UK's main ruleset for processing personal data. It works with the Data Protection Act 2018, which supplements the regime with conditions, exemptions, enforcement powers, and separate rules for law-enforcement and intelligence processing.

Start with one processing activity: confirm territorial and material scope, identify controller and processor roles, choose the Article 6 basis and any Article 9 or 10 condition, then connect transparency, rights, accountability, security, breach, transfer, and sector-specific duties. This guide reflects the consolidated law through the Data (Use and Access) Act 2025 amendments in force by 5 February 2026.

[Get a UK GDPR review](/contact.md)

## What teams can decide faster

- **Whether UK GDPR applies**: Test the processing activity against Article 2 and 3 scope, exclusions, UK establishment or UK targeting, and controller, joint-controller, or processor status.
- **What evidence the ICO expects**: Keep purpose and lawful-basis decisions, Article 9 or 10 conditions, notices, contracts, records of processing, DPIAs, rights records, and breach assessments.
- **How to transfer data lawfully**: First confirm there is a restricted transfer; then choose adequacy, an Article 46 safeguard such as the IDTA or UK Addendum, or a narrow Article 49 exception, and assess destination risk where required.

By Sorena AI | Updated 2026 | No signup required

### Quick scan

*UK GDPR*

- **Governance**: Accountability framework, Article 30 documentation, and controls.
- **Rights and incidents**: DSR operations, breach notification, and communication readiness.
- **Transfers and children**: IDTA and Addendum workflows plus the Children's Code implementation.

Follow the recommended path from scope and roles to lawful processing, rights, evidence, incidents, transfers, and UK-specific changes.

| Value | Metric |
| --- | --- |
| 72h | ICO clock where reportable |
| 17.5M | Higher-tier maximum GBP |
| IDTA | Transfer tool |
| AADC | Children code |

**Key highlights:** ICO-sourced | Transfer-ready | Audit-ready evidence

## Primary sources

- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io) - The Data Protection Act 2018 supplements UK GDPR, supplies conditions and exemptions, establishes the Commissioner's enforcement framework, and contains separate regimes for law-enforcement and intelligence-services processing.
  - Quote: "An Act to make provision for the regulation of the processing of information relating to individuals"
- [Consolidated UK GDPR text](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Primary consolidated text for UK GDPR scope, principles, lawful bases, rights, controller and processor duties, transfers, remedies, and amendments in force.
  - Quote: "The protection of natural persons in relation to the processing of personal data is a fundamental right"
- [ICO UK GDPR guidance and resources](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/?ref=sorena.io) - Regulator guidance for applying UK GDPR in organisational practice; it explains the law but is not itself the statutory text.
  - Quote: "UK GDPR guidance and resources"

*Recommended reading path*

## Choose the next UK GDPR decision

Start with a specific processing activity, scope, roles, and lawful basis. Then move to the rights, accountability evidence, risk, incident, transfer, deadline, or comparison that the facts trigger.

### 1. Start here: scope, roles, and lawful processing

Determine whether UK GDPR applies, how it interacts with the Data Protection Act 2018, who decides purposes and means, and which lawful basis and additional data condition apply.

1. [UK GDPR Applicability Test Guide](/artifacts/uk/general-data-protection-regulation/applicability-test.md): Practical guidance for the UK GDPR applicability test, with practical decisions, evidence, edge cases, and external source citations.
2. [UK GDPR Controller and Processor Status Guide](/artifacts/uk/general-data-protection-regulation/controller-and-processor-status.md): UK GDPR guidance for Controller and Processor Status, with practical decisions, evidence, edge cases, and external source citations.
3. [UK GDPR Lawful Bases Guide](/artifacts/uk/general-data-protection-regulation/lawful-bases.md): Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
4. [UK GDPR Requirements Guide](/artifacts/uk/general-data-protection-regulation/requirements.md): Practical guidance for the UK GDPR requirements, with practical decisions, evidence, edge cases, and external source citations.

### 2. Transparency, rights, children, and automated decisions

Design understandable information and request handling, then apply the additional safeguards for children and significant automated decisions under the amended UK rules.

5. [UK GDPR Data Subject Rights Guide](/artifacts/uk/general-data-protection-regulation/data-subject-rights.md): Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
6. [UK GDPR DSAR Workflow Guide](/artifacts/uk/general-data-protection-regulation/dsar-workflow.md): Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
7. [UK GDPR AI and Automated Decisions Guide](/artifacts/uk/general-data-protection-regulation/ai-and-automated-decisions.md): Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
8. [UK GDPR Children and Age Appropriate Design Guide](/artifacts/uk/general-data-protection-regulation/children-and-age-appropriate-design.md): UK GDPR guidance for Children and Age Appropriate Design, with practical decisions, evidence, edge cases, and external source citations.
9. [UK GDPR Children's Code Guide](/artifacts/uk/general-data-protection-regulation/children-s-code.md): UK GDPR guidance for Children's Code, with practical decisions, evidence, edge cases, and external source citations.
10. [UK GDPR PECR Cookies Guide](/artifacts/uk/general-data-protection-regulation/pecr-cookies.md): UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.

### 3. Accountability, risk, and operating evidence

Translate legal decisions into owned controls, records, assessments, contracts, security measures, and repeatable evidence rather than treating a checklist as proof of compliance.

11. [UK GDPR Compliance Checklist](/artifacts/uk/general-data-protection-regulation/checklist.md): Practical guidance for the UK GDPR checklist, with practical decisions, evidence, edge cases, and external source citations.
12. [UK GDPR Compliance Guide](/artifacts/uk/general-data-protection-regulation/compliance.md): Practical guidance for the UK GDPR compliance, with practical decisions, evidence, edge cases, and external source citations.
13. [UK GDPR Article 30 Records Guide](/artifacts/uk/general-data-protection-regulation/article-30-records.md): UK GDPR guidance for Article 30 Records, with practical decisions, evidence, edge cases, and external source citations.
14. [UK GDPR DPIAs and DPOs Guide](/artifacts/uk/general-data-protection-regulation/dpias-and-dpos.md): UK GDPR guidance for DPIAs and DPOs, with practical decisions, evidence, edge cases, and external source citations.
15. [UK GDPR DPIA Workflow Guide](/artifacts/uk/general-data-protection-regulation/dpia-workflow.md): UK GDPR guidance for DPIA Workflow, with practical decisions, evidence, edge cases, and external source citations.

### 4. Breaches, deadlines, and enforcement

Separate incident containment from the Article 33 ICO threshold, the Article 34 individual-notice threshold, operating clocks, and possible ICO remedies or fines.

16. [UK GDPR Breach Notification Guide](/artifacts/uk/general-data-protection-regulation/breach-notification.md): UK GDPR guidance for Breach Notification, with practical decisions, evidence, edge cases, and external source citations.
17. [UK GDPR 72-hour Breach Reporting Guide](/artifacts/uk/general-data-protection-regulation/72-hour-breach-reporting.md): UK GDPR guidance for 72-hour Breach Reporting, with practical decisions, evidence, edge cases, and external source citations.
18. [UK GDPR Breach Workflow Guide](/artifacts/uk/general-data-protection-regulation/breach-workflow.md): UK GDPR guidance for Breach Workflow, with practical decisions, evidence, edge cases, and external source citations.
19. [UK GDPR Deadlines and Compliance Calendar Guide](/artifacts/uk/general-data-protection-regulation/deadlines-and-compliance-calendar.md): UK GDPR operating clocks for rights requests, ICO breach notification, high-risk individual notice, privacy information, and transfer-instrument transitions.
20. [UK GDPR penalties and fines Guide](/artifacts/uk/general-data-protection-regulation/penalties-and-fines.md): UK GDPR guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.

### 5. International transfers and adequacy

Decide whether a restricted transfer exists, whether adequacy covers it, and when the IDTA, UK Addendum, risk assessment, or a narrow exception is needed.

21. [UK GDPR Adequacy Guide](/artifacts/uk/general-data-protection-regulation/adequacy.md): UK GDPR guidance for Adequacy, with practical decisions, evidence, edge cases, and external source citations.
22. [UK GDPR Transfers, IDTA, and UK Addendum Guide](/artifacts/uk/general-data-protection-regulation/transfers-idta-and-uk-addendum.md): UK GDPR guidance for transfers, IDTA, and UK Addendum, with practical decisions, evidence, edge cases, and external source citations.
23. [UK GDPR IDTA Addendum and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/idta-addendum-and-transfer-risk-assessment.md): UK GDPR guidance for IDTA addendum and transfer risk assessment, with practical decisions, evidence, edge cases, and external source citations.
24. [UK GDPR Transfer Workflow Guide](/artifacts/uk/general-data-protection-regulation/transfer-workflow.md): UK GDPR guidance for Transfer Workflow, with practical decisions, evidence, edge cases, and external source citations.
25. [UK GDPR IDTA vs EU SCCs Guide](/artifacts/uk/general-data-protection-regulation/idta-vs-eu-sccs.md): UK GDPR guidance for IDTA vs EU SCCs, with practical decisions, evidence, edge cases, and external source citations.

### 6. Compare regimes or answer a focused question

Use comparisons to identify parallel UK and EU workstreams-not equivalence-and use the FAQ when you already know the question to resolve.

26. [UK GDPR vs Data Protection Act 2018 Guide](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-data-protection-act-2018.md): Understand why UK GDPR and the Data Protection Act 2018 form one UK data-protection framework but perform different legal functions.
27. [UK GDPR vs EU GDPR Guide](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-eu-gdpr.md): Compare UK and EU GDPR scope, regulators, transfer tools, representatives, children, and post-2025 substantive divergence without assuming equivalence.
28. [UK GDPR UK vs EU Differences Guide](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-differences.md): Operational map of UK and EU differences across supervisory authorities, representatives, transfer mechanisms, local law, and evidence ownership.
29. [UK GDPR UK vs EU GDPR Differences Guide](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-gdpr-differences.md): Current substantive UK-EU GDPR divergence, including 2025-2026 UK lawful-basis, rights-request, and automated-decision amendments.
30. [UK GDPR Compliance FAQ](/artifacts/uk/general-data-protection-regulation/faq.md): Practical guidance for the UK GDPR FAQ, with practical decisions, evidence, edge cases, and external source citations.

### 7. More guides

Additional guidance related to this artifact.

31. [What should teams do about 72-hour Breach Reporting under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/72-hour-breach-reporting.md): UK GDPR guidance for 72-hour Breach Reporting, with practical decisions, evidence, edge cases, and external source citations.
32. [What should teams do about Adequacy under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/adequacy.md): UK GDPR guidance for Adequacy, with practical decisions, evidence, edge cases, and external source citations.
33. [What should teams do about AI and Automated Decisions under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/ai-and-automated-decisions.md): When UK GDPR Articles 22A-22D apply to significant automated decisions and which information, representation, human-review, and contest safeguards are required.
34. [What should teams do about Article 30 Records under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/article-30-records.md): UK GDPR guidance for Article 30 Records, with practical decisions, evidence, edge cases, and external source citations.
35. [What should teams do about Children's Code under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/children-s-code.md): UK GDPR guidance for Children's Code, with practical decisions, evidence, edge cases, and external source citations.
36. [What should teams do about Controller and Processor Status under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/controller-and-processor-status.md): UK GDPR guidance for Controller and Processor Status, with practical decisions, evidence, edge cases, and external source citations.
37. [What should teams do about DPIAs under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/dpias.md): UK GDPR guidance for DPIAs, with practical decisions, evidence, edge cases, and external source citations.
38. [What should teams do about DPOs under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/dpos.md): UK GDPR guidance for DPOs, with practical decisions, evidence, edge cases, and external source citations.
39. [What should teams do about IDTA addendum and transfer risk assessment under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/idta-addendum-and-transfer-risk-assessment.md): UK GDPR guidance for IDTA addendum and transfer risk assessment, with practical decisions, evidence, edge cases, and external source citations.
40. [What should teams do about Lawful Bases under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/lawful-bases.md): UK GDPR guidance for Lawful Bases, with practical decisions, evidence, edge cases, and external source citations.
41. [What should teams do about PECR Cookies under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md): UK GDPR guidance for PECR Cookies, with practical decisions, evidence, edge cases, and external source citations.

## Key milestones for UK data protection operations

*UK GDPR Timeline*

The chronology separates the original EU GDPR application, the UK's post-transition regime, transfer instruments, and later amendments. For operations, confirm scope and roles; document lawful basis and any special-category condition; run rights requests under the amended Article 12 and 12A timing rules; assess breaches against the separate ICO and individual-notice thresholds; and document the applicable Chapter V transfer route. Timeline dates are legal or policy milestones, not recurring internal review deadlines.

*Next step*

## Turn UK GDPR Timeline and Implementation Guide into a cited research workflow

UK GDPR Timeline and Implementation Guide should be the shared entry point for your team. Route execution into Research Copilot for live work and into SSOT when the artifact needs deeper research, evidence governance, or supporting analysis.

- Start from UK GDPR Timeline and Implementation Guide and route the work by entity, product, team, or control owner.
- Use Research Copilot to answer scope, timing, and interpretation questions with cited outputs.
- Use SSOT to keep documents, evidence, and control records in one governed system.
- Move from artifact reading to accountable execution without rebuilding the guidance in separate files.

- [Open Research Copilot](/solutions/research-copilot.md): Answer scope, timing, and interpretation questions with cited outputs for UK GDPR Timeline and Implementation Guide.
- [Open SSOT](/solutions/ssot.md): Keep documents, evidence, and control records in one governed system from the same artifact.
- [Talk through UK GDPR Timeline and Implementation Guide](/contact.md): Review your current process, evidence model, and next implementation steps.

## Compliance Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2003-09-18 | PECR 2003 made and laid before Parliament | PECR and ePrivacy | [Source](https://www.legislation.gov.uk/uksi/2003/2426/pdfs/uksi_20032426_en.pdf?ref=sorena.io) |
| 2003-12-11 | PECR 2003 comes into force | PECR and ePrivacy | [Source](https://www.legislation.gov.uk/uksi/2003/2426/pdfs/uksi_20032426_en.pdf?ref=sorena.io) |
| 2016-04-27 | GDPR adopted; later retained as UK GDPR text | GDPR and UK GDPR | [Source](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) |
| 2018-05-23 | Data Protection Act 2018 receives Royal Assent | Data Protection Act 2018 | [Source](https://www.legislation.gov.uk/ukpga/2018/12/notes/division/12/index.htm?ref=sorena.io) |
| 2018-05-25 | GDPR applies in the UK before retention | GDPR and UK GDPR | [Source](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) |
| 2020-08-12 | Children's Code issued by the ICO | Data Protection Act 2018 | [Source](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/transitional-arrangements/?ref=sorena.io) |
| 2020-09-02 | Children's Code comes into force | Data Protection Act 2018 | [Source](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/transitional-arrangements/?ref=sorena.io) |
| 2020-12-17 | EU Exit data protection amendment regulations made | Legislative Amendments | [Source](https://www.legislation.gov.uk/uksi/2020/1586/contents?ref=sorena.io) |
| 2021-01-01 | UK GDPR operates after the Brexit transition period | GDPR and UK GDPR | [Source](https://www.legislation.gov.uk/uksi/2020/1586/contents?ref=sorena.io) |
| 2021-06-04 | EU SCCs adopted for non-EEA transfers | International Transfers | [Source](https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf?ref=sorena.io) |
| 2021-06-28 | EU adopts UK adequacy decisions | International Transfers | [Source](https://ec.europa.eu/commission/presscorner/detail/en/ip_21_3183?ref=sorena.io) |
| 2021-08-26 | UK international transfer approach published | International Transfers | [Source](https://www.gov.uk/government/publications/uk-approach-to-international-data-transfers/international-data-transfers-building-trust-delivering-growth-and-firing-up-innovation?ref=sorena.io) |
| 2021-09-02 | Children's Code transition period ends | Data Protection Act 2018 | [Source](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/transitional-arrangements/?ref=sorena.io) |
| 2022-02-02 | IDTA and UK Addendum laid before Parliament | International Transfers | [Source](https://www.gov.uk/government/publications/uk-approach-to-international-data-transfers/international-data-transfers-building-trust-delivering-growth-and-firing-up-innovation?ref=sorena.io) |
| 2022-03-21 | IDTA version A1.0 in force | International Transfers | [Source](https://ico.org.uk/media2/migrated/4019538/international-data-transfer-agreement.pdf?ref=sorena.io) |
| 2022-03-21 | UK Addendum version B1.0 in force | International Transfers | [Source](https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf?ref=sorena.io) |
| 2023-09-21 | UK-US data bridge adequacy regulations laid | International Transfers | [Source](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-explainer?ref=sorena.io) |
| 2023-10-12 | UK-US data bridge comes into force | International Transfers | [Source](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-explainer?ref=sorena.io) |
| 2025-04-23 | UK-Japan adequacy joint statement published | International Transfers | [Source](https://www.gov.uk/government/publications/uk-japan-data-adequacy-joint-statement?ref=sorena.io) |
| 2025-06-19 | Data (Use and Access) Act 2025 amendments start for specified UK GDPR purposes | Legislative Amendments | [Source](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) |
| 2025-08-20 | Further Data (Use and Access) Act 2025 UK GDPR amendments commence | Legislative Amendments | [Source](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) |
| 2026-02-05 | Additional Data (Use and Access) Act 2025 UK GDPR amendments commence | Legislative Amendments | [Source](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) |

**Event details:**

- **2003-09-18 - PECR 2003 made and laid before Parliament**: The Privacy and Electronic Communications (EC Directive) Regulations 2003 were made and laid before Parliament on 18 September 2003.
- **2003-12-11 - PECR 2003 comes into force**: Regulation 1 states that PECR 2003 came into force on 11 December 2003, creating UK rules for privacy in electronic communications including storage or access on user devices and direct marketing channels.
- **2016-04-27 - GDPR adopted; later retained as UK GDPR text**: Regulation (EU) 2016/679 is dated 27 April 2016. The legislation.gov.uk version records the retained UK text and later UK amendments.
- **2018-05-23 - Data Protection Act 2018 receives Royal Assent**: The Data Protection Act 2018 received Royal Assent on 23 May 2018 and provides the UK statutory framework that works alongside the GDPR and later UK GDPR.
- **2018-05-25 - GDPR applies in the UK before retention**: The GDPR application date was 25 May 2018. The retained UK GDPR source records the GDPR text and the UK amendments made after the transition period.
- **2020-08-12 - Children's Code issued by the ICO**: The ICO transitional arrangements source states that the Age Appropriate Design Code, also known as the Children's Code, was issued on 12 August 2020.
- **2020-09-02 - Children's Code comes into force**: The ICO transitional arrangements source states that the Children's Code came into force on 2 September 2020, with a 12-month transition period.
- **2020-12-17 - EU Exit data protection amendment regulations made**: The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2020 were made on 17 December 2020, with most provisions coming into force immediately before IP completion day.
- **2021-01-01 - UK GDPR operates after the Brexit transition period**: From 1 January 2021, the retained and amended GDPR text operated as UK GDPR alongside the Data Protection Act 2018. Organisations subject to both UK and EU territorial scope may need parallel UK and EU analyses rather than treating one regime as automatically satisfying the other.
- **2021-06-04 - EU SCCs adopted for non-EEA transfers**: The UK Addendum references Commission Implementing Decision (EU) 2021/914 of 4 June 2021 as the Approved EU SCCs that can be paired with the UK Addendum for restricted transfers.
- **2021-06-28 - EU adopts UK adequacy decisions**: The European Commission adopted two adequacy decisions for the United Kingdom on 28 June 2021, one under the GDPR and one under the Law Enforcement Directive, allowing personal data to flow freely from the EU to the UK within their scope.
- **2021-08-26 - UK international transfer approach published**: The UK approach to international data transfers guidance was published on 26 August 2021, explaining UK adequacy decisions, alternative transfer mechanisms, and the adequacy assessment process.
- **2021-09-02 - Children's Code transition period ends**: The ICO transitional arrangements source states that providers of information society services likely to be accessed by children should bring processing into line with the Code by 2 September 2021, and that the Commissioner and courts must take the Code into account from that date where relevant.
- **2022-02-02 - IDTA and UK Addendum laid before Parliament**: The UK international transfer approach and the ICO transfer instruments record that the new UK International Data Transfer Agreement and the international data transfer Addendum were laid before Parliament on 2 February 2022.
- **2022-03-21 - IDTA version A1.0 in force**: The ICO International Data Transfer Agreement is marked as version A1.0 in force on 21 March 2022.
- **2022-03-21 - UK Addendum version B1.0 in force**: The ICO International Data Transfer Addendum to the EU SCCs is marked as version B1.0 in force on 21 March 2022.
- **2023-09-21 - UK-US data bridge adequacy regulations laid**: The UK-US data bridge explainer states that adequacy regulations were laid in Parliament on 21 September 2023 to give effect to the Secretary of State's decision under section 17A of the Data Protection Act 2018.
- **2023-10-12 - UK-US data bridge comes into force**: The UK-US data bridge explainer states that UK organisations could use the bridge for transfers to certified US organisations once the regulations came into force from 12 October 2023.
- **2025-04-23 - UK-Japan adequacy joint statement published**: The UK-Japan joint statement was published on 23 April 2025 and confirms that the UK currently has an adequacy decision for Japan.
- **2025-06-19 - Data (Use and Access) Act 2025 amendments start for specified UK GDPR purposes**: Editorial notes in the retained UK GDPR text record several Data (Use and Access) Act 2025 amendments beginning on 19 June 2025 for specified purposes, with other UK GDPR amendments commencing later.
- **2025-08-20 - Further Data (Use and Access) Act 2025 UK GDPR amendments commence**: The retained UK GDPR text records further Data (Use and Access) Act 2025 amendments commencing on 20 August 2025, including amendments to Article 32 and related provisions.
- **2026-02-05 - Additional Data (Use and Access) Act 2025 UK GDPR amendments commence**: Additional Data (Use and Access) Act 2025 changes commenced on 5 February 2026, including Article 6 recognised legitimate interests, Article 12A request timing, Article 15 reasonable and proportionate searches, and Articles 22A-22D on automated decisions. The consolidated text should be used for current decisions; older ICO guidance may still describe the former wording.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/uk/general-data-protection-regulation.md
