| Territorial scope | Applies to processing in the context of a UK establishment and to specified offering or monitoring by organisations outside the UK. | Applies to processing in the context of an establishment in the Union and to specified offering or monitoring by organisations outside the Union. | Run both tests on the actual processing; UK scope does not establish EU scope or the reverse. |
|---|
| Representatives | A controller or processor caught by Article 3(2) may need a representative established in the UK, subject to Article 27 exceptions. | A controller or processor caught by Article 3(2) may need a representative established in a member state where affected people are located, subject to Article 27 exceptions. | When both rules apply, one representative does not automatically satisfy both appointments. |
|---|
| Regulators and lead authority | The ICO supervises UK GDPR. UK GDPR does not use the EU one-stop-shop to make the ICO an EU lead authority. | Member-state authorities supervise EU GDPR; lead and concerned authority arrangements depend on the EU cross-border-processing rules. | Keep separate regulator and breach routes even when one incident affects both territories. |
|---|
| International transfers | UK exports use UK approval regulations, UK appropriate safeguards such as the IDTA or Addendum, or another UK route. | EEA exports use EU adequacy decisions, EU SCCs, binding corporate rules, or another EU Chapter V route. | Classify each export direction. The renewed EU adequacy decision covers qualifying EEA-to-UK transfers, not every transfer in the opposite direction. |
|---|
| Domestic law | The Data Protection Act 2018 supplies UK conditions, exemptions, enforcement procedure, and separate processing regimes. | EU GDPR leaves specified matters to Union or member-state law, so the applicable national rules can differ across member states. | A shared GDPR label is not enough for employment, health, research, journalism, public-interest, or children's-data decisions. |
|---|
| Current legal text | Includes UK amendments, including the Data (Use and Access) Act 2025 changes that commenced on different dates. | Retains the EU regulation text unless amended through EU law; UK legislation does not change it. | Version-control the legal basis for each control instead of assuming matching article numbers still produce matching answers. |
|---|
| Evidence and reuse | Keep the UK scope, role, lawful-basis, rights, regulator, transfer, and domestic-law records. | Keep the corresponding EU records and the member-state analysis where relevant. | Link shared notices, inventories, security controls, and assessments only after recording why they satisfy both current requirements. |
|---|