Artifact GuideUK and EUUK GDPR vs EU GDPR

UK GDPR vs EU GDPR

The regimes share their origin but now operate as separate laws. Test each regime against the organisation's establishments, target markets, monitoring, people, and data flows.

One activity can fall under both. Shared controls may produce evidence for both regimes, but scope, representatives, regulators, national-law conditions, transfers, and amended UK rules require separate conclusions.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
2

Structured answer sets in this page tree.

Primary sources
18

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

UK GDPR and EU GDPR are separate regimes. An organisation may be subject to one, both, or neither for a particular activity. Run the Article 3 test independently for the UK and the EU, identify the relevant controller or processor establishments, and check whether a non-established organisation offers goods or services to or monitors people in the relevant territory. Where both laws apply, one privacy programme can support both, but it cannot replace the separate legal analysis, representative, regulator, complaint, breach, transfer, and national-law decisions.

Side-by-side comparison

UK GDPR vs EU GDPR

Compare , representatives, regulators, transfers, domestic law, divergence, and evidence.

Review all sources
First framework
UK GDPR

The UK regime supervised by the ICO and supplemented by the Data Protection Act 2018.

Second framework
EU GDPR

The EU regime supervised by member-state authorities and supplemented by applicable Union and member-state law.

Comparison row 1

Territorial scope

UK GDPR

Applies to processing in the context of a UK establishment and to specified offering or monitoring by organisations outside the UK.

EU GDPR

Applies to processing in the context of an establishment in the Union and to specified offering or monitoring by organisations outside the Union.

Operational implication

Run both tests on the actual processing; UK scope does not establish EU scope or the reverse.

Comparison row 2

Representatives

UK GDPR

A controller or processor caught by Article 3(2) may need a representative established in the UK, subject to Article 27 exceptions.

EU GDPR

A controller or processor caught by Article 3(2) may need a representative established in a member state where affected people are located, subject to Article 27 exceptions.

Operational implication

When both rules apply, one representative does not automatically satisfy both appointments.

Comparison row 3

Regulators and lead authority

UK GDPR

The ICO supervises UK GDPR. UK GDPR does not use the EU one-stop-shop to make the ICO an EU lead authority.

EU GDPR

Member-state authorities supervise EU GDPR; lead and concerned authority arrangements depend on the EU cross-border-processing rules.

Operational implication

Keep separate regulator and breach routes even when one incident affects both territories.

Comparison row 4

International transfers

UK GDPR

UK exports use UK approval regulations, UK appropriate safeguards such as the IDTA or Addendum, or another UK route.

EU GDPR

EEA exports use EU adequacy decisions, EU SCCs, binding corporate rules, or another EU Chapter V route.

Operational implication

Classify each export direction. The renewed EU adequacy decision covers qualifying EEA-to-UK transfers, not every transfer in the opposite direction.

Comparison row 5

Domestic law

UK GDPR

The Data Protection Act 2018 supplies UK conditions, exemptions, enforcement procedure, and separate processing regimes.

EU GDPR

EU GDPR leaves specified matters to Union or member-state law, so the applicable national rules can differ across member states.

Operational implication

A shared GDPR label is not enough for employment, health, research, journalism, public-interest, or children's-data decisions.

Comparison row 6

Current legal text

UK GDPR

Includes UK amendments, including the Data (Use and Access) Act 2025 changes that commenced on different dates.

EU GDPR

Retains the EU regulation text unless amended through EU law; UK legislation does not change it.

Operational implication

Version-control the legal basis for each control instead of assuming matching article numbers still produce matching answers.

Comparison row 7

Evidence and reuse

UK GDPR

Keep the UK scope, role, lawful-basis, rights, regulator, transfer, and domestic-law records.

EU GDPR

Keep the corresponding EU records and the member-state analysis where relevant.

Operational implication

Link shared notices, inventories, security controls, and assessments only after recording why they satisfy both current requirements.

Practical decision rule

How should teams use this comparison?

  • Test UK and EU separately for each material activity.
  • Assign separate representatives, regulators, national-law checks, and transfer routes where required.
  • Reuse operational evidence only after documenting the legal conclusion for each regime.
Section 1

Decide which regime applies

UK GDPR applies to processing in the context of a UK controller or processor establishment. It can also apply to a controller or processor outside the UK when the processing relates to offering goods or services to people in the UK or monitoring their behaviour there. EU GDPR applies the corresponding tests for an establishment in the Union or for offering goods or services to or monitoring people in the Union.

A corporate group's office location, customer residence, server location, and contracting entity are relevant facts but none is a complete answer alone. Map the legal entity making each decision, the establishment whose activities are connected to the processing, the people targeted, the monitored behaviour, and the processor chain.

  • Write one UK Article 3 conclusion and one EU Article 3 conclusion for each material processing activity.
  • If Article 3(2) applies without an establishment, check the separate Article 27 representative requirement and its exceptions in each regime.
  • Identify the controller, joint controller, processor, and establishment for each side; do not assign scope only at group level.
  • Reassess when the organisation enters a new market, changes targeting or monitoring, moves decision-making, or changes contracting entities.
Section 2

Separate the jurisdiction-specific decisions

The ICO supervises UK GDPR. EU GDPR supervision belongs to member-state supervisory authorities, with the cooperation and consistency mechanisms and one-stop-shop rules available only when their conditions are met. The ICO cannot be an EU lead supervisory authority, and an EU lead authority does not replace the ICO for UK processing.

Transfer direction also matters. A restricted transfer from the UK uses the UK framework, including UK approval regulations, the IDTA or UK Addendum where appropriate, or another UK route. A restricted transfer from the EEA uses EU Chapter V. The European Commission renewed the UK's adequacy status in December 2025, so transfers from the EEA to the UK within that decision's scope do not need an additional Article 46 safeguard.

  • Maintain separate UK and EU regulator contacts, representative details, complaint routes, and breach-submission decisions.
  • Map each export direction and identify the applicable adequacy decision, contractual clauses, assessment, and derogation.
  • Apply relevant UK legislation or EU member-state law where the GDPR leaves room for domestic rules, including employment, health, research, journalism, and children's consent.
  • Use the current text for each regime; a UK amendment does not amend EU GDPR.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Supports the EU analysis.
eur-lex.europa.eu
Referenced sections
  • Sets the EU representative duty and exceptions.
legislation.gov.uk
Referenced sections
  • Requires establishment of the UK representative in the UK.
legislation.gov.uk
Referenced sections
  • Supports the separate UK scope conclusion.
legislation.gov.uk
Referenced sections
  • Assigns UK supervisory functions to the Commissioner.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.