Scope tag
Record the UK establishment or Article 3(2) offering or monitoring facts.
Record the Union establishment or Article 3(2) offering or monitoring facts.
Attach both conclusions to the activity when both regimes apply.
Use one inventory and control library, but route UK and EU representatives, regulators, rights requests, incidents, national-law decisions, and transfers through the correct jurisdiction.
The ICO is the UK regulator. EU lead-authority and one-stop-shop arrangements apply only when the EU GDPR conditions are met and do not replace the UK route.
Structured answer sets in this page tree.
Cited legal and guidance references.
This comparison focuses on operating the two regimes, not cataloguing every textual difference. A shared privacy programme can maintain one data inventory, vendor register, security baseline, and evidence store. It should still tag the governing regime, legal entity, establishment, people, representative, regulator, deadline, transfer direction, and national-law condition for each workflow. The EU does not combine the EU and UK routes. The same event can require separate UK and EU decisions even when one team and one technical control handle it.
Configure the same privacy programme for separate scope, contacts, requests, incidents, transfers, and evidence.
UK scope, UK representative where required, ICO supervision, and UK transfer tools.
EU scope, EU representative where required, member-state supervision, and EU transfer tools.
| Dimension | UK route | EU route | Operational implication |
|---|---|---|---|
| Scope tag | Record the UK establishment or Article 3(2) offering or monitoring facts. | Record the Union establishment or Article 3(2) offering or monitoring facts. | Attach both conclusions to the activity when both regimes apply. |
| Representative | Record the UK representative and its contact details when Article 27 requires one. | Record the EU representative and member state when EU Article 27 requires one. | Route people and regulators to the representative appointed for their regime. |
| Regulator route | Route UK complaints, consultations, and notifications to the ICO where the applicable rule requires it. | Identify the competent member-state authority and any valid lead or concerned authority arrangement. | One incident or complaint may create both routes. |
| Rights workflow | Use current UK Article 12A timing and clarification rules and the Article 15 reasonable and proportionate search rule. | Use EU Articles 12 and 15 and any applicable member-state restrictions. | The case system should preserve separate clocks, pauses, search rationale, exemptions, and response records. |
| Breach workflow | Assess notification to the ICO under UK Articles 33 and 34 and retain the UK risk and timing record. | Assess notification to the competent EU authority under EU Articles 33 and 34 and retain the EU risk and timing record. | Use one incident file with distinct regulator, deadline, content, and affected-person decisions. |
| Transfer workflow | For a UK restricted transfer, record the UK approval regulation, safeguard and assessment, or applicable exception. | For an EEA restricted transfer, record the EU adequacy decision, Article 46 safeguard and assessment, or applicable derogation. | A contract covering both directions should identify the UK and EU instruments and conclusions separately. |
| Shared evidence | Link the UK conclusion to the applicable inventory, notice, contract, assessment, incident, or response record. | Link the EU conclusion and any member-state analysis to the same artifact only where it satisfies the EU requirement. | Reuse the artifact, not an unsupported assumption that the legal tests are identical. |
Record the UK establishment or Article 3(2) offering or monitoring facts.
Record the Union establishment or Article 3(2) offering or monitoring facts.
Attach both conclusions to the activity when both regimes apply.
Record the UK representative and its contact details when Article 27 requires one.
Record the EU representative and member state when EU Article 27 requires one.
Route people and regulators to the representative appointed for their regime.
Route UK complaints, consultations, and notifications to the ICO where the applicable rule requires it.
Identify the competent member-state authority and any valid lead or concerned authority arrangement.
One incident or complaint may create both routes.
Use current UK Article 12A timing and clarification rules and the Article 15 reasonable and proportionate search rule.
Use EU Articles 12 and 15 and any applicable member-state restrictions.
The case system should preserve separate clocks, pauses, search rationale, exemptions, and response records.
Assess notification to the ICO under UK Articles 33 and 34 and retain the UK risk and timing record.
Assess notification to the competent EU authority under EU Articles 33 and 34 and retain the EU risk and timing record.
Use one incident file with distinct regulator, deadline, content, and affected-person decisions.
For a UK restricted transfer, record the UK approval regulation, safeguard and assessment, or applicable exception.
For an EEA restricted transfer, record the EU adequacy decision, Article 46 safeguard and assessment, or applicable derogation.
A contract covering both directions should identify the UK and EU instruments and conclusions separately.
Link the UK conclusion to the applicable inventory, notice, contract, assessment, incident, or response record.
Link the EU conclusion and any member-state analysis to the same artifact only where it satisfies the EU requirement.
Reuse the artifact, not an unsupported assumption that the legal tests are identical.
Tag processing activities by controller and processor entity, relevant establishment, target population, and UK or EU scope conclusion. Connect each privacy notice, request channel, DPIA, processor contract, retention rule, incident record, and transfer agreement to those tags rather than treating the corporate group as one controller.
Appoint separate UK and EU representatives when both Article 27 duties apply. Publish the correct contact details and give each representative access to the records needed for its jurisdiction. A DPO can support both regimes, but that does not merge the representative or supervisory-authority roles.
For a rights request, identify every controller and regime before calculating the response period, requesting clarification, searching, applying an exemption, or sending the response. Current UK Article 12A and Article 15 wording differs from EU Articles 12 and 15, so a shared case-management system needs jurisdiction-specific rules.
For an incident, assess UK and EU breach duties independently. Both regimes use a 72-hour supervisory-notification period where notification is required, but the recipient authority, risk analysis, content, delay explanation, and affected-controller duties must be recorded for each route. For a transfer, classify the exporter and direction before choosing adequacy, contractual clauses, or another safeguard.
The European Commission renewed the UK's GDPR adequacy decision on 19 December 2025. An EEA-to-UK transfer within that decision's scope does not need an additional EU Article 46 safeguard. The decision does not govern the opposite direction: a UK export still needs the applicable UK approval regulation, safeguard or exception.
Assign UK and EU scope, representative, regulator, request, incident, national-law, and transfer fields to each operational record.
Turn jurisdiction routing into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.