Legal ComparisonUK and EUSubstantive differences

UK vs EU GDPR substantive differences

The UK's Data (Use and Access) Act 2025 changed the UK GDPR without changing EU GDPR. The clearest operational differences now affect lawful bases, rights requests, access searches, automated decisions, and transfers.

Use the consolidated UK text and the current EU regulation for separate conclusions. Similar article numbers no longer guarantee the same rule.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
27

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

Apply each regulation's territorial-scope test before comparing the rules. The and can both govern the same processing, but neither applies merely because an organisation has chosen to follow it. The UK text still shares most principles and duties with EU GDPR, while UK amendments that took effect by 5 February 2026 created material differences. The UK now has a basis tied to Annex 1, request timing and clarification rules, an express reasonable and proportionate Article 15 search limit, Articles 22A-22D for significant automated decisions, and a revised international-transfer test. These changes do not apply to processing governed only by EU GDPR. A shared control can use one operational design where that design satisfies both regimes, but the organisation should record the UK and EU scope and legal conclusions separately.

Legal-text comparison

Current UK and EU GDPR differences

Compare the rules most likely to require a branch in shared privacy controls.

Review all sources
First framework
Current UK GDPR

The consolidated UK text after commenced Data (Use and Access) Act 2025 amendments.

Second framework
Current EU GDPR

Regulation (EU) 2016/679, supplemented by applicable Union and member-state law.

Comparison row 1

Territorial scope

Current UK GDPR

Article 3 covers processing in the context of a UK establishment. It can also cover specified processing by a or outside the UK that offers goods or services to people in the UK or monitors their behaviour there.

Current EU GDPR

Article 3 covers processing in the context of an establishment in the Union. It can also cover specified processing by a or outside the Union that offers goods or services to people in the Union or monitors their behaviour there.

Operational implication

Test each processing activity against both Article 3 provisions. The same activity may fall under one regime, both regimes, or neither, depending on the facts.

Comparison row 2

Recognised legitimate interests

Current UK GDPR

Article 6(1)(ea) applies only when processing is necessary and meets a condition in Annex 1. It is separate from ordinary legitimate interests under Article 6(1)(f).

Current EU GDPR

has no Article 6(1)(ea) or Annex 1 route; controllers use an EU Article 6 basis, including Article 6(1)(f) where its balancing test is met.

Operational implication

Record the exact Annex 1 condition for UK reliance and do not copy that lawful-basis label into EU records.

Comparison row 3

Rights-request timing

Current UK GDPR

starts the one-month period from the latest of request receipt, receipt of identity information requested under Article 12(6), and payment of a fee charged under Article 12(5). A two-month extension is available when necessary because of complexity or number, with notice and reasons due before the first month ends.

Current EU GDPR

EU Article 12 requires action within one month of receiving the request. It permits a two-month extension where necessary because of complexity or number, with notice and reasons due within one month of receipt.

Operational implication

Calculate and retain the deadline separately when both regimes govern the request.

Comparison row 4

Access clarification and search

Current UK GDPR

For Article 15, a reasonable request for information needed to identify the requested information or processing activities pauses the response period and the extension-notice period until the person replies. Entitlement is limited to results of a .

Current EU GDPR

EU Articles 12 and 15 do not contain those UK clauses. Recital 63 says that, where a processes a large quantity of information about the person, it should be able to ask the person to specify the information or processing activities to which the request relates before providing the information.

Operational implication

Do not use the UK pause or search limit as the EU legal basis.

Comparison row 5

Significant automated decisions

Current UK GDPR

Articles 22A-22D define significant solely automated decisions, restrict decisions using special-category data or , and require information, representations, human intervention, and contest safeguards for significant solely automated decisions.

Current EU GDPR

Article 22 gives a person the right not to be subject to a solely automated decision producing legal or similarly significant effects, subject to stated contract, law, and explicit-consent exceptions and safeguards.

Operational implication

Test each workflow under both structures and document actual human involvement rather than relying on a manual approval label.

Comparison row 6

Transfer assessment

Current UK GDPR

Article 46 requires the or to act reasonably and proportionately and decide whether the safeguard and any other relevant means provide protection as a whole that is not materially lower than UK protection. The circumstances include the nature and volume of the data.

Current EU GDPR

EU Articles 44 and 46 require Chapter V compliance and, where Article 46 is used, appropriate safeguards, enforceable data-subject rights, and effective legal remedies. The are one Article 46 safeguard.

Operational implication

Keep a UK conclusion and an EU conclusion even if the factual destination analysis and supplementary measures overlap. Use an or plus the for the UK standard-clause route; EU SCCs alone do not satisfy that UK route.

Comparison row 7

Commencement

Current UK GDPR

The UK reforms commenced in stages. The majority of Part 5 data-protection and privacy changes took effect on 5 February 2026.

Current EU GDPR

UK commencement regulations do not change the EU regulation or member-state law.

Operational implication

Check the commencement date of the UK provision relied on and the current EU text for the relevant processing date.

Practical decision rule

How should teams manage divergence?

  • Version-control the current UK and EU provision behind each shared control.
  • Branch lawful-basis, rights-request, automated-decision, and transfer workflows where the legal test or evidence differs.
  • Reuse factual evidence only after documenting how it supports each jurisdiction's conclusion.
Section 1

Decide which regulation governs the processing

Article 3 covers processing in the context of a or establishment in the United Kingdom, wherever the processing occurs. It also covers specified processing by an organisation outside the UK when the processing relates to offering goods or services to people in the UK or monitoring their behaviour there. Article 3 uses parallel tests for an establishment in the Union and for offering goods or services to, or monitoring the behaviour of, people in the Union.

Run those tests for the processing activity, not only for the organisation as a whole. For example, a UK-established that offers an online service to people in an EU Member State may need both analyses if the processing falls within both Article 3 tests. A UK-to-EU business relationship does not automatically trigger both regulations.

  • Identify the and any , each relevant establishment, the activity to which the processing relates, where affected people are located, and whether the service targets or monitors people in the UK or Union.
  • Record the facts and the Article 3 branch for each regime. Reassess when a new establishment, market, service, tracking activity, or processing purpose changes those facts.
  • Where both regimes apply, keep the scope analysis and the resulting obligations identifiable for each regime even if one system stores the records.
  • Where only one regime applies, do not describe the other regime's amended wording as the legal basis for the processing.
Section 3

Separate automated-decision and transfer analyses

UK Article 22A defines a solely automated decision as one with no meaningful human involvement and a as one producing a legal or similarly significant effect. Article 22B restricts significant solely automated decisions that use special-category data and decisions relying on . Article 22C requires safeguards for every significant solely automated decision based entirely or partly on personal data, including information, representations, human intervention, and a right to contest. Article 22 instead gives a person the right not to be subject to a solely automated decision with a legal or similarly significant effect, subject to its stated exceptions and safeguards.

For a UK transfer relying on Article 46 safeguards, the or must act reasonably and proportionately and conclude that the is met. The test considers the post-transfer protection supplied as a whole by the safeguard and any other relevant means; it must not be materially lower than protection under UK data protection law. Articles 44 and 46 instead require Chapter V compliance, appropriate safeguards, enforceable data-subject rights, and effective legal remedies. The factual evidence may overlap, but a UK assessment is not the EU conclusion.

  • Map whether a decision is solely automated, whether it is significant, which data and lawful bases it uses, and what human involvement and safeguards are real in practice.
  • For a workflow subject to both regimes, test UK Articles 22A-22D and EU Article 22 separately before choosing a common design.
  • For each export, identify the exporter, direction, destination, transfer tool, assessment test, other or supplementary measures, outcome, owner, and review triggers such as a change in recipient, destination law, data, purpose, volume, or safeguard.
  • For a UK restricted transfer using standard clauses, use the or the with the UK . The EU SCCs alone are not valid for that UK purpose. If also governs the transfer, confirm that the contract package and assessment separately satisfy the EU route.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Sets the UK establishment, offering of goods or services, monitoring, and public-international-law territorial-scope tests.
eur-lex.europa.eu
Referenced sections
  • Provides the current EU rules.
eur-lex.europa.eu
Referenced sections
  • Sets the EU territorial-scope tests.
eur-lex.europa.eu
Referenced sections
  • Provides the EU request and access text and the recital on specifying a request where the controller processes a large quantity of information.
eur-lex.europa.eu
Referenced sections
  • Requires EU Chapter V compliance and, for Article 46 transfers, appropriate safeguards, enforceable data-subject rights, and effective legal remedies.
legislation.gov.uk
Referenced sections
  • Supports a processing-specific UK scope analysis; compare the EU Article 3 source in the adjacent cell.
legislation.gov.uk
Referenced sections
  • Limits the UK recognised basis to listed conditions.
legislation.gov.uk
Referenced sections
  • Expressly limits the UK entitlement by the reasonable and proportionate search.
legislation.gov.uk
Referenced sections
  • Makes meaningful human involvement part of the UK definition.
legislation.gov.uk
Referenced sections
  • Sets the UK territorial-scope tests.
legislation.gov.uk
Referenced sections
  • Sets the current UK data protection test.
legislation.gov.uk
Referenced sections
  • Sets both UK legitimate-interests routes and the closed current Annex 1 conditions.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.