Page Banner

Is GDPR still law?

Home » Blog » Is GDPR still law?

Data protection sits at the centre of how modern businesses operate, and for many organisations across the UK, GDPR remains one of the most discussed pieces of legislation since its introduction. Whether you run a small consultancy in Farnborough or manage a marketing team for a national brand, the same question tends to surface regularly: is GDPR still law in the UK?

The short answer is yes, though the full picture is slightly more layered than that. Following the UK’s departure from the European Union, the legal framework around data protection underwent a formal transition, and understanding exactly where things stand today matters for anyone who handles personal data as part of their work.

Is the GDPR Still Applicable in the UK After Brexit?

When the UK left the European Union, the EU’s version of GDPR ceased to apply directly as domestic law. However, rather than creating a legal vacuum, the UK government converted the EU GDPR into domestic legislation through the European Union (Withdrawal) Act 2018, giving it continued legal force within the UK.

The result of this conversion is what is now known as the UK GDPR. It mirrors the EU GDPR in structure and principle, covering the same core obligations around lawful processing, data subject rights, accountability, and breach notification. For most organisations, the practical day-to-day requirements have not changed significantly, which is why GDPR remains the shorthand most people use even when referring to the UK-specific version.

AspectEU GDPRUK GDPR
Applies toEU member statesUnited Kingdom
Legal basisEU Regulation 2016/679EU (Withdrawal) Act 2018
Supervisory authorityNational DPAs (e.g. CNIL, BfDI)Information Commissioner’s Office (ICO)
Maximum fine€20 million or 4% global turnover£17.5 million or 4% global turnover
Data subject rightsRight to access, erasure, portability etc.Same rights retained in UK law
International transfersAdequacy decisions by EU CommissionAdequacy regulations by UK Government
StatusFully activeFully active

Looking to ensure your data remains GDPR compliant? Take a look at our Database Information here

Funeral Directors Database


What Replaced GDPR in the UK: The Role of the Data Protection Act 2018

A common misconception is that something entirely new replaced GDPR in the UK following Brexit. In reality, the UK GDPR works alongside the Data Protection Act 2018 (DPA 2018), which provides supplementary provisions and context for how data protection law applies in specific sectors and circumstances.

The DPA 2018 covers areas such as law enforcement processing, national security exemptions, and certain derogations that member states are permitted to apply under the EU GDPR framework. Together, the UK GDPR and DPA 2018 form the complete domestic data protection regime, with the Information Commissioner’s Office (ICO) acting as the independent regulator responsible for enforcement across England, Scotland, Wales, and Northern Ireland.


Will GDPR Be Scrapped? What the Data (Use and Access) Act Means for the UK

The question of whether GDPR will be scrapped in the UK has been debated actively in policy circles over recent years. The UK government proposed reforms through the Data Protection and Digital Information Bill, which went through several iterations before ultimately becoming the Data (Use and Access) Act 2025.

This legislation does not abolish UK GDPR. Instead, it introduces targeted amendments intended to reduce administrative burden on businesses, particularly smaller organisations, while retaining the fundamental rights and protections that individuals are entitled to. The ICO’s remit has also been updated to place greater emphasis on supporting economic growth alongside its regulatory duties, though core enforcement powers remain unchanged. You can read about the Data (Use and Access) Act directly via

Reform AreaPrevious Position (UK GDPR)Post-Data (Use and Access) Act 2025
Data Protection OfficersRequired for certain organisationsReplaced by Senior Responsible Individual in some cases
Record of Processing ActivitiesRequired for most controllersReduced requirements for lower-risk processing
Cookie consentOpt-in required for non-essential cookiesGreater flexibility being phased in
Legitimate InterestsBalancing test requiredRecognised interest categories introduced
International transfersTRA mechanismRetained with some simplification
ICO statutory objectivesPrimarily privacy-focusedNow includes economic growth objective
Recognised Legitimate InterestsNot specifiedDefined list introduced for clarity
Contact Our Team: 01276 69 11 99

Is GDPR Still Applicable? Understanding Your Compliance Obligations Today

For anyone asking whether GDPR is still applicable in a practical sense, the answer is unambiguously yes. UK GDPR remains fully in force, and the ICO continues to investigate complaints, issue enforcement notices, and levy financial penalties against organisations that fail to comply.

High-profile enforcement cases continue to demonstrate that the ICO takes its responsibilities seriously. Fines have been issued across sectors including retail, financial services, and the public sector, and there is no indication that enforcement appetite has diminished. Organisations must continue to maintain privacy notices, honour subject access requests within the statutory timeframe, and implement appropriate technical and organisational measures to protect the personal data they hold. The ICO’s official guidance on your obligations under UK GDPR is available at ico.org.uk.

Is GDPR Still Law? What Every UK Organisation Needs to Know

The legal position is clear: GDPR, in its UK form, is very much still law and shows no signs of being removed from the statute book. The Data (Use and Access) Act 2025 refines certain processes and introduces some welcome simplifications, but it does not represent a dismantling of data protection rights in the UK. If anything, the reforms signal a mature approach to regulation, one that seeks to maintain trust while reducing unnecessary friction for compliant businesses.

For organisations operating across the UK and the EU simultaneously, it is also worth noting that EU GDPR still applies to the processing of EU residents’ personal data, even when that processing occurs outside EU borders. A business based in Hampshire serving customers in France or Germany must still comply with both UK GDPR and EU GDPR, which requires careful consideration of data flows and privacy documentation. Getting this wrong is not simply an administrative inconvenience; regulators on both sides of the Channel have demonstrated a willingness to act.

The most practical step any organisation can take right now is to treat UK GDPR compliance as an ongoing process rather than a one-time exercise. Privacy law continues to evolve, and the businesses that manage it well tend to be the ones that have built data protection thinking into their everyday operations from the ground up.

  • UK GDPR replaced EU GDPR as domestic law following Brexit and is enforced by the Information Commissioner’s Office, with penalties of up to £17.5 million or 4% of global annual turnover.
  • The Data (Use and Access) Act 2025 modernises certain aspects of the regime but does not remove core data subject rights or reduce the ICO’s enforcement powers.
  • Organisations processing the personal data of EU residents must comply with both UK GDPR and EU GDPR simultaneously, regardless of where they are based.

Is GDPR Still Law: Frequently Asked Questions

Is GDPR still law in the UK in 2025?

Yes, UK GDPR remains fully in force in 2025 as domestic legislation. It was retained following Brexit through the European Union (Withdrawal) Act 2018 and continues to be enforced by the ICO.

What is the difference between EU GDPR and UK GDPR?

EU GDPR applies to organisations processing the personal data of individuals in EU member states, while UK GDPR applies within the United Kingdom. The two frameworks are closely aligned but diverge in areas such as international transfer mechanisms and supervisory authority.

Did Brexit mean the UK no longer had to follow GDPR?

No. Brexit meant the EU version of GDPR no longer applied directly, but the UK government incorporated it into domestic law as UK GDPR, maintaining the same core obligations for organisations operating in the UK.

What replaced GDPR in the UK?

Nothing replaced UK GDPR outright. The Data Protection Act 2018 works alongside UK GDPR to form the complete domestic framework, and the Data (Use and Access) Act 2025 introduced targeted updates rather than a wholesale replacement.

Will GDPR be scrapped in the UK?

There are no plans to scrap UK GDPR. The Data (Use and Access) Act 2025 introduced reforms to reduce administrative burden, but the fundamental rights and obligations established under the framework remain intact.

Who enforces GDPR in the UK?

The Information Commissioner’s Office (ICO) is the independent body responsible for enforcing UK GDPR. It investigates complaints, audits organisations, and can issue fines and enforcement notices where breaches are found.

What are the maximum fines under UK GDPR?

The ICO can issue fines of up to £17.5 million or 4% of an organisation’s global annual turnover, whichever is higher, for the most serious infringements of UK GDPR. For less serious breaches, a lower tier of up to £8.7 million or 2% of global turnover applies.

Does UK GDPR apply to small businesses?

Yes, UK GDPR applies to any organisation that processes personal data in the UK, regardless of size. However, the Data (Use and Access) Act 2025 introduced some reduced requirements for lower-risk processing activities carried out by smaller organisations.

Do I still need to comply with EU GDPR if my business is based in the UK?

If your organisation processes the personal data of individuals located in the EU, EU GDPR applies to that processing, even if your business is based in the UK. You can learn more about GDPR on its Wikipedia page.

What is a Subject Access Request under UK GDPR?

A Subject Access Request (SAR) is a right granted to individuals under UK GDPR that allows them to request a copy of the personal data an organisation holds about them. Organisations generally must respond within one calendar month of receiving a valid request.

What counts as personal data under UK GDPR?

Personal data is any information that relates to an identified or identifiable living individual, including names, email addresses, IP addresses, location data, and health information. Special category data, such as biometric or genetic data, attracts additional protection under the legislation.

Is consent the only lawful basis for processing under UK GDPR?

No. UK GDPR provides six lawful bases for processing personal data, including legitimate interests, contractual necessity, legal obligation, vital interests, and public task, in addition to consent. Organisations must identify and document the appropriate lawful basis before processing begins.

What changed under the Data (Use and Access) Act 2025?

The Data (Use and Access) Act 2025 introduced changes including recognised legitimate interest categories, adjustments to the requirement for Data Protection Officers in certain organisations, and new provisions around automated decision-making. It did not remove core individual rights under UK GDPR.

Where can I find official guidance on UK GDPR compliance?

The ICO publishes comprehensive guidance on all aspects of UK GDPR compliance, including templates, checklists, and sector-specific advice, at ico.org.uk. This is the most reliable and up-to-date source for organisations looking to understand their obligations.

Further Reading About Marketing Databases