
Data protection sits at the centre of how modern businesses operate, and for many organisations across the UK, GDPR remains one of the most discussed pieces of legislation since its introduction. Whether you run a small consultancy in Farnborough or manage a marketing team for a national brand, the same question tends to surface regularly: is GDPR still law in the UK?
The short answer is yes, though the full picture is slightly more layered than that. Following the UK’s departure from the European Union, the legal framework around data protection underwent a formal transition, and understanding exactly where things stand today matters for anyone who handles personal data as part of their work.
Is the GDPR Still Applicable in the UK After Brexit?
When the UK left the European Union, the EU’s version of GDPR ceased to apply directly as domestic law. However, rather than creating a legal vacuum, the UK government converted the EU GDPR into domestic legislation through the European Union (Withdrawal) Act 2018, giving it continued legal force within the UK.
The result of this conversion is what is now known as the UK GDPR. It mirrors the EU GDPR in structure and principle, covering the same core obligations around lawful processing, data subject rights, accountability, and breach notification. For most organisations, the practical day-to-day requirements have not changed significantly, which is why GDPR remains the shorthand most people use even when referring to the UK-specific version.
| Aspect | EU GDPR | UK GDPR |
|---|---|---|
| Applies to | EU member states | United Kingdom |
| Legal basis | EU Regulation 2016/679 | EU (Withdrawal) Act 2018 |
| Supervisory authority | National DPAs (e.g. CNIL, BfDI) | Information Commissioner’s Office (ICO) |
| Maximum fine | €20 million or 4% global turnover | £17.5 million or 4% global turnover |
| Data subject rights | Right to access, erasure, portability etc. | Same rights retained in UK law |
| International transfers | Adequacy decisions by EU Commission | Adequacy regulations by UK Government |
| Status | Fully active | Fully active |
Looking to ensure your data remains GDPR compliant? Take a look at our Database Information here

What Replaced GDPR in the UK: The Role of the Data Protection Act 2018
A common misconception is that something entirely new replaced GDPR in the UK following Brexit. In reality, the UK GDPR works alongside the Data Protection Act 2018 (DPA 2018), which provides supplementary provisions and context for how data protection law applies in specific sectors and circumstances.
The DPA 2018 covers areas such as law enforcement processing, national security exemptions, and certain derogations that member states are permitted to apply under the EU GDPR framework. Together, the UK GDPR and DPA 2018 form the complete domestic data protection regime, with the Information Commissioner’s Office (ICO) acting as the independent regulator responsible for enforcement across England, Scotland, Wales, and Northern Ireland.
Will GDPR Be Scrapped? What the Data (Use and Access) Act Means for the UK
The question of whether GDPR will be scrapped in the UK has been debated actively in policy circles over recent years. The UK government proposed reforms through the Data Protection and Digital Information Bill, which went through several iterations before ultimately becoming the Data (Use and Access) Act 2025.
This legislation does not abolish UK GDPR. Instead, it introduces targeted amendments intended to reduce administrative burden on businesses, particularly smaller organisations, while retaining the fundamental rights and protections that individuals are entitled to. The ICO’s remit has also been updated to place greater emphasis on supporting economic growth alongside its regulatory duties, though core enforcement powers remain unchanged. You can read about the Data (Use and Access) Act directly via
| Reform Area | Previous Position (UK GDPR) | Post-Data (Use and Access) Act 2025 |
|---|---|---|
| Data Protection Officers | Required for certain organisations | Replaced by Senior Responsible Individual in some cases |
| Record of Processing Activities | Required for most controllers | Reduced requirements for lower-risk processing |
| Cookie consent | Opt-in required for non-essential cookies | Greater flexibility being phased in |
| Legitimate Interests | Balancing test required | Recognised interest categories introduced |
| International transfers | TRA mechanism | Retained with some simplification |
| ICO statutory objectives | Primarily privacy-focused | Now includes economic growth objective |
| Recognised Legitimate Interests | Not specified | Defined list introduced for clarity |
Is GDPR Still Applicable? Understanding Your Compliance Obligations Today
For anyone asking whether GDPR is still applicable in a practical sense, the answer is unambiguously yes. UK GDPR remains fully in force, and the ICO continues to investigate complaints, issue enforcement notices, and levy financial penalties against organisations that fail to comply.
High-profile enforcement cases continue to demonstrate that the ICO takes its responsibilities seriously. Fines have been issued across sectors including retail, financial services, and the public sector, and there is no indication that enforcement appetite has diminished. Organisations must continue to maintain privacy notices, honour subject access requests within the statutory timeframe, and implement appropriate technical and organisational measures to protect the personal data they hold. The ICO’s official guidance on your obligations under UK GDPR is available at ico.org.uk.
Is GDPR Still Law? What Every UK Organisation Needs to Know
The legal position is clear: GDPR, in its UK form, is very much still law and shows no signs of being removed from the statute book. The Data (Use and Access) Act 2025 refines certain processes and introduces some welcome simplifications, but it does not represent a dismantling of data protection rights in the UK. If anything, the reforms signal a mature approach to regulation, one that seeks to maintain trust while reducing unnecessary friction for compliant businesses.
For organisations operating across the UK and the EU simultaneously, it is also worth noting that EU GDPR still applies to the processing of EU residents’ personal data, even when that processing occurs outside EU borders. A business based in Hampshire serving customers in France or Germany must still comply with both UK GDPR and EU GDPR, which requires careful consideration of data flows and privacy documentation. Getting this wrong is not simply an administrative inconvenience; regulators on both sides of the Channel have demonstrated a willingness to act.
The most practical step any organisation can take right now is to treat UK GDPR compliance as an ongoing process rather than a one-time exercise. Privacy law continues to evolve, and the businesses that manage it well tend to be the ones that have built data protection thinking into their everyday operations from the ground up.
Is GDPR Still Law: Frequently Asked Questions
Yes, UK GDPR remains fully in force in 2025 as domestic legislation. It was retained following Brexit through the European Union (Withdrawal) Act 2018 and continues to be enforced by the ICO.
EU GDPR applies to organisations processing the personal data of individuals in EU member states, while UK GDPR applies within the United Kingdom. The two frameworks are closely aligned but diverge in areas such as international transfer mechanisms and supervisory authority.
No. Brexit meant the EU version of GDPR no longer applied directly, but the UK government incorporated it into domestic law as UK GDPR, maintaining the same core obligations for organisations operating in the UK.
Nothing replaced UK GDPR outright. The Data Protection Act 2018 works alongside UK GDPR to form the complete domestic framework, and the Data (Use and Access) Act 2025 introduced targeted updates rather than a wholesale replacement.
There are no plans to scrap UK GDPR. The Data (Use and Access) Act 2025 introduced reforms to reduce administrative burden, but the fundamental rights and obligations established under the framework remain intact.
The Information Commissioner’s Office (ICO) is the independent body responsible for enforcing UK GDPR. It investigates complaints, audits organisations, and can issue fines and enforcement notices where breaches are found.
The ICO can issue fines of up to £17.5 million or 4% of an organisation’s global annual turnover, whichever is higher, for the most serious infringements of UK GDPR. For less serious breaches, a lower tier of up to £8.7 million or 2% of global turnover applies.
Yes, UK GDPR applies to any organisation that processes personal data in the UK, regardless of size. However, the Data (Use and Access) Act 2025 introduced some reduced requirements for lower-risk processing activities carried out by smaller organisations.
If your organisation processes the personal data of individuals located in the EU, EU GDPR applies to that processing, even if your business is based in the UK. You can learn more about GDPR on its Wikipedia page.
A Subject Access Request (SAR) is a right granted to individuals under UK GDPR that allows them to request a copy of the personal data an organisation holds about them. Organisations generally must respond within one calendar month of receiving a valid request.
Personal data is any information that relates to an identified or identifiable living individual, including names, email addresses, IP addresses, location data, and health information. Special category data, such as biometric or genetic data, attracts additional protection under the legislation.
No. UK GDPR provides six lawful bases for processing personal data, including legitimate interests, contractual necessity, legal obligation, vital interests, and public task, in addition to consent. Organisations must identify and document the appropriate lawful basis before processing begins.
The Data (Use and Access) Act 2025 introduced changes including recognised legitimate interest categories, adjustments to the requirement for Data Protection Officers in certain organisations, and new provisions around automated decision-making. It did not remove core individual rights under UK GDPR.
The ICO publishes comprehensive guidance on all aspects of UK GDPR compliance, including templates, checklists, and sector-specific advice, at ico.org.uk. This is the most reliable and up-to-date source for organisations looking to understand their obligations.
