UK GDPR Explained: What Businesses Must Do to Stay Compliant
UK GDPR explained is usually a list of principles that has not been updated since 2018. That is now actively misleading, because the biggest set of changes to UK data protection law since Brexit commenced on 5 February 2026, and a further duty landed on 19 June 2026. This page sets out the framework as it now stands, and flags what moved.
Two documents, one regime: the UK GDPR and the Data Protection Act 2018, both amended by the Data (Use and Access) Act 2025.
The reform date: most of the data protection provisions came into force on 5 February 2026 under SI 2026/82.
The complaints duty: from 19 June 2026 controllers must acknowledge a data protection complaint within 30 days.
The ceiling: 17.5 million pounds or 4 per cent of global turnover, and PECR fines now reach the same level.
What the UK GDPR actually is
The UK GDPR is the retained version of the EU regulation, brought into domestic law at the end of the Brexit transition period. It does not stand alone. The Data Protection Act 2018 supplies the exemptions, the conditions for processing special category and criminal offence data, the law enforcement and intelligence services regimes, and the Information Commissioner's powers. Read either on its own and you will get the answer wrong.
It applies to any processing of personal data by an organisation established in the UK, and to organisations outside the UK that offer goods or services to people in the UK or monitor their behaviour here. Personal data means information relating to an identified or identifiable living person, which is a wider category than most organisations assume: an IP address, a staff number, a CCTV image and a pseudonymised record can all qualify.
The seven principles
Article 5 is the spine of the whole regime, and almost every enforcement action traces back to it.
- Lawfulness, fairness and transparency. You need a lawful basis, the processing must be fair to the person, and they must be told about it.
- Purpose limitation. Collect for specified, explicit and legitimate purposes, and do not reuse in a way incompatible with those purposes.
- Data minimisation. Adequate, relevant and limited to what is necessary. In practice this is the principle most often breached by default settings.
- Accuracy. Keep it accurate and up to date, and correct or erase what is wrong.
- Storage limitation. Keep it in identifiable form no longer than necessary. A retention schedule that nobody applies is not compliance.
- Integrity and confidentiality. Appropriate technical and organisational security.
- Accountability. You must be able to demonstrate all of the above. This is what turns good intentions into documentation.
Lawful bases, and the new list
Article 6 gives six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. You must identify one before you process, record which one you chose, and tell people in your privacy notice. You cannot swap between them later because the first one became inconvenient.
Since 5 February 2026 there is an additional route. The Data (Use and Access) Act 2025 introduced a list of recognised legitimate interests, including disclosures to public bodies performing public functions, national and public security, defence, emergency response, safeguarding, and the detection, investigation or prevention of crime. Where processing falls into one of those categories, the usual three-part legitimate interests balancing test does not have to be carried out.
Two cautions. The list is narrow and specific, so it is not a general-purpose shortcut. And it does not remove the other principles: you still need transparency, minimisation and security. For everything outside the list, the legitimate interests assessment remains exactly as it was.
Special category data, meaning health, race, ethnic origin, political opinions, religious beliefs, trade union membership, genetics, biometrics used for identification, sex life and sexual orientation, needs an Article 6 basis and a separate Article 9 condition. Criminal offence data needs an Article 6 basis and a Schedule 1 condition under the DPA 2018.
Individual rights, and what changed for subject access
People have the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights related to automated decision-making and profiling. Most of these are qualified rather than absolute; the right to erasure in particular does not apply where you are processing to comply with a legal obligation or to establish or defend legal claims.
The subject access request is where most organisations meet the regime in anger. The deadline is one calendar month from receipt, extendable by a further two months where the request is complex or where an individual has made a number of requests. The Act made two working practices explicit in law from 5 February 2026:
- Stop the clock. Where you reasonably need the requester to confirm their identity or to clarify the scope of a broad request, the response period pauses until they reply. This was already the ICO's published position; it is now in the legislation.
- Reasonable and proportionate search. You must make a reasonable and proportionate search, not an exhaustive one. What is reasonable depends on the volume, the difficulty of locating it, the nature of your business and your resources. This does not license a thin search, but it does end the argument that every backup tape must be restored.
Automated decision-making was also reframed. Article 22 previously started from a prohibition on solely automated decisions with legal or similarly significant effects. The reformed regime starts from permission with safeguards, and reserves the stricter treatment for decisions based wholly or partly on special category data. Our guide to data ethics for business covers what that means once the law stops deciding for you.
Breaches: the 72 hour clock
A personal data breach is any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Not every one has to be reported, but every one has to be assessed and recorded.
- Report to the ICO within 72 hours of becoming aware, where the breach is likely to result in a risk to people's rights and freedoms. If you report late you must explain the delay.
- Tell the individuals without undue delay where the breach is likely to result in a high risk to them.
- Record everything, including breaches you decide not to report and why. The internal log is the first thing the ICO asks for.
The 72 hours runs from awareness, not from the incident, and awareness starts when you have a reasonable degree of certainty that a security incident has compromised personal data. In practice that means your incident process, not your legal team, determines whether you hit the deadline.
The paperwork that actually gets checked
| Obligation | Who it applies to |
|---|---|
| Record of processing activities (Article 30) | All controllers and processors, with a narrow exemption for organisations under 250 staff that does not apply to risky, regular or special category processing |
| Privacy notice (Articles 13 and 14) | Everyone, and it must be specific about purposes, lawful bases and retention |
| Data protection impact assessment | Any processing likely to result in a high risk, including large-scale special category processing, systematic monitoring of public areas and new technologies |
| Data protection officer | Public authorities, and organisations whose core activities involve large-scale regular and systematic monitoring or large-scale special category or criminal data |
| Data protection fee | Most organisations processing personal data, unless exempt |
The fee is worth a sentence of its own because it is the cheapest thing on the list to get wrong. It runs to 52 pounds for a micro organisation with turnover up to 632,000 pounds or no more than 10 staff, 78 pounds for one up to 36 million pounds turnover or 250 staff, and 3,763 pounds for everyone else, each reduced by 5 pounds for paying by direct debit.
Complaints: the duty from 19 June 2026
Section 103 of the Data (Use and Access) Act inserted a new section 164A into the Data Protection Act 2018, in force from 19 June 2026. Controllers must make it easy to complain about data protection, including by providing an electronic complaints form, acknowledge a complaint within 30 days of receiving it, and take appropriate steps to respond and tell the complainant the outcome without undue delay.
The duty applies only to complaints received on or after 19 June 2026, and it applies whatever the size of the organisation. Most organisations already have a complaints route; the work is usually adding a data protection path to it, setting the 30 day acknowledgement as a hard service level, and logging outcomes so you can show the pattern. Our guide to building a compliance programme covers how to wire that into existing processes.
Enforcement, and what it now costs
The Information Commissioner can issue information notices, assessment notices, enforcement notices and penalty notices, and since 5 February 2026 can also require an organisation to commission and hand over a report by an approved person, and compel individuals to attend for interview.
Fines have two ceilings. The standard maximum is 8.7 million pounds or 2 per cent of total worldwide annual turnover, whichever is higher. The higher maximum is 17.5 million pounds or 4 per cent, and covers breaches of the principles, the lawful basis requirements, individual rights and international transfer rules.
The change that will catch people out is elsewhere. The Privacy and Electronic Communications Regulations, which govern marketing emails, texts, calls and cookies, previously carried a maximum penalty of 500,000 pounds. That ceiling has been lifted to the UK GDPR level of 17.5 million pounds or 4 per cent of global turnover. Nuisance marketing, which the ICO enforces far more often than it enforces the UK GDPR, has just become a materially larger financial risk.
On cookies, three new exemptions from the consent requirement arrived on 5 February 2026: statistical or analytics cookies, cookies that remember display and appearance preferences, and cookies used to provide emergency assistance. The first two still require a clear opt-out. Everything else, including advertising and tracking cookies, still needs consent.
A practical order of work
- Update the record of processing activities and check every lawful basis is still the right one, particularly anywhere you were relying on consent out of caution.
- Check whether any processing now falls inside the recognised legitimate interests list, and if so, record that decision rather than quietly dropping the assessment.
- Rewrite the subject access procedure to reflect the clock-stopping and reasonable search provisions, and train whoever triages requests.
- Stand up the data protection complaints route, with an electronic form and a 30 day acknowledgement SLA.
- Re-audit the cookie banner against the three new exemptions, and make sure the opt-out for the first two actually works.
- Rehearse the 72 hour breach process, timed, at least once a year.
- Confirm the data protection fee is paid and the tier is right.
Frequently Asked Questions
What is the UK GDPR?
The UK GDPR is the retained version of the EU General Data Protection Regulation, which became UK law at the end of the Brexit transition period and sits alongside the Data Protection Act 2018. The two documents work together: the UK GDPR sets the principles, rights and obligations, and the DPA 2018 supplies the exemptions, the special category conditions and the enforcement machinery. Both were amended by the Data (Use and Access) Act 2025.
What changed in the UK GDPR in 2026?
The bulk of the Data (Use and Access) Act 2025 data protection reforms commenced on 5 February 2026. They added a list of recognised legitimate interests that do not need a balancing test, clarified when personal data can be reused for a new purpose, put the ICO's "reasonable and proportionate" search standard and clock-stopping practice for subject access requests into the legislation, reframed the automated decision-making rules, created three new cookie consent exemptions, and raised the maximum PECR fine from 500,000 pounds to 17.5 million pounds or 4 per cent of global turnover. A separate duty to run a data protection complaints process followed on 19 June 2026.
What are the seven principles of the UK GDPR?
Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The first six tell you how to process. The seventh, accountability, tells you that you must be able to demonstrate the other six, which is why documentation matters as much as behaviour.
How long do we have to answer a subject access request?
One calendar month from receipt, extendable by a further two months where the request is complex or where you have received a number of requests from the same person. Since 5 February 2026 the legislation also recognises that the clock pauses while you are waiting for the requester to confirm their identity or clarify the scope of a broad request, and that your search has to be reasonable and proportionate rather than exhaustive.
Do we have to register with the ICO?
Most organisations that process personal data must pay the data protection fee unless an exemption applies. There are three tiers: 52 pounds for micro organisations with turnover up to 632,000 pounds or no more than 10 staff, 78 pounds for organisations up to 36 million pounds turnover or 250 staff, and 3,763 pounds for everyone else. Paying by direct debit takes 5 pounds off. Failing to pay is itself enforceable, separately from any data breach.
What is the maximum fine under the UK GDPR?
There are two tiers. The standard maximum is 8.7 million pounds or 2 per cent of total worldwide annual turnover, whichever is higher, and applies to breaches such as failures of record keeping or security. The higher maximum is 17.5 million pounds or 4 per cent of turnover, and covers breaches of the principles, the lawful basis requirements, individual rights and the rules on international transfers.
Sources
- Data (Use and Access) Act 2025, for royal assent on 19 June 2025 and the complaints duty in section 103
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, for the 5 February 2026 and 19 June 2026 commencement dates and the section 164A transitional provision
- ICO: guide to the data protection fee, for the three tiers and the amounts
More from E-Business Ethics: data ethics for business, how to run a DPIA and how to build a compliance programme.
Checked on 13 September 2026. This is general guidance, not legal advice; confirm the position with your data protection officer or legal adviser before relying on it.