UK GDPR for US Businesses

UK GDPR for US Businesses: The Legal Framework and How It Differs from EU GDPR

A guide to the United Kingdom’s data protection regime for US-based organisations operating across the Atlantic

Data Protection Law  |  Updated April 2026

For US businesses that collect, process, or transfer the personal data of individuals located in the United Kingdom, compliance with UK data protection law is not optional. The UK maintains a comprehensive, independently governed data protection regime that is distinct from the European Union’s General Data Protection Regulation — even though it was built from the same foundations. Understanding what the UK framework is, how it is composed, and how it diverges from the EU’s approach is essential for any US organisation operating in or transacting with the UK market.

Background: From EU GDPR to UK GDPR

When the United Kingdom left the European Union, one of the most immediate consequences in the data protection sphere was the question of what would happen to the EU’s General Data Protection Regulation, which had applied directly in UK law since May 2018. The EU GDPR is an EU regulation — it has direct effect across EU Member States — but the UK’s departure from the EU meant that, from January 1, 2021, the EU GDPR ceased to apply in the United Kingdom.

To prevent a legal vacuum, the UK government used powers under the European Union (Withdrawal) Act 2018 to “retain” the text of the EU GDPR in UK domestic law, amending it as necessary to make it function as a standalone national instrument rather than an EU regulation. This retained and amended version of the regulation is what practitioners now call the “UK GDPR.” It sits alongside, and is supplemented by, the Data Protection Act 2018 and — most recently — the Data (Use and Access) Act 2025. Together, these instruments form the core of the United Kingdom’s data protection framework.

The result is a regime that is, in many respects, substantively similar to the EU GDPR. The key principles of data protection — lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability — are preserved in identical form. The rights afforded to data subjects, including the rights to access, rectification, erasure, restriction, portability, and to object to processing, are carried over in largely equivalent terms. For US businesses already familiar with EU GDPR compliance, the UK framework will feel recognisable. However, the differences are numerous and increasingly significant as the two regimes continue to diverge.

The Legislative Framework: What Composes UK GDPR?

Unlike the EU GDPR, which is a single supranational regulation, the UK’s data protection framework is a composite of several instruments that must be read together to understand the full scope of obligations.

The UK GDPR

The UK GDPR is the foundation of the framework. Its text is largely derived from the EU GDPR but has been modified in important ways to reflect the UK’s status as a third country outside the EU. References to EU institutions — the European Data Protection Board, the European Commission, and EU Member States — have been replaced with references to UK equivalents, primarily the Secretary of State and the Information Commissioner’s Office. Provisions that relied on EU-level coordination mechanisms have been adapted or removed. The UK GDPR establishes the same principal obligations that US businesses will recognise from the EU framework: the requirement for a lawful basis for processing, the rules on special category data, the obligations governing data processors, the requirements for data protection impact assessments, and the rules on international data transfers.

The Data Protection Act 2018

The Data Protection Act 2018 (DPA 2018) pre-dates Brexit and was enacted to supplement and give domestic effect to the EU GDPR during the UK’s EU membership. Post-Brexit, it continues to sit alongside the UK GDPR and performs a number of important functions. First, it implements the EU’s Law Enforcement Directive for processing by competent authorities for law enforcement purposes — a distinct regime from the UK GDPR proper. Second, it provides for intelligence services processing, which falls outside both the UK GDPR and the law enforcement regime. Third, and most significantly for most commercial organisations, it contains a series of exemptions and derogations from UK GDPR obligations that have been given domestic legislative form. These include exemptions for national security and defence, immigration enforcement, journalism and academic research, legal professional privilege, and crime and taxation. The immigration enforcement exemption is one notable area where UK data protection law has attracted controversy, having been the subject of litigation regarding its compatibility with the broader UK GDPR framework.

The DPA 2018 also establishes the Information Commissioner’s Office (ICO) on a statutory footing and sets out the Commissioner’s powers, including investigatory, corrective, and advisory powers, as well as the fining regime. For US organisations, the DPA 2018 is not a standalone compliance instrument in the way the EU GDPR is for EU-based entities — it must always be read alongside the UK GDPR — but it contains provisions that materially affect compliance obligations, particularly in relation to exemptions and the enforcement landscape.

The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on June 19, 2025 and represents the most significant reform to the UK’s data protection framework since Brexit. It amends both the UK GDPR and the DPA 2018 in a number of important respects. Its passage also proved consequential for the UK’s relationship with the EU: the European Commission, which had been reviewing whether to renew the UK’s adequacy status following the expiry of the original four-year adequacy decisions, extended those decisions through December 2025 while it assessed the DUAA’s impact on the UK’s data protection standards. In December 2025, the Commission renewed the adequacy decisions for a further period running until December 2031, having concluded that the UK’s framework — including the changes introduced by the DUAA — continues to ensure a level of protection essentially equivalent to that of the EU.

The DUAA introduces several changes of direct relevance to US businesses. It introduces a concept of “recognised legitimate interests,” a non-exhaustive list of processing activities that are deemed to satisfy the legitimate interests lawful basis without the need for the data controller to carry out a formal Legitimate Interests Assessment. It modifies the rules on automated decision-making, narrowing the scope of protections so that the key safeguards against solely automated decisions apply primarily where special category data is involved, rather than to all automated decisions with legal or similarly significant effects. It also amends the international data transfers regime, as discussed below. The DUAA’s provisions are being brought into force on a phased basis through commencement regulations, and US businesses should monitor implementation timelines carefully.

The Privacy and Electronic Communications Regulations 2003

No account of the UK’s data protection framework would be complete without reference to the Privacy and Electronic Communications Regulations 2003 (PECR). PECR implements the EU’s ePrivacy Directive in UK domestic law and governs electronic marketing, cookies and similar tracking technologies, and the security of electronic communications services. For US businesses engaged in email marketing, digital advertising, or the operation of websites accessed by UK users, PECR compliance runs in parallel with UK GDPR compliance and is enforced by the ICO. PECR’s cookie consent rules in particular are a routine compliance consideration for US companies with a UK-facing online presence.

Key Differences Between the UK GDPR and the EU GDPR

For US businesses that are already compliant with the EU GDPR — or that are building a compliance programme covering both regimes simultaneously — the following differences are the most practically significant.

Supervisory Authority and Enforcement

Under the EU GDPR, supervisory authority is distributed across the national data protection authorities (DPAs) of all EU Member States, coordinated through the European Data Protection Board (EDPB). The “one-stop-shop” mechanism allows organisations with a main establishment in one EU Member State to deal primarily with that state’s DPA for cross-border processing activities, with the lead supervisory authority coordinating with other concerned DPAs. Under the UK GDPR, there is a single supervisory authority: the Information Commissioner’s Office. The ICO has jurisdiction over processing that takes place in the UK or that involves the personal data of UK data subjects, and there is no one-stop-shop equivalent that would allow a US organisation to designate a preferred point of contact across multiple territories. A US business that processes data subject to both the EU GDPR and the UK GDPR may, in principle, face parallel investigative or enforcement action from EU DPAs and from the ICO simultaneously.

The ICO’s approach to enforcement has, to date, generally been considered somewhat more pragmatic than that of some EU DPAs, though it has issued substantial fines — up to £17.5 million or 4% of global annual turnover, whichever is higher — and has demonstrated willingness to investigate complaints from UK data subjects. US businesses should not assume that ICO oversight is lighter than EU oversight; the regulatory appetite and capacity of the ICO has grown considerably in recent years.

UK Representative Requirements

Both the EU GDPR and the UK GDPR impose a requirement on organisations that are not established in the relevant territory but that are subject to the regulation’s extraterritorial reach to designate a local representative. Under the EU GDPR, a non-EU organisation must appoint a representative established in one of the EU Member States in which its data subjects are located. Under the UK GDPR, the equivalent obligation requires a UK-established representative to be designated. These are separate obligations: a US business subject to both regimes must appoint both an EU representative and a separate UK representative. They cannot be the same entity unless that entity is established in both territories. This is a practical administrative burden that US businesses sometimes underestimate when initially setting up their compliance infrastructure.

International Data Transfers

This is the area where the UK GDPR has diverged most visibly from the EU GDPR. The EU GDPR restricts the transfer of personal data to third countries that do not benefit from an adequacy decision, unless an appropriate safeguard is in place. The principal mechanism for transfers from the EU is the use of Standard Contractual Clauses (SCCs) issued by the European Commission. The most recent set of EU SCCs, adopted in 2021, replaced earlier versions and introduced a modular structure covering controller-to-controller, controller-to-processor, processor-to-controller, and processor-to-processor transfer scenarios.

The UK operates its own parallel system. The ICO has issued two primary instruments for international data transfers from the UK. The first is the International Data Transfer Agreement (IDTA), a standalone contract that governs restricted transfers from the UK and replaces the old EU SCCs for UK-originating transfers. The second is the UK Addendum to the EU SCCs, which allows parties that have already signed the 2021 EU SCCs to “top up” that agreement so that it also covers UK-to-third-country transfers, without needing to execute the full IDTA as a separate document. US organisations receiving data from UK-based entities should be familiar with both instruments and should ensure that their transfer agreements are updated to incorporate the appropriate UK mechanism, in addition to any EU SCC they have already signed.

The DUAA has also introduced changes to how the UK assesses adequacy for third countries. Under the amended framework, the Secretary of State will assess whether a destination country’s data protection standards are “not materially lower” than the standard in the UK — a test that is arguably more flexible than the EU’s “essential equivalence” standard, and which may lead to divergence in the list of countries the UK considers adequate versus those recognised as adequate by the European Commission.

Adequacy Status: UK and US The United States does not currently hold an adequacy decision from the UK. Transfers of personal data from the UK to the United States must therefore rely on appropriate safeguards, typically the IDTA or the UK Addendum to the EU SCCs. US organisations should also note that the equivalent EU-to-US mechanism — the EU-US Data Privacy Framework — does not cover UK-to-US transfers. Separate UK adequacy or transfer mechanism analysis is required for UK-originating data flows.

Lawful Bases for Processing: Recognised Legitimate Interests

The six lawful bases for processing personal data — consent, contract, legal obligation, vital interests, public task, and legitimate interests — are substantively identical in the UK GDPR and the EU GDPR. However, the DUAA has introduced a UK-specific modification to the legitimate interests basis that represents a meaningful divergence. The DUAA creates a category of “recognised legitimate interests,” which are processing activities for which a data controller is permitted to rely on the legitimate interests basis without conducting a balancing test or Legitimate Interests Assessment. The initial list of recognised legitimate interests is set out in statute and includes, for example, certain processing activities for the purposes of national security, public safety, and the prevention or detection of crime.

This departure from the EU GDPR model — under which a Legitimate Interests Assessment is always expected when relying on the legitimate interests basis — is one of the clearer signals that the UK intends to use its post-Brexit legislative freedom to calibrate data protection obligations differently from the EU. For US businesses, the practical impact will depend on the specific processing activity in question, but it represents an area of growing divergence to monitor.

Automated Decision-Making

The EU GDPR contains a provision — Article 22 — that grants data subjects the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. This right applies broadly and is subject to specific exceptions. The UK GDPR carried over an equivalent provision, but the DUAA has substantially narrowed its scope. Under the amended UK regime, the key safeguards against solely automated decision-making now apply primarily where special category data is involved. Where decisions are based solely on non-special-category data, the prior restrictions have been largely removed, representing a significant relaxation of the protections available to UK data subjects compared to those available under the EU GDPR. For US technology companies deploying AI-driven decision-making tools in the UK — such as algorithmic credit scoring, insurance pricing, or automated hiring screening — this shift is directly relevant and may require a revision of existing data protection impact assessments and subject-facing privacy notices.

Data Protection Officers

The UK GDPR retains the requirement to appoint a Data Protection Officer (DPO) for public authorities, organisations that carry out large-scale systematic monitoring of individuals as a core activity, and organisations that process special category data or criminal offence data at large scale as a core activity. These thresholds are essentially identical to those in the EU GDPR. However, the DUAA introduces a concept of “Senior Responsible Individual” as an alternative to the DPO for certain types of organisations, which may affect how some UK-based entities structure their data governance. US businesses processing UK personal data are unlikely to be required to appoint a UK DPO unless they fall within the relevant categories, but those subject to both regimes should assess their obligations under each separately, as an EU GDPR DPO appointment does not automatically satisfy the UK obligation.

Codes of Conduct and Certification

Both the EU GDPR and the UK GDPR provide for the development of codes of conduct and certification mechanisms as tools for demonstrating compliance. In the EU, the EDPB plays a central coordinating role in approving codes and accrediting certification bodies, and a number of significant EU-level codes and certifications have been developed in sectors such as cloud computing and direct marketing. In the UK, the ICO has its own process for approving codes of conduct and certification schemes, and the ICO has published or endorsed codes in areas including direct marketing, data sharing, and the use of cookies. These are separately governed processes, and EU-approved codes do not automatically carry over to the UK. US businesses seeking to use codes of conduct or certification as a compliance tool must verify whether the relevant scheme has been approved under the applicable regime — EU, UK, or both.

Exemptions and Derogations

The DPA 2018 gives concrete statutory form to the exemptions and derogations that the UK has adopted from the menu of options available under the UK GDPR. Some of these mirror EU GDPR derogations closely; others reflect distinctly UK policy choices. The immigration exemption under Schedule 2 of the DPA 2018 — which restricts certain data subject rights where their exercise would prejudice immigration control — has no direct EU equivalent and reflects the UK government’s view that data protection rights must be balanced against immigration enforcement objectives. Similarly, the DPA 2018’s provisions on journalism, academic research, and freedom of expression contain UK-specific thresholds and procedural requirements. For US businesses engaged in research, journalism, or activities that may intersect with these exemptions, the UK-specific derogation framework warrants careful attention.

The EU’s Adequacy Decision for the UK: Current Status and Significance for US Businesses

One of the most consequential aspects of the UK-EU data protection relationship, from a practical standpoint, is the European Commission’s adequacy decision for the UK. In June 2021, the Commission adopted adequacy decisions concluding that the UK provides a level of data protection essentially equivalent to that of the EU, covering both the UK GDPR framework and the equivalent regime for law enforcement processing. Those decisions initially carried a four-year sunset clause. Before their expiry, the Commission extended and then renewed them, with the renewed adequacy decisions issued in December 2025 now valid until December 2031.

The adequacy status of the UK is of direct relevance to US businesses that act as data processors or sub-processors in transfer chains involving EU-to-UK and UK-to-US data flows. Where a US company receives personal data from an EU-based controller that has been transferred to a UK-based intermediary, the existence of an EU adequacy decision for the UK means that the EU-to-UK transfer does not require SCCs or other safeguards. The UK-to-US onward transfer, however, still requires an appropriate mechanism. US businesses should map their data flows carefully to understand how the adequacy status of the UK affects their contractual obligations and where separate transfer safeguards remain necessary.

It is also worth noting that the UK itself has adopted adequacy regulations for a number of countries, meaning that UK personal data can flow freely to those countries without requiring IDTAs or other safeguards. The list of countries the UK considers adequate is largely aligned with the EU’s list but is independently maintained and has begun to diverge. US businesses operating as part of global transfer chains need to be alive to this divergence and should not assume that a country considered adequate by the EU is necessarily also considered adequate by the UK.

Practical Implications for US Businesses

US businesses subject to UK GDPR have the same core compliance obligations as they would under the EU GDPR — maintaining records of processing activities, ensuring lawful bases are identified for each processing operation, honoring data subject rights requests within the applicable time limits, implementing appropriate technical and organisational security measures, notifying the ICO of personal data breaches within 72 hours, and conducting data protection impact assessments for high-risk processing. However, a number of UK-specific action points deserve emphasis.

First, US businesses that are already EU GDPR compliant should not assume that their existing documentation, policies, and contracts automatically satisfy UK GDPR requirements. Privacy notices, data processing agreements, transfer mechanisms, and DPO appointment records may all require UK-specific review and updating. In particular, transfer mechanisms must reflect the correct UK instrument — the IDTA or UK Addendum — rather than simply relying on EU SCCs, which do not cover UK-to-third-country transfers.

Second, the DUAA’s ongoing implementation means that the UK GDPR compliance landscape is actively changing. The phased commencement of the DUAA’s provisions through 2025 and 2026 means that certain obligations are coming into force on a rolling basis. US businesses should ensure they are monitoring ICO guidance and statutory commencement orders to track which provisions are now in force and what changes to existing compliance programmes are required.

Third, US businesses should give careful thought to how they handle UK data subject rights requests. The ICO has made consumer rights enforcement a priority area, and failure to respond to Subject Access Requests, erasure requests, or objection requests within the prescribed period can result not only in enforcement action but also in complaints to the ICO that trigger formal investigations. US businesses should have clear internal processes for identifying when a request relates to UK personal data and for routing those requests to a team capable of responding within the one-month (extendable in limited circumstances) deadline.

Key Takeaway for US Legal Counsel The UK GDPR is not the EU GDPR. While they share common origins and many substantive provisions, US businesses that treat UK compliance as an automatic consequence of EU GDPR compliance run significant legal risk. The differences in transfer mechanisms, supervisory authority, representative requirements, automated decision-making rules, and the evolving DUAA implementation create a set of discrete UK obligations that require dedicated attention in any transatlantic data protection programme.

Conclusion

The United Kingdom’s data protection framework is a sophisticated, multi-layered regime composed principally of the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025, with the Privacy and Electronic Communications Regulations 2003 governing electronic marketing and cookies in parallel. For US businesses, the framework carries significant extraterritorial reach: any US organisation that offers goods or services to individuals in the UK, or that monitors the behaviour of individuals in the UK, is subject to the UK GDPR regardless of where the organisation is based.

While the UK GDPR and the EU GDPR share common roots and many substantive provisions, the regimes have diverged in important ways since Brexit, and that divergence is accelerating. The UK’s independent transfer mechanism infrastructure, its modified lawful basis framework, its narrowed automated decision-making protections, and its separately maintained adequacy list are all areas where the two regimes now differ. US businesses cannot assume that EU GDPR compliance carries over to the UK. A properly structured transatlantic data protection programme must account for both regimes as separate, parallel obligations — each with its own supervisory authority, enforcement risks, and evolving compliance requirements.

If your organisation collects, processes, or transfers personal data relating to UK individuals and you have questions about whether UK GDPR applies to your activities, or about how to structure a compliant data transfer programme covering both the UK and the EU, please contact our data protection practice group.

This article is provided for general informational purposes only and does not constitute legal advice. It reflects the law as of April 2026. Data protection law is a rapidly evolving area, and readers should seek specific legal advice in relation to their individual circumstances. No attorney-client relationship is created by reading this content.