DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Europe · In force · Opt-in

🇬🇧 United Kingdom Data Privacy Laws

The UK kept the GDPR after Brexit, then rewrote parts of it. The Data (Use and Access) Act 2025 is the biggest change since 2018, and most of its data protection provisions went live on 5 February 2026.

Updated September 28, 2026 · digitalprivacyregs.com
Status
In force
Consent model
Opt-in
Primary law
UK GDPR + Data Protection Act 2018 + PECR, amended by the Data (Use and Access) Act 2025
Year
2018
Authority
Information Commissioner's Office (ICO), the Information Commission from September 30, 2026
Marketing consent
UK GDPR legal basis; PECR opt-in for cookies and e-marketing, with a soft opt-in for existing customers.
Transfers
UK adequacy regulations, IDTA and the UK Addendum to EU SCCs; EU adequacy for the UK renewed in July 2025.
Penalties
Fines reach GBP 17.5M or 4% of global annual turnover, whichever is higher.

The framework

The UK regime has three moving parts: the UK GDPR (the retained EU text), the Data Protection Act 2018 that supplements it, and PECR, which governs cookies and electronic marketing. The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and amends all three. It adjusts the UK GDPR without replacing it, adding a list of recognised legitimate interests that skip the balancing test, naming direct marketing in the statute as a purpose that may qualify as a legitimate interest, loosening the rules on automated decision-making outside special category data, and setting a reasonable-and-proportionate standard for subject access searches.

Commencement is staged. The Commencement No. 6 Regulations (SI 2026/82) switched on the bulk of the Part 5 data protection and e-privacy amendments on 5 February 2026, with further provisions following from 19 June 2026 and beyond, including the ICO's reorganisation into the Information Commission. The compressed notice period, with much ICO guidance still in draft, drew criticism, and the ICO has said it will assess conduct against the law and guidance in force at the time.

For advertisers, the DUAA's biggest changes sit in PECR. Its cookie rule gains limited exceptions, so certain low-risk uses such as first-party statistics and appearance settings can run without consent, subject to transparency and opt-out safeguards. The Act also aligns PECR's penalty ceiling with UK GDPR levels, replacing the old GBP 500,000 cap, which turns email, SMS and cookie violations from a rounding error into a boardroom risk as commencement completes.

The EU renewed its adequacy decisions for the UK after reviewing the DUAA, a process launched on 22 July 2025 and completed before the old decisions lapsed, keeping EU-to-UK data flows free until the scheduled expiry on 27 December 2031, subject to ongoing monitoring. The UK runs its own adequacy list and approved transfer tools (the IDTA and the UK Addendum) for onward transfers.

Key instruments

UK GDPR + Data Protection Act 2018

2018 · In force

The core framework: six legal bases, special category rules, data subject rights, ICO enforcement up to GBP 17.5M or 4% of turnover.

Official source →

Privacy and Electronic Communications Regulations (PECR)

2003 · In force, amended

Opt-in consent for cookies and similar technologies and for unsolicited electronic marketing, with the soft opt-in for a seller's own similar products. The DUAA adds narrow cookie exceptions and raises penalties toward UK GDPR levels.

Official source →

Data (Use and Access) Act 2025

2025 · In force (staged); main data provisions from 5 Feb 2026

Amends UK GDPR, DPA 2018 and PECR: recognised legitimate interests, direct marketing flagged as a possible legitimate interest, relaxed automated decision-making rules, subject access proportionality, smart data schemes, digital verification services, and the Information Commission.

Official source →

Marketing and advertising

UK GDPR legal basis; PECR opt-in for cookies and e-marketing, with a soft opt-in for existing customers. Most channel decisions here follow from that consent rule.

For marketers, the UK is still an opt-in market: cookies and tracking need consent, cold email to consumers needs consent, and the soft opt-in only covers your own customers for similar products. What changed is the texture. Direct marketing by legitimate interest has statutory support for some processing around marketing, low-risk analytics cookies are being carved out of the consent rule, and the ICO has signalled a pro-growth posture. Treat none of that as a green light for third-party data buys; the consent rules for tracking and outreach remain intact.

Cross-border transfers

UK adequacy regulations, IDTA and the UK Addendum to EU SCCs; EU adequacy for the UK renewed in July 2025.

Enforcement and penalties

Fines reach GBP 17.5M or 4% of global annual turnover, whichever is higher.

Primary sources

Cite this page: "United Kingdom Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/united-kingdom.html. Accessed [date].