The framework
The UK regime has three moving parts: the UK GDPR (the retained EU text), the Data Protection Act 2018 that supplements it, and PECR, which governs cookies and electronic marketing. The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and amends all three. It adjusts the UK GDPR without replacing it, adding a list of recognised legitimate interests that skip the balancing test, naming direct marketing in the statute as a purpose that may qualify as a legitimate interest, loosening the rules on automated decision-making outside special category data, and setting a reasonable-and-proportionate standard for subject access searches.
Commencement is staged. The Commencement No. 6 Regulations (SI 2026/82) switched on the bulk of the Part 5 data protection and e-privacy amendments on 5 February 2026, with further provisions following from 19 June 2026 and beyond, including the ICO's reorganisation into the Information Commission. The compressed notice period, with much ICO guidance still in draft, drew criticism, and the ICO has said it will assess conduct against the law and guidance in force at the time.
For advertisers, the DUAA's biggest changes sit in PECR. Its cookie rule gains limited exceptions, so certain low-risk uses such as first-party statistics and appearance settings can run without consent, subject to transparency and opt-out safeguards. The Act also aligns PECR's penalty ceiling with UK GDPR levels, replacing the old GBP 500,000 cap, which turns email, SMS and cookie violations from a rounding error into a boardroom risk as commencement completes.
The EU renewed its adequacy decisions for the UK after reviewing the DUAA, a process launched on 22 July 2025 and completed before the old decisions lapsed, keeping EU-to-UK data flows free until the scheduled expiry on 27 December 2031, subject to ongoing monitoring. The UK runs its own adequacy list and approved transfer tools (the IDTA and the UK Addendum) for onward transfers.
Key instruments
UK GDPR + Data Protection Act 2018
The core framework: six legal bases, special category rules, data subject rights, ICO enforcement up to GBP 17.5M or 4% of turnover.
Privacy and Electronic Communications Regulations (PECR)
Opt-in consent for cookies and similar technologies and for unsolicited electronic marketing, with the soft opt-in for a seller's own similar products. The DUAA adds narrow cookie exceptions and raises penalties toward UK GDPR levels.
Data (Use and Access) Act 2025
Amends UK GDPR, DPA 2018 and PECR: recognised legitimate interests, direct marketing flagged as a possible legitimate interest, relaxed automated decision-making rules, subject access proportionality, smart data schemes, digital verification services, and the Information Commission.
Marketing and advertising
UK GDPR legal basis; PECR opt-in for cookies and e-marketing, with a soft opt-in for existing customers. Most channel decisions here follow from that consent rule.
For marketers, the UK is still an opt-in market: cookies and tracking need consent, cold email to consumers needs consent, and the soft opt-in only covers your own customers for similar products. What changed is the texture. Direct marketing by legitimate interest has statutory support for some processing around marketing, low-risk analytics cookies are being carved out of the consent rule, and the ICO has signalled a pro-growth posture. Treat none of that as a green light for third-party data buys; the consent rules for tracking and outreach remain intact.
Cross-border transfers
UK adequacy regulations, IDTA and the UK Addendum to EU SCCs; EU adequacy for the UK renewed in July 2025.
Enforcement and penalties
Fines reach GBP 17.5M or 4% of global annual turnover, whichever is higher.