United Kingdom General Data Protection Regulation

United KingdomPrivacy2021
ByDecipherU Editorial

The UK GDPR is the retained version of the EU GDPR, forming the core cybersecurity and data protection law in the UK after Brexit. It operates alongside the Data Protection Act 2018. The Information Commissioner's Office (ICO) enforces it, and its requirements closely mirror EU GDPR, including 72-hour breach notification and Data Protection Impact Assessments.

Quick Reference

EnactedJanuary 1, 2021 (retained from EU GDPR post-Brexit)
Enforcement BodyInformation Commissioner's Office (ICO)
PenaltiesUp to 17.5 million GBP or 4% of global annual turnover, whichever is higher
Applicable ToOrganizations processing personal data of UK residents, regardless of where the organization is based

Key Requirements

Article 5 (Principles)

Same as EU GDPR: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality

Article 33 (Notification to Commissioner)

Controllers must notify the ICO of personal data breaches within 72 hours of becoming aware

Article 35 (Data Protection Impact Assessment)

Controllers must conduct a DPIA before processing likely to result in high risk to individuals

How Does UK GDPR Affect Cybersecurity Careers?

Cybersecurity professionals working with UK data or UK-based companies must understand UK GDPR alongside EU GDPR. The divergence between UK and EU data protection regimes (through future UK reforms) means professionals need to track both. DPO roles are required for the same categories of organizations as under EU GDPR.

How Does UK GDPR Affect Cybersecurity Sales?

Vendors serving UK customers face the same privacy technology requirements as under EU GDPR. The UK's international data transfer mechanisms (UK adequacy decisions, UK International Data Transfer Agreements) require specific compliance tooling. Sales teams should understand the UK's separate adequacy determination from the EU when discussing cross-border data flows.

Cybersecurity Roles That Work With UK GDPR

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of UK GDPR at the official source: https://www.legislation.gov.uk/eur/2016/679/contents

Frequently Asked Questions

The UK GDPR is the retained version of the EU GDPR, forming the core cybersecurity and data protection law in the UK after Brexit. It operates alongside the Data Protection Act 2018. The Information Commissioner's Office (ICO) enforces it, and its requirements closely mirror EU GDPR, including 72-hour breach notification and Data Protection Impact Assessments.

Cybersecurity professionals working with UK data or UK-based companies must understand UK GDPR alongside EU GDPR. The divergence between UK and EU data protection regimes (through future UK reforms) means professionals need to track both. DPO roles are required for the same categories of organizations as under EU GDPR.

Up to 17.5 million GBP or 4% of global annual turnover, whichever is higher

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?