For four years after Brexit, comparing UK GDPR and EU GDPR was largely an academic exercise. The UK GDPR was the EU regulation copied into domestic law with the references changed. The two were near-identical.

That changed on 5 February 2026, when the substantive data protection provisions of the Data (Use and Access) Act 2025 came into force. The DUAA does not replace the UK GDPR. It amends it, and the amendments create genuine operational divergence in five areas: legitimate interests, automated decision-making, subject access requests, cookies, and international transfers.

The European Commission renewed the UK’s adequacy decisions on 19 December 2025, extending free data flows from the EEA to the UK until 27 December 2031. Adequacy survived the DUAA. It is not guaranteed to survive whatever comes next.

This guide sets out where the two regimes now differ, what that means for organisations processing personal data in both jurisdictions, and why applying the more permissive UK standard across the board is the most common and most expensive mistake being made right now.

Key Definitions

TermDefinition
EU GDPRRegulation (EU) 2016/679. Applies directly across all EU member states since 25 May 2018
UK GDPRThe EU GDPR as retained in UK domestic law from 1 January 2021, as amended by the DPA 2018 and the DUAA 2025
DPA 2018Data Protection Act 2018. The UK statute that supplements the UK GDPR with national provisions, exemptions, and enforcement powers
DUAAData (Use and Access) Act 2025. Royal Assent 19 June 2025. Main data protection provisions in force 5 February 2026
Recognised legitimate interestsA new lawful basis under UK GDPR Article 6, covering a closed list of purposes, requiring no balancing test
Adequacy decisionA European Commission determination that a third country provides essentially equivalent data protection, permitting transfers without additional safeguards
ICOInformation Commissioner’s Office. The UK data protection regulator, transitioning to the Information Commission under the DUAA
EDPBEuropean Data Protection Board. Coordinates GDPR interpretation across EU supervisory authorities

How the Two GDPR Regimes Came Apart

The EU GDPR applied directly in the UK from 25 May 2018 until 31 December 2020. On 1 January 2021, the European Union (Withdrawal) Act incorporated the GDPR into UK domestic law as the UK GDPR, with statutory instruments correcting references that no longer made sense. “The Union” became “the United Kingdom.” Supervisory authority references became the ICO.

That near-identity was the basis on which the European Commission granted the UK an adequacy decision in June 2021.

The first attempt at reform, the Data Protection and Digital Information Bill, failed when Parliament was dissolved before the 2024 general election. Its successor, the Data (Use and Access) Act 2025, received Royal Assent on 19 June 2025 and commenced in phases through early 2026.

DateDevelopment
25 May 2018EU GDPR applies, including in the UK
1 January 2021UK GDPR comes into existence as retained law
28 June 2021EU grants UK adequacy decision
2023-2024Data Protection and Digital Information Bill fails
19 June 2025DUAA receives Royal Assent
19 December 2025EU renews UK adequacy to 27 December 2031
5 February 2026Main DUAA data protection provisions in force
19 June 2026DUAA complaints handling requirement in force
Late 2026 (expected)ICO transitions to Information Commission

The Five Areas of GDPR Divergence

1. Recognised Legitimate Interests

This is the most structurally significant change the DUAA introduced.

Under EU GDPR Article 6(1)(f), a controller relying on legitimate interests must conduct a three-part balancing test: identify the legitimate interest, demonstrate that processing is necessary for it, and show that the interest is not overridden by the interests or fundamental rights of the data subject. That assessment is documented in a Legitimate Interests Assessment.

The DUAA inserts a new lawful basis into UK GDPR Article 6: recognised legitimate interests. For a closed list of purposes, no balancing test is required. The controller must still satisfy the other GDPR principles, but the LIA obligation falls away for the listed purposes.

FeatureEU GDPRUK GDPR (post-DUAA)
Legitimate interests basisArticle 6(1)(f), balancing test requiredArticle 6(1)(f) retained, balancing test required
Recognised legitimate interestsDoes not existNew basis, no balancing test for listed purposes
Listed purposesNot applicableSafeguarding, crime prevention, emergencies, national security, and others on a closed list
LIA documentationRequired for all legitimate interests processingNot required for recognised legitimate interests purposes

The practical effect is narrower than the headlines suggested. The list is closed and the purposes are specific. Most commercial processing still requires a full LIA. But for organisations engaged in safeguarding, fraud prevention, or crime detection work, the documentation burden is materially reduced in the UK and unchanged in the EU.

2. Automated Decision-Making

This is the divergence most likely to affect organisations deploying AI.

EU GDPR Article 22 gives data subjects the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, subject to three narrow exceptions: contractual necessity, authorisation by law, and explicit consent.

The Dutch DPA’s €825 million fine against Uber in August 2026 for fully automated driver deactivations demonstrates that automated decision-making provision is being enforced seriously.

The DUAA restructures the UK equivalent. It permits a wider range of automated decisions provided specified safeguards are in place, including the ability to obtain human intervention, express a point of view, and contest the decision. The prohibition-with-exceptions structure of EU Article 22 becomes, in the UK, closer to a permission-with-safeguards structure.

FeatureEU GDPRUK GDPR (post-DUAA)
Default positionProhibition on solely automated decisions with significant effectsPermitted subject to safeguards
ExceptionsContract, law, explicit consentBroader, safeguard-based
Special category dataStricter restrictions applyRestrictions retained for special category data
Required safeguardsHuman intervention, right to contestHuman intervention, right to make representations, right to contest
Enforcement postureActive. See Uber, August 2026Untested at scale

For organisations deploying AI systems in employment, credit, or service-access decisions across both jurisdictions, this divergence is operationally significant. A decision architecture that satisfies the UK standard will not necessarily satisfy EU Article 22.

3. Subject Access Requests

The DUAA introduced two changes to the UK SAR regime.

The first is a proportionate search standard: controllers are required to conduct a reasonable and proportionate search rather than an exhaustive one. The second is a stop-the-clock mechanism, allowing controllers to pause the response deadline while seeking clarification from the requester or awaiting identity verification.

FeatureEU GDPRUK GDPR (post-DUAA)
Response deadlineOne month, extendable by two monthsOne month, extendable by two months
Search standardNot expressly qualifiedReasonable and proportionate search
Stop the clockNot expressly providedPermitted while seeking clarification or verifying identity
Refusing requestsManifestly unfounded or excessiveVexatious or excessive

The change in refusal terminology from “manifestly unfounded or excessive” to “vexatious or excessive” imports a lower threshold from freedom of information law. In practice, UK controllers have more room to refuse burdensome requests than EU controllers do.

4. Cookies and PECR

The DUAA amends the Privacy and Electronic Communications Regulations to create new exemptions from the consent requirement for certain cookie categories, including some analytics and functionality cookies.

Under EU law, the ePrivacy Directive requires consent for all non-essential cookies, including analytics. The EDPB and national supervisory authorities have consistently held that analytics cookies require consent. Under the amended UK regime, certain analytics cookies may be deployed without prior consent, subject to conditions and to a right to object.

FeatureEU (ePrivacy Directive)UK (PECR post-DUAA)
Strictly necessary cookiesNo consent requiredNo consent required
Analytics cookiesConsent requiredExemption available for certain analytics, subject to conditions
Functionality cookiesConsent requiredExemption available for certain functionality cookies
Advertising cookiesConsent requiredConsent required
Right to objectNot a substitute for consentMust be provided where exemption relied on

This is the divergence most visible to end users and the one most likely to create practical problems for organisations running a single cookie banner across both markets. A UK-configured banner deployed to EU users is an ePrivacy breach.

5. International Transfers

The DUAA changes the test for approving international transfers. The UK moves from an “essentially equivalent” standard to a “not materially lower” standard for assessing data protection in destination countries.

The government has signalled no immediate plans to approve transfers to new countries on the basis of this change. But the standard itself is lower, and over time it creates capacity for the UK to grant adequacy to countries the EU has not.

FeatureEU GDPRUK GDPR (post-DUAA)
Adequacy standardEssentially equivalent protectionNot materially lower protection
Transfer mechanismsSCCs, BCRs, Article 46 mechanismsIDTA, UK Addendum to EU SCCs, BCRs
Transfer risk assessmentTIA requiredTRA still required
Adequacy listEU adequacy decisionsUK adequacy regulations, currently mirroring EU

Exporters using the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses must still complete a Transfer Risk Assessment. The mechanism requirements have not been removed, only the underlying adequacy standard has moved.

Where the Two GDPR Regimes Remain Identical

The divergence is real but bounded. The following remain substantially aligned across both regimes:

ElementStatus
Data protection principles (Article 5)Identical
Lawful bases (Article 6), other than recognised legitimate interestsSubstantially aligned
Special category data conditions (Article 9)Substantially aligned
Transparency obligations (Articles 13-14)Identical
Data subject rights frameworkSubstantially aligned
Controller and processor definitionsIdentical
DPA requirements (Article 28)Identical
Security obligations (Article 32)Identical
Breach notification (Articles 33-34)Identical
DPIA requirements (Article 35)Substantially aligned
Maximum fine structure4% worldwide turnover in both; £17.5m UK cap, €20m EU cap

The Adequacy Question

The European Commission renewed the UK’s adequacy decisions on 19 December 2025, extending free EEA-to-UK data flows until 27 December 2031. The Commission reviewed the DUAA before renewing.

The renewal is important and it is conditional. The Commission monitors divergence and retains power to suspend, amend, or withdraw adequacy if it concludes the UK framework no longer provides essentially equivalent protection. The EDPB noted during the DUAA process that some changes move meaningfully away from EU GDPR principles.

Two factors will determine whether adequacy survives to 2031.

The first is whether the UK diverges further. The DUAA was reviewed and found acceptable. A subsequent reform package that widens the gap on automated decision-making or international transfers would face a harder assessment.

The second is how the ICO enforces the new provisions. Adequacy assessments consider practice as well as text. A UK regulator that interprets the recognised legitimate interests basis expansively or declines to enforce the automated decision-making safeguards will strain the adequacy finding more than the statutory text does on its own.

The Dual GDPR Compliance Problem

The most common error organisations are making in 2026 is applying the more permissive UK standard across all processing.

The divergence does not deregulate the processing of EU personal data. An organisation established in the UK that processes personal data of EU residents remains subject to the EU GDPR in full for that processing, enforced by the relevant EU supervisory authority. The DUAA changes UK law. It does not change what the EU requires.

The practical consequence is that organisations operating in both jurisdictions must map processing activities by jurisdiction rather than by entity.

Processing scenarioApplicable regime
UK entity, UK data subjectsUK GDPR and DPA 2018
UK entity, EU data subjectsEU GDPR (extraterritorial scope, Article 3(2))
EU entity, EU data subjectsEU GDPR
EU entity, UK data subjectsUK GDPR (extraterritorial scope)
Global entity, bothBoth regimes, mapped by data subject location

For most multinational organisations, the operational answer is to apply the stricter EU standard as a baseline and use the UK flexibilities only where the processing is genuinely UK-only and the compliance saving is material. Running two full parallel programmes is expensive. Running one programme at the EU standard is simpler and defensible in both jurisdictions.

The AI Dimension

The automated decision-making divergence intersects directly with AI governance obligations under the EU AI Act.

An organisation deploying a high-risk AI system that makes decisions about EU residents faces EU GDPR Article 22, EU AI Act Article 14 human oversight requirements, and EU AI Act Article 26 deployer obligations simultaneously. The same system deployed to UK residents faces the DUAA’s restructured automated decision-making provisions and no equivalent AI-specific statutory framework, since the UK has not enacted comprehensive AI legislation.

FAQ

Is UK GDPR the same as EU GDPR?

Not any more. They started identical, since the UK GDPR is the EU regulation retained in domestic law. The Data (Use and Access) Act 2025, in force since 5 February 2026, has introduced divergence in five areas: recognised legitimate interests, automated decision-making, subject access requests, cookies, and international transfers. The core framework of principles, lawful bases, and rights remains substantially aligned.

Does the EU GDPR still apply to UK companies?

Yes, where a UK company processes personal data of individuals in the EU in connection with offering goods or services to them or monitoring their behaviour. EU GDPR Article 3(2) applies extraterritorially. A UK company with EU customers complies with both regimes.

Did the DUAA replace the UK GDPR?

No. The DUAA amends the UK GDPR and the Data Protection Act 2018. It does not replace either. The UK GDPR remains the primary UK data protection instrument, now in amended form.

Is UK adequacy still in place?

Yes. The European Commission renewed the UK’s adequacy decisions on 19 December 2025, with a new expiry date of 27 December 2031. Personal data continues to flow freely from the EEA to the UK without additional transfer safeguards. The Commission monitors ongoing divergence and can withdraw adequacy if it concludes the UK framework has fallen below the essentially equivalent standard.

What are recognised legitimate interests under UK GDPR?

A new lawful basis inserted into UK GDPR Article 6 by the DUAA, in force from 5 February 2026. It covers a closed list of purposes including safeguarding, crime prevention, emergencies, and national security. Where it applies, no legitimate interests balancing assessment is required. The basis does not exist under EU GDPR.

Can we use one cookie banner for UK and EU users?

Not safely. The DUAA amendments to PECR create exemptions from consent for certain analytics and functionality cookies in the UK. EU law under the ePrivacy Directive still requires consent for those categories. A UK-configured banner deployed to EU users is an ePrivacy breach. Either geolocate and serve different configurations, or apply the stricter EU standard to all users.

How do the automated decision-making rules differ?

EU GDPR Article 22 prohibits solely automated decisions with legal or similarly significant effects except in three narrow circumstances. The DUAA restructures the UK position to permit a wider range of such decisions provided safeguards are in place, including human intervention, the right to make representations, and the right to contest. The EU position is prohibition with exceptions. The UK position is closer to permission with safeguards.

Which regime should we build our compliance programme around?

For organisations processing personal data in both jurisdictions, the practical answer is usually to build to the EU standard and treat the UK flexibilities as available where processing is genuinely UK-only and the saving is material. The EU standard is stricter across the areas where the regimes diverge, so an EU-compliant programme is generally UK-compliant. The reverse is not true.

What happens to the ICO?

The DUAA creates a new body corporate, the Information Commission, to take over from the ICO. As of August 2026 the transition is still under way, with the new board expected to be appointed in late 2026. The regulator continues to operate as the ICO with all existing powers until the transition completes.

Does the divergence affect Data Processing Agreements?

The Article 28 requirements for controller-processor contracts are unchanged in both regimes. A DPA that satisfies EU GDPR Article 28 satisfies UK GDPR Article 28. Where a processor is located outside the EU or UK, the transfer mechanism requirements differ, with the UK using the IDTA or the UK Addendum to the EU SCCs and the EU using the SCCs directly.

Disclaimer

This guide reflects the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and the European Commission’s adequacy decisions as at August 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations processing personal data across both jurisdictions should obtain advice specific to their processing activities and data subject populations.

Yuliia Habriiel

Founder, CLO LLB, IAPP AIGP
Fact Checked & Editorial Guidelines
Reviewed by: Subject Matter Experts