For four years after Brexit, comparing UK GDPR and EU GDPR was largely an academic exercise. The UK GDPR was the EU regulation copied into domestic law with the references changed. The two were near-identical.
That changed on 5 February 2026, when the substantive data protection provisions of the Data (Use and Access) Act 2025 came into force. The DUAA does not replace the UK GDPR. It amends it, and the amendments create genuine operational divergence in five areas: legitimate interests, automated decision-making, subject access requests, cookies, and international transfers.
The European Commission renewed the UK’s adequacy decisions on 19 December 2025, extending free data flows from the EEA to the UK until 27 December 2031. Adequacy survived the DUAA. It is not guaranteed to survive whatever comes next.
This guide sets out where the two regimes now differ, what that means for organisations processing personal data in both jurisdictions, and why applying the more permissive UK standard across the board is the most common and most expensive mistake being made right now.
Key Definitions
| Term | Definition |
|---|---|
| EU GDPR | Regulation (EU) 2016/679. Applies directly across all EU member states since 25 May 2018 |
| UK GDPR | The EU GDPR as retained in UK domestic law from 1 January 2021, as amended by the DPA 2018 and the DUAA 2025 |
| DPA 2018 | Data Protection Act 2018. The UK statute that supplements the UK GDPR with national provisions, exemptions, and enforcement powers |
| DUAA | Data (Use and Access) Act 2025. Royal Assent 19 June 2025. Main data protection provisions in force 5 February 2026 |
| Recognised legitimate interests | A new lawful basis under UK GDPR Article 6, covering a closed list of purposes, requiring no balancing test |
| Adequacy decision | A European Commission determination that a third country provides essentially equivalent data protection, permitting transfers without additional safeguards |
| ICO | Information Commissioner’s Office. The UK data protection regulator, transitioning to the Information Commission under the DUAA |
| EDPB | European Data Protection Board. Coordinates GDPR interpretation across EU supervisory authorities |
How the Two GDPR Regimes Came Apart
The EU GDPR applied directly in the UK from 25 May 2018 until 31 December 2020. On 1 January 2021, the European Union (Withdrawal) Act incorporated the GDPR into UK domestic law as the UK GDPR, with statutory instruments correcting references that no longer made sense. “The Union” became “the United Kingdom.” Supervisory authority references became the ICO.
That near-identity was the basis on which the European Commission granted the UK an adequacy decision in June 2021.
The first attempt at reform, the Data Protection and Digital Information Bill, failed when Parliament was dissolved before the 2024 general election. Its successor, the Data (Use and Access) Act 2025, received Royal Assent on 19 June 2025 and commenced in phases through early 2026.
| Date | Development |
|---|---|
| 25 May 2018 | EU GDPR applies, including in the UK |
| 1 January 2021 | UK GDPR comes into existence as retained law |
| 28 June 2021 | EU grants UK adequacy decision |
| 2023-2024 | Data Protection and Digital Information Bill fails |
| 19 June 2025 | DUAA receives Royal Assent |
| 19 December 2025 | EU renews UK adequacy to 27 December 2031 |
| 5 February 2026 | Main DUAA data protection provisions in force |
| 19 June 2026 | DUAA complaints handling requirement in force |
| Late 2026 (expected) | ICO transitions to Information Commission |
The Five Areas of GDPR Divergence
1. Recognised Legitimate Interests
This is the most structurally significant change the DUAA introduced.
Under EU GDPR Article 6(1)(f), a controller relying on legitimate interests must conduct a three-part balancing test: identify the legitimate interest, demonstrate that processing is necessary for it, and show that the interest is not overridden by the interests or fundamental rights of the data subject. That assessment is documented in a Legitimate Interests Assessment.
The DUAA inserts a new lawful basis into UK GDPR Article 6: recognised legitimate interests. For a closed list of purposes, no balancing test is required. The controller must still satisfy the other GDPR principles, but the LIA obligation falls away for the listed purposes.
| Feature | EU GDPR | UK GDPR (post-DUAA) |
|---|---|---|
| Legitimate interests basis | Article 6(1)(f), balancing test required | Article 6(1)(f) retained, balancing test required |
| Recognised legitimate interests | Does not exist | New basis, no balancing test for listed purposes |
| Listed purposes | Not applicable | Safeguarding, crime prevention, emergencies, national security, and others on a closed list |
| LIA documentation | Required for all legitimate interests processing | Not required for recognised legitimate interests purposes |
The practical effect is narrower than the headlines suggested. The list is closed and the purposes are specific. Most commercial processing still requires a full LIA. But for organisations engaged in safeguarding, fraud prevention, or crime detection work, the documentation burden is materially reduced in the UK and unchanged in the EU.
2. Automated Decision-Making
This is the divergence most likely to affect organisations deploying AI.
EU GDPR Article 22 gives data subjects the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, subject to three narrow exceptions: contractual necessity, authorisation by law, and explicit consent.
The Dutch DPA’s €825 million fine against Uber in August 2026 for fully automated driver deactivations demonstrates that automated decision-making provision is being enforced seriously.
The DUAA restructures the UK equivalent. It permits a wider range of automated decisions provided specified safeguards are in place, including the ability to obtain human intervention, express a point of view, and contest the decision. The prohibition-with-exceptions structure of EU Article 22 becomes, in the UK, closer to a permission-with-safeguards structure.
| Feature | EU GDPR | UK GDPR (post-DUAA) |
|---|---|---|
| Default position | Prohibition on solely automated decisions with significant effects | Permitted subject to safeguards |
| Exceptions | Contract, law, explicit consent | Broader, safeguard-based |
| Special category data | Stricter restrictions apply | Restrictions retained for special category data |
| Required safeguards | Human intervention, right to contest | Human intervention, right to make representations, right to contest |
| Enforcement posture | Active. See Uber, August 2026 | Untested at scale |
For organisations deploying AI systems in employment, credit, or service-access decisions across both jurisdictions, this divergence is operationally significant. A decision architecture that satisfies the UK standard will not necessarily satisfy EU Article 22.
3. Subject Access Requests
The DUAA introduced two changes to the UK SAR regime.
The first is a proportionate search standard: controllers are required to conduct a reasonable and proportionate search rather than an exhaustive one. The second is a stop-the-clock mechanism, allowing controllers to pause the response deadline while seeking clarification from the requester or awaiting identity verification.
| Feature | EU GDPR | UK GDPR (post-DUAA) |
|---|---|---|
| Response deadline | One month, extendable by two months | One month, extendable by two months |
| Search standard | Not expressly qualified | Reasonable and proportionate search |
| Stop the clock | Not expressly provided | Permitted while seeking clarification or verifying identity |
| Refusing requests | Manifestly unfounded or excessive | Vexatious or excessive |
The change in refusal terminology from “manifestly unfounded or excessive” to “vexatious or excessive” imports a lower threshold from freedom of information law. In practice, UK controllers have more room to refuse burdensome requests than EU controllers do.
4. Cookies and PECR
The DUAA amends the Privacy and Electronic Communications Regulations to create new exemptions from the consent requirement for certain cookie categories, including some analytics and functionality cookies.
Under EU law, the ePrivacy Directive requires consent for all non-essential cookies, including analytics. The EDPB and national supervisory authorities have consistently held that analytics cookies require consent. Under the amended UK regime, certain analytics cookies may be deployed without prior consent, subject to conditions and to a right to object.
| Feature | EU (ePrivacy Directive) | UK (PECR post-DUAA) |
|---|---|---|
| Strictly necessary cookies | No consent required | No consent required |
| Analytics cookies | Consent required | Exemption available for certain analytics, subject to conditions |
| Functionality cookies | Consent required | Exemption available for certain functionality cookies |
| Advertising cookies | Consent required | Consent required |
| Right to object | Not a substitute for consent | Must be provided where exemption relied on |
This is the divergence most visible to end users and the one most likely to create practical problems for organisations running a single cookie banner across both markets. A UK-configured banner deployed to EU users is an ePrivacy breach.
5. International Transfers
The DUAA changes the test for approving international transfers. The UK moves from an “essentially equivalent” standard to a “not materially lower” standard for assessing data protection in destination countries.
The government has signalled no immediate plans to approve transfers to new countries on the basis of this change. But the standard itself is lower, and over time it creates capacity for the UK to grant adequacy to countries the EU has not.
| Feature | EU GDPR | UK GDPR (post-DUAA) |
|---|---|---|
| Adequacy standard | Essentially equivalent protection | Not materially lower protection |
| Transfer mechanisms | SCCs, BCRs, Article 46 mechanisms | IDTA, UK Addendum to EU SCCs, BCRs |
| Transfer risk assessment | TIA required | TRA still required |
| Adequacy list | EU adequacy decisions | UK adequacy regulations, currently mirroring EU |
Exporters using the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses must still complete a Transfer Risk Assessment. The mechanism requirements have not been removed, only the underlying adequacy standard has moved.
Where the Two GDPR Regimes Remain Identical
The divergence is real but bounded. The following remain substantially aligned across both regimes:
| Element | Status |
|---|---|
| Data protection principles (Article 5) | Identical |
| Lawful bases (Article 6), other than recognised legitimate interests | Substantially aligned |
| Special category data conditions (Article 9) | Substantially aligned |
| Transparency obligations (Articles 13-14) | Identical |
| Data subject rights framework | Substantially aligned |
| Controller and processor definitions | Identical |
| DPA requirements (Article 28) | Identical |
| Security obligations (Article 32) | Identical |
| Breach notification (Articles 33-34) | Identical |
| DPIA requirements (Article 35) | Substantially aligned |
| Maximum fine structure | 4% worldwide turnover in both; £17.5m UK cap, €20m EU cap |
The Adequacy Question
The European Commission renewed the UK’s adequacy decisions on 19 December 2025, extending free EEA-to-UK data flows until 27 December 2031. The Commission reviewed the DUAA before renewing.
The renewal is important and it is conditional. The Commission monitors divergence and retains power to suspend, amend, or withdraw adequacy if it concludes the UK framework no longer provides essentially equivalent protection. The EDPB noted during the DUAA process that some changes move meaningfully away from EU GDPR principles.
Two factors will determine whether adequacy survives to 2031.
The first is whether the UK diverges further. The DUAA was reviewed and found acceptable. A subsequent reform package that widens the gap on automated decision-making or international transfers would face a harder assessment.
The second is how the ICO enforces the new provisions. Adequacy assessments consider practice as well as text. A UK regulator that interprets the recognised legitimate interests basis expansively or declines to enforce the automated decision-making safeguards will strain the adequacy finding more than the statutory text does on its own.
The Dual GDPR Compliance Problem
The most common error organisations are making in 2026 is applying the more permissive UK standard across all processing.
The divergence does not deregulate the processing of EU personal data. An organisation established in the UK that processes personal data of EU residents remains subject to the EU GDPR in full for that processing, enforced by the relevant EU supervisory authority. The DUAA changes UK law. It does not change what the EU requires.
The practical consequence is that organisations operating in both jurisdictions must map processing activities by jurisdiction rather than by entity.
| Processing scenario | Applicable regime |
|---|---|
| UK entity, UK data subjects | UK GDPR and DPA 2018 |
| UK entity, EU data subjects | EU GDPR (extraterritorial scope, Article 3(2)) |
| EU entity, EU data subjects | EU GDPR |
| EU entity, UK data subjects | UK GDPR (extraterritorial scope) |
| Global entity, both | Both regimes, mapped by data subject location |
For most multinational organisations, the operational answer is to apply the stricter EU standard as a baseline and use the UK flexibilities only where the processing is genuinely UK-only and the compliance saving is material. Running two full parallel programmes is expensive. Running one programme at the EU standard is simpler and defensible in both jurisdictions.
The AI Dimension
The automated decision-making divergence intersects directly with AI governance obligations under the EU AI Act.
An organisation deploying a high-risk AI system that makes decisions about EU residents faces EU GDPR Article 22, EU AI Act Article 14 human oversight requirements, and EU AI Act Article 26 deployer obligations simultaneously. The same system deployed to UK residents faces the DUAA’s restructured automated decision-making provisions and no equivalent AI-specific statutory framework, since the UK has not enacted comprehensive AI legislation.
FAQ
Is UK GDPR the same as EU GDPR?
Not any more. They started identical, since the UK GDPR is the EU regulation retained in domestic law. The Data (Use and Access) Act 2025, in force since 5 February 2026, has introduced divergence in five areas: recognised legitimate interests, automated decision-making, subject access requests, cookies, and international transfers. The core framework of principles, lawful bases, and rights remains substantially aligned.
Does the EU GDPR still apply to UK companies?
Yes, where a UK company processes personal data of individuals in the EU in connection with offering goods or services to them or monitoring their behaviour. EU GDPR Article 3(2) applies extraterritorially. A UK company with EU customers complies with both regimes.
Did the DUAA replace the UK GDPR?
No. The DUAA amends the UK GDPR and the Data Protection Act 2018. It does not replace either. The UK GDPR remains the primary UK data protection instrument, now in amended form.
Is UK adequacy still in place?
Yes. The European Commission renewed the UK’s adequacy decisions on 19 December 2025, with a new expiry date of 27 December 2031. Personal data continues to flow freely from the EEA to the UK without additional transfer safeguards. The Commission monitors ongoing divergence and can withdraw adequacy if it concludes the UK framework has fallen below the essentially equivalent standard.
What are recognised legitimate interests under UK GDPR?
A new lawful basis inserted into UK GDPR Article 6 by the DUAA, in force from 5 February 2026. It covers a closed list of purposes including safeguarding, crime prevention, emergencies, and national security. Where it applies, no legitimate interests balancing assessment is required. The basis does not exist under EU GDPR.
Can we use one cookie banner for UK and EU users?
Not safely. The DUAA amendments to PECR create exemptions from consent for certain analytics and functionality cookies in the UK. EU law under the ePrivacy Directive still requires consent for those categories. A UK-configured banner deployed to EU users is an ePrivacy breach. Either geolocate and serve different configurations, or apply the stricter EU standard to all users.
How do the automated decision-making rules differ?
EU GDPR Article 22 prohibits solely automated decisions with legal or similarly significant effects except in three narrow circumstances. The DUAA restructures the UK position to permit a wider range of such decisions provided safeguards are in place, including human intervention, the right to make representations, and the right to contest. The EU position is prohibition with exceptions. The UK position is closer to permission with safeguards.
Which regime should we build our compliance programme around?
For organisations processing personal data in both jurisdictions, the practical answer is usually to build to the EU standard and treat the UK flexibilities as available where processing is genuinely UK-only and the saving is material. The EU standard is stricter across the areas where the regimes diverge, so an EU-compliant programme is generally UK-compliant. The reverse is not true.
What happens to the ICO?
The DUAA creates a new body corporate, the Information Commission, to take over from the ICO. As of August 2026 the transition is still under way, with the new board expected to be appointed in late 2026. The regulator continues to operate as the ICO with all existing powers until the transition completes.
Does the divergence affect Data Processing Agreements?
The Article 28 requirements for controller-processor contracts are unchanged in both regimes. A DPA that satisfies EU GDPR Article 28 satisfies UK GDPR Article 28. Where a processor is located outside the EU or UK, the transfer mechanism requirements differ, with the UK using the IDTA or the UK Addendum to the EU SCCs and the EU using the SCCs directly.
Disclaimer
This guide reflects the EU GDPR, the UK GDPR as amended by the Data (Use and Access) Act 2025, and the European Commission’s adequacy decisions as at August 2026. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice. Organisations processing personal data across both jurisdictions should obtain advice specific to their processing activities and data subject populations.
