The EU GDPR and UK GDPR share the same core structure, but they are separate legal regimes. An organisation operating across the EEA and UK must assess territorial scope, representation, regulators and international transfers under each regime rather than treating one compliance file as automatically sufficient for both.
Key operational differences
| Topic | EU GDPR | UK GDPR |
|---|---|---|
| Territory | EU/EEA-facing scope under EU GDPR Article 3 | UK-facing scope under the UK GDPR’s territorial provisions |
| Regulator | Relevant EU/EEA supervisory authority or authorities | Information Commissioner’s Office (ICO) |
| Non-local representative | EU representative may be required | UK representative may be required |
| Legitimate interests | Article 6(1)(f) normally requires the controller's balancing assessment | DUAA adds specified “recognised legitimate interests” for which that balancing step is not required; ordinary legitimate interests remain available |
| Significant automated decisions | Article 22 restricts qualifying solely automated decisions, subject to its exceptions and safeguards | DUAA permits a wider range of lawful bases for qualifying decisions with safeguards; special-category data remains subject to stricter rules |
| Access and complaints | EU GDPR rights procedures and applicable national complaint routes | SAR searches need only be reasonable and proportionate; organisations must facilitate complaints, acknowledge them within 30 days and respond without undue delay |
| Transfers | EU adequacy decisions, Article 46 safeguards and derogations | UK adequacy regulations, UK safeguards and exceptions |
| Standard clauses | 2021 EU SCCs where applicable | UK IDTA or UK Addendum; EU SCCs alone are not valid for a UK restricted transfer |
| Regulatory cooperation and enforcement | EU GDPR cooperation/consistency mechanisms may apply | Separate UK procedure; DUAA gives the ICO additional powers, including compelling witness interviews and requesting approved-person reports |
The Data (Use and Access) Act 2025 (DUAA) amends rather than replaces the UK GDPR, Data Protection Act 2018 and PECR. All its data-protection provisions were in force by 19 June 2026. Some changes create options, while complaint handling creates specific duties, so check the current UK text and ICO guidance for the processing at issue rather than assuming EU and UK provisions remain identical.
Material UK changes under the DUAA
The new recognised legitimate interests basis covers specified purposes and removes the usual balancing step for those purposes. It does not turn every useful business purpose into a recognised legitimate interest; organisations relying on ordinary legitimate interests must still apply the relevant assessment.
For qualifying significant solely automated decisions, the UK rules now allow the full range of lawful bases if required safeguards are applied. Those safeguards include giving people information and routes to make representations, obtain human intervention and contest the decision. The broader rule does not apply in the same way to special-category data.
For subject access requests, the DUAA confirms that searches need only be reasonable and proportionate. Separately, organisations must facilitate data-protection complaints, acknowledge them within 30 days, and respond without undue delay. These complaint duties do not replace the statutory response rules for rights requests.
Scope and dual obligations
An EU establishment can bring processing within EU GDPR scope; a UK establishment can bring processing within UK GDPR scope. Each regime can also reach certain organisations outside its territory in connection with offering goods or services or monitoring behaviour in that territory.
A company can therefore be subject to both regimes for overlapping or different activities. Build a matrix by legal entity, establishment, product, individual location and processing purpose.
Representatives are separate appointments
A UK organisation without an EEA establishment that is subject to EU GDPR Article 3(2) may need an EU representative under Article 27. An EEA or other non-UK organisation caught by the UK GDPR’s extra-territorial scope may need a UK representative. Each exception and location rule must be assessed under the applicable regime.
Neither representative is automatically the DPO. A representative appointment also does not, by itself, create a main establishment for EU one-stop-shop purposes.
International transfers
Treat the exporting regime as the starting point:
- for an EEA exporter, assess EU GDPR Chapter V and current EU adequacy or safeguards;
- for a UK exporter, apply the ICO’s restricted-transfer analysis and current UK mechanisms;
- where one arrangement contains both EU and UK restricted transfers, document a lawful route for each.
The ICO states that the EU SCCs are not valid on their own for restricted transfers under the UK GDPR. Depending on the circumstances, organisations may use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, after completing the applicable UK assessment and any necessary extra protections. Following the DUAA, the UK data protection test asks the sender, acting reasonably and proportionately, to decide that protection after transfer is not materially lower than in the UK.
Do not assume that a transfer permitted in one direction or under one regime is automatically permitted in every direction under the other. Verify current adequacy coverage, recipient and onward-transfer facts.
DPO, DPIA and core programme controls
Both regimes retain familiar concepts: data-protection principles, lawful bases, transparency, individual rights, processor controls, privacy by design, DPIAs, DPOs, security and breach response. Reuse a common control framework where requirements align, while maintaining jurisdiction-specific overlays for:
- legal references and national conditions;
- regulator contacts and notification portals;
- representative details;
- transfer mechanisms and assessments;
- rights exceptions and response rules; and
- record, notice and contract wording.
A dual-regime action plan
- Map entities, establishments, individuals and processing activities.
- Record why each regime applies or does not apply.
- Assess EU and UK representative requirements separately.
- Identify the competent regulator and escalation path for each activity.
- Map transfers by exporter and applicable regime.
- Update notices, contracts and incident procedures for both regimes.
- Assign an owner to monitor legal and guidance changes.
For EU-side implementation and governance, see our data protection services. Where Article 27 applies, our EU representative service can cover the EU role; it does not replace any separate UK appointment.
Sources and review
- Regulation (EU) 2016/679, official EU GDPR text
- ICO: what the Data (Use and Access) Act 2025 means for organisations
- ICO: detailed guide to international transfers, updated January 2026
- ICO: UK IDTA and Addendum guidance
Reviewed on 8 August 2026. UK-specific claims reflect the fully commenced DUAA and current ICO guidance; the guide avoids asserting that EU and UK rules or transfer permissions are interchangeable.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.