The UK GDPR (retained EU law post-Brexit) applies alongside the Data Protection Act 2018. The UK is diverging from EU GDPR in certain areas through ongoing reform.
Enforcement authority
Maximum sanctions
Up to GBP 17.5 million or 4% of global turnover. The ICO has issued fines exceeding GBP 40 million.
Obligations
What GDPR requires from organizations operating in the UK.
Local context
The UK Data Protection and Digital Information Bill introduces divergences from EU GDPR including relaxed rules on legitimate interest, research processing, and subject access requests. Companies operating in both UK and EU must track both regimes.
The UK GDPR (retained EU law post-Brexit) applies alongside the Data Protection Act 2018. The UK is diverging from EU GDPR in certain areas through ongoing reform.
ICO (Information Commissioner's Office)
Up to GBP 17.5 million or 4% of global turnover. The ICO has issued fines exceeding GBP 40 million.
Start free scan to see your risk score and applicable obligations.