UK GDPR and EU GDPR are substantively near-identical, because UK GDPR is retained EU law. Comply with one properly and you are most of the way to the other. The differences that create real work are administrative: a second representative, second transfer contracts, a second regulator, an annual ICO fee and fines in a different currency. The first genuine legal divergence, under the Data (Use and Access) Act 2025, is now in force, and this guide flags exactly where.
The differences at a glance
Every row traces to a tier 1 source, checked on 6 August 2026.
| Where they differ | EU GDPR | UK GDPR | Source |
|---|---|---|---|
| Transfer contracts | European Commission SCCs | IDTA or UK Addendum to the EU SCCs; bare SCCs are invalid for UK transfers | ICO |
| Adequacy mechanism | Commission decisions, “essentially equivalent” | Secretary of State regulations, “not materially lower” test | Commission / ICO |
| Supervisory authority | Lead DPA via the one-stop-shop (Arts 56, 60); 27 DPAs under the EDPB | One authority: the ICO | EUR-Lex / ICO |
| Annual regulator fee | None | £52, £78 or £3,763 per year by tier | ICO |
| Fine ceilings | €10m or 2% (lower tier); €20m or 4% (upper) | £8.7m or 2%; £17.5m or 4% | EUR-Lex, Art 83 / legislation.gov.uk, Art 83 |
| Child consent age | 16 by default; member states may set 13 to 16 | 13 | EUR-Lex, Art 8 / legislation.gov.uk, Art 8 |
| Lawful bases | Six | Seven, adding “recognised legitimate interests” | legislation.gov.uk, Art 6 |
| Automated decisions | Art 22 prohibition unchanged | Arts 22A to 22D: wider lawful bases with safeguards | legislation.gov.uk, Art 22A |
| Subject access searches | No statutory search limit | “Reasonable and proportionate” only | DUAA ss. 75 to 78 |
| Complaints handling | No controller complaints duty | Mandatory procedure; acknowledge within 30 days | DUAA s. 103 |
| Cookie and ePrivacy fines | Varying national laws | PECR fines up to £17.5m or 4% of global turnover | ICO |
Atoro is an Irish AI governance and cyber compliance consultancy, and the first consultancy in Europe certified against ISO 42001. We act as EU and UK representative from our Irish establishment and UK entity in one engagement, so we run both regimes side by side for software companies.
Representatives: the difference most companies discover last
Verdict: if your company is established in neither the EU nor the UK and you serve both markets, you need two representatives. Both regimes carry Article 27, but the texts differ. EU Article 27(3) requires your representative to be established in a member state where your data subjects are (EUR-Lex, Art 27). The UK revoked that paragraph; UK law requires only a representative “in the United Kingdom” (legislation.gov.uk, Art 27). The ICO is blunt: a non-UK organisation without a UK establishment that offers goods or services to, or monitors, people in the UK “must comply with UK GDPR and appoint a representative in the UK”, with the same two exemptions as the EU, occasional low-risk processing and public authorities (ICO, updated 15 January 2026). One appointment cannot cover both territories.
International transfers: two toolkits, not one
Verdict: your EU standard contractual clauses do not work for UK restricted transfers on their own. The UK uses the IDTA or the UK Addendum bolted onto the EU SCCs, both ICO-issued under section 119A DPA 2018 (ICO, appropriate safeguards, updated 15 January 2026). A common approach is to run the EU SCCs with the UK Addendum as one contract package.
Adequacy is granted by different hands. The European Commission decides for the EU against an “essentially equivalent” standard; the Secretary of State makes UK adequacy regulations against a “data protection test” of protection “not materially lower” than the UK standard, introduced by the DUAA (Commission; ICO, adequacy regulations, updated 30 July 2026).
EU to UK flows are covered: the EU renewed its adequacy decisions for the UK on 19 December 2025, they run until 27 December 2031, and the GDPR decision is now a full adequacy finding with the immigration carve-outs removed (ICO). This is in flux: the Commission monitors UK divergence and can review or withdraw adequacy early.
Who regulates you: a lead DPA versus the ICO
Verdict: in the EU you deal with a lead supervisory authority; in the UK you deal with the ICO, full stop. The EU one-stop-shop (Articles 56 and 60) gives you a single lead DPA for cross-border processing, backed by 27 DPAs coordinated by the EDPB (EUR-Lex, Art 56; EDPB FAQ). There is no UK equivalent: the ICO is the single authority for the whole UK (ICO, who we are).
One change is in flux: DUAA Part 6 creates a new body, the Information Commission, replacing the office of Information Commissioner, while the ICO operates as normal. New ICO powers, including compelling witness interviews and requiring technical reports, are already in force (ICO, DUAA one year on, 23 June 2026).
The ICO data protection fee: the cost the EU does not have
Verdict: the UK charges most controllers an annual data protection fee; the EU charges nothing equivalent. UK controllers pay £52 (micro), £78 (small and medium) or £3,763 (large) per year, with a £5 direct debit discount, unless exempt (ICO, data protection fee). Non-payment draws a fixed penalty of between £400 and £4,000 depending on tier (ICO registration FAQs).
Fines: same structure, different currencies
Verdict: both regimes run the same two tiers with the same turnover percentages; only the currency caps differ. Lower tier: €10,000,000 or 2% of worldwide annual turnover in the EU, £8,700,000 or 2% in the UK. Upper tier: €20,000,000 or 4% in the EU, £17,500,000 or 4% in the UK (EUR-Lex, Art 83; legislation.gov.uk, Art 83). For any company with meaningful turnover, the percentage is the number that matters, and it is identical.
Where the UK is genuinely diverging: the Data (Use and Access) Act 2025
Verdict: the DUAA amends UK GDPR rather than replacing it, and all of its data protection provisions are in force as of 19 June 2026 (legislation.gov.uk, DUAA 2025; ICO, DUAA one year on). The changes now live that have no EU equivalent:
- A seventh lawful basis. Article 6(1)(ea) “recognised legitimate interests” allows listed purposes without a balancing test; EU GDPR still has six (legislation.gov.uk, Art 6).
- Automated decision-making rewritten. Articles 22A to 22D replace Article 22, opening significant solely automated decisions to the full range of lawful bases, with safeguards and stricter special category rules; the EU prohibition is unchanged (legislation.gov.uk, Art 22A).
- Subject access searches limited to “reasonable and proportionate” (DUAA ss. 75 to 78), a limit the EU text lacks.
- A mandatory complaints procedure: acknowledgement within 30 days, response without undue delay (DUAA s. 103); there is no EU equivalent.
- Children’s higher protection matters (DUAA s. 81): online services likely used by children must explicitly take their needs into account.
- PECR changes: cookie consent exceptions for statistical and functionality purposes, a charitable soft opt-in, and fines raised to £17.5m or 4% of global turnover (ICO, DUAA: what it means for organisations).
Still in flux: the ICO’s final enforcement procedural guidance (draft published), a statutory AI and automated decision-making code of practice, and the age-of-consent power below.
Age of consent: 13 versus 16
Verdict: the UK sets the digital age of consent at 13; the EU default is 16, and member states may set 13 to 16 (legislation.gov.uk, Art 8; EUR-Lex, Art 8). If children use your product across both markets, the EU is the fragmented side: you check each member state, not Brussels alone. In flux: the DUAA gives the Secretary of State a power to change the UK age by regulations; none have been made at the time of writing, so the age remains 13.
Who each regime actually applies to
Verdict: both regimes apply extraterritorially, so serving both markets usually means both apply to you. EU GDPR catches companies outside the EU that offer goods or services to, or monitor, people in the Union; UK GDPR mirrors this for people in the UK. A US software company selling into France and England is inside both regimes; so is an Irish company with UK customers. The DPO triggers are the same Article 37 tests in both texts; our guide Do I need a DPO? walks through them.
Do I have to do everything twice?
Verdict: no. One well-run privacy programme gets you most of the way with both regimes. The principles, rights, records of processing, DPIA discipline and breach clocks are the same. What the second regime adds is a short list: a UK representative alongside your EU one, the UK Addendum or IDTA next to your SCCs, the ICO fee, a complaints procedure meeting the 30-day rule, and a check against the DUAA deltas above if you rely on legitimate interests or make solely automated decisions. Our GDPR implementation service covers both regimes as one project.
FAQs
1. Is UK GDPR still the same as EU GDPR?
Substantively, almost. UK GDPR is retained EU law, so the principles, rights and most obligations match word for word. The operational differences are administrative: representatives, transfer tools, the regulator, the ICO fee and fine currencies. Since 19 June 2026 the Data (Use and Access) Act 2025 has added the first real legal divergence.
2. Do I need both a UK representative and an EU representative?
Yes, if your company is established in neither the EU nor the UK and you offer goods or services to, or monitor, people in both. Article 27 exists in both regimes, and one appointment cannot cover both territories. The same two exemptions apply in each: occasional low-risk processing and public authorities.
3. Can I use my EU standard contractual clauses for transfers out of the UK?
Not on their own. UK restricted transfers require the ICO’s IDTA or the UK Addendum to the EU SCCs; bare EU SCCs are not valid for UK GDPR transfers. Most companies attach the UK Addendum to their EU SCCs as one package.
4. Has the Data (Use and Access) Act 2025 replaced UK GDPR?
No. The DUAA amends UK GDPR, the DPA 2018 and PECR rather than replacing them. It received Royal Assent on 19 June 2025, and all of its data protection provisions were in force by 19 June 2026. Your existing UK GDPR programme remains the foundation; the Act changes specific provisions around it.
5. Is the EU’s adequacy decision for the UK still valid?
Yes. The EU renewed its adequacy decisions for the UK on 19 December 2025, and they run until 27 December 2031. The renewed GDPR decision is a full adequacy finding, with the 2021 immigration carve-outs removed. The Commission monitors UK divergence and can review the decision early.
6. How much is the ICO data protection fee?
£52 per year for micro organisations, £78 for small and medium ones, and £3,763 for large ones, with a £5 direct debit discount, unless you are exempt. Non-payment draws a fixed penalty of between £400 and £4,000 depending on tier. There is no equivalent fee under EU GDPR.
7. Will the two regimes diverge further?
Probably, and some of it is already scheduled. The DUAA lets the Secretary of State change the children’s consent age, the ICO is preparing automated decision-making guidance and a statutory AI code of practice, and the Commission watches UK divergence. Nothing in force removes the Article 27 representative requirement; the earlier Data Protection and Digital Information Bill, which proposed removing it, fell before the 2024 general election.
8. Do the same DPO rules apply in the UK?
Yes. The Article 37 triggers for appointing a data protection officer are the same in both texts: public authority processing, regular and systematic large-scale monitoring, or large-scale special category processing. Our Do I need a DPO? guide applies the tests step by step.
The honest next step
If you sell into both markets and your Article 27 coverage stops at one territory, the cheapest fix in this guide is sorting the second representative. Atoro provides EU and UK GDPR representation from our Irish establishment and our UK entity in one engagement, covering both regimes under one contract and one point of contact.
Sources
All sources checked 6 August 2026.
- EUR-Lex, Regulation (EU) 2016/679 (Articles 6, 8, 27, 56, 83): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679
- legislation.gov.uk, UK GDPR (Articles 6, 8, 22A, 27, 83): https://www.legislation.gov.uk/eur/2016/679/contents
- legislation.gov.uk, Data (Use and Access) Act 2025 c. 18: https://www.legislation.gov.uk/ukpga/2025/18/contents
- legislation.gov.uk, SI 2026/82 (DUAA Commencement No. 6 Regulations 2026): https://www.legislation.gov.uk/uksi/2026/82/contents/made
- ICO, Receiving personal information from the EEA (updated 15 January 2026): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/
- ICO, Appropriate safeguards (updated 15 January 2026): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/
- ICO, Adequacy regulations (updated 30 July 2026): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/
- ICO, Data protection fee: https://ico.org.uk/for-organisations/data-protection-fee/
- ICO, published fee and penalty table (PDF): https://ico.org.uk/media2/migrated/4026216/ic-245761-z6l2-attachment-1.pdf
- ICO, Who we are: https://ico.org.uk/about-the-ico/who-we-are/
- ICO, One year on: marking the 12-month commencement of the Data (Use and Access) Act (23 June 2026): https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/one-year-on-marking-the-12-month-commencement-of-the-data-use-and-access-act/
- ICO, The Data (Use and Access) Act 2025: what does it mean for organisations?: https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/
- European Commission, Data protection adequacy for non-EU countries: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en
- EDPB, FAQ: What is the EDPB?: https://www.edpb.europa.eu/about-edpb/faq-frequently-asked-questions_en
Items flagged as in flux (per research R10, stated in the draft rather than guessed)
- ICO final enforcement procedural guidance (draft published; final “in due course”)
- Statutory AI and automated decision-making code of practice in preparation
- Information Commission transition under DUAA Part 6 (ICO operating during changeover)
- EU adequacy for the UK: valid to 27 December 2031 but under ongoing Commission monitoring
- DUAA age-of-consent regulation-making power: no regulations identified, age remains 13