Praeferre/Frameworks/UK GDPR
Privacy & Data Protection · United Kingdom

UK GDPR & Data Protection Act 2018

The UK's version of the GDPR, retained in domestic law after Brexit and read alongside the Data Protection Act 2018. It mirrors the EU regulation closely, with enforcement and guidance provided by the ICO rather than an EU supervisory authority.

REGULATORInformation Commissioner's Office (ICO) REGIONUnited Kingdom EFFECTIVE1 January 2021 (post-Brexit retained law)

Who it applies to

  • Organisations processing personal data of people in the UK
  • Public authorities, businesses and third-sector organisations
  • Non-UK organisations offering goods or services to UK residents

Key requirements

  • Lawful basis for processing, documented and reviewable
  • DPO appointment where UK GDPR Article 37 thresholds are met
  • 72-hour breach notification to the ICO
  • Data Protection Impact Assessments for high-risk processing
  • Respecting the same core data subject rights as EU GDPR

Maximum penaltyUp to £17.5 million or 4% of global annual turnover, whichever is higher

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates UK GDPR compliance

Continuous monitoring, evidence and reporting for UK GDPR — alongside every other framework you need to satisfy.