AMLEGALS — Strategic Lawyering
Jurisdiction: United Kingdom

UK Data
Protection.

Post-Brexit data protection framework. UK GDPR retained with domestic adaptations under the Data Protection Act 2018.

£17.5M
Maximum Fine
or 4% Global Turnover
72hrs
Breach Window
ICO Notification
Art. 22
Automated Decisions
Human Review Rights
Retained
EU Adequacy
Until June 2025
Legal Framework

UK GDPR

Following Brexit, the UK retained the GDPR as the "UK GDPR" through the European Union (Withdrawal) Act 2018. The Data Protection Act 2018 provides supplementary provisions and exemptions.

The Information Commissioner's Office (ICO) serves as the independent supervisory authority, with powers to investigate, audit, and issue fines up to £17.5 million or 4% of global turnover.

The EU granted the UK an adequacy decision in June 2021, allowing continued data flows. This decision is subject to review and renewal.

Data Protection Principles

01

Lawfulness, Fairness & Transparency

Processing must be lawful with clear information provided

02

Purpose Limitation

Collected for specified, explicit and legitimate purposes

03

Data Minimisation

Adequate, relevant and limited to what is necessary

04

Accuracy

Accurate and, where necessary, kept up to date

05

Storage Limitation

Kept no longer than necessary

06

Security

Appropriate security against unauthorised processing

Regulatory Landscape

UK Regulators

ICO

Information Commissioner's Office

Primary data protection authority

GDPR enforcement, guidance, and investigations

CMA

Competition & Markets Authority

Competition oversight

Digital markets and data-related competition issues

FCA

Financial Conduct Authority

Financial services regulator

Data protection in banking and financial services

Ofcom

Office of Communications

Communications regulator

Online safety and digital communications

Brexit Impact

Divergence Tracker

The UK government has signaled intentions to diverge from EU GDPR in certain areas, prioritizing a "pro-innovation" approach while maintaining adequacy.

Legitimate Interests

Expanded

Broader scope for business activities

International Transfers

Simplified

New transfer mechanisms proposed

Research Exemptions

Enhanced

Reduced restrictions on scientific research

Cookie Consent

Under Review

Potential opt-out model consideration

UK-India Data Flows

Understand the adequacy landscape for cross border transfers between the UK and India under DPDPA Section 16.

View Adequacy Matrix →
Insights & Answers

What practitioners and boards are asking

How does the UK data protection regime compare with India's DPDPA?

The UK GDPR and Data Protection Act 2018 form the UK regime, using adequacy and international data transfer agreements, data portability rights and enforcement by the ICO. India's DPDPA differs with its Section 16 negative-list transfer model, no portability right, a single Data Protection Board, and fixed penalty maximums up to ₹250 crore.

Must UK companies comply with India's DPDPA?

Yes, where they offer goods or services to Data Principals in India. DPDPA's Section 3 extraterritorial scope means UK businesses serving Indian customers must meet DPDPA obligations — India-specific notice, consent, processor contracts and cross-border rules — alongside their UK GDPR duties.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to Regulations UK?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on Regulations UK under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on Regulations UK under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on Regulations UK?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for Regulations UK rather than a generic checklist.

How do I get a first view of my DPDPA exposure on Regulations UK?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.