Law / United Kingdom

United Kingdom

privacy

The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018, but that copy has now materially diverged: the Data (Use and Access) Act 2025, in force from 5 February 2026, replaced UK GDPR Article 22 with a permit-and-safeguard automated decision-making regime, added a new recognised legitimate interests lawful basis, restructured the cross-border transfer chapter around a new Article 44A, and gave the ICO a statutory duty to write a binding AI and automated decision-making Code of Practice.

The UK's own Supreme Court has separately narrowed the private right of action further than the CJEU's EU-wide line, foreclosing a no-injury, opt-out representative class action in Lloyd v Google.

14 instruments named 7 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

UK GDPR Articles 33-34 and PECR, Breach Notification in the United Kingdom

cite UK GDPR, Arts. 33-34; Privacy and Electronic Communications Regulations (PECR), as amended by the Data (Use and Access) Act 2025 stage In effect since 2018-05-25 source legislation.gov.uk, official consolidated text

UK General Data Protection Regulation (GDPR) Articles 33 and 34 retain the same 72-hour and without-undue-delay structure as EU GDPR, with no threshold for how serious a breach must be before it is notifiable. The DUA Act shortened the separate PECR breach-notification window for telecoms and ISP-type breaches from 24 hours to 72 hours, in force 20 August 2025, aligning it with the UK GDPR timeline, and raised the maximum PECR fine to GBP 17.5 million or 4 percent global turnover, up from GBP 500,000.

What it asks of an app

Comprehensive regime

UK GDPR and Data Protection Act 2018, as Amended by the Data (Use and Access) Act 2025

cite Data Protection Act 2018 (c. 12); UK GDPR, as amended by the Data (Use and Access) Act 2025, c. 18 stage In effect since 2018-05-25 source legislation.gov.uk, official consolidated text

The UK retained a copy of the General Data Protection Regulation (GDPR) at Brexit (UK GDPR) alongside the Data Protection Act 2018 (DPA 2018), but that copy has now materially diverged: the Data (Use and Access) Act 2025 (DUA Act, Royal Assent 19 June 2025), whose main data protection reforms took effect 5 February 2026, added a new closed-list "recognised legitimate interests" lawful basis (Article 6(1)(ea)) needing no balancing test, for purposes such as safeguarding, crime prevention, emergencies, national security, direct marketing, and intra-group administrative sharing.

This basis is unavailable to a public authority exercising its own core functions, and has no equivalent in the EU GDPR Article 6 list.

What it asks of an app

Cross border transfer

UK GDPR Articles 44A-50, Cross-Border Transfer of Personal Data from the United Kingdom

cite UK GDPR, Arts. 44A-50, as amended by the Data (Use and Access) Act 2025 stage In effect since 2026-02-05 source legislation.gov.uk, official consolidated text, verified by direct crawler fetch

The European Commission's own adequacy decisions for the UK were reaffirmed 19 December 2025 and now run to 27 December 2031. For UK-outbound transfers, the ICO administers its own International Data Transfer Agreement (IDTA, in force since 21 March 2022) and IDTA Addendum as the appropriate-safeguards mechanism where no UK adequacy regulation covers the destination.

The DUA Act restructured UK General Data Protection Regulation (GDPR)'s transfer chapter: the original Article 44 was omitted and replaced from 5 February 2026 by a new Article 44A, which requires that a transfer either be approved by regulations, made subject to appropriate safeguards, or made in reliance on a derogation for specific situations, the same three-track adequacy, safeguards, or derogation structure as EU GDPR Chapter V, run through the UK's own instruments rather than the EU's. This is a real, structured condition on outbound transfer, not an absence of restriction.

What it asks of an app

Data subject rights

Data (Use and Access) Act 2025 Section 80, Automated Decision-Making, UK GDPR Articles 22A-22D

cite Data (Use and Access) Act 2025, c. 18, §80 (new UK GDPR Arts. 22A-22D); S.I. 2026/425 stage In effect since 2026-02-05 source legislation.gov.uk, official consolidated text

Before the DUA Act, UK General Data Protection Regulation (GDPR) Article 22, inherited unchanged from EU GDPR, generally prohibited a decision based solely on automated processing that produces legal or similarly significant effects, subject to narrow exceptions.

Section 80 of the DUA Act replaced Article 22 with four new articles, 22A to 22D, in force from 5 February 2026: solely automated significant decisions are now permitted generally, with the controller required to inform the individual in advance, provide a meaningful human review on request, and let the decision be contested.

The general prohibition now applies only where the automated processing relies entirely or partly on special category data or on the new recognised legitimate interests basis.

A related statutory duty, S.I. 2026/425 (made 16 April 2026, in force 12 May 2026), requires the ICO to prepare and publish a binding Code of Practice on AI and automated decision-making; the ICO's own non-binding draft guidance was under public consultation from 31 March to 29 May 2026, with the statutory Code itself not expected to take effect until 2027.

That still-unmade Code is recorded on this same row rather than as a separate instrument, since it exists specifically to implement this reform and does not yet have content of its own to describe.

What it asks of an app

Enforcement supervision

UK GDPR Article 82, Data Protection Act 2018 Section 169, and ICO Enforcement

cite UK GDPR, Arts. 82-83; Data Protection Act 2018 §169 stage In effect since 2018-05-25 source legislation.gov.uk, official consolidated text, verified by direct crawler fetch

The Information Commissioner's Office (ICO) is the UK's single supervisory authority, unlike Germany's 17-authority structure, with UK General Data Protection Regulation (GDPR) Article 83 fines up to the greater of GBP 17.5 million or 4 percent of global turnover. Section 169 DPA 2018 supplies a private right of action for contravention of data protection legislation other than UK GDPR itself, while UK GDPR's own Article 82 covers contraventions of the Regulation directly; both cover material and non-material damage.

The UK's own Supreme Court has gone further than the CJEU in limiting what counts: Lloyd v Google LLC [2021] UKSC 50 (10 November 2021) unanimously rejected a representative claim brought on behalf of 4.4 million iPhone users, holding that compensation for a non-trivial data protection breach requires the individual to show tangible financial loss or distress, not a bare loss of control alone, and that such a claim cannot succeed without showing unlawful use and resulting damage for each individual claimant rather than the group as a whole.

What it asks of an app

Sensitive categories

R (Bridges) v Chief Constable of South Wales Police, Automated Facial Recognition by Police

cite R (Bridges) v Chief Constable of South Wales Police [2020] EWCA Civ 1058 stage In effect since 2020-08-11 source Court of Appeal (Civil Division) judgment, published by the Judicial Office

The Court of Appeal held South Wales Police's automated facial recognition trials unlawful, for breach of Article 8 ECHR, the Data Protection Acts 1998 and 2018 (no adequate legal framework, no proper Data Protection Impact Assessment), and the public-sector equality duty.

This is a public-authority case: it establishes that biometric surveillance deployment needs a proper legal framework, not just a lawful basis, and it is recorded here with `applies_to` government even though the underlying UK General Data Protection Regulation (GDPR) and DPA 2018 biometric rules apply to both public and private actors.

What it asks of an app

UK GDPR Article 9, Special Categories of Personal Data Including Biometric Data

cite UK GDPR, Art. 9; Data Protection Act 2018, Sch. 1 stage In effect since 2018-05-25 source legislation.gov.uk, official consolidated text

Biometric data used for identification, fingerprints, facial templates, voiceprints, is special category data under UK General Data Protection Regulation (GDPR) Article 9, the same definition as EU GDPR.

The DPA 2018's Schedule 1 supplies the UK's own list of Article 9(2)(g) substantial public interest conditions, 23 conditions in Part 2 of Schedule 1, in addition to explicit consent, employment and social-security processing authorised by law, vital interests, not-for-profit bodies, data manifestly made public, legal claims, health and social care, public health, and archiving and research.

The ICO's own "Biometric recognition" guidance, published in final form 5 March 2024, states that biometric data becomes special category personal data from the moment of collection once a purpose of unique identification has been determined for it, and that explicit consent is likely to be the legal basis most organisations need for biometric recognition specifically.

The Data (Use and Access) Act 2025 inserted a new Article 11A UK GDPR giving the Secretary of State a ministerial power to expand what falls within Article 9's restricted scope, covering genetic data, biometric data for unique identification, and health data, by regulation; no such regulation had been made as of this research.

The ICO fined Clearview AI Inc GBP 7,552,800 for, among other findings, failing to meet the higher data protection standard biometric data requires; the Upper Tribunal restored that finding in October 2025 after the First-tier Tribunal had overturned it on jurisdictional grounds.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.