ISMS Copilot

Learn

UK GDPR vs EU GDPR

Which statute applies, where transfers and the regulator diverge, and why swapping names on a GDPR template does not make it fit both.

Last reviewed 2026-09-17. Next review 2026-09-30 (ICO to Information Commission). Vendor-neutral. Not legal advice.

1. Name the establishment and the people, not the brand of the template

EU GDPR (Regulation (EU) 2016/679) applies to processing in the context of an establishment in the Union, and to offering goods or services to people in the Union or monitoring their behaviour there (Article 3). UK GDPR is EU GDPR incorporated into UK law and subsequently amended (now assimilated law), read with the Data Protection Act 2018. It applies to processing in the context of the activities of a UK establishment, and to the processing of an overseas organisation that is related to offering goods or services to people in the UK or monitoring their behaviour there. Residence is not a shortcut for establishment-based coverage. Dual scope is common: UK-only, EEA-only, or both. Use processing context and location, not citizenship.

2. The ICO is not an EU supervisory authority

UK GDPR replaced Member State supervisory authorities and the EDPB consistency machinery with the Commissioner. Chapter VII of EU GDPR is omitted. An EU one-stop-shop, where it applies, does not cover the UK part of a dual programme. Governance changes take effect on 30 September 2026: the organisation continues to be known as the ICO. That is a review date, not a new privacy statute.

3. Restricted transfers use different paper

Identify the transfer mechanism first. Adequacy can remove the need for extra safeguards on covered flows, including many UK to EEA and EEA to UK flows under current adequacy arrangements. A transfer risk assessment comes in when you rely on Article 46 safeguards such as the IDTA or the UK Addendum sitting on EU SCCs; other safeguards and limited exceptions also exist. Dual-jurisdiction teams often use EU SCCs plus the UK Addendum on the same processor, not one EU SCC pack reused as if the UK were still a Member State.

4. ISS-consent age 13 is UK law, and only for that gate

EU GDPR Article 8 lets Member States set the ISS-consent age between 13 and 16 (default 16). Ireland is 16. The UK is not a Member State. Under UK GDPR the age for consent to an information-society service offered directly to a child is 13, and only when consent is the lawful basis. It is not a universal age for every processing activity involving a child.

5. DUA 2025 amends the framework. It does not replace it.

The Data (Use and Access) Act 2025 amends UK GDPR, DPA 2018, and PECR. It is not a third privacy statute you swap in. The ICO states that the data-protection and PECR provisions are in force. The 30 September 2026 Information Commission change is governance, not a delayed DUA commencement. Treat DUA as a changelog on the existing UK GDPR plus DPA 2018 stack. Framework pages: UK GDPR, DPA 2018, DUA 2025.

Side-by-side

TopicEU GDPRUK GDPR
RegulatorNational SA; EDPB consistency; one-stop-shop only where the conditions are metThe Commissioner (ICO). No EDPB one-stop-shop
Restricted transfersEU SCCs and EU adequacyIDTA or UK Addendum, UK adequacy regulations
ISS-consent age13 to 16 by Member State (default 16)13, only for that ISS-consent gate

UK hub: ISMS Copilot for UK compliance teams. SaaS buying page: UK SaaS companies.

FAQ

Which GDPR applies if we are based in the EU and sell into the UK?

Both can. EU GDPR applies through your Union establishment, and UK GDPR applies through the offering-goods-or-services test even without a UK office. That means one UK-EU customer base can put you in dual scope: decide which regulator you notify, document the divergence points (transfers, ISS-consent age, DUA 2025 amendments), and do not assume the EEA arm answers for the UK arm.

Do UK to EU transfers need the same paperwork as EU to UK transfers?

Treat each direction as its own restricted-transfer question. UK adequacy regulations currently cover many UK to EEA flows, and the EU adequacy decision covers UK flows the other way. When no adequacy route applies, paper the gap with the IDTA or the UK Addendum on EU SCCs, and complete a transfer risk assessment where you rely on those Article 46 safeguards.

Is this legal advice?

No. This page is a vendor-neutral explainer of when each statute typically applies. It is not a determination for your facts.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.