UK GDPR
The UK GDPR is the version of the EU General Data Protection Regulation retained in United Kingdom law after Brexit under the European Union (Withdrawal) Act 2018, as modified by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019. It applies since 1 January 2021 together with the Data Protection Act 2018, which supplements it with UK-specific provisions on special category data conditions (Schedule 1), exemptions, law enforcement and intelligence processing. The Data (Use and Access) Act 2025 introduced targeted amendments, including recognised legitimate interests, a statutory definition of scientific research, relaxed rules for automated decision-making outside special category data, and a reformed regulator.
The substance mirrors the EU GDPR: the same principles, legal bases, rights, DPIA and DPO requirements, breach notification and fine levels (up to GBP 17.5 million or 4% of turnover). Key differences lie in enforcement by the Information Commissioner's Office (to become the Information Commission), in the UK's own adequacy regulations (which recognise the EEA and other countries), in UK transfer tools (the International Data Transfer Agreement and the UK Addendum to the EU SCCs, plus the UK Extension to the Data Privacy Framework), and in Art. 3A, which requires controllers and processors outside the UK that offer goods or services to, or monitor, people in the UK to appoint a UK representative.
For life sciences, the UK remains a major trial location, and clinical trials there are regulated by the Medicines for Human Use (Clinical Trials) Regulations 2004 as reformed in 2025, with the Health Research Authority overseeing ethics. A sponsor running trials in both the EU and the UK therefore needs two representatives, two transfer analyses and dual references in its informed consent forms and records. The European Commission renewed the UK's EU adequacy decisions in December 2025, so EU-to-UK transfers remain free of additional safeguards. iliomad acts as UK Data Protection Representative; see also the UK Data Protection Act service page.
