{"id":1001,"date":"2022-05-02T12:51:00","date_gmt":"2022-05-02T12:51:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=1001"},"modified":"2026-03-12T09:15:45","modified_gmt":"2026-03-12T08:15:45","slug":"gdpr-brexit","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/gdpr-brexit\/","title":{"rendered":"GDPR after Brexit"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-and-brexit-2021-update\">GDPR and Brexit - 2021 update<\/h2>\n\n\n\n<p>On January 1, 2021, the United Kingdom formally and effectively left the European Union.<\/p>\n\n\n\n<p>Although the UK is now \u201ca third country\u201d under the EU\u2019s GDPR (i.e. a country outside of the EU without an adequacy decision), a provision in the agreement signed by the UK and EU in December 2020 secures <a href=\"\/en\/gdpr-brexit\/\" target=\"_blank\" rel=\"noreferrer noopener\">an interim period of six months<\/a>&nbsp;of unrestricted data flow between the two blocs.<\/p>\n\n\n\n<p>On June 28, 2021, the EU adopted <a href=\"https:\/\/ec.europa.eu\/info\/files\/decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">an adequacy decision for the UK<\/a>, ensuring the free flow of personal data between the two blocs for a four-year period (until June 2025).<\/p>\n\n\n\n<p>For UK websites, companies and organizations processing personal data from individuals inside the EU, this UK adequacy decision means unrestricted business-as-usual for the next four years.<\/p>\n\n\n\n<p>After June 2025, the EU will have to engage in a new adequacy process to determine whether the UK still ensures an equivalent level of data protection for the adequacy decision to be renewed.<\/p>\n\n\n\n<p><a href=\"https:\/\/ec.europa.eu\/info\/files\/decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the UK adequacy decision from June 2021<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/iapp.org\/news\/a\/faqs-for-uk-icos-data-transfer-consultation-including-approach-to-eu-sccs\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the ICO\u2019s consultation on data transfers to and from the U.K. from August 2021<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4238\/image-1.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustration of a person holding a clipboard - Cookiebot \" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">GDPR\/Brexit: Upon independence from the EU, the UK&nbsp;has adopted the same data regulations as before its exit.<\/figcaption><\/figure>\n\n\n\n<p>What happens to GDPR after Brexit in the UK?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>UK adequacy from June 2021 ensures unrestricted personal data flow between EU and UK for four years (till June 2025),<\/li>\n\n\n\n<li>The general data protection regime in UK data law has been changed to accommodate the disappearance of the EU GDPR\u2019s domestic applicability, including new domestic data privacy laws such as the new UK-GDPR and an updated Data Protection Act,<\/li>\n\n\n\n<li>After January 1, 2021, the EU\u2019s GDPR will still apply inside the EU for UK websites and companies that process personal data from inside the EU.<\/li>\n<\/ul>\n\n\n\n<p>We will look at the changes made to the legal landscape of UK data law, but first let\u2019s&nbsp;recap&nbsp;the European General Data Protection Regulation (GDPR).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-compliance-with-gdpr-after-brexit\">Compliance with GDPR after Brexit<\/h2>\n\n\n\n<p><a href=\"\/\">Our consent management platform (CMP)<\/a>&nbsp;is a world-leading solution for achieving full data privacy compliance on your website.<\/p>\n\n\n\n<p>With a powerful scanner that detects all cookies, trackers and trojan horses on your domain and maps exactly where in the world you send data to, <a href=\"\/\">Cookiebot CMP<\/a>&nbsp;takes the hard and difficult part out of privacy protection and compliance.<\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot CMP<\/a>&nbsp;offers plug-and-play compliance with the <a href=\"\/en\/gdpr\/\">EU\u2019s GDPR<\/a>, <a href=\"\/en\/uk-gdpr\/\">UK-GDPR<\/a>, <a href=\"\/en\/ccpa\/\">California\u2019s CCPA\/CPRA<\/a>, <a href=\"\/en\/popia\/\">South Africa\u2019s POPIA<\/a>, <a href=\"\/en\/lgpd\/\">Brazil\u2019s LGPD<\/a>, <a href=\"\/en\/singapore-pdpa\/\">Singapore\u2019s PDPA<\/a>&nbsp;and many other data privacy laws.<\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about GDPR and consent<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-reminder-what-is-the-gdpr\">Reminder: what is the GDPR?<\/h2>\n\n\n\n<p>The European regulation known as <strong>GDPR (General Data Protection Regulation)<\/strong>&nbsp;is a law in all EU member states that <strong>govern the protection of personal data<\/strong>&nbsp;and the ways it is allowed to be collected and processed by websites, companies, organizations and more.<\/p>\n\n\n\n<p><strong>GDPR<\/strong>&nbsp;has extraterritorial scope, which means that no matter where in the world your company and website is located, it has to comply with the GDPR if it has visitors from inside the European Union.<\/p>\n\n\n\n<p><strong>GDPR<\/strong>&nbsp;sets up a data protection regime in the EU that requires companies and websites (known as \u201ccontrollers\u201d and \u201cprocessors\u201d in the law) to have a legal basis in order to process the personal data of individuals (\u201cdata subjects\u201d) inside the EU.<\/p>\n\n\n\n<p>The most common legal basis for processing is prior consent \u2013 this means that in order to collect and process personal data of an individual in the EU, websites must obtain their consent to do so before any collection or processing can take place.<\/p>\n\n\n\n<p><a href=\"\/en\/gdpr\/\">Learn more about GDPR and cookie consent<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-after-brexit-in-the-uk\">GDPR after Brexit in the UK<\/h2>\n\n\n\n<p>The European Withdrawal Agreement signed by the UK and EU includes specific provisions on the processing of personal data and the flow of information between the UK and EU.<\/p>\n\n\n\n<p>In particular, <strong>Articles 70-73<\/strong>&nbsp;of the Agreement state that the UK&nbsp;<em>\u201cshall ensure a level of protection of personal data essentially equivalent to that under [European] Union law.\u201d<\/em><\/p>\n\n\n\n<p>Ensuring an EU equivalent level of personal data protection is very important for the UK, as it is the only way to be <strong>deemed<\/strong> <strong>adequate<\/strong>&nbsp;by the EU and thus ensure the free, uninhibited flow of data between the two countries.<\/p>\n\n\n\n<p><strong>Article 45<\/strong>&nbsp;of the GDPR rules that&nbsp;<em>\u201ca transfer of personal data to a third country or an international organization may take place where the Commission has decided that the third country (\u2026) ensures an adequate level of protection.\u201d<\/em><\/p>\n\n\n\n<p>In December 2020, a provision for <a href=\"https:\/\/ico.org.uk\/about-the-ico\/media-centre\/news-and-blogs\/2020\/12\/ico-statement-in-response-to-uk-governments-announcement-on-the-extended-period-for-personal-data-flows-that-will-allow-time-to-complete-the-adequacy-process\/\" target=\"_blank\" rel=\"noreferrer noopener\">an interim six month-period of free personal data flow<\/a>&nbsp;between UK and EU was agreed to, which means that for websites, businesses and organizations in the UK, <strong>all remains the same as it was before Brexit<\/strong>&nbsp;when it comes to the processing of personal data from inside the EU.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4241\/image-2.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustation of person holding the union jack flag - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">GDPR after Brexit is fortified in UK law upon Exit Day.<\/figcaption><\/figure>\n\n\n\n<p>On June 28, 2021, an adequacy decision was given by the EU to the UK, acknowledging the country\u2019s data protection level as equivalent as the bloc\u2019s own and thereby ensuring free flow of data for a period of four years (until June 2025).<\/p>\n\n\n\n<p><a href=\"https:\/\/ec.europa.eu\/info\/files\/decision-adequate-protection-personal-data-united-kingdom-general-data-protection-regulation_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">See the UK adequacy decision from June 2021<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-brexit-gdpr-and-the-dppec-regulations\">Brexit, GDPR and the DPPEC regulations<\/h3>\n\n\n\n<p>The GDPR\/Brexit changes made to UK data&nbsp;privacy law&nbsp;are all contained in the government\u2019s&nbsp;<em><a href=\"https:\/\/www.legislation.gov.uk\/ukdsi\/2019\/9780111177594\/contents\/\" target=\"_blank\" rel=\"noreferrer noopener\">Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019<\/a><\/em>, also known as the DPPEC regulations.&nbsp;<\/p>\n\n\n\n<p>They took effect on January 31, 2020, in accordance with the now-passed EU Withdrawal Agreement.<\/p>\n\n\n\n<p>The <strong>DPPEC regulation<\/strong>s do two major things:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>create a whole \"new\" domestic law known as UK-GDPR.<\/li>\n\n\n\n<li>revise the Data Protection Act 2018.<\/li>\n<\/ol>\n\n\n\n<p>In order to keep the promise in the Withdrawal Agreement\u2019s Articles 70-73, the UK has decided to create a whole \u201cnew\u201d domestic law known as the <strong>UK-GDPR<\/strong>&nbsp;(United Kingdom General Data Protection Regulation).<\/p>\n\n\n\n<p>The <a href=\"\/en\/uk-gdpr\/\">new UK-GDPR<\/a>&nbsp;is essentially the same as the European GDPR.<\/p>\n\n\n\n<p>It is literally made from the same law text as the EU GDPR but amended so as to substitute the parts of text that read&nbsp;<em>EU<\/em>&nbsp;and&nbsp;<em>Union law<\/em>&nbsp;with&nbsp;<em>UK<\/em>&nbsp;and&nbsp;<em>domestic law<\/em>.<\/p>\n\n\n\n<p>The <a href=\"\/en\/uk-gdpr\/\">UK-GDPR<\/a>&nbsp;merge the two pre-existing regimes for personal data protection \u2013 namely that established by the European GDPR and that established by the Data Protection Act 2018 (specifically the parts of that law known as the \u201capplied GDPR\u201d).<\/p>\n\n\n\n<p>The <a href=\"\/en\/data-protection-act-2018\/\">DPA2018\u2019s<\/a>&nbsp;\u201capplied GDPR\u201d section is the one that extended the GDPR\u2019s standards to areas that were out of scope of EU law and the GDPR, namely that of <strong>law enforcement<\/strong>,<strong>&nbsp;intelligence services&nbsp;<\/strong>and<strong>&nbsp;immigration<\/strong>&nbsp;(among others).<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4239\/image-3.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustration of an exit sign above a door opening - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">Brexit means GDPR-like regulation became domestic law in the UK on January 1, 2021.<\/figcaption><\/figure>\n\n\n\n<p>But let\u2019s be clear: <strong>there are more things that don\u2019t change than do change<\/strong>&nbsp;after Brexit with GDPR.<\/p>\n\n\n\n<p>The <a href=\"\/en\/uk-gdpr\/\">UK-GDPR&nbsp;<\/a>after Brexit will be the same as the <a href=\"\/en\/gdpr\/\">EU's GDPR<\/a>&nbsp;with slight changes, most of which are of superficial nature.<\/p>\n\n\n\n<p>The core provisions of the GDPR for which it has become known all over the world all remain the same under the new domestic UK-GDPR, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The principles relating to the processing of personal data and the lawfulness of processing (Article 5), the rules around processing of special categories of personal data (Article 9), also known as sensitive personal data such as data on race, political opinions, religious or philosophical beliefs, biometric data, sexual orientation and more.<\/li>\n\n\n\n<li>The conditions for consent (Article 7), with the exception of the valid age of consent (Article 8) that is lowered to 13 years in the UK-GDPR from 16 years in the EU GDPR.<\/li>\n\n\n\n<li>The rights of the data subject (Articles 15-22), including the right to access, right to be forgotten, right to data portability and the right to rectification etc.<\/li>\n<\/ul>\n\n\n\n<p><a href=\"\/en\/uk-gdpr\/\">Check out more on the new UK-GDPR after Brexit.<\/a><\/p>\n\n\n\n<p>The changes made to the GDPR after Brexit in order to create the new domestic version are visible in the following Keeling Schedule, which is a document comprising all the changes of the DPPEC regulations made to the GDPR.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.gov.uk\/government\/publications\/data-protection-law-eu-exit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Keeling Schedule for the new domestic post-Brexit GDPR.<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-amended-data-protection-act-2018\">The amended Data Protection Act 2018<\/h3>\n\n\n\n<p>The <a href=\"\/en\/data-protection-act-2018\/\">new and amended Data Protection Act 2018<\/a>&nbsp;also&nbsp;took effect on January 31, 2020.<\/p>\n\n\n\n<p>The <a href=\"\/en\/data-protection-act-2018\/\">DPA2018<\/a>&nbsp;will no longer rely on the EU GDPR, but on the <a href=\"\/en\/uk-gdpr\/\">UK-GDPR<\/a>&nbsp;instead. It will instead refer to the new domestic GDPR after Brexit.<\/p>\n\n\n\n<p>UK citizens will now be protected by a comprehensive data protection regime that is made up of the <a href=\"\/en\/uk-gdpr\/\">UK-GDPR<\/a>&nbsp;on the one hand that defines (just as the EU GDPR does today) what personal data is and how it is allowed to be processed, and the <a href=\"\/en\/data-protection-act-2018\/\">Data Protection Act 2018<\/a>&nbsp;on the other hand, supplementing the domestic GDPR and extending beyond it as well.<\/p>\n\n\n\n<p><a href=\"\/en\/data-protection-act-2018\/\">More on the new and amended Data Protection Act 2018 here.<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.gov.uk\/government\/publications\/data-protection-law-eu-exit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Keeling Schedule for the Data Protection Act 2018.<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-brexit-and-gdpr-in-short\">Brexit and GDPR in short<\/h3>\n\n\n\n<p>Here\u2019s a short recap of what happened on&nbsp;January&nbsp;1, 2021:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Six months interim period secures free personal data flow between UK and EU.<\/li>\n\n\n\n<li>The new UK-GDPR is in effect.<\/li>\n\n\n\n<li>An amended version of the Data Protection Act 2018 is in effect.<\/li>\n<\/ul>\n\n\n\n<p>According the UK government,&nbsp;<em>\u201cno, or no significant, impact on the private, voluntary or public sector is foreseen\u201d<\/em>&nbsp;as a consequence of the changes made to UK data protection law.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized is-style-cb-rounded\"><img loading=\"lazy\" decoding=\"async\" src=\"\/media\/4240\/image-4.jpeg?width=450&amp;&amp;mode=max\" alt=\"Illustrated close-up of someone stepping through doorway - Cookiebot - Cookiebot\" width=\"770\" height=\"513\"\/><figcaption class=\"wp-element-caption\">GDPR after Brexit means both old and new, as same things become different.<\/figcaption><\/figure>\n\n\n\n<p>Now, with regards to the GDPR after Brexit in the EU \u2013 <strong>there are no changes<\/strong>.<\/p>\n\n\n\n<p>If a website based in the UK has visitors from the EU, it still has to comply with the European GDPR after Brexit just as it did before.<\/p>\n\n\n\n<p>That\u2019s because the EU GDPR has extraterritorial scope and applies to any website, company or organization in the world that collects or processes data from inside Europe.<\/p>\n\n\n\n<p>The biggest change here will be who is the supervisor and enforcer.<\/p>\n\n\n\n<p>Since the EU GDPR won\u2019t apply domestically to the UK after the transition period of Brexit, data law in the UK will&nbsp;<em>not<\/em>&nbsp;be supervised or enforced by the <a href=\"https:\/\/edpb.europa.eu\/about-edpb\/about-edpb_en\/\" target=\"_blank\" rel=\"noreferrer noopener\">European Data Protection Board (EDPB)<\/a>, the main power of supervision and enforcement today.<\/p>\n\n\n\n<p>Rather, it will be the <a href=\"https:\/\/ico.org.uk\/\" target=\"_blank\" rel=\"noreferrer noopener\">Information Commissioner (ICO)<\/a>&nbsp;that will supervise and enforce the domestic UK-GDPR and Data Protection Act 2018 on UK soil.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-brexit-and-your-website\">GDPR, Brexit and your website<\/h2>\n\n\n\n<p>What does all of this Brexit and GDPR stuff ultimately mean for you and your website and its use of cookies and similar tracking technology?<\/p>\n\n\n\n<p>It means that <strong>until June 2021<\/strong>, the interim provision allows unrestricted personal data flow between UK and EU.<\/p>\n\n\n\n<p>Your website will need to comply with the GDPR (both UK and EU versions) just as before, but no additional measures need to be taken when processing personal data from the EU:<\/p>\n\n\n\n<p>You still need the <strong>prior consent<\/strong>&nbsp;of your end-users before you are allowed to collect or process their personal data, e.g. with a cookie banner.<\/p>\n\n\n\n<p><a href=\"\/en\/gdpr-cookies\/\">Learn more about GDPR and consent on your website<\/a><\/p>\n\n\n\n<p><a href=\"\/\">Cookiebot&nbsp;CMP<\/a>&nbsp;scans your website and finds all cookies and similar tracking technologies, then blocks them all apart from the strictly necessary, and therefore compliant, until the user has given their consent as to which they want to activate.<\/p>\n\n\n\n<p>This way, your website can be sure to be in compliance with the requirements of obtaining prior consent from individuals, before collecting or processing their personal data.<\/p>\n\n\n\n<p>Protecting users in the UK after Brexit requires the same insight, transparency and control of what happens on your website as before.<\/p>\n\n\n\n<p>In short, before Brexit, under Brexit and after Brexit, our solution ensures your website full EU and <a href=\"\/en\/uk-gdpr\/\">UK-GDPR compliance<\/a>, as well as compliance with the <a href=\"\/en\/data-protection-act-2018\/\">Data Protection Act 2018<\/a>.<\/p>\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>GDPR and Brexit - 2021 update On January 1, 2021, the United Kingdom formally and effectively left the European Union. Although the UK is now \u201ca third country\u201d under the EU\u2019s GDPR (i.e. a country outside of the EU without an adequacy decision), a provision in the agreement signed by the UK and EU in [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":1023,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1001","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2022\/05\/hero_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1001","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=1001"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/1001\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/1023"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=1001"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=1001"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=1001"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}