{"id":643,"date":"2022-05-04T07:54:00","date_gmt":"2022-05-04T07:54:00","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=643"},"modified":"2026-03-12T09:15:23","modified_gmt":"2026-03-12T08:15:23","slug":"uk-gdpr","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/uk-gdpr\/","title":{"rendered":"UK-GDPR law after Brexit"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The GDPR post-Brexit<\/h2>\n\n\n\n<p>Although the United Kingdom (UK) formally withdrew from the European Union (EU) on 31 January 2020, it remained subject to EU law, including the<a href=\"https:\/\/www.cookiebot.com\/en\/gdpr\/\"> General Data Protection Regulation (EU GDPR)<\/a>, until the end of the transition period on 31 December 2020.<\/p>\n\n\n\n<p>After Brexit, as the UK\u2019s withdrawal from the EU is commonly known, the UK passed<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/contents\" target=\"_blank\" rel=\"noreferrer noopener\"> the United Kingdom General Data Protection Regulation (UK-GDPR)<\/a> to protect the personal data of its citizens and residents. The new UK-GDPR took effect on January 1, 2021 so that there was no gap between the EU GDPR and UK-GDPR. Alongside the<a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\/enacted\" target=\"_blank\" rel=\"noreferrer noopener\"> Data Protection Act of 2018 (DPA)<\/a> and the<a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\/enacted\" target=\"_blank\" rel=\"noreferrer noopener\"> Privacy and Electronic Communications (EC Directive) Regulations 2003<\/a>, it governs the processing of personal data belonging to individuals located in the UK.<\/p>\n\n\n\n<p>Since Brexit and the passing of the UK-GDPR, the EU GDPR no longer applies in the UK, as it applies only to the processing of personal data of individuals located in the EU and EEA.<\/p>\n\n\n\n<p>We look at the key provisions of the UK-GDPR, including its scope, main principles, and key obligations related to consent, data processing, and data subject rights.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-uk-gdpr\">What is the UK-GDPR?<\/h2>\n\n\n\n<p>The UK-GDPR is the UK's data protection regulation that governs the processing of personal data belonging to individuals located in the UK, including both citizens and residents. They are known as \u201cdata subjects\u201d under the UK-GDPR, identified or identifiable natural persons. The UK-GDPR protects the personal data of individuals only, and not other legal entities.<\/p>\n\n\n\n<p>\u201cPersonal data\u201d under the UK-GDPR means <em>\u201cany information relating to an identified or identifiable natural person\u201d <\/em>who can be directly or indirectly identified using it<em>. <\/em>Examples of personal data include:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>names<\/li>\n\n\n\n<li>ID numbers<\/li>\n\n\n\n<li>phone numbers<\/li>\n\n\n\n<li>online identifiers, such as an IP address<\/li>\n\n\n\n<li>information collected via<a href=\"https:\/\/www.cookiebot.com\/en\/tracking-cookies\/\"> tracking cookies<\/a><\/li>\n\n\n\n<li>sensitive personal details, such as racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership<\/li>\n<\/ul>\n\n\n\n<p>Processing includes both automatic and manual <em>\"collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction\"<\/em> of personal data.<\/p>\n\n\n\n<p>The UK-GDPR is almost word for word identical to the EU GDPR, which was adapted after Brexit to suit UK-specific requirements. It provides the main principles, rights, and obligations for data protection in the UK.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-does-the-uk-gdpr-apply-to\">Who does the UK-GDPR apply to?<\/h2>\n\n\n\n<p>Under<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/3\" target=\"_blank\" rel=\"noreferrer noopener\"> Art. 3 UK-GDPR<\/a>, the regulation applies to the following:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>a person or entity in the UK that processes personal data, whether or not the processing takes place in the UK<\/li>\n\n\n\n<li>a person or entity located outside the UK that processes the personal data of UK citizens or residents, when the processing activities are related to:\n<ul class=\"wp-block-list\">\n<li>goods and services offered to UK citizens and residents, even if no payment takes place<\/li>\n\n\n\n<li>the monitoring of their behavior within the UK<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>a person or entity that processes personal data in a place where the law of the UK (or part of the UK) applies by virtue of public international law<\/li>\n<\/ul>\n\n\n\n<p>The UK-GDPR thus has extraterritorial scope and applies to entities located outside the UK if the regulation's requirements are met.<\/p>\n\n\n\n<p>A person or entity that processes personal data may be either a data controller or data processor under the UK-GDPR. A data controller is a <em>\u201cnatural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.\u201d <\/em>When two or more data controllers jointly determine the purposes and means of processing personal data, they are known as \u201cjoint controllers\u201d under the regulation.<\/p>\n\n\n\n<p>A data processor is a <em>\u201cnatural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.\u201d<\/em>If any one of these circumstances applies to you, the UK-GDPR applies to you and you must comply with its requirements.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/06\/cb_blog_body_770x513_brexit_gdpr_202406_1.svg\" alt=\"\" class=\"wp-image-14394\" width=\"683px\" height=\"auto\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-exemptions-from-the-uk-gdpr\">Exemptions from the UK-GDPR<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/2\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 2 UK-GDPR<\/a> specifies that the regulation does not apply to the processing of personal data:\u00a0<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>by an individual in the course of a purely personal or household activity<\/li>\n\n\n\n<li>by a competent authority for law enforcement purposes<\/li>\n\n\n\n<li>by intelligence services, such as MI5<\/li>\n<\/ul>\n\n\n\n<p>The processing of personal data for law enforcement and intelligence services purposes is governed by the DPA, which supplements the UK-GDPR. The DPA expands the scope of data protection in the UK to include national security and intelligence services, which are outside the scope of the EU GDPR as it doesn\u2019t have jurisdiction over national security within member states.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/schedule\/2\/enacted\" target=\"_blank\" rel=\"noreferrer noopener\">Schedule 2<\/a> of the DPA also contains exemptions to some provisions of the UK GDPR for the processing of personal data for certain purposes. These exemptions include, among others:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>crime and taxation risk assessments<\/li>\n\n\n\n<li>legal professional and parliamentary privilege<\/li>\n\n\n\n<li>immigration<\/li>\n\n\n\n<li>Bank of England functions<\/li>\n\n\n\n<li>judicial appointments, independence, and proceedings<\/li>\n\n\n\n<li>journalism, academia, art, and literature, to balance freedom of expression with privacy rights<\/li>\n\n\n\n<li>research and statistics<\/li>\n\n\n\n<li>health data and social work data in certain circumstances\u00a0<\/li>\n\n\n\n<li>child abuse data<\/li>\n\n\n\n<li>corporate finance<\/li>\n\n\n\n<li>exam scripts and marks<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-principles-of-the-uk-gdpr\">What are the principles of the UK-GDPR?<\/h2>\n\n\n\n<p>The UK-GDPR sets out seven key principles (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/5\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 5 UK-GDPR<\/a>) that you must uphold when processing your users\u2019 personal data.<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li><strong>Lawfulness, fairness, and transparency: <\/strong>you must have a legal basis for processing personal data and must provide clear and transparent information about your data processing activities to users.<\/li>\n\n\n\n<li><strong>Purpose limitation: <\/strong>you must not process personal data for any purpose other than the ones for which you have obtained explicit, informed consent, unless you obtain new consent if purposes change.<\/li>\n\n\n\n<li><strong>Data minimization: <\/strong>you must only process that data that is adequate, relevant, and limited to what you need for the intended purposes.<\/li>\n\n\n\n<li><strong>Accuracy:<\/strong> you must keep users\u2019 personal data up to date and accurate, and correct or delete inaccurate data without delay.<\/li>\n\n\n\n<li><strong>Storage limitation:<\/strong> you must keep personal data only for as long as necessary for the intended purposes.<\/li>\n\n\n\n<li><strong>Integrity and confidentiality:<\/strong> you must safeguard personal data and protect it against unauthorized or unlawful processing, accidental loss, destruction, or damage.<\/li>\n\n\n\n<li><strong>Accountability:<\/strong> you must be responsible for the personal data you process and be able to demonstrate compliance with these principles.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/06\/cb_blog_body_770x513_brexit_gdpr_202406_2.svg\" alt=\"\" class=\"wp-image-14395\" width=\"707px\" height=\"auto\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-legal-bases-for-processing-data-under-the-uk-gdpr\">What are the legal bases for processing data under the UK-GDPR?<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/6\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 6 UK-GDPR<\/a> provides six legal bases for processing personal data under the UK-GDPR. One of these must apply and be provable for the data processing to be lawful:<\/p>\n\n\n\n<ol class=\"is-style-default wp-block-list\">\n<li>with the explicit consent of the data subject<\/li>\n\n\n\n<li class=\"cb-rounded\">to perform a contract you have entered into with the data subject<\/li>\n\n\n\n<li>to comply with a legal obligation<\/li>\n\n\n\n<li>to protect the vital interests of the data subject or of another person<\/li>\n\n\n\n<li>to perform a task carried out in the public interest or in the exercise of official authority you may have<\/li>\n\n\n\n<li>where you have legitimate interests, except where they infringe upon the interests or fundamental rights and freedoms of the data subject<\/li>\n<\/ol>\n\n\n\n<p>Legitimate interest is not a legal basis for processing carried out by public authorities performing their tasks. The<a href=\"https:\/\/www.cookiebot.com\/en\/iab-tcf-cookies\/\"> Interactive Advertising Bureau\u2019s Transparency and Consent Framework v2.2 (IAB TCF v2.2)<\/a> has also removed legitimate interest as a basis for data processing related to advertising and content personalization. Under the IAB TCF v2.2, explicit consent is the only acceptable legal basis for processing personal data for these purposes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-considered-uk-gdpr-compliant-consent\">What is considered UK-GDPR compliant consent?<\/h2>\n\n\n\n<p>Consent under the regulation means <em>\u201cany freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.\u201d<\/em><\/p>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/introduction\" target=\"_blank\" rel=\"noreferrer noopener\">Recital 32<\/a> explains consent under the UK-GDPR further. Although the recital is not legally binding, it provides important context to help understand the law and what does, and does not, constitute legally valid consent.<\/p>\n\n\n\n<p>It may be via a written statement, including by electronic means, or an oral statement. It may include checking a box on a website or choosing technical settings on an electronic service that the user requests, such as an ecommerce store, streaming service, social media platform, or digital marketplace. Silence, pre-checked boxes and inactivity are not considered valid consent. When there are multiple purposes for processing, the user must give explicit consent for all of them, or if they make granular consent selections only for some of them, processing may only proceed for those selected.<\/p>\n\n\n\n<p>The UK-GDPR gives users the right to withdraw consent at any time once it has been given (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/7\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 7 UK-GDPR<\/a>). The method for withdrawing consent should be as easy as the method for giving it.<\/p>\n\n\n\n<p>When it comes to processing the personal data of a child under the age of 13 years, you must obtain consent from the parent or legal guardian for it to be legally valid (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/8\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 8 UK-GDPR<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-cookies-and-the-uk-gdpr-compliance\">Cookies and the UK-GDPR compliance<\/h3>\n\n\n\n<p>If you collect personal data from users online, such as from your website or app, the UK-GDPR requires you to obtain explicit consent from users before processing their personal data via cookies and other<a href=\"https:\/\/www.cookiebot.com\/en\/website-tracking\/\"> website tracking<\/a> technologies. Websites often display<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-banner\/\"> cookie banners<\/a> requesting this consent or<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-walls\/\"> cookie walls<\/a> that at times deny access without consent. These cookie banners serve as the initial point of contact between the website and its visitors, informing users about data collection practices and setting the stage for compliance with the UK GDPR.<\/p>\n\n\n\n<p>The transparency of these banners varies widely, with some sites clearly explaining user rights and options while others fall short. Many sites allow users to customize their consent choices, specifying which types of data they are comfortable sharing. However, a significant number of these cookie banners still do not meet UK-GDPR compliance standards, meaning they don't fully adhere to legal requirements for user consent and data protection. Cookie walls that block site access unless consent is given are prohibited under many global data privacy regulations, and are not recommended.<\/p>\n\n\n\n<p>To be UK-GDPR compliant, your cookie banner should:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>provide clear information about the use of cookies and their purposes<\/li>\n\n\n\n<li>obtain explicit consent before any non-essential cookies are stored on the user's device<\/li>\n\n\n\n<li>enable users to make granular choices about the types of cookies they are willing to accept<\/li>\n\n\n\n<li>be user-friendly, ensuring that users can easily navigate the options and provide (or withdraw) explicit consent<\/li>\n<\/ul>\n\n\n\n<p>Implementing robust<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-consent\/\"> cookie consent<\/a> practices that prioritize transparency, user control, and clear communication can help you achieve compliance with the UK-GDPR\u2019s consent requirements.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Obtain valid consent with the help of a UK-GDPR compliant cookie banner. Sign up for your free Cookiebot CMP trial.                    <\/h2>\n                                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"5a9442b5-0b61-48d1-b3c2-3a8898821f97\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/admin.cookiebot.com\/signup\" target=\"_blank\">\n<span>Start now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-rights-of-data-subjects-under-the-uk-gdpr\">What are the rights of data subjects under the UK-GDPR?<\/h2>\n\n\n\n<p>Data subjects have eight rights under the regulation (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/chapter\/III\" target=\"_blank\" rel=\"noreferrer noopener\">Chapter 3 UK-GDPR<\/a>). These are the same as the rights under the EU GDPR.<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li><strong>Right to be informed <\/strong>about how you collect and use their personal data (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/13\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 13<\/a> and<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/14\" target=\"_blank\" rel=\"noreferrer noopener\"> 14<\/a>)<\/li>\n\n\n\n<li><strong>Right of access <\/strong>to their personal data and to receive a copy of it (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/15\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 15<\/a>)<\/li>\n\n\n\n<li><strong>Right of rectification <\/strong>or correction of inaccurate data you may hold, including completion of incomplete data (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/16\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 16<\/a>)<\/li>\n\n\n\n<li><strong>Right of erasure <\/strong>of their personal data in certain circumstances, such as when they revoke consent and there\u2019s no other lawful basis for processing, among others \u2014 also known as the \u201cright to be forgotten\u201d (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/17\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 17<\/a>)<\/li>\n\n\n\n<li><strong>Right to restrict processing <\/strong>in certain circumstances, such as when the processing is unlawful or you no longer need the personal data, among others (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/18\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 18<\/a>)<\/li>\n\n\n\n<li><strong>Right to data portability <\/strong>or to receive the personal data they have provided to you in a \u201cstructured, commonly used and machine-readable format\u201d (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/20\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 20<\/a>)<\/li>\n\n\n\n<li><strong>Right to object <\/strong>to the processing of their personal data in certain circumstances, such as when it is used for direct marketing (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/21\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 21<\/a>)<\/li>\n\n\n\n<li><strong>Rights related to automated decision-making, including profiling <\/strong>to provide data subjects with the right to not have decisions made about them automatically by computers (e.g. AI tools) if those decisions can significantly affect their legal rights or have other major impacts on their life (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/22\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 22<\/a>)<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-obligations-of-controllers-under-the-uk-gdpr-an-overview-of-key-requirements\">What are the obligations of controllers under the UK-GDPR? An overview of key requirements<\/h2>\n\n\n\n<p>Controllers are responsible for compliance with all the obligations laid out by the UK-GDPR. This includes not only their own compliance but also ensuring that any processors they work with adhere to the regulation.<\/p>\n\n\n\n<p>A vital obligation for controllers is informing data subjects about your data processing activities (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/13\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 13<\/a> and <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/14\" target=\"_blank\" rel=\"noreferrer noopener\">14<\/a> UK-GDPR). The UK-GDPR requires you to inform them of:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>what personal data you process<\/li>\n\n\n\n<li>the purposes for processing personal data<\/li>\n\n\n\n<li>the legal basis for processing<\/li>\n\n\n\n<li>how long you will retain the data for<\/li>\n\n\n\n<li>the recipients or categories of recipients of the personal data, if any<\/li>\n\n\n\n<li>information about international transfer of personal data, if applicable<\/li>\n\n\n\n<li>information about users\u2019 rights under the regulation, including the right to revoke consent<\/li>\n\n\n\n<li>your contact information<\/li>\n\n\n\n<li>the contact details of your Data Protection Officer (DPO), if you are required to appoint one<\/li>\n<\/ul>\n\n\n\n<p>This information is commonly provided in a<a href=\"https:\/\/usercentrics.com\/knowledge-hub\/what-is-a-privacy-policy-and-why-do-you-need-one\/\" target=\"_blank\" rel=\"noreferrer noopener\"> privacy policy<\/a> or privacy notice. If you collect data through the website cookies and other tracking technologies, you should include a<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-policy\/\"> cookie policy<\/a> that details the use of cookies, including the types of cookies, their purposes, what personal data they collect, who has access to the personal data collected, how long the cookies will stay on users\u2019 browsers for, and how users can set or change their cookie preferences. A cookie policy can be a separate policy or part of the privacy policy.<\/p>\n\n\n\n<p>Your privacy policy must be written in clear, plain language, without using legal jargon, so that anyone can understand it without legal or technical knowledge. It must be clearly accessible for users to find and is commonly shared through a link in a website\u2019s footer and on the cookie banner.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Instantly create your privacy policy with the Cookiebot\u2122 Privacy Policy Generator                    <\/h2>\n                                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"5c21cfb9-f78b-4615-af20-548d5e2caff7\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"\/en\/privacy-policy-generator-gdpr\/\" target=\"\">\n<span>Generate now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<p>You must use appropriate technical and organizational measures to comply with the regulation, and be able to show you have complied (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/24\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 24 UK-GDPR<\/a>). Examples of appropriate measures include, among other actions:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>establishing and maintaining data protection policies that provide a framework for how personal data is handled and protected within the organization<\/li>\n\n\n\n<li>conducting regular audits and reviews of data processing activities to help identify and mitigate risks associated with data processing, enabling ongoing compliance<\/li>\n\n\n\n<li>training staff on data protection practices to educate employees about their responsibilities and the importance of protecting personal data<\/li>\n<\/ul>\n\n\n\n<p>If you are not an entity registered in the UK, you may be required to appoint a designated representative in the country (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/27\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 27 UK-GDPR<\/a>), whether you are a controller or processor. However, you remain liable for violations of the UK-GDPR, even after appointment of a representative. The provisions of Art. 27 don\u2019t apply to a public authority or body or when data processing happens occasionally and doesn\u2019t include large-scale processing of:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>special categories of data under the regulation, such as health data, racial or ethnic origin, political opinions<\/li>\n\n\n\n<li>personal data related to criminal convictions and offenses<\/li>\n<\/ul>\n\n\n\n<p>The UK-GDPR requires both controllers and processors to appoint a Data Protection Officer (DPO) in specific cases (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/37\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 37 UK-GDPR<\/a>), including:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>if you are a public authority or body carrying out data processing<\/li>\n\n\n\n<li>your data processing operations require regular, systematic, and large-scale monitoring of data subjects<\/li>\n\n\n\n<li>your data processing activities consist of large-scale processing of special categories of data under the regulation or personal data relating to criminal convictions and offenses<\/li>\n\n\n\n<li>You must publish the details of your DPO in your privacy policy and communicate them to the Information Commissioner, referred to as the Commissioner in the regulation.<\/li>\n<\/ul>\n\n\n\n<p>Controllers and processors both must maintain records of processing activities containing information about, among other things (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/30\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 30 UK-GDPR<\/a>):<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>name and contact details of the controller, joint controller, processor, or Data Protection Officer, if appointed<\/li>\n\n\n\n<li>any personal data is transferred to third countries or international organizations\u00a0<\/li>\n\n\n\n<li>technical and organizational security measures<\/li>\n<\/ul>\n\n\n\n<p>These records demonstrate your compliance with the UK-GDPR and must be made available to supervisory authorities upon request.<\/p>\n\n\n\n<p>If you appoint a third-party processor to process personal data on your behalf, you must enter into a written contract with the processor that is binding on them (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/28\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 28 UK-GDPR<\/a>). This contract or Data Processing Agreement (DPA) must set out:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>the subject matter and duration of the processing<\/li>\n\n\n\n<li>the nature and purpose of the processing<\/li>\n\n\n\n<li>the type of personal data and categories of data subjects\u00a0<\/li>\n\n\n\n<li>your obligations and rights<\/li>\n<\/ul>\n\n\n\n<p>Processors cannot process personal data without instructions from the controller (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/29\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 29 UK-GDPR<\/a>). They must also assist in complying with the regulation, including deleting personal data, ensuring confidentiality of the data, and implementing appropriate security measures.<\/p>\n\n\n\n<p>In the event of a data breach, you must notify the Commissioner without undue delay and not later than 72 hours after you become aware of it (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/33\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 33 UK-GDPR<\/a>). If there is a further delay, you must inform the Commissioner why there has been a delay. In case the breach may result in a high risk to the rights and freedoms of natural persons, you must also communicate the breach to the affected data subjects without delay (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/34\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 34 UK-GDPR<\/a>).<\/p>\n\n\n\n<p>The UK-GDPR requires you to carry out a Data Protection Impact Assessment (DPIA) in situations where processing is likely to result in a high risk to the rights and freedoms of natural persons, especially when using new technologies (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/35\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 35 UK-GDPR<\/a>). The DPIA must be conducted before the processing takes place, and you must consult your DPO when carrying it out.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-data-transfers-outside-the-uk-under-the-uk-gdpr\">Data transfers outside the UK under the UK-GDPR<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/chapter\/V\" target=\"_blank\" rel=\"noreferrer noopener\">Chapter 5 UK-GDPR<\/a> addresses the transfer of personal data from the UK to third countries or international organizations, whether during processing or after it has been processed.<\/p>\n\n\n\n<p>Transferring personal data outside of the UK needs additional measures to ensure its protection. These measures often include a specific adequacy agreement, which verifies that the destination country or organization provides an adequate level of data protection comparable to that provided under the UK-GDPR (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/45\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 45 UK-GDPR<\/a>). It allows for the free flow of personal data from the UK to the designated country without requiring additional safeguards. The UK has two adequacy agreements currently in place, with the European Economic Area (EEA) and<a href=\"https:\/\/www.gov.uk\/government\/news\/uk-finalises-landmark-data-decision-with-south-korea-to-help-unlock-millions-in-economic-growth\" target=\"_blank\" rel=\"noreferrer noopener\"> South Korea<\/a>.<\/p>\n\n\n\n<p>When assessing whether the level of protection of the third country or international organization is adequate, the considerations include:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>rule of law and respect for human rights and fundamental freedoms\u00a0<\/li>\n\n\n\n<li>existence of one or more independent supervisory authorities<\/li>\n\n\n\n<li>existing international commitments of the third country or international organization, or obligations arising from legally binding conventions<\/li>\n<\/ul>\n\n\n\n<p>You may transfer personal data outside the UK in the absence of an adequacy agreement, but only if you have provided appropriate safeguards and can ensure data subject rights and legal remedies are available (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/46\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 46 UK-GDPR<\/a>).<\/p>\n\n\n\n<p>Data transfers can be done to a third country or international organization when there\u2019s no adequacy agreement or appropriate safeguards in place only if one of the following conditions is fulfilled (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/49\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 49 UK-GDPR<\/a>):<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>the data subject has given explicit consent after being informed of the potential risks of the transfer\u00a0<\/li>\n\n\n\n<li>the transfer is necessary for you to perform a contract with the data subject<\/li>\n\n\n\n<li>the transfer is necessary for the conclusion or performance of a contract in the data subject\u2019s interest with another person or entity<\/li>\n\n\n\n<li>for reasons of public interest<\/li>\n\n\n\n<li>for establishing, exercising, or defending legal claims<\/li>\n\n\n\n<li>to protect the data subject\u2019s or another person\u2019s vital interests, particularly when the data subject is physically or legally incapable of consenting<\/li>\n\n\n\n<li>the transfer is made from a public register intended to provide information to the public, and access to this register is granted based on domestic law<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large is-resized is-style-cb-rounded\"><img decoding=\"async\" src=\"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/06\/cb_blog_body_770x513_brexit_gdpr_202406_3.svg\" alt=\"\" class=\"wp-image-14396\" width=\"657px\" height=\"auto\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-penalties-under-the-uk-gdpr\">Penalties under the UK-GDPR<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/83\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 83 UK-GDPR<\/a> outlines two levels of penalties for violations of the UK-GDPR.<\/p>\n\n\n\n<p>Infringement of the following provisions are subject to fines up to GBP 8.7 million, or up to 2 percent of the total worldwide annual turnover for the preceding financial year, whichever is higher:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>obligations of the controller and processor under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/8\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 8<\/a>, <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/11\" target=\"_blank\" rel=\"noreferrer noopener\">11<\/a>, <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/chapter\/IV\/section\/1\" target=\"_blank\" rel=\"noreferrer noopener\">25<\/a> to <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/chapter\/IV\/section\/4\" target=\"_blank\" rel=\"noreferrer noopener\">39<\/a>, <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/42\" target=\"_blank\" rel=\"noreferrer noopener\">42<\/a>, <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/43\" target=\"_blank\" rel=\"noreferrer noopener\">43<\/a><\/li>\n\n\n\n<li>obligations of the certification body under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/42\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 42<\/a> and <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/43\" target=\"_blank\" rel=\"noreferrer noopener\">43<\/a><\/li>\n\n\n\n<li>obligations of the monitoring body under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/41\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 41(4)<\/a><\/li>\n<\/ul>\n\n\n\n<p>Infringements of the following provisions are subject to fines up to GBP 17.5 million, or up to 4 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher:<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>basic principles for processing, including conditions for consent, under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/5\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 5<\/a>, <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/6\" target=\"_blank\" rel=\"noreferrer noopener\">6<\/a>, <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/7\" target=\"_blank\" rel=\"noreferrer noopener\">7<\/a>, and <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/9\" target=\"_blank\" rel=\"noreferrer noopener\">9<\/a><\/li>\n\n\n\n<li>data subjects' rights under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/chapter\/III\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 12 to 22<\/a><\/li>\n\n\n\n<li>transfers of personal data to a recipient in a third country or an international organization under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/chapter\/V\" target=\"_blank\" rel=\"noreferrer noopener\">Arts. 44 to 49<\/a><\/li>\n\n\n\n<li>any obligations under Schedule 2, Parts 5 or 6 of the DPA or regulations made under section 16(1)(c) of the DPA<\/li>\n\n\n\n<li>noncompliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the Commissioner under <a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/58\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 58<\/a>, or failure to provide access in violation of Art. 58<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-is-responsible-for-enforcing-the-uk-gdpr\">Who is responsible for enforcing the UK-GDPR?<\/h2>\n\n\n\n<p>The Commissioner, who heads the Information Commissioner's Office (ICO), is responsible for enforcement of the UK-GDPR (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/57\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 57 UK-GDPR<\/a>). The ICO is the UK's independent authority set up to uphold information rights in the public interest.<\/p>\n\n\n\n<p>The Commissioner has various powers under the UK-GDPR, including (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/58\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 58<\/a>):<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li><strong>investigative powers<\/strong>, including ordering controllers and processors to provide necessary information, notifying controllers and processors of alleged violations of the regulation, and obtaining access to personal data and premises for their tasks<\/li>\n\n\n\n<li><strong>corrective powers<\/strong>, including issuing warnings and reprimands, ordering compliance with data subject requests, imposing limitations or bans on processing, and imposing administrative fines<\/li>\n\n\n\n<li><strong>authorization and advisory powers<\/strong>, including advising controllers and processors, issuing opinions to Parliament and the government, accrediting certification bodies, and authorizing contractual clauses and binding corporate rules for data transfers<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-remedies-for-data-subjects-under-the-uk-gdpr\">Remedies for data subjects under the UK-GDPR<\/h2>\n\n\n\n<p>The UK data protection law provides data subjects with multiple remedies if their rights have been violated.<\/p>\n\n\n\n<p>Under<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/77\" target=\"_blank\" rel=\"noreferrer noopener\"> Art. 77 UK-GDPR<\/a>, data subjects have the right to lodge a complaint with the Commissioner, who shall inform them of the progress and outcome of the complaint.<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/78\" target=\"_blank\" rel=\"noreferrer noopener\"> Art. 78 UK-GDPR<\/a> provides the right to an an effective judicial remedy in the following cases:\u00a0<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>against a legally binding decision of the Commissioner<\/li>\n\n\n\n<li>where the Commissioner does not handle a complaint<\/li>\n\n\n\n<li>where the Commissioner does not inform the data subject on the progress or outcome of a complaint lodged under Art. 77 within three months<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/79\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 79 UK-GDPR<\/a> gives data subjects a private right of action against controllers and processors where they believe their rights have been infringed as a result of processing of their personal data in violation of the UK-GDPR. Lodging a complaint with the Commissioner does not prevent them from also exercising a private right of action.<\/p>\n\n\n\n<p>Any person who has suffered \u201dmaterial or non-material damage\u201d as a result of a violation by the controller or processor has the right to receive compensation from the violating party for the damage suffered (<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/82\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 82 UK-GDPR<\/a>). The controller or processor are not liable if they can prove they are not responsible for the event that caused the damage.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-steps-to-achieve-uk-gdpr-compliance\">Steps to achieve UK-GDPR compliance<\/h2>\n\n\n\n<p>If you\u2019re a data controller or processor under the UK-GDPR, you can take steps to comply with its requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-audit-your-website-s-use-of-cookies\"> 1. Audit your website\u2019s use of cookies<\/h3>\n\n\n\n<p>To satisfy regulatory requirements, you must know which cookies your website uses and list them accurately on your cookie consent banner. Tools like Cookiebot CMP can scan your website to detect all cookies and other trackers and generate a detailed audit report to help you meet this requirement. By understanding and clearly listing these cookies, you can provide transparency to your users and adhere to legal standards.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Scan your website for free to find out which cookies and tracking technologies it uses.                    <\/h2>\n                                                                                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"b87c5a47-8b21-4706-a61d-c38b563959ca\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/cookie-checker\/\" target=\"\">\n<span>Check now<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                                                <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-create-a-comprehensive-privacy-policy\">2. Create a comprehensive privacy policy<\/h3>\n\n\n\n<p>Creating a detailed privacy policy that\u2019s easily accessible to users can help meet the UK-GDPR\u2019s transparency requirements. Whenever there are changes in your data handling practices, make sure to update your privacy policy.&nbsp;<\/p>\n\n\n\n<p>Your privacy policy should include:&nbsp;<\/p>\n\n\n\n<ul style=\"background-color:#f2f7fe\" class=\"cb-rounded has-background wp-block-list\">\n<li>types of personal data collected<\/li>\n\n\n\n<li>legal basis and purposes for processing this data<\/li>\n\n\n\n<li>how long you will keep the data for\u00a0<\/li>\n\n\n\n<li>data subjects rights, and how they can exercise these rights<\/li>\n\n\n\n<li>how they can withdraw consent<\/li>\n\n\n\n<li>contact details for the DPO, if you have appointed one<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-obtain-explicit-user-consent\">3. Obtain explicit user consent<\/h3>\n\n\n\n<p>User consent must meet all the UK-GDPR\u2019s criteria to be considered valid and must be obtained without manipulation. If you handle the personal data of users in the UK, you can use a consent management platform (CMP) or<a href=\"https:\/\/www.cookiebot.com\/en\/cookie-consent-solution\/\"> cookie consent solution<\/a> like Cookiebot CMP to obtain explicit, informed, and legally valid consent.<\/p>\n\n\n\n<p>A UK-GDPR compliant cookie banner from Cookiebot CMP helps you secure user consent that meets regulatory standards. It enables you to collect opt-in consent from users and records this consent as required by the regulation. Cookiebot CMP also supports granular consent collection, enabling users consent to certain purposes while rejecting others. It also provides an easy way for users to change or withdraw their consent at any time, and records that information as well to provide an audit trail.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-maintain-records-of-data-processing-activities\">4. Maintain records of data processing activities<\/h3>\n\n\n\n<p>Both data controllers and processors must keep detailed records of processing activities. The information required differs slightly depending on whether you\u2019re a controller or a processor, as outlined in<a href=\"https:\/\/www.legislation.gov.uk\/eur\/2016\/679\/article\/30\" target=\"_blank\" rel=\"noreferrer noopener\"> Art. 30 UK-GDPR<\/a> of the GDPR. These records are a mandatory requirement and are essential to demonstrate compliance with the UK-GDPR.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-differences-between-the-uk-gdpr-and-eu-gdpr\">What are the differences between the UK-GDPR and EU GDPR?<\/h2>\n\n\n\n<p>The UK-GDPR is nearly identical to the European GDPR, with changes to accommodate domestic areas of law. It was drafted from the EU GDPR law text and revised to \u201c<em>United Kingdom\u201d<\/em> instead of \u201c<em>Union\u201d<\/em> and \u201c<em>domestic law\u201d<\/em> rather than \u201c<em>EU law\u201d<\/em>.<\/p>\n\n\n\n<p>Some sections of the EU GDPR that are not applicable to the UK have been removed.<a href=\"https:\/\/gdpr.eu\/article-60-lead-supervisory-authority-and-other-authority-cooperation\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Chapter 7<\/a> of the EU GDPR, which contains provisions for cooperation and consistency between multiple supervisory authorities or Data Protection Authorities of different EU nations, as well as the establishment of the European Data Protection Board, has been removed entirely from the UK-GDPR. Similarly,<a href=\"https:\/\/gdpr.eu\/article-81-suspension-of-duplicate-proceedings\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Art. 81<\/a> of the EU GDPR, which deals with suspension of proceedings when there are two or more proceedings on the same subject before different EU member states, has also been removed. These are two examples of EU GDPR provisions that have been removed from the UK-GDPR as they do not apply to UK law and legal procedures.<\/p>\n\n\n\n<p>A notable difference between the UK-GDPR and EU GDPR is that the age for obtaining valid consent is lowered to 13 years in the UK from 16 years in the EU. For data subjects under 13 years old, you need to obtain consent from a parent or legal guardian.<\/p>\n\n\n\n<p>You can see the differences between the UK-GDPR and EU GDPR in a<a href=\"https:\/\/uk-gdpr.org\/wp-content\/uploads\/2022\/01\/20201102_-_GDPR_-__MASTER__Keeling_Schedule__with_changes_highlighted__V3.pdf\" target=\"_blank\" rel=\"noreferrer noopener\"> Keeling Schedule<\/a>, an unofficial document highlighting what has been changed in legislation. It is very transparent for getting a precise picture of how the UK has amended the regulation \u2014 where it deviates and where it stays the same.<\/p>\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>The GDPR post-Brexit Although the United Kingdom (UK) formally withdrew from the European Union (EU) on 31 January 2020, it remained subject to EU law, including the General Data Protection Regulation (EU GDPR), until the end of the transition period on 31 December 2020. After Brexit, as the UK\u2019s withdrawal from the EU is commonly [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":17280,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"inline_featured_image":false,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-643","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2025\/06\/Social-image-fallback_1200x630_ffffff.png","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/643","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=643"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/643\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/17280"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=643"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=643"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=643"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}