Introduction
For the initial years after Brexit, most organisation believed that privacy program for both EU and UK GDPR (General Data Protection Regulation) could be built around the fact that a strong compliance with the EU GDPR would be enough for compliance with the UK GDPR.
In 2026, with the oncoming of the Data (Use and Access) Act 2025 (DUAA) this assumption has been difficult to sustain. DUAA makes targeted amendments to the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR). These amendments have been introduced in stages with provisions on automated decision-making coming into force from 5th February 2026, whereas the new statutory data-protection complaints requirements took effect on 19 June 2026.
However, this change does not affect the principals of the EU GDPR. The UK GDPR remains within the purview of EU GDPR when it comes to lawful bases, transparency, data-subject rights, accountability and security these controls still remain central to the framework. Organisations need to take a note that the UK may remain a jurisdiction to which EU personal data can flow under the European Commission's adequacy framework while adopting materially different rules in individual areas.
Diverging Areas:
The following sections set out the key areas of divergence between the UK GDPR and EU GDPR and explain how these differences operate in practice:
1. Automated decision-making: the UK's starting point has fundamentally changed
One of the clearest divergences we can see is on the concerns relating to the automated decision making (ADM). Article 22 GDPR states that the individual has the right to not be subjected to decisions which shall be solely based on automated processing, especially where the processing would result in profiling or create legal effects or similar outcomes which can significantly affect an individual. Exceptions to this rule are restricted to certain circumstances where they are necessary for entering into or performing a contract, authorised by law, or based on explicit consent. These provisions were reinforced by the CJEU’s decisions on SCHUFA case where the Court held that automated creation of a probability or credit score can itself constitute a decision under Article 22 where a third party gives that score a determining role in deciding whether to enter into, perform or terminate a contractual relationship. The ruling is significant because it confirms that Article 22 is not confined to a computer literally making the final decision; an automated output that effectively determines another actor's decision may also come within its scope.
UK has adopted a different architecture:
Section 80 of DUAA repeals the existing UK GDPR Article 22 and replace it with Articles 22A- 22D.
- Article 22A: defines automated decision, it is the processing where there is no meaningful human involvement.
- Article 22B: sets the out the core conditions under which such automated decisions are permitted. These include cases where the data subject has given explicit, where decision is essential for entering into or performing contract between data subject and controller or where the said processing is authorised by law or required for substantial public interest. In each case, appropriate safeguards and limitations must be applied depending on the context of the processing.
- Article 22C: introduces enhanced protections where special-category data is used, imposing stricter controls and narrowing when the fully automated processing can take place. It also sets out the rights framework, including the right to obtain information about the decision, to make representations, to contest the outcome, and to request meaningful human intervention.
- Article 22D: Grants the Secretary of State powers to make further regulations, including clarifying what counts as meaningful human involvement, what constitutes a significant decision, and further provision concerning safeguards.
2. Legitimate interests:
Ordinary legitimate interests remain similar under both the laws.
Article 6(1)(f) GDPR- states that a controller can process personal data where the processing is necessary for a legitimate interest being pursued by the controller or a third party. With the only exceptions to that fact being that the legitimate interest pursued by the controller should not override the interest or fundamental rights and freedom of data subjects.
The UK GDPR retains its equivalent of Article 6 (1) (f), but DUAA adds a separate basis under Article 6(1)(ea) “Recognised legitimate interests”. The term recognised legitimate interest widens the scope of the article. When Article 6 (1) (ea) is read with Section 70 of DUAA and Annexure 1 it states that processing connected with crime prevention, public security, national security and defence, safeguarding vulnerable people, emergencies, and specified disclosures supporting public tasks, do not need to undertake the normal balancing test against the individual's rights and interests. However, the ICO states that data subjects still retain their right to object in relevant circumstances.
Importantly, the DUAA does not remove legitimate-interest assessments altogether. Organisations relying on ordinary UK GDPR Article 6(1)(f) still need the familiar purpose, necessity and balancing analysis. The new basis instead creates a narrower legal route for certain listed purposes where the UK Parliament has effectively done the balancing in advance.
3. Cookies: UK divergence is real, but the EU is not one cookie regime
In the EU, cookie compliance governance is governed through mainly by Article 5(3) of the ePrivacy Directive, and then later implemented through national law. As a general rule, user consent is required before storing information on, or accessing information from, a user’s terminal equipment, unless a specific exemption applies.
Similarly, the cookie compliance law for the UK jurisdiction is PECR, with the emergence of DUAA, PECR has incorporated five express exceptions on cookies and similar technologies. The ICO in its advisory states that the five exceptions to the prohibition on storing or accessing information on people’s devices are:
- Communication exception: Organisations must ensure that this exception applies to technologies whose sole purpose is to enable the transmission of a communication over an electronic communications network. Organisations must also be able to prove that transmission of communication is impossible without the use of such technologies and must also ensure this does not extend to additional purposes such as analytics or advertising.
- Strictly necessary use: This exception applies in cases where the storage or access is essential, from the user's perspective, to provide an online service the user has requested and that such service could not be provided without it. PECR considers uses such as authentication, security, prevention/ detection of fraud, to find technical faults or for remembering information to provide the requested service. Organisation cannot claim the exception of necessity in the case of advertising, cross-site tracking and similar activities, these remain subject to consent.
- Statistical purposes: Organisation is not required to take consent from the user if the purpose for deploying of the cookies and technology is to collect statistical information about how a website or service is used with a view to improving it. This exception should not be used for individual tracking or profiling. Third-party analytics may also be used, provided that the third party acts only on behalf of the deploying organisation and uses the information solely to improve the relevant service. The information must not be combined with other data or used for advertising or the third party’s own purposes. Users must also be provided with clear information and a simple, free means of objecting.
- Appearance: Under this exception organisations can deploy such cookies or technologies that solely adapt or improve the appearance or functionality of the service, including reflecting a user's preferences, for example, by remembering language choices, adapting a page to the user’s screen size, or applying a preferred colour theme. However, the exception does not cover changing content based on inferred interests, browsing behaviour or profiles, or choosing advertisements for a user. As with the statistical purpose exception, organisations must inform the user and give them an easy opt-out.
- Emergency assistance: This applies to situations where the sole purpose is to identify the geographical position of a user's device in order to provide emergency assistance. However, the organisation must be able to prove that the first communication was received from the user seeking emergency assistance or some similar indication is received from the user seeking emergency assistance. Examples include vehicle eCall system, a GPS-enabled personal safety alarm activated by the user, or a smartwatch configured to contact emergency services following detection of a fall or absence of pulse.
These exceptions are very purpose specific and narrow. Other purposes such as advertising, profiling or cross-site tracking continue to require consent from the user. In particular, the statistical purposes and appearance exceptions are conditional on giving users clear and comprehensive information and an easy, free way to object; if a user objects, the storage or access must stop.
4. Research Purposes: largely a divergence in statutory certainty, not a whole lot of change of principle
Scientific research is another area where UK and EU regimes slightly differ. The EU GDPR has always given researches a little bit of flexibility as per Article 89. Recital 33 of GDPR acknowledges that it is not often possible to identify fully the purposes of scientific research when the data is collected. But at the same time EDPB through its Guidelines 05/2020 on consent explains that this should not be interpreted too broadly, and considered to authorise unrestricted blanket consent. where applicable research consent should also require meaningful specification and safeguards.
With the introduction of DUAA, scientific research has been defined more explicitly under the UK GDPR. Section 67 of DUAA inserts an express definition of scientific research, clarifying that research maybe considered scientific regardless of whether it is publicly or privately funded and irrespective of the fact whether it is undertaken commercially or non-commercially.
Section 67 also makes it clear that technological development or demonstration, fundamental research and applied research may fall within this definition where they can reasonably be described as scientific. Public-health research is included where it is conducted in the public interest.
Section 68 clarifies when consent can cover an area of scientific research rather than requiring every specific research purpose being identified in advance. This is permitted only where it is genuinely not possible to specify all purposes at the time consent is obtained. If anyone plans to use consent for research purposes, they should allow individuals the option to consent to only a part of the research. The key point is that this is not blanket consent for any future research. The DUAA instead gives researchers a clearer statutory route for obtaining broader consent where the direction of a scientific programme cannot be fully mapped at the outset. ICO’s DUAA overview reflects this approach.
5. Complaints: the UK has added a controller-level procedure
The UK government has introduced a new procedural obligation for controllers. From 19th June 2026, organisations that are subjected to the UK GDPR, must ensure that individuals have an accessible way to complain, the organisations should acknowledge that complaint within 30 days, investigate the issue, and keep the complainant informed about the progress and outcome without undue any delay.
The key thing to note here is that a data protection complaint is not the same thing as a formal exercise of an individual right. A rights request is a request by an individual to exercise a specific right under the UK GDPR, such as access, erasure or objection. By contrast, a data protection complaint raises a concern about whether an organisation has complied with data protection law in the way it has handled personal data. The recent ICO guidance states that data protection complaints can introduce concerns how an organisation collected or used personal data, whether it kept that data secure, or how it handled a subject access or other rights request.
The EU GDPR takes a different approach to complaints. Article 77, grants individuals the right to complain directly to the supervisory authority, whereas Article 12 of GDPR governs how controllers must respond when individuals exercise their rights such as access, erasure or objection. However, the EU GDPR does not itself impose a general requirement on controllers to operate a separate internal complaints procedure or acknowledge general privacy complaints.
A complaint may also contain a separate rights request, such as a request for access or erasure. In that case, the organisation may need to manage both processes and their respective deadlines in parallel.
Conclusion
The EU and UK data protection regimes are and remain closely aligned, but certain differences are introduced by DUAA which are significant enough to affect day to day compliance. The key changes only affect a few targeted controls such as automated decision-making, legitimate interests, cookies, research and complaints, giving the UK framework a more distinct shape without abandoning the core principles of the GDPR.
For organisations operating across both the jurisdictions, a single GDPR compliance can still provide the foundation, however with the oncoming of DUAA certain UK jurisdiction specific checks and controls need to be added. So, the question is not if your organisation GDPR compliant, its is which GDPR regime applies and have you accounted for all the differences to see it.
We at Data Secure (Data Privacy Automation Solution) DATA SECURE - Data Privacy Automation Solution can help you to understand Privacy and Trust while lawfully processing the personal data and provide Privacy Training and Awareness sessions in order to increase the privacy quotient of the organisation.
We can design and implement RoPA, DPIA and PIA assessments for meeting compliance and mitigating risks as per the requirement of legal and regulatory frameworks on privacy regulations across the globe especially conforming to GDPR, UK DPA 2018, CCPA, India Digital Personal Data Protection Act 2023. For more details, kindly visit DPO India – Your outsourced DPO Partner in 2025 (dpo-india.com).
For any demo/presentation of solutions on Data Privacy and Privacy Management as per EU GDPR, CCPA, CPRA or India DPDP Act 2023 and Secure Email transmission, kindly write to us at info@datasecure.ind.in or dpo@dpo-india.com.
For downloading the various Global Privacy Laws kindly visit the Resources page of DPO India - Your Outsourced DPO Partner in 2025
We serve as a comprehensive resource on the Digital Personal Data Protection Act, 2023 (Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025), India's landmark legislation on digital personal data protection. It provides access to the full text of the Act, the Draft DPDP Rules 2025, and detailed breakdowns of each chapter, covering topics such as data fiduciary obligations, rights of data principals, and the establishment of the Data Protection Board of India. For more details, kindly visit DPDP Act 2023 – Digital Personal Data Protection Act 2023 & Draft DPDP Rules 2025
We provide in-depth solutions and content on AI Risk Assessment and compliance, privacy regulations, and emerging industry trends. Our goal is to establish a credible platform that keeps businesses and professionals informed while also paving the way for future services in AI and privacy assessments. To Know More, Kindly Visit – Your Trusted Partner in AI Risk Assessment and Privacy Compliance | AI-Nexus