TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL·TODAY: 1 NEW BREACH·LAST 30 DAYS: 4·RECORDS THIS YEAR: 5.6M·MOST TARGETED: GOVERNMENT·TOP ORIGIN: France·LARGEST BREACH: MedCore Systems — S3 Bucket Exposure (4.2M)·GLOBAL THREAT LEVEL: NORMAL
🇬🇧

United Kingdom Data Privacy Regulations

UK GDPR & Data Protection Act 2018
Critical Severity
Enacted: 2018 (Amended: 2021 (Post-Brexit adaptations))

Overview

Following Brexit, the UK retained the EU GDPR in domestic law as the "UK GDPR," sitting alongside the Data Protection Act 2018. It outlines the standard for data protection for individuals residing in the UK.

Scope of Application:

Controllers and processors based in the UK, or outside the UK if they offer goods/services or monitor behavior of UK residents.

Key Rules & Obligations

Breach Notification

Within 72 hours of becoming aware of the breach to the ICO.

Maximum Penalties

Up to £17.5 million or 4% of global annual turnover, whichever is higher.

Data Transfers

Transfers outside the UK require adequacy regulations, UK-approved Addendums (IDTA), or binding corporate rules.

Individual Rights

  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object

Enforcement Authority

Information Commissioner's Office(ICO)

Contact: 0303 123 1113

Visit Authority Website

Notable Breaches in United Kingdom

CompanyYearRecords ExposedRegulation Violated
British Airways2018400,000+UK GDPR
Marriott2018339,000,000UK GDPR
Electoral Commission202340,000,000UK GDPR

Official Sources

Frequently Asked Questions

Is UK GDPR the same as EU GDPR?

Largely yes, but they are separate legal regimes following Brexit. Companies operating in both markets may need to comply with both laws and appoint dual representatives.

What happens if a company breaches UK GDPR?

The ICO investigates and can issue enforcement notices or sweeping fines up to £17.5 million or 4% of turnover.

How do I report a data breach in the UK?

Organizations must report to the ICO via their online portal or helpline within 72 hours of discovery.

Last updated: March 5, 2026

Notice an error? Report a correction