🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
UK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing52 sources retrieved model claude-sonnet-5 · 2026-07-28

United Kingdom

UK schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 65 claims · 58 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
65Claimsbaseline..claims[]
39Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 11 sub-modules are flagged red.

Jurisdiction brief

Latest update · 25 August 2026

Lead Signal

The Data (Use and Access) Act 2025 continues its phased implementation in the United Kingdom, and the Information Commissioner's Office is understood to be reorganised into a new Information Commission carrying expanded powers and responsibilities, part of a four-stage implementation programme running through 2026. Key DUAA provisions affecting UK GDPR and PECR took effect on 5 February 2026 under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, introducing a new 'recognised legitimate interest' lawful basis for processing. A further statutory duty introduced by section 103 of the Act requires organisations to have a compliant complaints-handling process in place by June 2026, a deadline the ICO has stated explicitly. Taken together, these developments mark one of the most consequential recalibrations of the UK's post-Brexit data protection framework since UK GDPR was established, touching the regulator's own institutional form as well as the substantive rules controllers must follow.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Framework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.

Primary frameworkUK GDPR / Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025
Traffic-light rationale — AmberFramework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.

Sub-modules (5)

Regulator And AuthorityAmber

The ICO is the UK's independent regulator for data protection and information rights, with responsibilities under DPA 2018, UK GDPR, FOIA, EIR and PECR, among other statutes. The DUAA abolishes the office of Information Commissioner and transfers its functions to a new corporate body, the Information Commission, moving from a corporation-sole model to a chair/CEO/board structure.

Claims (3):

  • The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.
  • The DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.
  • As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.

Act And InstrumentsGreen

The operative instruments are UK GDPR, DPA 2018 and PECR 2003, amended but not replaced by the DUAA 2025.

Claims (1):

  • The DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.

Material ScopeGreen

UK GDPR/DPA 2018 apply to processing of personal data by controllers and processors; the DUAA makes targeted amendments to purpose limitation, research processing and lawful bases without expanding core material scope.

Claims (1):

  • The DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.

Territorial ScopeGreen

UK GDPR has extraterritorial reach equivalent to EU GDPR Article 3(2): non-UK controllers/processors offering goods/services to, or monitoring the behaviour of, UK data subjects fall within scope and generally must appoint a UK representative.

Claims (1):

  • A UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.

Regulator Registration And FilingGreen

Controllers processing personal data must generally pay an annual data protection fee to the ICO under the Data Protection (Charges and Information) Regulations 2018, across three tiers (£52/£78/£3,763), with over one million controllers on the public register.

Claims (2):

  • Under the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.
  • The ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.

Key findings (1)

Category narrative85 words

The UK's data protection regime is anchored in UK GDPR, the Data Protection Act 2018 (DPA 2018) and PECR 2003, all substantially amended by the Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025 and reached full commencement on 19 June 2026. The Information Commissioner's Office (ICO) is the supervisory authority, currently a corporation sole but transitioning under the DUAA to a board-governed 'Information Commission' with the office of Information Commissioner abolished and functions transferred to the new body.

Periodic update · new data 2026-08-25

Regulator & Framework

The Data (Use and Access) Act 2025 continues its phased implementation in the United Kingdom, and the Information Commissioner's Office is understood to be reorganised into a new Information Commission carrying expanded powers and responsibilities, part of a four-stage implementation programme running through 2026.

Outlook

The precise timing of the Information Commission's formal establishment under DUAA Part 6 has not been independently confirmed this cycle, and further secondary legislation is expected before the transition completes.

Sources and claims (8)
  1. ConfirmedInformation Commissioner's Office — The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.observed
  2. ConfirmedInformation Commissioner's Office — The DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.observed
  3. ProbableIAPP — As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.observed
  4. ConfirmedInformation Commissioner's Office — The DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.observed
  5. ConfirmedInformation Commissioner's Office — The DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.observed
  6. ConfirmedIAPP — A UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.observed
  7. ConfirmedInformation Commissioner's Office — Under the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.observed
  8. ConfirmedInformation Commissioner's Office — The ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.observed

#

Substantive alignment with EU GDPR continues, but amber reflects the newly-introduced recognised legitimate interest basis and consequential ICO guidance still being finalised post-DUAA.

Primary frameworkUK GDPR Articles 6-11; DPA 2018 Schedule 1; DUAA 2025 Schedule 4
Traffic-light rationale — AmberSubstantive alignment with EU GDPR continues, but amber reflects the newly-introduced recognised legitimate interest basis and consequential ICO guidance still being finalised post-DUAA.

Sub-modules (4)

Lawful BasesAmber

The DUAA introduces 'recognised legitimate interest' as a new UK GDPR lawful basis limited to an exhaustive statutory list (e.g., crime prevention, safeguarding, public security, emergencies) and unavailable to public authorities performing their tasks.

Claims (2):

  • The DUAA 2025 introduces 'recognised legitimate interest' as a new UK GDPR lawful basis, separate from ordinary legitimate interests, limited to an exhaustive list of public-interest purposes such as crime prevention, safeguarding and emergencies.
  • Recognised legitimate interest cannot be relied upon by public authorities performing their public tasks, which must continue to use the public task lawful basis.

Special CategoriesGreen

Article 9 special category conditions and DPA 2018 Schedule 1 additional conditions remain the operative framework, including for biometric data, with minor DUAA clarifications to crime, journalism and fraud exemption wording.

Claims (1):

  • Processing biometric data for unique identification purposes constitutes special category processing under UK GDPR Article 9, requiring both an Article 6 lawful basis and a separate Article 9/DPA 2018 Schedule 1 condition, with explicit consent typically the most applicable condition.

Pseudonymisation And AnonymisationRed

No dedicated post-DUAA ICO code or statutory redefinition of pseudonymisation/anonymisation was located in this research pass; searches covered ICO guidance-and-resources indexes and DUAA summary pages without surfacing a standalone anonymisation instrument update.

Category narrative64 words

UK GDPR retains the six lawful bases from EU GDPR Article 6 but the DUAA 2025 inserts a new 'recognised legitimate interest' basis for a closed list of public-interest purposes, and clarifies that direct marketing may qualify as an ordinary legitimate interest. Special category processing (Article 9) and DPA 2018 Schedule 1 conditions remain largely intact, with minor clarifications to crime and journalism exemptions.

Periodic update · new data 2026-08-25

Lawful Processing & Special Data

Key DUAA provisions affecting UK GDPR and PECR took effect on 5 February 2026 under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, introducing a new 'recognised legitimate interest' lawful basis for processing.

Outlook

Final ICO guidance on the recognised legitimate interest basis remains pending, and its practical scope will likely only become clear once that guidance is published.

Sources and claims (4)
  1. ConfirmedInformation Commissioner's Office — The DUAA 2025 introduces 'recognised legitimate interest' as a new UK GDPR lawful basis, separate from ordinary legitimate interests, limited to an exhaustive list of public-interest purposes such as crime prevention, safeguarding and emergencies.observed
  2. ConfirmedInformation Commissioner's Office — Recognised legitimate interest cannot be relied upon by public authorities performing their public tasks, which must continue to use the public task lawful basis.observed
  3. ConfirmedInformation Commissioner's Office — Where an online service relies on consent as its lawful basis, UK data protection law requires parental authorisation for children under 13.observed
  4. ConfirmedInformation Commissioner's Office — Processing biometric data for unique identification purposes constitutes special category processing under UK GDPR Article 9, requiring both an Article 6 lawful basis and a separate Article 9/DPA 2018 Schedule 1 condition, with explicit consent typically the most applicable condition.observed

#

Core rights framework unchanged; DUAA amendments are procedural clarifications rather than reductions in substantive rights.

Primary frameworkUK GDPR Articles 12-22; DPA 2018 Part 2
Traffic-light rationale — GreenCore rights framework unchanged; DUAA amendments are procedural clarifications rather than reductions in substantive rights.

Sub-modules (5)

Access RightGreen

The subject access request (SAR) regime continues under UK GDPR Article 15/DPA 2018, with the DUAA inserting a 'stopping the clock' provision allowing controllers to pause the response time limit when reasonably requesting clarification from the requester.

Claims (1):

  • The DUAA 2025 inserts provisions into UK GDPR and DPA 2018 Part 3 allowing controllers to pause ('stop the clock') the SAR response time limit in order to request reasonably required clarification from the requester.

Rectification And ErasureAmber

Rectification and erasure rights under UK GDPR Articles 16-17 are unaffected in substance by the DUAA; no dedicated new instrument was located for this sub-module beyond the general 'no material change' framing in ICO's DUAA summary.

Claims (1):

  • Most DUAA changes offer organisations optional flexibility rather than mandating specific changes to existing rectification/erasure obligations, meaning the substantive right to rectification and erasure is not materially altered.

Restriction And ObjectionGreen

Individuals retain an absolute right to object to processing for direct marketing purposes at any time, with a qualified right to object in other circumstances (e.g., public task, legitimate interests, research).

Claims (1):

  • Individuals have an absolute right under UK GDPR Article 21 to stop their personal data being used for direct marketing, and controllers must inform individuals of this right at the latest at first communication.

Data PortabilityAmber

No DUAA-specific change to the Article 20 data portability right was identified in this research pass; the underlying UK GDPR Article 20 portability right is presumed to continue unamended, but this was not separately confirmed against a primary source in this run.

Deadlines And Response WindowsGreen

The standard one-month response window applies to rights requests including the right to object; the DUAA's 'stopping the clock' mechanism allows this to be paused for SARs pending clarification from the data subject.

Claims (2):

  • Controllers have one calendar month to respond to a right-to-object request under UK GDPR.
  • The DUAA 2025 inserts provisions into UK GDPR and DPA 2018 Part 3 allowing controllers to pause ('stop the clock') the SAR response time limit in order to request reasonably required clarification from the requester.
Category narrative42 words

UK GDPR data subject rights (access, rectification, erasure, restriction, objection, portability) are preserved post-DUAA, with the DUAA adding a 'stopping the clock' mechanism allowing controllers to pause SAR response deadlines when seeking clarification, and clarifying some Article 13/14 transparency exemptions for research.

Periodic update · new data 2026-08-25

Data Subject Rights

Separately, the standard for responding to subject access requests has been relaxed: organisations now need only carry out 'reasonable and proportionate' searches for relevant information, a change applied retrospectively from 1 January 2025. A further statutory duty introduced by section 103 of the Act requires organisations to have a compliant complaints-handling process in place by June 2026, a deadline the ICO has stated explicitly.

Outlook

Both changes are already in force or on a fixed statutory timeline, meaning organisations must reconcile a lighter search standard for access requests with a new, formally documented complaints channel by 19 June 2026.

Sources and claims (4)
  1. ConfirmedInformation Commissioner's Office — The DUAA 2025 inserts provisions into UK GDPR and DPA 2018 Part 3 allowing controllers to pause ('stop the clock') the SAR response time limit in order to request reasonably required clarification from the requester.observed
  2. ProbableInformation Commissioner's Office — Most DUAA changes offer organisations optional flexibility rather than mandating specific changes to existing rectification/erasure obligations, meaning the substantive right to rectification and erasure is not materially altered.observed
  3. ConfirmedInformation Commissioner's Office — Individuals have an absolute right under UK GDPR Article 21 to stop their personal data being used for direct marketing, and controllers must inform individuals of this right at the latest at first communication.observed
  4. ConfirmedInformation Commissioner's Office — Controllers have one calendar month to respond to a right-to-object request under UK GDPR.observed

#

Framework is mature and enforced, but amber reflects live enforcement activity indicating gaps in DPIA and security practice among controllers, and ongoing DUAA-driven guidance updates.

Primary frameworkUK GDPR Articles 5, 24-39; DPA 2018
Traffic-light rationale — AmberFramework is mature and enforced, but amber reflects live enforcement activity indicating gaps in DPIA and security practice among controllers, and ongoing DUAA-driven guidance updates.

Sub-modules (7)

Accountability And DpiaAmber

Accountability requires documented compliance measures; DPIAs are required for high-risk processing including profiling and children's services. Failure to conduct a DPIA was a finding in both the Reddit and MediaLab enforcement actions.

Claims (3):

  • Accountability is a UK GDPR principle requiring organisations to take responsibility for and demonstrate compliance, including through data protection by design/default, processor contracts, documented processing activities and DPIAs.
  • The ICO's £14.47m fine against Reddit found the company failed to carry out a DPIA to assess and mitigate risks to children before January 2025.
  • The ICO's £247,590 fine against MediaLab (Imgur) similarly found a failure to carry out a data protection impact assessment to identify and reduce privacy risks to children.

Dpo RequirementsGreen

Organisations required (or choosing) to appoint a DPO must notify the ICO; DPO contact details are published on the fee-payer register, with DPO tasks including advising on UK GDPR compliance, monitoring compliance and staff training.

Claims (2):

  • Where an organisation has appointed a DPO, the DPO's contact details (and name, with consent) are published on the ICO's public register of fee payers.
  • A DPO's tasks include advising the organisation about UK GDPR compliance, monitoring compliance and training staff.

Ropa RequirementsAmber

Accountability guidance requires maintaining documentation of processing activities as part of demonstrating UK GDPR compliance; a dedicated post-DUAA ROPA-specific instrument was not separately identified in this research pass beyond the general accountability guide.

Claims (1):

  • Demonstrating accountability includes maintaining documentation of an organisation's processing activities, a measure the ICO expects controllers to adopt as part of governance.

Joint Controller ArrangementsGreen

Where two or more parties jointly determine the purposes and means of processing the same personal data, they are joint controllers; controllers bear the highest level of compliance responsibility including for their processors.

Claims (1):

  • If two or more controllers jointly determine the purposes and means of processing the same personal data, they are joint controllers; they are not joint controllers where processing the same data for different purposes.

Security MeasuresAmber

Article 32(1) technical and organisational security obligations remain enforceable, as demonstrated by the May 2026 £963,900 penalty against South Staffordshire Water following a cyber incident affecting circa 633,887 UK data subjects.

Claims (1):

  • The ICO imposed a £963,900 fine on South Staffordshire Plc and South Staffordshire Water Plc for infringing Article 5(1)(f) and Article 32(1) UK GDPR following a cyber incident exfiltrating personal data of approximately 633,887 UK data subjects.

Breach NotificationGreen

The DUAA aligns the PECR personal-data-breach notification timeline with the UK GDPR standard, standardising the duty to notify the Commissioner across both regimes.

Claims (1):

  • The DUAA aligns the timeline for notifying the Commissioner of a PECR security breach with the UK GDPR breach-notification timeline.

Retention And DisposalRed

No DUAA-specific retention/disposal instrument was identified in this research pass; the underlying UK GDPR storage-limitation principle (Article 5(1)(e)) continues to apply, but a dedicated primary-source citation for updated retention rules was not located in this run.

Key findings (1)

Category narrative61 words

Controllers must demonstrate accountability (Article 5(2)), conduct DPIAs for high-risk processing, appoint DPOs where required, maintain records of processing, secure personal data (Article 32), and notify breaches. The DUAA aligns PECR breach-notification timelines with UK GDPR's 72-hour standard and gives the ICO enhanced investigatory powers. Recent ICO enforcement (South Staffordshire Water, Reddit, MediaLab) demonstrates active supervision of security and DPIA obligations.

Periodic update · new data 2026-08-25

Controller/Processor Duties

The same complaints-handling regime, introduced as new section 164A of the Data Protection Act 2018, takes effect from 19 June 2026 and requires organisations subject to UK GDPR to update privacy notices and introduce formal complaint-handling processes meeting specified legal requirements, extending to complaints raised by employees.

Outlook

Organisations subject to UK GDPR have a compliance runway to 19 June 2026 to build the new complaint-handling process into existing accountability documentation, including updated privacy notices covering employee complaints.

Sources and claims (9)
  1. ConfirmedInformation Commissioner's Office — Accountability is a UK GDPR principle requiring organisations to take responsibility for and demonstrate compliance, including through data protection by design/default, processor contracts, documented processing activities and DPIAs.observed
  2. ConfirmedInformation Commissioner's Office — The ICO's £14.47m fine against Reddit found the company failed to carry out a DPIA to assess and mitigate risks to children before January 2025.observed
  3. ConfirmedInformation Commissioner's Office — The ICO's £247,590 fine against MediaLab (Imgur) similarly found a failure to carry out a data protection impact assessment to identify and reduce privacy risks to children.observed
  4. ConfirmedInformation Commissioner's Office — Where an organisation has appointed a DPO, the DPO's contact details (and name, with consent) are published on the ICO's public register of fee payers.observed
  5. ConfirmedInformation Commissioner's Office — A DPO's tasks include advising the organisation about UK GDPR compliance, monitoring compliance and training staff.observed
  6. ProbableInformation Commissioner's Office — Demonstrating accountability includes maintaining documentation of an organisation's processing activities, a measure the ICO expects controllers to adopt as part of governance.observed
  7. ConfirmedInformation Commissioner's Office — If two or more controllers jointly determine the purposes and means of processing the same personal data, they are joint controllers; they are not joint controllers where processing the same data for different purposes.observed
  8. ConfirmedInformation Commissioner's Office — The ICO imposed a £963,900 fine on South Staffordshire Plc and South Staffordshire Water Plc for infringing Article 5(1)(f) and Article 32(1) UK GDPR following a cyber incident exfiltrating personal data of approximately 633,887 UK data subjects.observed
  9. ConfirmedInformation Commissioner's Office — The DUAA aligns the timeline for notifying the Commissioner of a PECR security breach with the UK GDPR breach-notification timeline.observed

#

Mutual UK-EU adequacy is now confirmed to 2031 and the US data bridge is operative, though EDPB flagged monitoring concerns around new Secretary of State transfer powers.

Primary frameworkUK GDPR Chapter 5 (Articles 44A-49A, as amended by DUAA 2025)
Traffic-light rationale — GreenMutual UK-EU adequacy is now confirmed to 2031 and the US data bridge is operative, though EDPB flagged monitoring concerns around new Secretary of State transfer powers.

Sub-modules (6)

Transfer MechanismsGreen

Restricted transfers require adequacy regulations, Article 46 appropriate safeguards, or an Article 49 exception; the DUAA reworded but retained this three-tier structure under new Articles 44A-46.

Claims (2):

  • Restricted transfers under UK GDPR require one of: adequacy regulations, Article 46 appropriate safeguards, or an Article 49 derogation for specific situations.
  • The DUAA replaces UK GDPR Article 44 with a new Article 44A retaining the same general transfer principles while introducing new terminology of 'regulations approving the transfer' in place of 'adequacy regulations'.

Adequacy ReceivedGreen

The European Commission renewed its adequacy decisions for the UK under both GDPR and the Law Enforcement Directive on 19 December 2025, extending validity to 27 December 2031 and covering transfers from the whole EEA to the whole UK.

Claims (2):

  • The European Commission adopted amended UK adequacy decisions on 19 December 2025, renewing adequacy under both the GDPR and the Law Enforcement Directive.
  • Both the renewed EU GDPR and LED adequacy decisions for the UK are valid until 27 December 2031, applying to personal information transferred from the whole EEA to the whole UK.

Adequacy GrantedGreen

The UK grants full adequacy to all EEA states and partial adequacy to the US (via the UK Extension to the EU-US Data Privacy Framework), allowing UK organisations to transfer to DPF-certified US businesses without additional safeguards.

Claims (2):

  • All EEA countries have full UK adequacy status, permitting UK organisations to transfer personal information to them without additional safeguards.
  • The UK Extension to the EU-US Data Privacy Framework is a partial adequacy finding allowing UK (and Gibraltar) organisations to make restricted transfers to self-certified US businesses regulated by the FTC or DoT, without appropriate safeguards.

Sccs And BcrsGreen

UK organisations can use the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, or UK Binding Corporate Rules as Article 46 appropriate safeguards.

Claims (1):

  • UK organisations may use the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, or UK Binding Corporate Rules as Article 46 appropriate safeguards for restricted transfers.

Transfer Impact AssessmentGreen

Organisations relying on appropriate safeguards must complete a Transfer Risk Assessment (TRA) confirming the destination country's protection is not materially lower than under UK GDPR.

Claims (1):

  • Organisations relying on appropriate safeguards for restricted transfers must complete a Transfer Risk Assessment (TRA) to confirm the standard of protection is not materially lower after transfer.

Data LocalisationRed

No general data-localisation mandate for personal data was identified for the UK regime in this research pass; UK GDPR instead relies on the adequacy/safeguards/derogation transfer model rather than in-country storage requirements. Searches covered ICO's international transfer guidance without surfacing a localisation obligation.

Key findings (1)

Category narrative63 words

UK GDPR transfer rules (recast as Article 44A-46 by the DUAA) preserve a three-tier structure of adequacy regulations, appropriate safeguards (SCCs/IDTA/BCRs) and Article 49 derogations. The EU renewed its UK adequacy decisions (GDPR and LED) on 19 December 2025, valid until 27 December 2031, and the UK operates a partial 'UK Extension' adequacy finding for the US via the EU-US Data Privacy Framework.

Periodic update · new data 2026-08-25

Cross-Border & Adequacy

On cross-border transfers, the Act replaces the prior adequacy test with a new 'data protection test', under which a third country's protection standard must be assessed as 'not materially lower' than the UK standard; the same test now also applies to controllers and processors relying on appropriate safeguards. This marks a formal divergence from the EU's 'essential equivalence' formulation, though how far the two tests will diverge in practice has not yet been tested.

Outlook

How far the new UK data protection test will diverge in practice from the EU's essential-equivalence approach is likely to become clearer only as the first assessments under the revised framework are carried out.

Sources and claims (8)
  1. ConfirmedInformation Commissioner's Office — Restricted transfers under UK GDPR require one of: adequacy regulations, Article 46 appropriate safeguards, or an Article 49 derogation for specific situations.observed
  2. ConfirmedEUR-Lex / European Commission — The DUAA replaces UK GDPR Article 44 with a new Article 44A retaining the same general transfer principles while introducing new terminology of 'regulations approving the transfer' in place of 'adequacy regulations'.observed
  3. ConfirmedInformation Commissioner's Office — The European Commission adopted amended UK adequacy decisions on 19 December 2025, renewing adequacy under both the GDPR and the Law Enforcement Directive.observed
  4. ConfirmedInformation Commissioner's Office — Both the renewed EU GDPR and LED adequacy decisions for the UK are valid until 27 December 2031, applying to personal information transferred from the whole EEA to the whole UK.observed
  5. ConfirmedInformation Commissioner's Office — All EEA countries have full UK adequacy status, permitting UK organisations to transfer personal information to them without additional safeguards.observed
  6. ConfirmedInformation Commissioner's Office — The UK Extension to the EU-US Data Privacy Framework is a partial adequacy finding allowing UK (and Gibraltar) organisations to make restricted transfers to self-certified US businesses regulated by the FTC or DoT, without appropriate safeguards.observed
  7. ConfirmedInformation Commissioner's Office — UK organisations may use the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, or UK Binding Corporate Rules as Article 46 appropriate safeguards for restricted transfers.observed
  8. ConfirmedInformation Commissioner's Office — Organisations relying on appropriate safeguards for restricted transfers must complete a Transfer Risk Assessment (TRA) to confirm the standard of protection is not materially lower after transfer.observed

#

Telecoms/ePrivacy and employment ADM are well evidenced; financial, health, credit, education and insurance sub-modules carry material gaps requiring escalation.

Primary frameworkPECR 2003 (as amended by DUAA 2025); UK GDPR sectoral guidance
Traffic-light rationale — AmberTelecoms/ePrivacy and employment ADM are well evidenced; financial, health, credit, education and insurance sub-modules carry material gaps requiring escalation.

Sub-modules (7)

Financial Sector OverlayRed

The ICO and the Financial Conduct Authority (FCA) both have jurisdiction touching financial-sector personal data, but no specific FCA-ICO memorandum of understanding or overlay instrument was retrieved in this research pass; this is flagged for escalation given the disambiguation risk between DP and financial-conduct regulation.

Health Sector OverlayRed

No health-sector-specific UK data protection overlay (e.g., NHS data-sharing codes) was retrieved in this research pass; searches focused on ICO/DUAA general resources without surfacing dedicated health-sector primary sources.

Telecoms And EprivacyAmber

PECR governs cookies, unsolicited electronic marketing and traffic/location data; the ICO fined KRA Consultancy £300,000 for breaching PECR regulations 22 and 23 via 5.5 million unsolicited marketing/fake-bailiff texts, and the DUAA inserts new PECR cookie exceptions.

Claims (2):

  • The ICO fined KRA Consultancy Ltd £300,000 for sending over 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of PECR, generating over 60,000 complaints to the 7726 spam-reporting service.
  • The DUAA inserts a new schedule into PECR setting out exceptions from the prohibition on storing or accessing information on a subscriber's or user's terminal equipment (the cookie rules).

Employment DataAmber

The ICO issued specific guidance and a compliance report on automated decision-making (ADM) in recruitment, following DUAA changes lifting some ADM restrictions, requiring transparency, bias testing and a right to request human review of hiring decisions.

Claims (2):

  • UK GDPR Article 22A defines automated decision-making (ADM) as a decision based solely on automated processing with no meaningful human involvement that has a legal or similarly significant effect on a person.
  • The ICO wrote to 16 organisations likely using ADM in hiring, securing commitments to improve transparency, bias monitoring and human-review safeguards following a March 2026 compliance report.

Credit And ScoringRed

No credit-scoring-specific UK data protection overlay was retrieved in this research pass beyond the general Article 22-equivalent ADM rules; flagged as a research gap.

EducationAmber

The ICO publishes FAQs on applying the Children's code to schools and education technology providers, but a dedicated education-sector data protection statute or code beyond the Children's code was not separately identified in this pass.

Claims (1):

  • The ICO publishes dedicated FAQs applying the Children's code (Age Appropriate Design Code) to schools and education technology providers.

InsuranceRed

No insurance-sector-specific UK data protection overlay was retrieved in this research pass; flagged as a research gap requiring targeted follow-up.

Category narrative57 words

PECR functions as the UK's ePrivacy overlay on cookies, direct marketing and electronic communications, with DUAA-driven reforms including new cookie-consent exemptions and a charity soft opt-in. Employment-sector ADM guidance has been issued by the ICO. Financial services, health, credit-scoring, education and insurance sector-specific overlays were not substantively surfaced in this research pass beyond general FCA/ICO coexistence awareness.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedInformation Commissioner's Office — The ICO fined KRA Consultancy Ltd £300,000 for sending over 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of PECR, generating over 60,000 complaints to the 7726 spam-reporting service.observed
  2. ConfirmedInformation Commissioner's Office — The DUAA inserts a new schedule into PECR setting out exceptions from the prohibition on storing or accessing information on a subscriber's or user's terminal equipment (the cookie rules).observed
  3. ConfirmedInformation Commissioner's Office — UK GDPR Article 22A defines automated decision-making (ADM) as a decision based solely on automated processing with no meaningful human involvement that has a legal or similarly significant effect on a person.observed
  4. ConfirmedInformation Commissioner's Office — The ICO wrote to 16 organisations likely using ADM in hiring, securing commitments to improve transparency, bias monitoring and human-review safeguards following a March 2026 compliance report.observed
  5. ConfirmedInformation Commissioner's Office — The ICO publishes dedicated FAQs applying the Children's code (Age Appropriate Design Code) to schools and education technology providers.observed

#

Cookies and direct marketing are well evidenced; opt-out signal standards, clean rooms and cross-context advertising remain research gaps.

Primary frameworkPECR 2003 (as amended by DUAA 2025); UK GDPR Article 21
Traffic-light rationale — AmberCookies and direct marketing are well evidenced; opt-out signal standards, clean rooms and cross-context advertising remain research gaps.

Sub-modules (6)

Cookies And TrackersAmber

PECR prohibits storing or accessing information on a user's device absent consent or an applicable exception; the DUAA inserts a new schedule of cookie-rule exceptions into PECR.

Claims (1):

  • The DUAA inserts a new schedule into PECR setting out exceptions from the prohibition on storing or accessing information on a subscriber's or user's terminal equipment (the cookie rules).

Dark PatternsAmber

The Children's code prohibits 'nudge techniques' that encourage children to weaken privacy settings or provide unnecessary personal data, functioning as a sector-specific anti-dark-pattern standard for minors.

Claims (1):

  • The Children's code requires that nudge techniques not be used to encourage children to provide unnecessary personal data or weaken/turn off their privacy settings.

Opt Out SignalsRed

No UK-specific standard equivalent to Global Privacy Control or DAA opt-out signal recognition was identified in this research pass.

Clean Rooms And DcrRed

No ICO guidance on data clean rooms or data-collaboration-room arrangements was identified in this research pass.

Cross Context AdvertisingAmber

The ICO has previously found that legitimate-interest justifications offered by organisations for real-time bidding (RTB) in programmatic advertising were insufficient, indicating heightened scrutiny of cross-context ad-tech data sharing.

Claims (1):

  • The ICO reviewed justifications for using legitimate interests as the lawful basis for real-time bidding (RTB) in adtech and found the justifications offered by organisations insufficient.

Direct MarketingGreen

The DUAA clarifies that direct marketing can qualify as a legitimate interest, and introduces a new charity 'soft opt-in' permitting electronic marketing to supporters without prior consent if safeguards are met.

Claims (2):

  • The DUAA clarifies that direct marketing can be conducted on the basis of legitimate interests as a lawful basis under UK GDPR.
  • Since 5 February 2026, charities may send electronic mail marketing (including texts and social media direct messages) furthering their charitable purposes to individuals who have expressed interest or offered support, without prior consent, under a new 'soft opt-in', subject to safeguards.
Category narrative67 words

PECR governs cookie consent, with DUAA-inserted exceptions; the ICO has historically found legitimate-interest justifications for real-time-bidding (RTB) adtech insufficient. The Children's code prohibits nudge techniques and off-by-default profiling for minors. Direct marketing rules were liberalised for charities via a new soft opt-in, and legitimate interest was clarified to cover direct marketing generally. Opt-out signals (e.g., GPC), clean-room/data-collaboration rules and cross-context-advertising-specific instruments were not surfaced in this pass.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedInformation Commissioner's Office — The Children's code requires that nudge techniques not be used to encourage children to provide unnecessary personal data or weaken/turn off their privacy settings.observed
  2. ProbableOffice of the Australian Information Commissioner — The ICO reviewed justifications for using legitimate interests as the lawful basis for real-time bidding (RTB) in adtech and found the justifications offered by organisations insufficient.observed
  3. ConfirmedInformation Commissioner's Office — The DUAA clarifies that direct marketing can be conducted on the basis of legitimate interests as a lawful basis under UK GDPR.observed
  4. ConfirmedInformation Commissioner's Office — Since 5 February 2026, charities may send electronic mail marketing (including texts and social media direct messages) furthering their charitable purposes to individuals who have expressed interest or offered support, without prior consent, under a new 'soft opt-in', subject to safeguards.observed

#

Substantial regulatory activity and guidance exist, but the AI/ADM statutory code of practice is still being developed and national-security exemption scope remains a monitored risk per EDPB.

Primary frameworkUK GDPR Articles 22A-22D (as inserted by DUAA 2025); UK GDPR Article 9 (biometric special category data)
Traffic-light rationale — AmberSubstantial regulatory activity and guidance exist, but the AI/ADM statutory code of practice is still being developed and national-security exemption scope remains a monitored risk per EDPB.

Sub-modules (6)

Profiling RestrictionsAmber

UK GDPR Article 22A (inserted by DUAA) defines ADM as a solely-automated decision with no meaningful human involvement having a legal or similarly significant effect, replacing the prior more restrictive Article 22 default-prohibition model.

Claims (1):

  • UK GDPR Article 22A, inserted by the DUAA, defines automated decision-making (ADM) as a decision based solely on automated processing (no meaningful human involvement) that has a legal or similarly significant effect on a person.

Automated Decision Making TransparencyAmber

The ICO expects organisations using ADM to be transparent with affected individuals, explain how ADM works, and provide a route to request human review, as set out in March 2026 hiring-sector guidance and an ongoing ADM/profiling guidance consultation.

Claims (2):

  • Organisations using ADM must explain to affected candidates/individuals how it works and how to exercise their right to challenge a decision and request human review.
  • The ICO is developing draft ADM and profiling guidance for public consultation, which will inform a forthcoming statutory AI and ADM code of practice.

Ai Risk AssessmentsAmber

The ICO's AI and Biometrics Strategy commits to developing an AI/ADM code of practice (mandated by secondary legislation under the DUAA) and continues to audit police use of facial recognition technology.

Claims (2):

  • The UK government is developing secondary legislation, committed to during passage of the DUAA 2025, requiring the ICO to produce an AI and ADM statutory code of practice.
  • The ICO has conducted or is conducting facial recognition technology (FRT) audits of multiple UK police forces including South Wales, Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester Police.

Biometric RegimeGreen

Biometric recognition processing (e.g., facial recognition, fingerprint) constitutes special category biometric data under UK GDPR Article 9, generally requiring explicit consent absent another applicable condition.

Claims (1):

  • Processing biometric data through a biometric recognition system meets all three elements of the UK GDPR biometric data definition, constituting special category biometric data requiring explicit consent or another valid Article 9 condition.

Genetic DataRed

No genetic-data-specific UK regulatory instrument beyond the general Article 9 special category framework was identified in this research pass.

State Surveillance CarveoutsAmber

The EDPB has raised concerns that UK national security exemptions may waive most data protection principles and limit the ICO's enforcement and inspection powers, urging the European Commission to closely monitor their application in practice.

Claims (1):

  • The EDPB has flagged that UK national security exemptions may waive most data protection principles and some international transfer rules for law enforcement authorities and can limit the ICO's enforcement and inspection powers, calling for ongoing Commission monitoring.
Category narrative78 words

The DUAA introduces new UK GDPR Articles 22A-22D governing solely-automated significant decisions, relaxing some prior restrictions while retaining a right to human intervention for significant decisions using sensitive or non-sensitive data. Biometric data is treated as special category data requiring an Article 9 condition (typically explicit consent), and the ICO is actively auditing police facial recognition technology (FRT) deployments and developing an AI/ADM code of practice. EDPB has flagged UK national-security exemptions as an area requiring ongoing monitoring.

no periodic updates on record for this sub-brief

Sources and claims (7)
  1. ConfirmedInformation Commissioner's Office — UK GDPR Article 22A, inserted by the DUAA, defines automated decision-making (ADM) as a decision based solely on automated processing (no meaningful human involvement) that has a legal or similarly significant effect on a person.observed
  2. ConfirmedInformation Commissioner's Office — Organisations using ADM must explain to affected candidates/individuals how it works and how to exercise their right to challenge a decision and request human review.observed
  3. ProbableInformation Commissioner's Office — The ICO is developing draft ADM and profiling guidance for public consultation, which will inform a forthcoming statutory AI and ADM code of practice.observed
  4. ProbableInformation Commissioner's Office — The UK government is developing secondary legislation, committed to during passage of the DUAA 2025, requiring the ICO to produce an AI and ADM statutory code of practice.observed
  5. ConfirmedInformation Commissioner's Office — The ICO has conducted or is conducting facial recognition technology (FRT) audits of multiple UK police forces including South Wales, Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester Police.observed
  6. ConfirmedInformation Commissioner's Office — Processing biometric data through a biometric recognition system meets all three elements of the UK GDPR biometric data definition, constituting special category biometric data requiring explicit consent or another valid Article 9 condition.observed
  7. ProbableEuropean Data Protection Board — The EDPB has flagged that UK national security exemptions may waive most data protection principles and some international transfer rules for law enforcement authorities and can limit the ICO's enforcement and inspection powers, calling for ongoing Commission monitoring.observed

#

Children's protections are mature, statutory and actively enforced (amber reflects ongoing enforcement gaps industry-wide); dependent-adults sub-module is an evidenced gap.

Primary frameworkAge Appropriate Design Code (Children's code), DPA 2018 s.125; UK GDPR
Traffic-light rationale — AmberChildren's protections are mature, statutory and actively enforced (amber reflects ongoing enforcement gaps industry-wide); dependent-adults sub-module is an evidenced gap.

Sub-modules (5)

Age VerificationAmber

Children's code Standard 3 requires establishing user age with a level of certainty appropriate to processing risk, or applying the code to all users; 2026 enforcement (Reddit, MediaLab) centred on failures to implement robust age assurance.

Claims (3):

  • The Children's code applies to information society services likely to be accessed by children under 18, including UK-based and non-UK companies processing UK children's personal data, even if children are not the target audience.
  • The ICO fined Reddit £14.47m for failing to apply any robust age assurance mechanism, resulting in no lawful basis for processing personal information of children under 13.
  • The ICO fined MediaLab (Imgur) £247,590 for failing to implement any age assurance measures to determine the age of users between September 2021 and September 2025, exposing children to harmful content.

Minor Profiling BansGreen

Children's code Standard 10 requires profiling options to be switched off by default for children unless a compelling, best-interests-justified reason exists, with protective measures against harmful content.

Claims (1):

  • Children's code Standard 10 requires profiling to be switched off by default unless the organisation can demonstrate a compelling reason accounting for the best interests of the child, with protections against harmful content effects.

Education SettingsAmber

The ICO provides FAQs applying the Children's code to schools and education technology, but no separate education-specific statutory instrument was identified.

Claims (1):

  • The ICO publishes dedicated FAQs applying the Children's code (Age Appropriate Design Code) to schools and education technology providers.

Dependent AdultsRed

No dependent-adults-specific (elderly/mentally incapacitated) UK data protection instrument was identified in this research pass; flagged as a research gap.

Key findings (1)

Category narrative72 words

The Children's code (Age Appropriate Design Code), a statutory code under DPA 2018 s.125 in force since 2 September 2020, sets 15 standards for online services likely accessed by children, including high-privacy defaults, age-appropriate age assurance, and profiling/geolocation off by default. Enforcement has intensified in 2026 with major fines against Reddit and MediaLab for inadequate age assurance and unlawful processing of under-13s' data. Dependent-adults protections were not separately evidenced in this pass.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedInformation Commissioner's Office — The Children's code applies to information society services likely to be accessed by children under 18, including UK-based and non-UK companies processing UK children's personal data, even if children are not the target audience.observed
  2. ConfirmedInformation Commissioner's Office — The ICO fined Reddit £14.47m for failing to apply any robust age assurance mechanism, resulting in no lawful basis for processing personal information of children under 13.observed
  3. ConfirmedInformation Commissioner's Office — The ICO fined MediaLab (Imgur) £247,590 for failing to implement any age assurance measures to determine the age of users between September 2021 and September 2025, exposing children to harmful content.observed
  4. ConfirmedInformation Commissioner's Office — UK law requires that online services using personal information of children under 13 rely on consent given by the child's parent or carer where consent is the chosen lawful basis; MediaLab was found to lack such parental consent measures for Imgur.observed
  5. ConfirmedInformation Commissioner's Office — Children's code Standard 10 requires profiling to be switched off by default unless the organisation can demonstrate a compelling reason accounting for the best interests of the child, with protections against harmful content effects.observed

#

Enforcement powers and recent activity are robust and well evidenced across multiple 2026 cases; collective redress remains constrained by case law, which is a known and stable limitation rather than a gap.

Primary frameworkUK GDPR Articles 83-84 (as implemented via DPA 2018); PECR 2003
Traffic-light rationale — GreenEnforcement powers and recent activity are robust and well evidenced across multiple 2026 cases; collective redress remains constrained by case law, which is a known and stable limitation rather than a gap.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The ICO can issue fines of up to £17.5 million or 4% of an organisation's annual worldwide turnover, whichever is higher, for UK GDPR/DPA 2018 breaches, and the DUAA raised PECR's maximum fine to the same ceiling while granting the ICO new powers to compel witness interviews and technical reports.

Claims (2):

  • Under UK GDPR and the DPA 2018, the ICO can issue fines of up to £17.5 million or 4% of an organisation's annual worldwide turnover, whichever is higher.
  • The DUAA gives the ICO new powers, including the ability to compel witnesses to attend interviews and request technical reports, and raises the PECR maximum fine to £17.5 million or 4% of global turnover.

Enforcement Activity IndexGreen

2026 enforcement actions include Reddit (£14.47m, Feb 2026), MediaLab/Imgur (£247,590, Feb 2026), South Staffordshire Water (£963,900, May 2026) and KRA Consultancy (£300,000, May 2026), reflecting a heavy focus on children's data and security/PECR marketing breaches.

Claims (4):

  • On 23 February 2026, the ICO imposed a £14,472,500 penalty on Reddit, Inc. for infringing UK GDPR Articles 5(1)(a), 6, 8 and 35.
  • On 26 February 2026, the ICO published a £247,590 monetary penalty notice against MediaLab for unlawful processing of children's data on the Imgur platform.
  • On 7 May 2026, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 for infringing UK GDPR Articles 5(1)(f) and 32(1) following a cyber incident.
  • On 20 May 2026, the ICO fined KRA Consultancy Ltd £300,000 for breaching PECR regulations 22 and 23 through mass unsolicited marketing texts.

Regulator Funding And CapacityAmber

The ICO is transitioning from a corporation-sole structure to a chair/CEO/board governance model as part of DUAA reforms intended to provide greater institutional continuity and resilience, though the final transition timeline remained unconfirmed as of mid-2026.

Claims (2):

  • The DUAA-driven governance reform moves the ICO from a corporation-sole structure to a traditional chair, CEO and board model intended to provide institutional continuity and resilience.
  • As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.

Collective Redress And Class ActionsAmber

The UK lacks a general opt-out class action mechanism for data protection claims; the Supreme Court's Lloyd v Google ruling held that a representative action under the (then) Data Protection Act failed because damages require individualised proof of material damage or distress, not mere loss of control of data.

Claims (2):

  • In Lloyd v Google LLC [2021] UKSC 50, the UK Supreme Court held that damages under the (then) Data Protection Act require proof of material damage or distress caused by unlawful processing, not merely the unlawful processing (loss of control) itself, precluding the proposed representative 'class action' claim.
  • Following Lloyd v Google, claimant law firms pursuing UK data-breach mass actions face the requirement that individual class members evidence the damage or distress they personally suffered, constraining opt-out-style collective redress.

Private Right Of ActionGreen

Individuals have a direct right to claim compensation from a controller in court for material or non-material damage suffered from a UK GDPR/DPA 2018 breach, though the ICO itself cannot award compensation.

Claims (1):

  • UK GDPR gives individuals a right to claim compensation from an organisation in court for both material damage (e.g., financial loss) and non-material damage (e.g., distress) suffered from a breach of data protection law, though the ICO cannot itself award compensation.

Recent Developments 180DAmber

Within the last 180 days, the DUAA reached full commencement (19 June 2026) requiring all organisations to have a complaints-handling process; the ICO fined South Staffordshire Water (May 2026) and KRA Consultancy (May 2026); and the ICO published its AI and Biometrics strategy update (March 2026) alongside ADM hiring guidance.

Claims (3):

  • As of 19 June 2026, all data protection provisions of the DUAA 2025 are in force, including a new mandatory requirement for all organisations to have a data protection complaints-handling process in place.
  • On 7 May 2026, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 for infringing UK GDPR Articles 5(1)(f) and 32(1) following a cyber incident.
  • On 20 May 2026, the ICO fined KRA Consultancy Ltd £300,000 for breaching PECR regulations 22 and 23 through mass unsolicited marketing texts.

Key findings (1)

Category narrative87 words

The ICO can issue fines of up to £17.5m or 4% of global annual turnover for UK GDPR/DPA 2018 breaches, with the DUAA also raising PECR fines to the same ceiling. 2026 enforcement activity has been intense, including Reddit (£14.47m), South Staffordshire Water (£963,900), MediaLab (£247,590) and KRA Consultancy (£300,000). Private compensation claims exist under UK GDPR/DPA 2018, but the Supreme Court's Lloyd v Google ruling constrains representative 'class action' style claims absent individualised proof of damage. The ICO itself is mid-transition to a board-governed Information Commission.

Periodic update · new data 2026-08-25

Enforcement & Redress

On the enforcement side, the ICO fined outsourcing firm Capita £14 million in October 2025 — reduced from an initial £45 million — over cybersecurity failures that exposed the data of 6.6 million people, reported as the regulator's largest fine to date; since 2019, UK GDPR enforcement has produced £65 million in fines across just 16 penalty notices. The scale of the Capita penalty, set against that low case count, points to a regulator concentrating enforcement weight on a small number of serious security failures rather than broadening case volume.

Outlook

With enforcement weight concentrated in a small number of high-impact cases, the next significant test of the ICO's posture is likely to come from how the regulator applies its expanded Information Commission powers to future security-failure investigations.

Sources and claims (11)
  1. ConfirmedInformation Commissioner's Office — Under UK GDPR and the DPA 2018, the ICO can issue fines of up to £17.5 million or 4% of an organisation's annual worldwide turnover, whichever is higher.observed
  2. ConfirmedInformation Commissioner's Office — The DUAA gives the ICO new powers, including the ability to compel witnesses to attend interviews and request technical reports, and raises the PECR maximum fine to £17.5 million or 4% of global turnover.observed
  3. ConfirmedInformation Commissioner's Office — On 23 February 2026, the ICO imposed a £14,472,500 penalty on Reddit, Inc. for infringing UK GDPR Articles 5(1)(a), 6, 8 and 35.observed
  4. ConfirmedInformation Commissioner's Office — On 26 February 2026, the ICO published a £247,590 monetary penalty notice against MediaLab for unlawful processing of children's data on the Imgur platform.observed
  5. ConfirmedInformation Commissioner's Office — On 7 May 2026, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 for infringing UK GDPR Articles 5(1)(f) and 32(1) following a cyber incident.observed
  6. ConfirmedInformation Commissioner's Office — On 20 May 2026, the ICO fined KRA Consultancy Ltd £300,000 for breaching PECR regulations 22 and 23 through mass unsolicited marketing texts.observed
  7. ConfirmedIAPP — The DUAA-driven governance reform moves the ICO from a corporation-sole structure to a traditional chair, CEO and board model intended to provide institutional continuity and resilience.observed
  8. ConfirmedDataGuidance — In Lloyd v Google LLC [2021] UKSC 50, the UK Supreme Court held that damages under the (then) Data Protection Act require proof of material damage or distress caused by unlawful processing, not merely the unlawful processing (loss of control) itself, precluding the proposed representative 'class action' claim.observed
  9. ProbableIAPP — Following Lloyd v Google, claimant law firms pursuing UK data-breach mass actions face the requirement that individual class members evidence the damage or distress they personally suffered, constraining opt-out-style collective redress.observed
  10. ConfirmedInformation Commissioner's Office — UK GDPR gives individuals a right to claim compensation from an organisation in court for both material damage (e.g., financial loss) and non-material damage (e.g., distress) suffered from a breach of data protection law, though the ICO cannot itself award compensation.observed
  11. ConfirmedInformation Commissioner's Office — As of 19 June 2026, all data protection provisions of the DUAA 2025 are in force, including a new mandatory requirement for all organisations to have a data protection complaints-handling process in place.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct84.48
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United Kingdom
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 65 claim(s) (65 category placement(s)), 58 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redresscollective redress and class actions
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

T1 (primary ICO guidance/enforcement notices, EU implementing decisions) and T2 (ICO press releases, EDPB opinions) coverage is strong for regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, cross_border_and_adequacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups and enforcement_and_redress. sectoral_watch is unevenly covered: telecoms/ePrivacy and employment_data have T1/T2 grounding, but financial_sector_overlay, health_sector_overlay, credit_and_scoring and insurance rest on T3/absent evidence and are flagged red with absent_field_provenance. adtech_and_commercial_privacy has gaps in opt_out_signals and clean_rooms_and_dcr (no evidence located; T4/absent). pseudonymisation_and_anonymisation, retention_and_disposal, data_portability, genetic_data and dependent_adults sub-modules also carry no direct T1/T2 citation in this run and are marked with explicit absent-field narratives rather than inferred claims.

Unresolved questions (6):

  • What is the confirmed statutory transition date for the ICO's move from corporation-sole to the board-governed Information Commission, and does it affect any claims keyed to 'ICO' as supervisory authority name?
  • Is there a specific FCA-ICO memorandum of understanding or overlay instrument governing financial-sector personal data comparable to the DSIT-ICO adequacy MoU?
  • Does UK data protection law contain any sector-specific health-data-sharing code (e.g., NHS-specific) beyond general UK GDPR/DPA 2018 special-category rules?
  • What are the DUAA's specific retention/disposal and data-portability provisions, if any, beyond the general 'no material change' framing in ICO's DUAA summary?
  • Will the planned secondary legislation requiring an ICO AI/ADM statutory code of practice be laid before Parliament, and on what timeline?
  • Are there UK-specific rules recognising browser-based opt-out signals (e.g., Global Privacy Control) under PECR/UK GDPR?

Escalate to primary-source review: yes