UK GDPR & Data Protection Act (DPA) 2018
They started as the same document. They're no longer guaranteed to stay that way — and "we're GDPR compliant" is quietly becoming two separate claims instead of one.
What Is UK GDPR & the Data Protection Act 2018?
UK GDPR is the United Kingdom's post-Brexit data protection framework, enforced alongside the Data Protection Act (DPA) 2018, which supplements it with UK-specific provisions. At the moment of Brexit, UK GDPR was effectively a direct copy of EU GDPR, transposed into UK domestic law so that data protection obligations wouldn't change overnight for businesses. Since then, the two frameworks have begun to diverge, gradually, as the UK pursues its own regulatory reform path independent of the EU.
This divergence matters practically because the two regimes are now enforced by entirely separate regulators: the UK's Information Commissioner's Office (ICO) oversees UK GDPR and the DPA 2018, while EU GDPR remains enforced by each EU member state's national Data Protection Authority, coordinated by the EDPB. A company can no longer safely assume that satisfying one regulator automatically satisfies the other — what started as identical rules are increasingly two separate compliance relationships that happen to still look similar.
Practical Industrial Use
A company that built its AI product's compliance program around EU GDPR — serving customers in Germany and France, for example — and later expands into the UK market is a common scenario where this divergence becomes practically relevant. Immediately after Brexit, this expansion was low-risk from a compliance standpoint, since UK GDPR mirrored EU GDPR almost exactly. Today, that assumption carries more risk: the UK has pursued its own reform efforts around data protection, and the ICO issues its own guidance independently of the EDPB, meaning a practice fully aligned with EDPB expectations isn't automatically guaranteed to align with the ICO's current position, and vice versa.
The DPA 2018 also includes UK-specific provisions not present in EU GDPR, covering areas like law enforcement data processing and specific national exemptions, which a company operating only under an EU GDPR compliance framework may not have accounted for at all.
What Happens Without It
Treating "GDPR compliant" as a single, permanent status covering both the UK and EU is an increasingly risky assumption as the two frameworks continue to develop independently. A company that only tracks EU GDPR and EDPB guidance may miss UK-specific regulatory developments entirely, since the ICO isn't obligated to align with EU positions and has its own enforcement priorities and interpretive guidance.
⚠ Risk Without Tracking Both Frameworks Separately As UK GDPR and EU GDPR diverge further, a company's data-handling practice could, in principle, be found compliant under one regime and out of step with the other for the exact same conduct — and discovering that gap during an ICO inquiry or an EU regulator's review, rather than through proactive monitoring, is a considerably worse position to be in. The two frameworks look similar enough on the surface that it's easy to assume ongoing equivalence without actually verifying it, which is precisely the assumption that becomes more fragile with each year of independent regulatory development.
With Both Frameworks Tracked Separately
- UK-specific ICO guidance and EU-specific EDPB guidance are both monitored independently
- DPA 2018's UK-only provisions are accounted for, not assumed to be covered by EU GDPR work
- Divergence between the frameworks is caught early, through monitoring, not during an inquiry
- Compliance claims accurately reflect two distinct regulatory relationships, not one blended one
Without It
- "GDPR compliant" is treated as a single status that automatically covers both jurisdictions
- UK-specific reforms and ICO guidance can go unnoticed if only EU sources are monitored
- A practice could be compliant under one regime and non-compliant under the other, undetected
- UK-specific DPA 2018 provisions may be missed entirely by an EU-only compliance program
What began as one law is becoming two related, but independently evolving, ones — and compliance programs need to catch up to that reality rather than assume it hasn't changed.
How This Relates to Questa AI
Questa AI supports this dual-framework reality by anonymizing sensitive data based on the shared core principles both UK GDPR and EU GDPR still hold in common, which reduces exposure regardless of which specific regulator's current interpretation applies. This shared-baseline approach lowers the risk of a divergence-driven gap opening up between the two frameworks' requirements.
Questa AI's governance dashboard also tracks jurisdiction-level obligations specifically, distinguishing UK-relevant requirements from EU-relevant ones where they differ, rather than treating "GDPR compliance" as a single undifferentiated status. This gives organizations operating in both markets visibility into where the two frameworks' expectations currently align, and where they've started to diverge.
Frequently asked questions
They started as identical, since UK GDPR was created by transposing EU GDPR into UK domestic law at the point of Brexit. Since then, the two have begun to diverge as each jurisdiction pursues independent regulatory development, so while they remain very similar, they're no longer guaranteed to be identical on every point.
The UK's Information Commissioner's Office (ICO) enforces UK GDPR and the DPA 2018. The EDPB has no enforcement authority over the UK; it coordinates guidance among EU member states' own national Data Protection Authorities, which is a separate regulatory structure entirely from the UK's.
Not automatically, and this assumption carries growing risk as the two frameworks diverge. While the core principles remain closely aligned, UK-specific provisions in the DPA 2018 and independent ICO guidance mean a company should verify UK compliance separately rather than assuming EU GDPR compliance covers it.
The DPA 2018 is UK legislation that works alongside UK GDPR, providing additional detail and UK-specific provisions not covered by the core UK GDPR framework, including rules around law enforcement processing, immigration-related exemptions, and other domestic matters specific to the UK context.
It's a reasonable expectation, given that the UK has pursued independent reform efforts since Brexit and is no longer bound to mirror EU regulatory developments. Organizations operating in both jurisdictions should expect the frameworks to require increasingly separate monitoring, rather than assuming continued equivalence indefinitely.
Related terms
Data Privacy Laws
There isn't one rulebook — there are dozens, they overlap unevenly, and several of them apply to your company whether or not you have an office in that country.
EU Market Compliance
Zero offices in Europe doesn't mean zero exposure — a handful of EU customers can bring two overlapping regulatory regimes down on a company that never planned for either.
Data Sovereignty
Storing data in the right country isn't the same as keeping it out of reach of the wrong one — that gap is exactly what data sovereignty addresses.
Jurisdiction-Level Obligations
The recognition that AI compliance isn't one rulebook applied everywhere — it's a different, sometimes conflicting set of requirements depending on where the data comes from, where it's processed, and where the person it describes actually is, all of which can vary within a single organization's operations.
See UK GDPR & Data Protection Act (DPA) 2018 in practice
Questa AI anonymizes sensitive data before it reaches any AI model — across documents and live prompts, with governance and data-residency control.