Following Brexit, the UK is no longer subject to the EU’s GDPR directly, but it has incorporated the regulation into domestic law as the UK GDPR, which sits alongside the Data Protection Act 2018. The UK GDPR mirrors the EU GDPR in almost all respects, maintaining the same principles, rights, and obligations. It is enforced by the Information Commissioner’s Office (ICO), which has the power to issue fines of up to £17.5 million or 4% of global annual turnover for serious breaches. Organisations operating in both the UK and the EU must comply with both frameworks separately, as they are now distinct legal regimes, though the two remain closely aligned in substance.





