KomplyaBack to blog

UK GDPR vs EU GDPR: do I need to comply with both?

Published 2026-08-13· 6 min readUnited Kingdom

Your data protection officer, or whoever wears that hat alongside three other jobs, has UK GDPR under control: a record of processing, a privacy notice that's actually been updated this decade, breach procedures that get tested rather than just filed. Then a prospective customer in Germany or France sends a due diligence questionnaire asking about your Article 27 representative, or your EU GDPR lawful basis for a specific processing activity, and the honest answer is that nobody has looked at it, because "we do GDPR" has always meant the UK version. That gap catches out a lot of otherwise well-run UK businesses, and it's worth being precise about why it exists.

UK GDPR is a real, separate, fully domestic law

Since the end of the Brexit transition period, the UK has run its own version of the GDPR, commonly called the UK GDPR, which sits alongside the Data Protection Act 2018 and is enforced by the Information Commissioner's Office (ICO). It was built by carrying the EU GDPR's text into UK law and adapting the references that no longer made sense outside the EU, so its structure, principles, and most of its article numbering will look immediately familiar: lawful bases, data subject rights, the accountability principle, breach notification within 72 hours. For processing that is purely domestic, UK-based customers, UK-based staff, UK-based marketing, the UK GDPR is the only regime in play, and a mature UK GDPR programme is a genuinely complete answer to that slice of the business.

Why EU GDPR keeps applying anyway

The UK's departure from the EU didn't make EU GDPR stop existing, and it didn't make it stop applying to UK companies. Article 3(2) of the EU GDPR sets its own extraterritorial test, entirely independent of where a company is established: it applies to the processing of personal data of people who are in the EU where the processing relates to offering them goods or services, whether or not payment is required, or to monitoring their behaviour within the EU. A UK SaaS company with subscribers in France, a UK D2C retailer shipping to customers in Germany, or a UK professional services firm advising clients in Ireland is, for that specific slice of activity, squarely inside EU GDPR's scope. It runs in parallel to UK GDPR, not instead of it: the same company can be fully compliant with UK GDPR for its domestic processing and still be exposed under EU GDPR for the part of the business that touches people in the EU.

This is also where the UK's data adequacy status is commonly, and wrongly, treated as a blanket answer. The European Commission adopted adequacy decisions for the UK in June 2021, which make it easier for EU-based organisations to transfer personal data to the UK without extra safeguards, and that adequacy status is periodically reviewed rather than granted once and forgotten. Adequacy is about the flow of data from the EU into the UK. It has nothing to do with whether EU GDPR applies to a UK company's own EU-facing offering, goods and services aimed at people in France, monitoring of visitors from Germany, and so on. A UK business can hold the benefit of adequacy for its inbound transfers and still owe EU GDPR obligations directly for its outbound-facing activity. The two questions don't cancel each other out.

One-stop-shop doesn't cover you any more

Inside the EU, a company can usually deal with a single lead supervisory authority under the GDPR's one-stop-shop mechanism, even when its processing touches people across several member states. A UK company sits outside that mechanism, because it's no longer an EU establishment. In practice, that means a UK business whose EU-facing activity draws regulatory attention may need to deal with the supervisory authority in each member state where the affected individuals are, or the authority local to its EU representative, rather than a single familiar contact point. That's a meaningfully different, and often more fragmented, enforcement experience than most UK compliance teams are used to picturing when they hear "GDPR regulator".

Two fine regimes that look alike and aren't the same pot

The headline numbers are close enough to blur together, and different enough to matter if you're the one facing them. The UK GDPR, enforced by the ICO under the Data Protection Act 2018, caps its most serious fines at £17.5 million or 4% of global annual turnover, whichever is higher. EU GDPR's ceiling, enforced by the relevant EU supervisory authority, is €20 million or 4% of global annual turnover, whichever is higher. These are not the same fine paid twice under two currencies; they are two independent maximum exposures, from two independent regulators, that can in principle both apply to the same underlying company if it has both UK-facing and EU-facing processing that each go wrong.

What to check before assuming UK GDPR has you covered

This isn't a call to duplicate your entire compliance programme. It's a call to check, deliberately, which parts of your business trigger the EU side at all:

  • Do you have customers, users, or website visitors based in the EU, even as a minority of your customer base, whom you're targeting with goods or services rather than just incidentally reaching?
  • Do you run analytics, advertising pixels, or behavioural tracking that could count as monitoring the behaviour of people in the EU, separate from any direct sales relationship?
  • Have you mapped which processing activities are purely UK-facing versus which are EU-facing, rather than treating your record of processing as one undifferentiated list?
  • Do you have an EU representative appointed under Article 27 of the EU GDPR where the exemption for occasional, low-risk processing doesn't apply to you?
  • If a French or German customer's data subject access request landed tomorrow, do you know whether it should be handled under UK GDPR, EU GDPR, or genuinely both?
  • Does your privacy notice actually distinguish the two legal bases you're relying on, or does it just say "GDPR" as if there were only one?

General information, not legal advice: the interaction between UK GDPR and EU GDPR depends on the specific detail of who your business processes data about and how, which a general article like this one can't resolve for your particular situation. Where Komplya publishes guidance like this, we're clear about which layers have been legally reviewed and which remain draft material, so you can weigh it accordingly.

The fastest way to find out whether your EU-facing activity actually triggers EU GDPR obligations on top of your UK GDPR programme, rather than guessing from a due diligence questionnaire under time pressure, is to work through your actual customer base and data flows. Answer a short questionnaire on your business and get a plain-language read on where UK GDPR alone covers you and where EU GDPR adds a separate set of obligations.