UK GDPR, without the
parallel paperwork.
Most teams in scope are in scope twice. Whisperly runs one privacy programme with a UK overlay, so compliance never doubles.
ICO enforcement is
accelerating sharply.
Fines collected in 2025 were seven times the 2024 figure, and the share attributable to UK GDPR breaches rose from one sixth to two thirds. Security failures are the pattern.
Capita, 2025
Issued for failing to secure the personal data of 6.6 million people ahead of a ransomware attack, the ICO's largest security-failure penalty of 2025.
Advanced Computer Software, 2025
The first ICO fine issued to a processor. Missing MFA and weak patch management were the cited failures, so processors can no longer point upstream.
Year on year increase
More than £19.6 million collected in 2025, roughly seven times the 2024 figure. Enforcement capacity, not just appetite, has changed.
UK GDPR vs EU GDPR,
what actually changed?
The principles, the rights and the lawful bases carried over almost unchanged. Everything that costs teams time sits in the gaps below.
Dual compliance is
the new normal.
Almost nobody is subject to the UK GDPR alone. The instinct is to stand up a second programme, and that is the mistake: you double the maintenance and guarantee the two versions drift apart. Run one core programme with jurisdiction overlays instead.
Tag every record by regime
Each processing activity, assessment and vendor carries a UK, EU or both marker. One record satisfies either regulator, and a filter produces the pack the ICO asks for.
Modularise your privacy notices
Shared clauses live once; jurisdiction-specific blocks sit in their own modules. A DUAA cookie change updates the UK notice without touching the EU one, and version history shows which regime each edit affected.
Keep one control set, two mappings
A security measure or a DPIA template is documented once and mapped to both regimes. Where they genuinely diverge, such as transfer mechanisms, the platform holds the IDTA alongside the EU SCCs rather than forcing a choice.
Plan for two notifications
There is no one-stop-shop across the Channel. A breach touching both populations means notifying the ICO and the relevant EU authority, on the same 72 hour clock, from one incident record and one evidence pack.
Four stages. One
continuous programme.
This is the dual-compliance model in practice: every record tagged by regime, so one control satisfies the UK and the EU at once and each output doubles as evidence for the ICO.
Document
Records for controller and processor roles, tagged UK, EU or both, with privacy notices modularised so a UK change does not force an EU rewrite.
Assess
Impact assessments on templates aligned to ICO guidance and the DPA 2018, with security measures synced back to the activities they protect.
Respond
The obligations that arrive with a clock. DSAR intake with identity verification and DUAA stop-the-clock handling, and a 72 hour ICO notification workflow.
Prove
Kanban boards give each obligation an owner and a date, and every action is logged so an ICO enquiry is answered from the record rather than from memory.
Headquarters are
irrelevant to scope.
The UK GDPR and the DPA 2018 follow the individual. If you process the personal data of people in the United Kingdom, you are in scope.
Data controllers
You set the purposes and means, and carry accountability for lawfulness, rights and notifying the ICO within 72 hours.
Data processors
Security measures, your own records and breach reporting all apply, and since 2025 the ICO fines processors directly.
Non-UK organisations
Offering goods or services to UK residents, or monitoring their behaviour, brings you in scope and requires a UK representative under Article 27.
Public authorities
A DPO is mandatory, DPIAs are required for high-risk processing, and transparency duties toward citizens are stricter.
Frequently asked questions
One programme.
Both regimes.
Run UK and EU data protection as one programme with jurisdiction overlays, and answer either regulator from a record that is already current.