In Effect United Kingdom Fintech, Healthcare, All industries

UK GDPR

UK General Data Protection Regulation – Data Protection Act 2018

Organizations processing UK residents' personal data must establish a documented lawful basis, respect data subject rights including access and erasure, conduct Data Protection Impact Assessments for biometric processing, and notify the ICO of breaches within 72 hours.

Effective: May 25, 2018 Verified: July 2026 Official source

What this covers

UK GDPR is the retained EU law version of GDPR as amended by the Data Protection Act 2018. It is enforced by the Information Commissioner's Office, which operates independently of EU data protection authorities post-Brexit. EU-to-UK transfers required new legal mechanisms after the UK left the EU – the European Commission granted an adequacy decision for the UK in June 2021.

Biometric data for unique identification is explicitly prohibited under Article 9 unless a Schedule 1 DPA 2018 condition applies. Conditions include explicit consent, substantial public interest, employment law obligations, and vital interests. The applicable condition must be documented in a Record of Processing Activity before any biometric processing begins – the ICO has fined organizations for retrospective justification.

A Data Protection Impact Assessment is mandatory before deploying biometric identification systems. The ICO lists biometric processing as explicitly high-risk. The DPIA must assess necessity, proportionality, and residual risks – and must be reviewed with the Data Protection Officer if one is appointed. The ICO expects DPIAs to be living documents, updated when the system changes materially.

Maximum fines reach £17.5 million or 4% of global annual turnover for serious violations, including unlawful biometric processing. The ICO has issued multi-million pound fines for facial recognition and biometric data breaches. Fines from EU supervisory authorities apply separately for any processing that touches EU residents' data – a UK business with EU customers faces dual enforcement risk.

Frequently asked questions

How does UK GDPR differ from EU GDPR post-Brexit?

UK GDPR mirrors EU GDPR as retained law under the Data Protection Act 2018, enforced by the Information Commissioner's Office (ICO). Key differences: UK adequacy decisions are independent of EU findings, EU-to-UK transfers require UK-specific mechanisms, and the ICO issues fines and leads investigations for UK-established controllers.

Does UK GDPR require consent to process biometric data?

Not always. UK GDPR Article 9 prohibits processing biometrics for unique identification unless a specific Schedule 1 condition applies. Explicit consent is one condition, but substantial public interest, employment obligations, and health/social care contexts also qualify. The applicable condition must be documented before any biometric processing begins.

What are the ICO's maximum fines under UK GDPR?

Maximum ICO fines reach £17.5 million or 4% of annual global turnover for the most serious violations – including unlawful biometric data processing. Less serious infringements carry fines up to £8.75 million or 2% of global turnover. UK fines are separate from and in addition to EU GDPR penalties issued by EU supervisory authorities.

Is a DPIA required for biometric processing?

A Data Protection Impact Assessment is mandatory before deploying biometric identification systems. Biometric processing for unique identification is explicitly listed as high-risk by the ICO. The DPIA must assess necessity, proportionality, and risks – and must be reviewed with the DPO if your organization has appointed one.