AI regulation and data protection lawyer | UK compliance

Data Protection

A business that processes personal data must comply with the UK GDPR (as retained in UK law), the Data Protection Act 2018 and the amendments made by the Data (Use and Access) Act 2025. The ICO enforces that framework. Bratby Law advises controllers, processors and technology businesses on lawful basis, DPIAs, international transfers, data protection for AI-enabled products and breach response. The Lexology Index recognises Rob Bratby as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection. Four current fractional General Counsel appointments keep the practice in day-to-day contact with operational compliance.

A general counsel, data protection officer or in-house product lawyer needs a position on the lawful basis for each processing activity, the mechanism for each international transfer, whether a DPIA is required, and what the Data (Use and Access) Act 2025 changed about processing already under way. Advice on an AI-enabled product is data protection advice: whether the product is lawful depends on lawful basis, transparency, automated decision-making and DPIA, not on a separate body of law.

The regulatory framework

A controller must process personal data lawfully, fairly and transparently, collect it only for specified purposes, limit it to what is necessary, keep it accurate, keep it no longer than necessary, keep it secure, and be able to demonstrate that it has done so. Those are the core principles of the UK GDPR (as retained in UK law). The Data Protection Act 2018 adds provisions on law enforcement processing, intelligence services processing and the powers of the Information Commissioner. The ICO is the independent supervisory authority responsible for enforcement.

A controller must now comply with the UK data protection framework as amended by the Data (Use and Access) Act 2025. The principal amendments (lawful bases, automated decision-making and international transfers) commenced on 5 February 2026 under the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), which also commenced the complaints provisions on 19 June 2026. The Act also reformed the ICO’s enforcement powers. A controller must maintain a complaints procedure and acknowledge a complaint within 30 days (new section 164A of the Data Protection Act 2018, in force since 19 June 2026). The ICO has published guidance for organisations on what the DUAA 2025 changed, updated on 19 June 2026 to record that all of the Act's data protection provisions are now in force. Its enforcement procedural guidance, which covers how it will use the new investigatory powers, remains in draft.

A business sending electronic marketing, setting cookies or processing traffic or location data must comply with the Privacy and Electronic Communications Regulations 2003 (PECR) as well as the UK GDPR. A telecoms operator must obtain consent to process location data for value-added services (regulation 14). The two sets of rules apply separately: a lawful basis under the UK GDPR does not satisfy a consent requirement under PECR.

The wider UK position on AI, including copyright, the EU AI Act and the sector-led approach taken by Ofcom, the FCA, the PSR and the CMA, is set out at UK AI Regulation: What the Law Actually Says.

Data protection advice

The obligations below arise across the life of a processing activity, from choosing a lawful basis to notifying a breach.


Why data protection matters

In my view the ICO's enforcement work is increasingly directed at systemic failures rather than isolated incidents. The DUAA 2025 has expanded the ICO’s powers, including a power to compel a witness to attend an interview and a power to require reports from approved persons, and has introduced new obligations on controllers covering children's online services and complaint handling. A controller that treats data protection as a compliance function separate from how its products are designed risks enforcement action, delay to a transaction and damage to its reputation. The DUAA 2025 amends the UK GDPR, the Data Protection Act 2018 and PECR rather than sitting alongside them, so a controller reads each of those instruments as amended, and still has to satisfy the UK GDPR and PECR separately on the same processing.

Regulator, operator and advisor perspectives

Bratby Law brings the regulator, operator and advisor perspectives together on every data protection instruction. A year on secondment to Oftel gave direct insight into how a regulator writes, interprets and enforces its own rules, and that informs how the firm engages with the ICO. Four current fractional General Counsel appointments give continuous exposure to how organisations process personal data in practice, with live vendor relationships and live regulatory risk. 30 years in City law firms in the United Kingdom and the United States, including that secondment and senior in-house roles at UK telecoms operators, grounds advice on DPIAs, international transfers, breach response, data protection for AI-enabled products and data commercialisation in the telecoms, payments and technology sectors. That background also shows where data protection and sector-specific regulation meet. Why Bratby Law sets out how the three perspectives combine.


Our data protection credentials

The Lexology Index recognises Rob Bratby as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection. Chambers UK ranks Bratby Law in Band 2 for Telecommunications, and the Legal 500 lists Rob Bratby as a Leading Partner for telecoms. Four current fractional General Counsel appointments at regulated businesses keep the data protection practice in day-to-day contact with operational compliance.

Specialist boutique compared with a general privacy practice

The table below compares Bratby Law with a general privacy practice or a City firm’s data team on regulatory experience, sector depth, who does the work and cost.

FactorBratby LawGeneral privacy practices and City firms
Regulatory insider perspectiveOftel secondment and four ongoing fractional GC appointments. Direct experience of how regulatory frameworks are designed and enforced.Advisory-only perspective. Limited exposure to regulator behaviour or operational compliance.
Sector focus and depthData protection advice integrated with telecoms, payments and technology regulation. Understands how PECR, FCA requirements and Ofcom obligations interact with UK GDPR.Data protection treated as a horizontal practice. Limited understanding of sector-specific regulatory overlays.
Senior partner deliveryAdvice delivered by Rob Bratby, Managing Partner with 30 years’ experience. No delegation to junior associates.Data protection work routinely delegated. Senior partner involvement limited to sign-off.
Cost and engagement flexibilityBoutique pricing. Fractional GC arrangements available for ongoing data protection support.Full-service firm billing rates. Data protection advice priced as part of a broader privacy or regulatory mandate.
Data protection advisory: specialist boutique versus general privacy practices and City firms

Recent data protection insights

How we work

Bratby Law works with clients in three ways: as direct legal advisers on specific matters, as specialist co-counsel supporting other legal teams, and as fractional general counsel on a longer-term retained basis. Each model delivers partner-level input without delegation.

Specialist data protection advice

The TelXL case study covers data protection advice for AI-enabled products, and the Core Communication case study covers UK GDPR compliance across consumer services.

Frequently asked questions about data protection

Has the Data (Use and Access) Act 2025 changed my data protection obligations?

Yes. The DUAA 2025 amends the UK GDPR framework. Key changes include reforms to the ICO’s enforcement powers, a statutory complaints handling obligation requiring controllers to maintain a procedure and acknowledge complaints within 30 days, and modifications to international transfer provisions. A controller must check its lawful bases, its complaints procedure and its transfer mechanisms against the amended text.

How has ICO enforcement changed?

The DUAA 2025 has expanded the ICO’s powers, and the ICO has said that it will use the new investigatory powers where necessary for the most serious cases while its enforcement procedural guidance is still in draft. In my view the areas most exposed are inadequate DPIAs, unlawful international transfers and insufficient technical measures. A controller should test its own DPIAs, transfer mechanisms and security measures against them.

Do I need separate UK and EU data protection compliance?

If you process personal data of UK and EU residents, you need to comply with both the UK GDPR and the EU GDPR. The regimes are diverging. The DUAA 2025 has introduced UK-specific changes that do not apply in the EU. Where the two regimes differ, a controller must satisfy each of them on its own terms.

Is AI governance a separate compliance requirement?

No. AI governance is part of data protection compliance. A controller that trains a model on personal data or takes automated decisions must establish a lawful basis under the UK GDPR, comply with Articles 22A to 22D where a significant decision about a person is taken solely by automated processing, and carry out a DPIA where the processing is likely to result in a high risk. Those are data protection questions, not a separate body of AI law.

When should I instruct external data protection counsel?

When the matter involves regulatory risk that your in-house team cannot assess independently. Common trigger points include ICO investigations, high-risk DPIAs, international transfer structuring, data breach response, and integration of data processing arrangements in M&A.

What does the new complaints handling obligation require?

Section 164A of the Data Protection Act 2018 requires a controller to facilitate the making of data protection complaints, for example by providing a complaint form that can be completed electronically, to acknowledge receipt of a complaint within 30 days, and then without undue delay to take appropriate steps to respond and to tell the complainant the outcome. Only the acknowledgement carries a fixed period. Failure to comply is enforceable by an ICO enforcement notice under section 149(5A) of that Act.

How does the DUAA affect DPIAs?

It does not change the DPIA obligation. The DUAA 2025 left Article 35 and Article 36 UK GDPR substantively untouched, so a controller must still carry out a DPIA before processing that is likely to result in a high risk, and must still consult the ICO under Article 36 where a high residual risk cannot be mitigated. What has changed is the surrounding law a DPIA has to describe, in particular the lawful bases and the automated decision-making provisions, and the ICO's DPIA guidance is under review for that reason.

What data protection issues arise in telecoms and payments transactions?

Acquiring a telecoms operator or payment service provider changes the controller relationship. Data migration requires new processor agreements, may trigger DPIAs, and involves re-establishing international transfer mechanisms. PECR adds sector-specific requirements for telecoms data.

Also see

The Telecoms Regulation, Payments Regulation, Transactions and Digital Regulation pages cover where data protection meets each of those areas. How We Work sets out the engagement models, and Insights carries commentary on current developments.

Some clients retain Rob Bratby as their fractional general counsel for longer-term specialist regulatory support.

Independent directory rankings

Our specialist expertise is recognised in major independent legal directories:

  • Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
  • The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
  • Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology
Chambers and Partners accreditation
Legal 500 accreditation
Lexology Global Elite Thought Leader accreditation