Note: Where “GDPR” appears unqualified below, it refers to both regimes as a shared regulatory heritage; UK GDPR and EU GDPR are distinguished where the divergence is material.

UK/EU Data Protection Divergence
Managing compliance across the diverging UK and EU data protection regimes
What the UK and EU regimes now require of the same processing
An organisation processing personal data in both the UK and the EU must now satisfy two different sets of rules for the same processing. The Data (Use and Access) Act 2025 has been commenced in stages from Royal Assent on 19 June 2025: a first data protection tranche on 20 August 2025 under SI 2025/904, and the principal amendments to the UK GDPR on 5 February 2026 under SI 2026/82. Those amendments have taken the UK GDPR away from the EU regime on recognised legitimate interests, automated decision-making and international transfers, and the reasonable and proportionate search limit on subject access has applied since 1 January 2024 under section 78 of the Act. The UK standard cannot be applied to EU personal data, because the DUAA 2025 did not change the rules that govern it. The organisation must map its processing activities by jurisdiction and build controls that satisfy both standards without unnecessary duplication.
A UK organisation that places an AI system on the market or puts it into service in the Union is a provider within Article 2(1)(a) of the EU AI Act, Regulation (EU) 2024/1689, whether or not it is established in the Union, and a UK provider or deployer established outside the Union is caught by Article 2(1)(c) where the output the system produces is used in the Union. The UK has no equivalent statute, and for an AI-enabled product the operative UK rules are the data protection rules, applied by the ICO alongside the sector regulators. UK AI Regulation: What the Law Actually Says sets out the UK position in full.
When divergence becomes a compliance problem
Organisations processing personal data in both the UK and EU must now apply different legal tests to the same processing activities. The position is sharpest for a UK company selling into the EU single market, an EU-headquartered group with UK operations or subsidiaries, and any business whose post-Brexit restructuring left its processing unseparated by jurisdiction. It arises again on an M&A transaction where the target has dual-jurisdiction data flows, and wherever a privacy team has kept a single global compliance framework. One set of controls does not satisfy both regimes. An organisation may process employee data under the recognised legitimate interest basis in the UK but must fall back on a different Article 6 basis for equivalent EU processing. A fintech may operate ADM for creditworthiness assessment in the UK under permission-based rules but must meet the stricter EU GDPR conditions for an EU data subject. This affects mainstream operations at any business with a material EU market or EU workforce.
Why divergence matters now
A UK controller may rely on recognised legitimate interests under Article 6(1)(ea) UK GDPR, a seventh lawful basis introduced by the DUAA 2025, without carrying out a balancing test against data subject rights and freedoms. The basis is narrow. Article 6(5) allows it only where the processing is necessary for a purpose that meets one of the conditions in Annex 1 to the UK GDPR, Article 6(6) lets the Secretary of State add to or vary that list by regulations, and the closing words of Article 6(1) keep it, like Article 6(1)(f), away from a public authority processing in the performance of its tasks. The EU GDPR has no equivalent. A controller processing EU personal data must still satisfy Article 6 EU GDPR, and may rely on legitimate interests there only after completing a Legitimate Interests Assessment that balances its own interests against individual rights. It cannot avoid that assessment by treating EU data subjects’ information as recognised legitimate interests processing. Two separate compliance obligations run in parallel.
The DUAA 2025 replaced the old Article 22 UK GDPR prohibition with a framework (Articles 22A to 22D) that permits automated decision-making where the Article 22C safeguards are in place. Article 22 EU GDPR gives the data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. That right does not apply where the decision is necessary for entering into, or the performance of, a contract between the data subject and the controller; is authorised by Union or Member State law which also lays down suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests; or is based on the data subject’s explicit consent. In the UK a significant decision taken solely by automated processing is permitted without consent or contractual necessity, provided the controller has the Article 22C safeguards in place: information about the decision, the ability to make representations, human intervention on the controller’s part, and the ability to contest the decision. Article 22B keeps two restrictions. Such a decision may not be taken where it is based entirely or partly on special category data unless explicit consent or a contract or legal requirement with Article 9(2)(g) applies, and Article 22B(4) bars it outright where the processing for the purposes of the decision relies on recognised legitimate interests. A controller running customer segmentation to UK rules may therefore breach Article 22 EU GDPR where a segmentation decision taken solely by automated processing produces legal effects concerning a data subject in the EU, or similarly significantly affects them, and none of the Article 22(2) exceptions applies.
Transfer standards have also diverged. Articles 44 and 45 UK GDPR were omitted on 5 February 2026 and two tests took their place. Article 45B sets the data protection test for the Secretary of State’s approval of transfers to a third country by regulations under Article 45A, asking whether the standard of protection there is not materially lower, taken as a whole, than the UK standard. Article 46(6) sets a parallel test for a controller or processor relying on appropriate safeguards, and Article 46(1A) leaves that judgement to the controller, acting reasonably and proportionately. The European Data Protection Board has said the UK test removes elements that figured in the previous UK adequacy test and that play an important role in assessing whether a third country offers an essentially equivalent level of protection (Opinion 26/2025, adopted 16 October 2025, paragraphs 42 and 87). Where a third country meets the UK threshold, an organisation may transfer personal data there under UK law and the same transfer may still fail the EU test. It cannot rely on UK approval to transfer personal data from the EU where the European Commission has made no adequacy finding for the recipient country.
Subject access has also diverged. Article 15(1A) UK GDPR, inserted by section 78 of the DUAA 2025 and applying since 1 January 2024, entitles the data subject only to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search. The EU GDPR carries no such limit. The EDPB’s guidance is that the controller will have to search for personal data throughout all IT systems and non-IT filing systems, and that the right of access is subject to no general reservation to proportionality as regards the effort the controller has to take to comply (Guidelines 01/2022 on data subject rights, right of access, version 2.1 adopted 28 March 2023, paragraph 166). The English courts had reached the UK position under the Data Protection Act 1998 long before the statute said it: in Ittihadieh v 5-11 Cheyne Gardens RTM Co Ltd [2017] EWCA Civ 121 at [103] Lewison LJ held that the implied obligation to search is limited to a reasonable and proportionate search, or, as he recorded counsel putting it, “it is not an obligation to leave no stone unturned”. For an organisation handling subject access requests on both sides, and litigation disclosure alongside them, the same search may satisfy the UK standard and fall short of the EU requirement.
Commission Implementing Decision (EU) 2025/2574 of 19 December 2025 amended the UK adequacy decision under the EU GDPR, Implementing Decision (EU) 2021/1772, so that it now expires on 27 December 2031 unless extended under the procedure in Article 93(2) EU GDPR. The same decision repealed Article 1(2) of the 2021 decision, which had excluded personal data transferred for United Kingdom immigration control, so that carve-out is gone. The EDPB gave two Opinions on the draft renewals, one on the GDPR limb and one on the Law Enforcement Directive limb, adopted on 16 October 2025. In the GDPR Opinion the Board welcomed the continuing alignment of the two frameworks but invited the Commission to name, in the final decision, the areas it intends to monitor closely because there is a risk of further divergence through UK secondary legislation, singling out the Secretary of State’s new powers over international transfers, automated decision-making and the governance of the Information Commissioner (Opinion 26/2025, paragraph 20). The term is not a guarantee: the Commission must monitor developments and may suspend, amend or repeal the decision under Article 45(4) and (5) EU GDPR.
Where divergence compliance fails
UK adequacy does not mean the rules are the same. Adequacy means the EU considers the UK’s overall protective framework sufficiently equivalent to allow free data flows, not that every UK legal rule mirrors its EU counterpart. An organisation applying UK-only standards to its processing of EU personal data is exposed. Nor did the DUAA 2025 deregulate data protection: where the EU retains a prohibition, the UK now permits the processing if stated conditions are met. Permission is not the absence of conditions.
Records of processing activities must show which jurisdiction governs each activity. Without a jurisdictional tag on the entry, a controller cannot identify the legal test that applies to it. A controller processing employment data for UK and EU payroll cannot rely on a single LIA built on UK recognised legitimate interests. The LIA must be split by jurisdiction, with EU personal data assessed against EU balancing standards and UK data assessed against either the traditional balancing test or the recognised legitimate interests basis.
A privacy notice must name the regime it is describing. A notice that refers only to “GDPR”, or that states “we rely on legitimate interests”, does not tell the reader whether the controller relies on the recognised legitimate interest basis, which is available for UK personal data only, or on the standard balancing-based legitimate interests test, which applies in the EU and remains available in the UK. A controller-to-processor agreement must do the same: a clause requiring the processor to comply with “applicable GDPR” leaves dual-jurisdiction processing unallocated, and the agreement must identify which processing activities fall under which regime and what compliance obligations attach.
An LIA for EU processing must be built on the standard balancing framework. The conditions in Annex 1 to the UK GDPR (disclosure to another person who needs the data for a task described in Article 6(1)(e); safeguarding national security, protecting public security or defence purposes; responding to an emergency within the meaning of Part 2 of the Civil Contingencies Act 2004; detecting, investigating or preventing crime, or apprehending or prosecuting offenders; and safeguarding a vulnerable individual) reach only processing to which the UK GDPR applies, whether or not the same processing would meet one of them for equivalent UK processing.
What dual compliance looks like in practice
Dual compliance starts with a map of processing activities by jurisdiction. For each operation the organisation identifies the lawful basis or bases available in each jurisdiction and records where the UK and EU standards diverge, then builds controls that satisfy both regimes without duplicating documentation for its own sake. That may mean two separate LIAs for one processing activity, where the recognised legitimate interests basis introduced by the DUAA 2025 cannot be used for EU personal data. It may mean a single set of ADM controls that implements both the UK safeguards and the stricter EU consent or contractual-necessity conditions.
A group can separate processing by jurisdiction, with a UK controller for UK personal data and an EU controller for EU personal data; hold it under a single controller operating dual-regime compliance matrices; or use a processor model with responsibility allocated by contract. Each carries different compliance costs and operational friction. On international transfers, the mechanism (adequacy decision, contractual safeguards, binding corporate rules) must be tested against both the UK “not materially lower” test and the EU “essentially equivalent” standard. A transfer that relies on EU adequacy without a UK equivalent leaves the organisation exposed where it later has to justify the same transfer under UK law.
A single record of processing activities may need dual coding to separate UK and EU processing. Consent management platforms must distinguish between UK and EU data subjects and apply jurisdiction-specific consent requirements. Privacy impact assessments should include a jurisdictional matrix identifying where standards diverge and how risks are mitigated. Incident response procedures should account for different notification and investigation timelines between the UK and EU.
When to instruct specialist divergence advice
Internal compliance teams manage day-to-day compliance under a single regime without difficulty. Specialist advice earns its cost where DUAA 2025 implementation is under way at an organisation operating in both jurisdictions; where post-Brexit restructuring has created dual-jurisdiction processing without formal legal separation; where a lender or acquirer has asked about divergence ahead of a financing round or an M&A transaction and an adequacy risk assessment is needed; where international transfer mechanisms are under review against both the UK and EU standards; and where divergence affects deal shape or the representations being negotiated.
Frequently asked questions about UK/EU data protection divergence
Does the EU adequacy decision mean UK and EU rules are now the same?
No. Adequacy is not equivalence. The EU’s renewal in December 2025 confirms that the UK’s overall protective framework is sufficiently strong to permit data flows: the GDPR adequacy decision now expires on 27 December 2031 unless extended. It does not mean individual UK rules mirror EU rules. The DUAA created material divergences on recognised legitimate interests, automated decision-making, the scope of a subject access search and international transfer standards. Organisations must apply both standards simultaneously for dual-jurisdiction processing.
Can we rely on the recognised legitimate interest basis for EU data subjects?
No. The recognised legitimate interest basis (Article 6(1)(ea) UK GDPR) applies only to UK data. For EU personal data, you must use one of the six standard Article 6 bases and, if relying on standard legitimate interests (Article 6(1)(f) EU GDPR), conduct a full Legitimate Interests Assessment with balancing. The recognised legitimate interests list provides no shortcut for EU processing.
Does the UK’s ADM regime work for EU data subjects?
No. The DUAA’s permission-based approach to automated decision-making (Articles 22A to 22D) applies to UK processing. For EU data, Article 22 EU GDPR retains the prohibition-plus-exceptions model. If the decision is taken solely by automated processing and produces legal effects concerning an EU data subject, or similarly significantly affects them, you need the data subject’s explicit consent, necessity for entering into or performing a contract with them, or authorisation by Union or Member State law that itself lays down suitable safeguarding measures (Article 22(2) EU GDPR). Permission-based safeguards alone are insufficient.
How does the “not materially lower” standard work for international transfers?
The UK test asks whether the standard of protection is not materially lower than the UK standard, taken as a whole (Articles 45B and 46(6) UK GDPR). The EDPB has said that test removes elements which figured in the previous UK adequacy test and which play an important role in assessing whether a third country offers an essentially equivalent level of protection (Opinion 26/2025, paragraphs 42 and 87). A third country may meet the UK threshold without meeting the EU threshold. Where you transfer data outside both jurisdictions, you must satisfy both tests. A UK-only adequacy assessment is insufficient if the organisation also processes EU personal data. Build the transfer mechanism to satisfy the stricter EU standard where dual-jurisdiction processing is involved.
What should our privacy notice say about divergence?
Clearly identify which regime applies to which data. A notice that states “we rely on legitimate interests” is ambiguous in a dual-jurisdiction context. Instead, specify: “For UK personal data, we rely on legitimate interests” (and note the recognised legitimate interests basis if applicable). “For EU personal data, we rely on the balancing-based legitimate interests basis under Article 6(1)(f) EU GDPR.” Clarity reduces enforcement risk from both the ICO and supervisory authorities.
When should we split our processing into separate UK and EU systems?
Only when necessary. Architectural separation (UK controller, EU controller) is expensive and operationally complex. Instead, maintain unified processing with dual-compliance matrices. Separate systems are justified where: processing differs fundamentally by jurisdiction; audit and control segregation is required by group governance or M&A; or transfer mechanisms are materially different. For most organisations, a single processing operation with dual-regime documentation is more efficient.
Advice on UK-EU data protection divergence
Representative experience
Recent and representative matters include:
- Advised a global telecoms group on maintaining dual compliance with the UK GDPR and EU GDPR following the UK’s departure from the EU, including the restructuring of data processing agreements and transfer mechanisms.
- Prepared an impact assessment of the Data (Use and Access) Act 2025 reforms for a financial services client, identifying the practical divergences from the EU GDPR and the implications for the UK’s adequacy status.
- Advised on the risks to UK adequacy arising from proposed changes to the legitimate interests processing condition, including contingency planning for alternative transfer mechanisms.
- Reviewed a multinational’s privacy programme to ensure it addressed both UK and EU requirements, including the differences in regulatory guidance from the ICO and EU supervisory authorities.
- Advised a data-intensive business on the application of the UK’s reformed research processing provisions under the Data (Use and Access) Act 2025, assessing the scope of the new exemptions against the EU position.
Rob Bratby advises on the practical implications of UK-EU data protection divergence for businesses operating across both jurisdictions. He is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection.
Related data protection pages
See also our other data protection pages:
Data Protection
UK GDPR Compliance
Lawful Basis and Legitimate Interests
Data Protection Impact Assessments
Data Governance, Transfers and Accountability
AI and Automated Decision-Making
The EU AI Act: what UK businesses need to know
Sector-Specific Data Protection
Data Breach Response and ICO Notification
PECR and ePrivacy
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



Discuss your matter
Primary sources
- Retained EU Law (Revocation and Reform) Act 2023
- Data (Use and Access) Act 2025
- Regulation (EU) 2016/679 (EU GDPR) on EUR-Lex
- European Commission: Adequacy decisions (including the UK adequacy decision)
- Commission Implementing Decision (EU) 2021/1772 (UK adequacy under the EU GDPR)
- Commission Implementing Decision (EU) 2025/2574 of 19 December 2025 (amending the UK adequacy decision)
