UK GDPR / Data Protection Act 2018

UK General Data Protection Regulation

Regulation — United Kingdom
Effective: January 1, 2021 73 platforms tracked 2399 provisions indexed Enforced by: Information Commissioner's Office (ICO) Last reviewed May 9, 2026

Overview

The UK General Data Protection Regulation is the United Kingdom's post-Brexit data protection framework, retaining the substance of the EU GDPR as domestic law through the European Union (Withdrawal) Act 2018, supplemented by the Data Protection Act 2018.

The UK GDPR mirrors the EU GDPR in most respects — same principles, lawful bases, data subject rights, and accountability obligations. Key differences include independent adequacy status, UK-specific standard contractual clauses (IDTA), and the ICO's independent enforcement approach.

Platforms serving UK users must comply with both EU GDPR and UK GDPR as separate legal regimes, often with UK-specific supplements in their privacy policies.

Penalties

Maximum: GBP 17.5 million or 4% of worldwide annual turnover. Lower tier: GBP 8.7 million or 2% of turnover.

Key Articles & Sections

Platforms We Track Subject to UK GDPR

Recent Changes Related to UK GDPR

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by UK GDPR (2399 across 73 platforms)

GDPR Data Processing Agreement Adobe
Medium
Data Sharing with Advertising Partners and Data Brokers Adobe
Medium
Content Analytics Opt-Out Adobe
Medium
Cross-Border Data Transfers Adobe
Medium
Cloud Content Analytics and Human Review Adobe
Medium
Legitimate Interests Legal Basis Adobe
Medium
Age Restriction and Minors Adobe
Medium
Cross-Border Data Transfer Authorization Adobe
Medium
Sensitive Personal Information Prohibition Adobe
Medium
Children's Privacy and Age Restrictions Adobe
Medium
Social Media Integration and Data Sharing Adobe
Medium
Business Transfer and Merger Data Disclosure Adobe
Medium
Generative AI Training Prohibition (with Adobe Stock Exception) Adobe
Medium
Data Retention Adobe
Medium
Content Analytics Opt-Out Right Adobe
Medium
Business Email Account Sharing with Employers Adobe
Medium
Generative AI Training Carve-Out Adobe
Medium
Legitimate Interests as Default Legal Basis for Marketing and Processing Adobe
Medium
Business Email Domain Account Takeover Adobe
Medium
Inferred Data and Third-Party Data Broker Sourcing Adobe
Medium
Children's Privacy Restrictions Adobe
Medium
Data Retention Airbnb
Medium
Geolocation Data Collection Airbnb
Medium
Location Data Collection Airbnb
Medium
Data Retention Policy Airbnb
Medium
User Rights: Access, Deletion, and Portability Airbnb
Medium
Government and Law Enforcement Disclosure Airbnb
Medium
Data Sharing with Hosts and Guests Airbnb
Medium
Cross-Border Data Transfers Airbnb
Medium
GDPR Rights for EU and UK Users Airbnb
Medium

Showing 30 of 2399 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Get alerted when platforms change their policies — including UK GDPR-relevant provisions.

Subscribe to Monitor — $19/mo

Frequently Asked Questions

What does UK GDPR require?

Which platforms does UK GDPR apply to?

ConductAtlas tracks UK GDPR-relevant provisions across 73 platforms. Each platform's specific provisions are classified by severity and mapped to UK GDPR requirements.

How does ConductAtlas monitor UK GDPR compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect UK GDPR obligations. Every change is archived with cryptographic verification.