UK GDPR / Data Protection Act 2018

UK General Data Protection Regulation

Regulation — United Kingdom
Effective: January 1, 2021 73 platforms tracked 4923 provisions indexed Enforced by: Information Commissioner's Office (ICO) Last reviewed May 9, 2026

Overview

The UK General Data Protection Regulation is the United Kingdom's post-Brexit data protection framework, retaining the substance of the EU GDPR as domestic law through the European Union (Withdrawal) Act 2018, supplemented by the Data Protection Act 2018.

The UK GDPR mirrors the EU GDPR in most respects — same principles, lawful bases, data subject rights, and accountability obligations. Key differences include independent adequacy status, UK-specific standard contractual clauses (IDTA), and the ICO's independent enforcement approach.

Platforms serving UK users must comply with both EU GDPR and UK GDPR as separate legal regimes, often with UK-specific supplements in their privacy policies.

Penalties

Maximum: GBP 17.5 million or 4% of worldwide annual turnover. Lower tier: GBP 8.7 million or 2% of turnover.

Key Articles & Sections

Platforms We Track Subject to UK GDPR

Recent Changes Related to UK GDPR

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by UK GDPR (4923 across 73 platforms)

Adobe Shares Behavioral Data With Social Media Ad Partners Adobe
Medium
Publicly Posted Content May Persist After Deletion Request Adobe
Medium
Adobe Processes Content To Provide Requested Services Adobe
Medium
Adobe Shares Data Within Adobe Family Of Companies Adobe
Medium
Adobe Discloses Data To Fraud And Security Service Providers Adobe
Medium
Social Sign On Shares Profile Data With Adobe Adobe
Medium
Adobe Retains Marketing Data Until Opt Out Plus Short Period Adobe
Medium
Adobe Will Not Use Content License to Market Adobe Adobe
Medium
License to Adobe to Operate Services on User Behalf Adobe
Medium
Adobe Uses Data For Direct Marketing Without Consent Where Permitted Adobe
Medium
Deleted Content Stops Being Publicly Available Within Reasonable Time Adobe
Medium
Adobe Collects Visitor Name And Biometrics At Physical Offices Adobe
Medium
Adobe Processes Data For Legal Compliance And Fraud Detection Adobe
Medium
Adobe Collects Accessibility And Disability Information Adobe
Medium
Adobe Infers Data From Third Party Sources Adobe
Medium
Adobe Collects Data From Data Brokers For Fraud Prevention Adobe
Medium
User Can Object To Legitimate Interest Based Processing Adobe
Medium
Content Analytics on Cloud Content Subject to Opt-Out Adobe
Medium
Human Review of Cloud Content in Limited Circumstances Adobe
Medium
Business Must Ensure Business User Compliance with Sensitive Data Prohibition Adobe
Medium
Fonts Deleted Upon Account Termination Adobe
Medium
Authorization for Cross-Border Personal Information Transfer Adobe
Medium
License for Content Analytics to Improve Services Adobe
Medium
Adobe Collects Customer Support Call Recordings Adobe
Medium
User Has Right to Opt Out of Content Analytics Adobe
Medium
Adobe Will Not Publicly Display Content Under Analytics License Adobe
Medium
Adobe Collects Payment And Billing Information Adobe
Medium
Adobe Collects Identity And Contact Information At Registration Adobe
Medium
Session Replay Partners Recreate User Web And App Sessions Adobe
Medium
Adobe Transfers Personal Data Internationally Adobe
Medium

Showing 30 of 4923 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Get alerted when platforms change their policies, including UK GDPR-relevant provisions.

Subscribe to Monitor, $19/mo

Frequently Asked Questions

What does UK GDPR require?

Which platforms does UK GDPR apply to?

ConductAtlas tracks UK GDPR-relevant provisions across 73 platforms. Each platform's specific provisions are classified by severity and mapped to UK GDPR requirements.

How does ConductAtlas monitor UK GDPR compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect UK GDPR obligations. Every change is archived with cryptographic verification.