{
 "jurisdiction_id": "UK",
 "jurisdiction": "United Kingdom",
 "url": "https://dataprotection.gi/jurisdictions/united-kingdom/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 65,
  "sub_modules": 57,
  "source_register": 52
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Framework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.",
   "claims": [
    {
     "statement": "The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/charities-given-new-flexibility-to-contact-supporters-under-data-law-change/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-duaa-summary-of-the-changes/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ico-ceo-paul-arnold-on-what-s-ahead-for-the-agency-s-reforms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-representatives-in-the-eu-and-the-uk-after-brexit",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/accountability-and-governance/guide-to-the-data-protection-fee/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/data-protection-fee/faqs-data-protection-fee-payment-and-online-registration/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Substantive alignment with EU GDPR continues, but amber reflects the newly-introduced recognised legitimate interest basis and consequential ICO guidance still being finalised post-DUAA.",
   "claims": [
    {
     "statement": "The DUAA 2025 introduces 'recognised legitimate interest' as a new UK GDPR lawful basis, separate from ordinary legitimate interests, limited to an exhaustive list of public-interest purposes such as crime prevention, safeguarding and emergencies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/08/ico-launches-consultations-for-data-use-and-access-act-2025-amendments/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Recognised legitimate interest cannot be relied upon by public authorities performing their public tasks, which must continue to use the public task lawful basis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/08/ico-launches-consultations-for-data-use-and-access-act-2025-amendments/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where an online service relies on consent as its lawful basis, UK data protection law requires parental authorisation for children under 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/code-standards/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing biometric data for unique identification purposes constitutes special category processing under UK GDPR Article 9, requiring both an Article 6 lawful basis and a separate Article 9/DPA 2018 Schedule 1 condition, with explicit consent typically the most applicable condition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/how-do-we-process-biometric-data-lawfully/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights framework unchanged; DUAA amendments are procedural clarifications rather than reductions in substantive rights.",
   "claims": [
    {
     "statement": "The DUAA 2025 inserts provisions into UK GDPR and DPA 2018 Part 3 allowing controllers to pause ('stop the clock') the SAR response time limit in order to request reasonably required clarification from the requester.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-duaa-summary-of-the-changes/data-protection/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Most DUAA changes offer organisations optional flexibility rather than mandating specific changes to existing rectification/erasure obligations, meaning the substantive right to rectification and erasure is not materially altered.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Individuals have an absolute right under UK GDPR Article 21 to stop their personal data being used for direct marketing, and controllers must inform individuals of this right at the latest at first communication.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Controllers have one calendar month to respond to a right-to-object request under UK GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Framework is mature and enforced, but amber reflects live enforcement activity indicating gaps in DPIA and security practice among controllers, and ongoing DUAA-driven guidance updates.",
   "claims": [
    {
     "statement": "Accountability is a UK GDPR principle requiring organisations to take responsibility for and demonstrate compliance, including through data protection by design/default, processor contracts, documented processing activities and DPIAs.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO's £14.47m fine against Reddit found the company failed to carry out a DPIA to assess and mitigate risks to children before January 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/reddit-issued-with-1447m-fine-for-children-s-privacy-failures/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO's £247,590 fine against MediaLab (Imgur) similarly found a failure to carry out a data protection impact assessment to identify and reduce privacy risks to children.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/imgur-owner-medialab-fined-over-children-s-privacy-failures/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Where an organisation has appointed a DPO, the DPO's contact details (and name, with consent) are published on the ICO's public register of fee payers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/register-of-data-controllers/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A DPO's tasks include advising the organisation about UK GDPR compliance, monitoring compliance and training staff.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Demonstrating accountability includes maintaining documentation of an organisation's processing activities, a measure the ICO expects controllers to adopt as part of governance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "If two or more controllers jointly determine the purposes and means of processing the same personal data, they are joint controllers; they are not joint controllers where processing the same data for different purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-for-the-use-of-personal-data-in-political-campaigning-1/controllers-joint-controllers-and-processors/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO imposed a £963,900 fine on South Staffordshire Plc and South Staffordshire Water Plc for infringing Article 5(1)(f) and Article 32(1) UK GDPR following a cyber incident exfiltrating personal data of approximately 633,887 UK data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/action-weve-taken/enforcement/2026/05/south-staffordshire-plc-and-south-staffordshire-water-plc/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA aligns the timeline for notifying the Commissioner of a PECR security breach with the UK GDPR breach-notification timeline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-duaa-summary-of-the-changes/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Mutual UK-EU adequacy is now confirmed to 2031 and the US data bridge is operative, though EDPB flagged monitoring concerns around new Secretary of State transfer powers.",
   "claims": [
    {
     "statement": "Restricted transfers under UK GDPR require one of: adequacy regulations, Article 46 appropriate safeguards, or an Article 49 derogation for specific situations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-transfers-a-guide/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA replaces UK GDPR Article 44 with a new Article 44A retaining the same general transfer principles while introducing new terminology of 'regulations approving the transfer' in place of 'adequacy regulations'.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex / European Commission",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32025D2574",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The European Commission adopted amended UK adequacy decisions on 19 December 2025, renewing adequacy under both the GDPR and the Law Enforcement Directive.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Both the renewed EU GDPR and LED adequacy decisions for the UK are valid until 27 December 2031, applying to personal information transferred from the whole EEA to the whole UK.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "All EEA countries have full UK adequacy status, permitting UK organisations to transfer personal information to them without additional safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/is-the-restricted-transfer-covered-by-adequacy-regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The UK Extension to the EU-US Data Privacy Framework is a partial adequacy finding allowing UK (and Gibraltar) organisations to make restricted transfers to self-certified US businesses regulated by the FTC or DoT, without appropriate safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/how-does-the-uk-extension-to-the-eu-us-data-privacy-framework-work/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UK organisations may use the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, or UK Binding Corporate Rules as Article 46 appropriate safeguards for restricted transfers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-transfers-a-guide/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organisations relying on appropriate safeguards for restricted transfers must complete a Transfer Risk Assessment (TRA) to confirm the standard of protection is not materially lower after transfer.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/international-transfers-a-guide/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecoms/ePrivacy and employment ADM are well evidenced; financial, health, credit, education and insurance sub-modules carry material gaps requiring escalation.",
   "claims": [
    {
     "statement": "The ICO fined KRA Consultancy Ltd £300,000 for sending over 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of PECR, generating over 60,000 complaints to the 7726 spam-reporting service.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/action-weve-taken/enforcement/2026/05/kra-consultancy-ltd-mpn/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA inserts a new schedule into PECR setting out exceptions from the prohibition on storing or accessing information on a subscriber's or user's terminal equipment (the cookie rules).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-duaa-summary-of-the-changes/schedules/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UK GDPR Article 22A defines automated decision-making (ADM) as a decision based solely on automated processing with no meaningful human involvement that has a legal or similarly significant effect on a person.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/03/automated-decisions-can-streamline-the-hiring-process-with-the-right-safeguards-in-place/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO wrote to 16 organisations likely using ADM in hiring, securing commitments to improve transparency, bias monitoring and human-review safeguards following a March 2026 compliance report.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/03/automated-decisions-can-streamline-the-hiring-process-with-the-right-safeguards-in-place/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO publishes dedicated FAQs applying the Children's code (Age Appropriate Design Code) to schools and education technology providers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookies and direct marketing are well evidenced; opt-out signal standards, clean rooms and cross-context advertising remain research gaps.",
   "claims": [
    {
     "statement": "The Children's code requires that nudge techniques not be used to encourage children to provide unnecessary personal data or weaken/turn off their privacy settings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO reviewed justifications for using legitimate interests as the lawful basis for real-time bidding (RTB) in adtech and found the justifications offered by organisations insufficient.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Office of the Australian Information Commissioner",
     "source_url": "https://www.oaic.gov.au/__data/assets/pdf_file/0014/2903/oaic-research-international-regulation-of-digital-platforms-final-paper-publish2.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA clarifies that direct marketing can be conducted on the basis of legitimate interests as a lawful basis under UK GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Since 5 February 2026, charities may send electronic mail marketing (including texts and social media direct messages) furthering their charitable purposes to individuals who have expressed interest or offered support, without prior consent, under a new 'soft opt-in', subject to safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/04/charities-given-new-flexibility-to-contact-supporters-under-data-law-change/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Substantial regulatory activity and guidance exist, but the AI/ADM statutory code of practice is still being developed and national-security exemption scope remains a monitored risk per EDPB.",
   "claims": [
    {
     "statement": "UK GDPR Article 22A, inserted by the DUAA, defines automated decision-making (ADM) as a decision based solely on automated processing (no meaningful human involvement) that has a legal or similarly significant effect on a person.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/03/automated-decisions-can-streamline-the-hiring-process-with-the-right-safeguards-in-place/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Organisations using ADM must explain to affected candidates/individuals how it works and how to exercise their right to challenge a decision and request human review.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/03/automated-decisions-can-streamline-the-hiring-process-with-the-right-safeguards-in-place/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO is developing draft ADM and profiling guidance for public consultation, which will inform a forthcoming statutory AI and ADM code of practice.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/artificial-intelligence-and-biometrics-strategy/ai-and-biometrics-strategy-update-march-2026/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The UK government is developing secondary legislation, committed to during passage of the DUAA 2025, requiring the ICO to produce an AI and ADM statutory code of practice.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/artificial-intelligence-and-biometrics-strategy/ai-and-biometrics-strategy-update-march-2026/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO has conducted or is conducting facial recognition technology (FRT) audits of multiple UK police forces including South Wales, Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester Police.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/our-information/our-strategies-and-plans/artificial-intelligence-and-biometrics-strategy/ai-and-biometrics-strategy-update-march-2026/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Processing biometric data through a biometric recognition system meets all three elements of the UK GDPR biometric data definition, constituting special category biometric data requiring explicit consent or another valid Article 9 condition.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/biometric-data-guidance-biometric-recognition/biometric-recognition/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB has flagged that UK national security exemptions may waive most data protection principles and some international transfer rules for law enforcement authorities and can limit the ICO's enforcement and inspection powers, calling for ongoing Commission monitoring.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/draft-uk-adequacy-decisions-edpb-adopts-opinions_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Children's protections are mature, statutory and actively enforced (amber reflects ongoing enforcement gaps industry-wide); dependent-adults sub-module is an evidenced gap.",
   "claims": [
    {
     "statement": "The Children's code applies to information society services likely to be accessed by children under 18, including UK-based and non-UK companies processing UK children's personal data, even if children are not the target audience.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/introduction-to-the-childrens-code/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO fined Reddit £14.47m for failing to apply any robust age assurance mechanism, resulting in no lawful basis for processing personal information of children under 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/reddit-issued-with-1447m-fine-for-children-s-privacy-failures/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ICO fined MediaLab (Imgur) £247,590 for failing to implement any age assurance measures to determine the age of users between September 2021 and September 2025, exposing children to harmful content.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/imgur-owner-medialab-fined-over-children-s-privacy-failures/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UK law requires that online services using personal information of children under 13 rely on consent given by the child's parent or carer where consent is the chosen lawful basis; MediaLab was found to lack such parental consent measures for Imgur.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/imgur-owner-medialab-fined-over-children-s-privacy-failures/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Children's code Standard 10 requires profiling to be switched off by default unless the organisation can demonstrate a compelling reason accounting for the best interests of the child, with protections against harmful content effects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/code-standards/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-kingdom/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers and recent activity are robust and well evidenced across multiple 2026 cases; collective redress remains constrained by case law, which is a known and stable limitation rather than a gap.",
   "claims": [
    {
     "statement": "Under UK GDPR and the DPA 2018, the ICO can issue fines of up to £17.5 million or 4% of an organisation's annual worldwide turnover, whichever is higher.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/ico-announces-investigation-into-grok/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA gives the ICO new powers, including the ability to compel witnesses to attend interviews and request technical reports, and raises the PECR maximum fine to £17.5 million or 4% of global turnover.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/06/uk-organisations-stand-to-benefit-from-new-data-protection-laws/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 23 February 2026, the ICO imposed a £14,472,500 penalty on Reddit, Inc. for infringing UK GDPR Articles 5(1)(a), 6, 8 and 35.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/action-weve-taken/enforcement/2026/02/reddit-inc/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 26 February 2026, the ICO published a £247,590 monetary penalty notice against MediaLab for unlawful processing of children's data on the Imgur platform.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/imgur-owner-medialab-fined-over-children-s-privacy-failures/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 7 May 2026, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 for infringing UK GDPR Articles 5(1)(f) and 32(1) following a cyber incident.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/action-weve-taken/enforcement/2026/05/south-staffordshire-plc-and-south-staffordshire-water-plc/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 20 May 2026, the ICO fined KRA Consultancy Ltd £300,000 for breaching PECR regulations 22 and 23 through mass unsolicited marketing texts.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/action-weve-taken/enforcement/2026/05/kra-consultancy-ltd-mpn/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DUAA-driven governance reform moves the ICO from a corporation-sole structure to a traditional chair, CEO and board model intended to provide institutional continuity and resilience.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/ico-ceo-paul-arnold-on-what-s-ahead-for-the-agency-s-reforms",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In Lloyd v Google LLC [2021] UKSC 50, the UK Supreme Court held that damages under the (then) Data Protection Act require proof of material damage or distress caused by unlawful processing, not merely the unlawful processing (loss of control) itself, precluding the proposed representative 'class action' claim.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/uk-supreme-court-overturns-court-appeal-judgment-lloyd",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following Lloyd v Google, claimant law firms pursuing UK data-breach mass actions face the requirement that individual class members evidence the damage or distress they personally suffered, constraining opt-out-style collective redress.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/uk-supreme-court-halts-billion-dollar-privacy-class-action-against-google",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "UK GDPR gives individuals a right to claim compensation from an organisation in court for both material damage (e.g., financial loss) and non-material damage (e.g., distress) suffered from a breach of data protection law, though the ICO cannot itself award compensation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/for-the-public/data-protection-and-journalism/taking-your-case-to-court-and-claiming-compensation/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of 19 June 2026, all data protection provisions of the DUAA 2025 are in force, including a new mandatory requirement for all organisations to have a data protection complaints-handling process in place.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Information Commissioner's Office",
     "source_url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/one-month-to-go-what-businesses-need-to-know-to-meet-new-data-law/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}