🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
UK · run data-protection-2026-07-28 v13-gdpri-1.0.0
content: ai_generated 52 sources retrieved model claude-sonnet-5 ·

United Kingdom

UK schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 65 claims · 52 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
65Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The Data Use and Access Act 2025 reached full commencement on 19 June 2026, requiring all organisations to have a data protection complaints-handling process in place. The Act abolishes the office of the Information Commissioner and transfers its functions to a new Information Commission body governed by a board rather than a single office-holder. The transition to this new Information Commission is understood to still lack a confirmed final transition date as of mid-2026. The DUAA amends but does not replace the UK GDPR, the Data Protection Act 2018 and PECR 2003. It restructures rather than materially changing the scope of personal information use, clarifying legitimate interests, research processing and purpose limitation. Full commencement lands alongside a run of large ICO penalties this year touching children's privacy, industrial cyber security and unsolicited marketing, discussed further below.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Framework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.

Primary frameworkUK GDPR / Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025
Traffic-light rationale — AmberFramework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.

Sub-modules (5)

Regulator And AuthorityAmber

The ICO is the UK's independent regulator for data protection and information rights, with responsibilities under DPA 2018, UK GDPR, FOIA, EIR and PECR, among other statutes. The DUAA abolishes the office of Information Commissioner and transfers its functions to a new corporate body, the Information Commission, moving from a corporation-sole model to a chair/CEO/board structure.

Claims: CLM-UK-a1f30b21, CLM-UK-a1f30b22, CLM-UK-a1f30b23

Act And InstrumentsGreen

The operative instruments are UK GDPR, DPA 2018 and PECR 2003, amended but not replaced by the DUAA 2025.

Claims: CLM-UK-a1f30b24

Material ScopeGreen

UK GDPR/DPA 2018 apply to processing of personal data by controllers and processors; the DUAA makes targeted amendments to purpose limitation, research processing and lawful bases without expanding core material scope.

Claims: CLM-UK-a1f30b25

Territorial ScopeGreen

UK GDPR has extraterritorial reach equivalent to EU GDPR Article 3(2): non-UK controllers/processors offering goods/services to, or monitoring the behaviour of, UK data subjects fall within scope and generally must appoint a UK representative.

Claims: CLM-UK-a1f30b26

Regulator Registration And FilingGreen

Controllers processing personal data must generally pay an annual data protection fee to the ICO under the Data Protection (Charges and Information) Regulations 2018, across three tiers (£52/£78/£3,763), with over one million controllers on the public register.

Claims: CLM-UK-a1f30b27, CLM-UK-a1f30b28

Category narrative85 words

The UK's data protection regime is anchored in UK GDPR, the Data Protection Act 2018 (DPA 2018) and PECR 2003, all substantially amended by the Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025 and reached full commencement on 19 June 2026. The Information Commissioner's Office (ICO) is the supervisory authority, currently a corporation sole but transitioning under the DUAA to a board-governed 'Information Commission' with the office of Information Commissioner abolished and functions transferred to the new body.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedInformation Commissioner's OfficeThe Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.
  2. ConfirmedInformation Commissioner's OfficeThe DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.
  3. ProbableIAPPAs of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.
  4. ConfirmedInformation Commissioner's OfficeThe DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.
  5. ConfirmedInformation Commissioner's OfficeThe DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.
  6. ConfirmedIAPPA UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.
  7. ConfirmedInformation Commissioner's OfficeUnder the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.
  8. ConfirmedInformation Commissioner's OfficeThe ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.

#

Substantive alignment with EU GDPR continues, but amber reflects the newly-introduced recognised legitimate interest basis and consequential ICO guidance still being finalised post-DUAA.

Primary frameworkUK GDPR Articles 6-11; DPA 2018 Schedule 1; DUAA 2025 Schedule 4
Traffic-light rationale — AmberSubstantive alignment with EU GDPR continues, but amber reflects the newly-introduced recognised legitimate interest basis and consequential ICO guidance still being finalised post-DUAA.

Sub-modules (4)

Lawful BasesAmber

The DUAA introduces 'recognised legitimate interest' as a new UK GDPR lawful basis limited to an exhaustive statutory list (e.g., crime prevention, safeguarding, public security, emergencies) and unavailable to public authorities performing their tasks.

Claims: CLM-UK-b2e41c31, CLM-UK-b2e41c32

Special CategoriesGreen

Article 9 special category conditions and DPA 2018 Schedule 1 additional conditions remain the operative framework, including for biometric data, with minor DUAA clarifications to crime, journalism and fraud exemption wording.

Claims: CLM-UK-b2e41c34

Pseudonymisation And AnonymisationRed

No dedicated post-DUAA ICO code or statutory redefinition of pseudonymisation/anonymisation was located in this research pass; searches covered ICO guidance-and-resources indexes and DUAA summary pages without surfacing a standalone anonymisation instrument update.

Category narrative64 words

UK GDPR retains the six lawful bases from EU GDPR Article 6 but the DUAA 2025 inserts a new 'recognised legitimate interest' basis for a closed list of public-interest purposes, and clarifies that direct marketing may qualify as an ordinary legitimate interest. Special category processing (Article 9) and DPA 2018 Schedule 1 conditions remain largely intact, with minor clarifications to crime and journalism exemptions.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedInformation Commissioner's OfficeThe DUAA 2025 introduces 'recognised legitimate interest' as a new UK GDPR lawful basis, separate from ordinary legitimate interests, limited to an exhaustive list of public-interest purposes such as crime prevention, safeguarding and emergencies.
  2. ConfirmedInformation Commissioner's OfficeRecognised legitimate interest cannot be relied upon by public authorities performing their public tasks, which must continue to use the public task lawful basis.
  3. ConfirmedInformation Commissioner's OfficeWhere an online service relies on consent as its lawful basis, UK data protection law requires parental authorisation for children under 13.
  4. ConfirmedInformation Commissioner's OfficeProcessing biometric data for unique identification purposes constitutes special category processing under UK GDPR Article 9, requiring both an Article 6 lawful basis and a separate Article 9/DPA 2018 Schedule 1 condition, with explicit consent typically the most applicable condition.

#

Core rights framework unchanged; DUAA amendments are procedural clarifications rather than reductions in substantive rights.

Primary frameworkUK GDPR Articles 12-22; DPA 2018 Part 2
Traffic-light rationale — GreenCore rights framework unchanged; DUAA amendments are procedural clarifications rather than reductions in substantive rights.

Sub-modules (5)

Access RightGreen

The subject access request (SAR) regime continues under UK GDPR Article 15/DPA 2018, with the DUAA inserting a 'stopping the clock' provision allowing controllers to pause the response time limit when reasonably requesting clarification from the requester.

Claims: CLM-UK-c3d52e41

Rectification And ErasureAmber

Rectification and erasure rights under UK GDPR Articles 16-17 are unaffected in substance by the DUAA; no dedicated new instrument was located for this sub-module beyond the general 'no material change' framing in ICO's DUAA summary.

Claims: CLM-UK-c3d52e42

Restriction And ObjectionGreen

Individuals retain an absolute right to object to processing for direct marketing purposes at any time, with a qualified right to object in other circumstances (e.g., public task, legitimate interests, research).

Claims: CLM-UK-c3d52e43

Data PortabilityAmber

No DUAA-specific change to the Article 20 data portability right was identified in this research pass; the underlying UK GDPR Article 20 portability right is presumed to continue unamended, but this was not separately confirmed against a primary source in this run.

Deadlines And Response WindowsGreen

The standard one-month response window applies to rights requests including the right to object; the DUAA's 'stopping the clock' mechanism allows this to be paused for SARs pending clarification from the data subject.

Claims: CLM-UK-c3d52e44, CLM-UK-c3d52e41

Category narrative42 words

UK GDPR data subject rights (access, rectification, erasure, restriction, objection, portability) are preserved post-DUAA, with the DUAA adding a 'stopping the clock' mechanism allowing controllers to pause SAR response deadlines when seeking clarification, and clarifying some Article 13/14 transparency exemptions for research.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedInformation Commissioner's OfficeThe DUAA 2025 inserts provisions into UK GDPR and DPA 2018 Part 3 allowing controllers to pause ('stop the clock') the SAR response time limit in order to request reasonably required clarification from the requester.
  2. ProbableInformation Commissioner's OfficeMost DUAA changes offer organisations optional flexibility rather than mandating specific changes to existing rectification/erasure obligations, meaning the substantive right to rectification and erasure is not materially altered.
  3. ConfirmedInformation Commissioner's OfficeIndividuals have an absolute right under UK GDPR Article 21 to stop their personal data being used for direct marketing, and controllers must inform individuals of this right at the latest at first communication.
  4. ConfirmedInformation Commissioner's OfficeControllers have one calendar month to respond to a right-to-object request under UK GDPR.

#

Framework is mature and enforced, but amber reflects live enforcement activity indicating gaps in DPIA and security practice among controllers, and ongoing DUAA-driven guidance updates.

Primary frameworkUK GDPR Articles 5, 24-39; DPA 2018
Traffic-light rationale — AmberFramework is mature and enforced, but amber reflects live enforcement activity indicating gaps in DPIA and security practice among controllers, and ongoing DUAA-driven guidance updates.

Sub-modules (7)

Accountability And DpiaAmber

Accountability requires documented compliance measures; DPIAs are required for high-risk processing including profiling and children's services. Failure to conduct a DPIA was a finding in both the Reddit and MediaLab enforcement actions.

Claims: CLM-UK-d4e63f51, CLM-UK-d4e63f52, CLM-UK-d4e63f53

Dpo RequirementsGreen

Organisations required (or choosing) to appoint a DPO must notify the ICO; DPO contact details are published on the fee-payer register, with DPO tasks including advising on UK GDPR compliance, monitoring compliance and staff training.

Claims: CLM-UK-d4e63f54, CLM-UK-d4e63f55

Ropa RequirementsAmber

Accountability guidance requires maintaining documentation of processing activities as part of demonstrating UK GDPR compliance; a dedicated post-DUAA ROPA-specific instrument was not separately identified in this research pass beyond the general accountability guide.

Claims: CLM-UK-d4e63f56

Joint Controller ArrangementsGreen

Where two or more parties jointly determine the purposes and means of processing the same personal data, they are joint controllers; controllers bear the highest level of compliance responsibility including for their processors.

Claims: CLM-UK-d4e63f57

Security MeasuresAmber

Article 32(1) technical and organisational security obligations remain enforceable, as demonstrated by the May 2026 £963,900 penalty against South Staffordshire Water following a cyber incident affecting circa 633,887 UK data subjects.

Claims: CLM-UK-d4e63f58

Breach NotificationGreen

The DUAA aligns the PECR personal-data-breach notification timeline with the UK GDPR standard, standardising the duty to notify the Commissioner across both regimes.

Claims: CLM-UK-d4e63f59

Retention And DisposalRed

No DUAA-specific retention/disposal instrument was identified in this research pass; the underlying UK GDPR storage-limitation principle (Article 5(1)(e)) continues to apply, but a dedicated primary-source citation for updated retention rules was not located in this run.

Category narrative61 words

Controllers must demonstrate accountability (Article 5(2)), conduct DPIAs for high-risk processing, appoint DPOs where required, maintain records of processing, secure personal data (Article 32), and notify breaches. The DUAA aligns PECR breach-notification timelines with UK GDPR's 72-hour standard and gives the ICO enhanced investigatory powers. Recent ICO enforcement (South Staffordshire Water, Reddit, MediaLab) demonstrates active supervision of security and DPIA obligations.

No periodic updates recorded against this sub-brief.

Sources and claims (9)
  1. ConfirmedInformation Commissioner's OfficeAccountability is a UK GDPR principle requiring organisations to take responsibility for and demonstrate compliance, including through data protection by design/default, processor contracts, documented processing activities and DPIAs.
  2. ConfirmedInformation Commissioner's OfficeThe ICO's £14.47m fine against Reddit found the company failed to carry out a DPIA to assess and mitigate risks to children before January 2025.
  3. ConfirmedInformation Commissioner's OfficeThe ICO's £247,590 fine against MediaLab (Imgur) similarly found a failure to carry out a data protection impact assessment to identify and reduce privacy risks to children.
  4. ConfirmedInformation Commissioner's OfficeWhere an organisation has appointed a DPO, the DPO's contact details (and name, with consent) are published on the ICO's public register of fee payers.
  5. ConfirmedInformation Commissioner's OfficeA DPO's tasks include advising the organisation about UK GDPR compliance, monitoring compliance and training staff.
  6. ProbableInformation Commissioner's OfficeDemonstrating accountability includes maintaining documentation of an organisation's processing activities, a measure the ICO expects controllers to adopt as part of governance.
  7. ConfirmedInformation Commissioner's OfficeIf two or more controllers jointly determine the purposes and means of processing the same personal data, they are joint controllers; they are not joint controllers where processing the same data for different purposes.
  8. ConfirmedInformation Commissioner's OfficeThe ICO imposed a £963,900 fine on South Staffordshire Plc and South Staffordshire Water Plc for infringing Article 5(1)(f) and Article 32(1) UK GDPR following a cyber incident exfiltrating personal data of approximately 633,887 UK data subjects.
  9. ConfirmedInformation Commissioner's OfficeThe DUAA aligns the timeline for notifying the Commissioner of a PECR security breach with the UK GDPR breach-notification timeline.

#

Mutual UK-EU adequacy is now confirmed to 2031 and the US data bridge is operative, though EDPB flagged monitoring concerns around new Secretary of State transfer powers.

Primary frameworkUK GDPR Chapter 5 (Articles 44A-49A, as amended by DUAA 2025)
Traffic-light rationale — GreenMutual UK-EU adequacy is now confirmed to 2031 and the US data bridge is operative, though EDPB flagged monitoring concerns around new Secretary of State transfer powers.

Sub-modules (6)

Transfer MechanismsGreen

Restricted transfers require adequacy regulations, Article 46 appropriate safeguards, or an Article 49 exception; the DUAA reworded but retained this three-tier structure under new Articles 44A-46.

Claims: CLM-UK-e5f74061, CLM-UK-e5f74062

Adequacy ReceivedGreen

The European Commission renewed its adequacy decisions for the UK under both GDPR and the Law Enforcement Directive on 19 December 2025, extending validity to 27 December 2031 and covering transfers from the whole EEA to the whole UK.

Claims: CLM-UK-e5f74063, CLM-UK-e5f74064

Adequacy GrantedGreen

The UK grants full adequacy to all EEA states and partial adequacy to the US (via the UK Extension to the EU-US Data Privacy Framework), allowing UK organisations to transfer to DPF-certified US businesses without additional safeguards.

Claims: CLM-UK-e5f74065, CLM-UK-e5f74066

Sccs And BcrsGreen

UK organisations can use the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, or UK Binding Corporate Rules as Article 46 appropriate safeguards.

Claims: CLM-UK-e5f74067

Transfer Impact AssessmentGreen

Organisations relying on appropriate safeguards must complete a Transfer Risk Assessment (TRA) confirming the destination country's protection is not materially lower than under UK GDPR.

Claims: CLM-UK-e5f74068

Data LocalisationRed

No general data-localisation mandate for personal data was identified for the UK regime in this research pass; UK GDPR instead relies on the adequacy/safeguards/derogation transfer model rather than in-country storage requirements. Searches covered ICO's international transfer guidance without surfacing a localisation obligation.

Category narrative63 words

UK GDPR transfer rules (recast as Article 44A-46 by the DUAA) preserve a three-tier structure of adequacy regulations, appropriate safeguards (SCCs/IDTA/BCRs) and Article 49 derogations. The EU renewed its UK adequacy decisions (GDPR and LED) on 19 December 2025, valid until 27 December 2031, and the UK operates a partial 'UK Extension' adequacy finding for the US via the EU-US Data Privacy Framework.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedInformation Commissioner's OfficeRestricted transfers under UK GDPR require one of: adequacy regulations, Article 46 appropriate safeguards, or an Article 49 derogation for specific situations.
  2. ConfirmedEUR-Lex / European CommissionThe DUAA replaces UK GDPR Article 44 with a new Article 44A retaining the same general transfer principles while introducing new terminology of 'regulations approving the transfer' in place of 'adequacy regulations'.
  3. ConfirmedInformation Commissioner's OfficeThe European Commission adopted amended UK adequacy decisions on 19 December 2025, renewing adequacy under both the GDPR and the Law Enforcement Directive.
  4. ConfirmedInformation Commissioner's OfficeBoth the renewed EU GDPR and LED adequacy decisions for the UK are valid until 27 December 2031, applying to personal information transferred from the whole EEA to the whole UK.
  5. ConfirmedInformation Commissioner's OfficeAll EEA countries have full UK adequacy status, permitting UK organisations to transfer personal information to them without additional safeguards.
  6. ConfirmedInformation Commissioner's OfficeThe UK Extension to the EU-US Data Privacy Framework is a partial adequacy finding allowing UK (and Gibraltar) organisations to make restricted transfers to self-certified US businesses regulated by the FTC or DoT, without appropriate safeguards.
  7. ConfirmedInformation Commissioner's OfficeUK organisations may use the UK International Data Transfer Agreement (IDTA), the UK Addendum to EU Standard Contractual Clauses, or UK Binding Corporate Rules as Article 46 appropriate safeguards for restricted transfers.
  8. ConfirmedInformation Commissioner's OfficeOrganisations relying on appropriate safeguards for restricted transfers must complete a Transfer Risk Assessment (TRA) to confirm the standard of protection is not materially lower after transfer.

#

Telecoms/ePrivacy and employment ADM are well evidenced; financial, health, credit, education and insurance sub-modules carry material gaps requiring escalation.

Primary frameworkPECR 2003 (as amended by DUAA 2025); UK GDPR sectoral guidance
Traffic-light rationale — AmberTelecoms/ePrivacy and employment ADM are well evidenced; financial, health, credit, education and insurance sub-modules carry material gaps requiring escalation.

Sub-modules (7)

Financial Sector OverlayRed

The ICO and the Financial Conduct Authority (FCA) both have jurisdiction touching financial-sector personal data, but no specific FCA-ICO memorandum of understanding or overlay instrument was retrieved in this research pass; this is flagged for escalation given the disambiguation risk between DP and financial-conduct regulation.

Health Sector OverlayRed

No health-sector-specific UK data protection overlay (e.g., NHS data-sharing codes) was retrieved in this research pass; searches focused on ICO/DUAA general resources without surfacing dedicated health-sector primary sources.

Telecoms And EprivacyAmber

PECR governs cookies, unsolicited electronic marketing and traffic/location data; the ICO fined KRA Consultancy £300,000 for breaching PECR regulations 22 and 23 via 5.5 million unsolicited marketing/fake-bailiff texts, and the DUAA inserts new PECR cookie exceptions.

Claims: CLM-UK-f6085172, CLM-UK-f6085173

Employment DataAmber

The ICO issued specific guidance and a compliance report on automated decision-making (ADM) in recruitment, following DUAA changes lifting some ADM restrictions, requiring transparency, bias testing and a right to request human review of hiring decisions.

Claims: CLM-UK-f6085174, CLM-UK-f6085175

Credit And ScoringRed

No credit-scoring-specific UK data protection overlay was retrieved in this research pass beyond the general Article 22-equivalent ADM rules; flagged as a research gap.

EducationAmber

The ICO publishes FAQs on applying the Children's code to schools and education technology providers, but a dedicated education-sector data protection statute or code beyond the Children's code was not separately identified in this pass.

Claims: CLM-UK-f6085176

InsuranceRed

No insurance-sector-specific UK data protection overlay was retrieved in this research pass; flagged as a research gap requiring targeted follow-up.

Category narrative57 words

PECR functions as the UK's ePrivacy overlay on cookies, direct marketing and electronic communications, with DUAA-driven reforms including new cookie-consent exemptions and a charity soft opt-in. Employment-sector ADM guidance has been issued by the ICO. Financial services, health, credit-scoring, education and insurance sector-specific overlays were not substantively surfaced in this research pass beyond general FCA/ICO coexistence awareness.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedInformation Commissioner's OfficeThe ICO fined KRA Consultancy Ltd £300,000 for sending over 5.5 million unsolicited direct marketing and fake bailiff texts in breach of regulations 22 and 23 of PECR, generating over 60,000 complaints to the 7726 spam-reporting service.
  2. ConfirmedInformation Commissioner's OfficeThe DUAA inserts a new schedule into PECR setting out exceptions from the prohibition on storing or accessing information on a subscriber's or user's terminal equipment (the cookie rules).
  3. ConfirmedInformation Commissioner's OfficeUK GDPR Article 22A defines automated decision-making (ADM) as a decision based solely on automated processing with no meaningful human involvement that has a legal or similarly significant effect on a person.
  4. ConfirmedInformation Commissioner's OfficeThe ICO wrote to 16 organisations likely using ADM in hiring, securing commitments to improve transparency, bias monitoring and human-review safeguards following a March 2026 compliance report.
  5. ConfirmedInformation Commissioner's OfficeThe ICO publishes dedicated FAQs applying the Children's code (Age Appropriate Design Code) to schools and education technology providers.

#

Cookies and direct marketing are well evidenced; opt-out signal standards, clean rooms and cross-context advertising remain research gaps.

Primary frameworkPECR 2003 (as amended by DUAA 2025); UK GDPR Article 21
Traffic-light rationale — AmberCookies and direct marketing are well evidenced; opt-out signal standards, clean rooms and cross-context advertising remain research gaps.

Sub-modules (6)

Cookies And TrackersAmber

PECR prohibits storing or accessing information on a user's device absent consent or an applicable exception; the DUAA inserts a new schedule of cookie-rule exceptions into PECR.

Claims: CLM-UK-f6085173

Dark PatternsAmber

The Children's code prohibits 'nudge techniques' that encourage children to weaken privacy settings or provide unnecessary personal data, functioning as a sector-specific anti-dark-pattern standard for minors.

Claims: CLM-UK-g7196283

Opt Out SignalsRed

No UK-specific standard equivalent to Global Privacy Control or DAA opt-out signal recognition was identified in this research pass.

Clean Rooms And DcrRed

No ICO guidance on data clean rooms or data-collaboration-room arrangements was identified in this research pass.

Cross Context AdvertisingAmber

The ICO has previously found that legitimate-interest justifications offered by organisations for real-time bidding (RTB) in programmatic advertising were insufficient, indicating heightened scrutiny of cross-context ad-tech data sharing.

Claims: CLM-UK-g7196284

Direct MarketingGreen

The DUAA clarifies that direct marketing can qualify as a legitimate interest, and introduces a new charity 'soft opt-in' permitting electronic marketing to supporters without prior consent if safeguards are met.

Claims: CLM-UK-g7196285, CLM-UK-g7196286

Category narrative67 words

PECR governs cookie consent, with DUAA-inserted exceptions; the ICO has historically found legitimate-interest justifications for real-time-bidding (RTB) adtech insufficient. The Children's code prohibits nudge techniques and off-by-default profiling for minors. Direct marketing rules were liberalised for charities via a new soft opt-in, and legitimate interest was clarified to cover direct marketing generally. Opt-out signals (e.g., GPC), clean-room/data-collaboration rules and cross-context-advertising-specific instruments were not surfaced in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedInformation Commissioner's OfficeThe Children's code requires that nudge techniques not be used to encourage children to provide unnecessary personal data or weaken/turn off their privacy settings.
  2. ProbableOffice of the Australian Information CommissionerThe ICO reviewed justifications for using legitimate interests as the lawful basis for real-time bidding (RTB) in adtech and found the justifications offered by organisations insufficient.
  3. ConfirmedInformation Commissioner's OfficeThe DUAA clarifies that direct marketing can be conducted on the basis of legitimate interests as a lawful basis under UK GDPR.
  4. ConfirmedInformation Commissioner's OfficeSince 5 February 2026, charities may send electronic mail marketing (including texts and social media direct messages) furthering their charitable purposes to individuals who have expressed interest or offered support, without prior consent, under a new 'soft opt-in', subject to safeguards.

#

Substantial regulatory activity and guidance exist, but the AI/ADM statutory code of practice is still being developed and national-security exemption scope remains a monitored risk per EDPB.

Primary frameworkUK GDPR Articles 22A-22D (as inserted by DUAA 2025); UK GDPR Article 9 (biometric special category data)
Traffic-light rationale — AmberSubstantial regulatory activity and guidance exist, but the AI/ADM statutory code of practice is still being developed and national-security exemption scope remains a monitored risk per EDPB.

Sub-modules (6)

Profiling RestrictionsAmber

UK GDPR Article 22A (inserted by DUAA) defines ADM as a solely-automated decision with no meaningful human involvement having a legal or similarly significant effect, replacing the prior more restrictive Article 22 default-prohibition model.

Claims: CLM-UK-h8207394

Automated Decision Making TransparencyAmber

The ICO expects organisations using ADM to be transparent with affected individuals, explain how ADM works, and provide a route to request human review, as set out in March 2026 hiring-sector guidance and an ongoing ADM/profiling guidance consultation.

Claims: CLM-UK-h8207395, CLM-UK-h8207396

Ai Risk AssessmentsAmber

The ICO's AI and Biometrics Strategy commits to developing an AI/ADM code of practice (mandated by secondary legislation under the DUAA) and continues to audit police use of facial recognition technology.

Claims: CLM-UK-h8207397, CLM-UK-h8207398

Biometric RegimeGreen

Biometric recognition processing (e.g., facial recognition, fingerprint) constitutes special category biometric data under UK GDPR Article 9, generally requiring explicit consent absent another applicable condition.

Claims: CLM-UK-h8207399

Genetic DataRed

No genetic-data-specific UK regulatory instrument beyond the general Article 9 special category framework was identified in this research pass.

State Surveillance CarveoutsAmber

The EDPB has raised concerns that UK national security exemptions may waive most data protection principles and limit the ICO's enforcement and inspection powers, urging the European Commission to closely monitor their application in practice.

Claims: CLM-UK-h8207400

Category narrative78 words

The DUAA introduces new UK GDPR Articles 22A-22D governing solely-automated significant decisions, relaxing some prior restrictions while retaining a right to human intervention for significant decisions using sensitive or non-sensitive data. Biometric data is treated as special category data requiring an Article 9 condition (typically explicit consent), and the ICO is actively auditing police facial recognition technology (FRT) deployments and developing an AI/ADM code of practice. EDPB has flagged UK national-security exemptions as an area requiring ongoing monitoring.

No periodic updates recorded against this sub-brief.

Sources and claims (7)
  1. ConfirmedInformation Commissioner's OfficeUK GDPR Article 22A, inserted by the DUAA, defines automated decision-making (ADM) as a decision based solely on automated processing (no meaningful human involvement) that has a legal or similarly significant effect on a person.
  2. ConfirmedInformation Commissioner's OfficeOrganisations using ADM must explain to affected candidates/individuals how it works and how to exercise their right to challenge a decision and request human review.
  3. ProbableInformation Commissioner's OfficeThe ICO is developing draft ADM and profiling guidance for public consultation, which will inform a forthcoming statutory AI and ADM code of practice.
  4. ProbableInformation Commissioner's OfficeThe UK government is developing secondary legislation, committed to during passage of the DUAA 2025, requiring the ICO to produce an AI and ADM statutory code of practice.
  5. ConfirmedInformation Commissioner's OfficeThe ICO has conducted or is conducting facial recognition technology (FRT) audits of multiple UK police forces including South Wales, Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester Police.
  6. ConfirmedInformation Commissioner's OfficeProcessing biometric data through a biometric recognition system meets all three elements of the UK GDPR biometric data definition, constituting special category biometric data requiring explicit consent or another valid Article 9 condition.
  7. ProbableEuropean Data Protection BoardThe EDPB has flagged that UK national security exemptions may waive most data protection principles and some international transfer rules for law enforcement authorities and can limit the ICO's enforcement and inspection powers, calling for ongoing Commission monitoring.

#

Children's protections are mature, statutory and actively enforced (amber reflects ongoing enforcement gaps industry-wide); dependent-adults sub-module is an evidenced gap.

Primary frameworkAge Appropriate Design Code (Children's code), DPA 2018 s.125; UK GDPR
Traffic-light rationale — AmberChildren's protections are mature, statutory and actively enforced (amber reflects ongoing enforcement gaps industry-wide); dependent-adults sub-module is an evidenced gap.

Sub-modules (5)

Age VerificationAmber

Children's code Standard 3 requires establishing user age with a level of certainty appropriate to processing risk, or applying the code to all users; 2026 enforcement (Reddit, MediaLab) centred on failures to implement robust age assurance.

Claims: CLM-UK-i9318405, CLM-UK-i9318406, CLM-UK-i9318407

Minor Profiling BansGreen

Children's code Standard 10 requires profiling options to be switched off by default for children unless a compelling, best-interests-justified reason exists, with protective measures against harmful content.

Claims: CLM-UK-i9318409

Education SettingsAmber

The ICO provides FAQs applying the Children's code to schools and education technology, but no separate education-specific statutory instrument was identified.

Claims: CLM-UK-f6085176

Dependent AdultsRed

No dependent-adults-specific (elderly/mentally incapacitated) UK data protection instrument was identified in this research pass; flagged as a research gap.

Category narrative72 words

The Children's code (Age Appropriate Design Code), a statutory code under DPA 2018 s.125 in force since 2 September 2020, sets 15 standards for online services likely accessed by children, including high-privacy defaults, age-appropriate age assurance, and profiling/geolocation off by default. Enforcement has intensified in 2026 with major fines against Reddit and MediaLab for inadequate age assurance and unlawful processing of under-13s' data. Dependent-adults protections were not separately evidenced in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedInformation Commissioner's OfficeThe Children's code applies to information society services likely to be accessed by children under 18, including UK-based and non-UK companies processing UK children's personal data, even if children are not the target audience.
  2. ConfirmedInformation Commissioner's OfficeThe ICO fined Reddit £14.47m for failing to apply any robust age assurance mechanism, resulting in no lawful basis for processing personal information of children under 13.
  3. ConfirmedInformation Commissioner's OfficeThe ICO fined MediaLab (Imgur) £247,590 for failing to implement any age assurance measures to determine the age of users between September 2021 and September 2025, exposing children to harmful content.
  4. ConfirmedInformation Commissioner's OfficeUK law requires that online services using personal information of children under 13 rely on consent given by the child's parent or carer where consent is the chosen lawful basis; MediaLab was found to lack such parental consent measures for Imgur.
  5. ConfirmedInformation Commissioner's OfficeChildren's code Standard 10 requires profiling to be switched off by default unless the organisation can demonstrate a compelling reason accounting for the best interests of the child, with protections against harmful content effects.

#

Enforcement powers and recent activity are robust and well evidenced across multiple 2026 cases; collective redress remains constrained by case law, which is a known and stable limitation rather than a gap.

Primary frameworkUK GDPR Articles 83-84 (as implemented via DPA 2018); PECR 2003
Traffic-light rationale — GreenEnforcement powers and recent activity are robust and well evidenced across multiple 2026 cases; collective redress remains constrained by case law, which is a known and stable limitation rather than a gap.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The ICO can issue fines of up to £17.5 million or 4% of an organisation's annual worldwide turnover, whichever is higher, for UK GDPR/DPA 2018 breaches, and the DUAA raised PECR's maximum fine to the same ceiling while granting the ICO new powers to compel witness interviews and technical reports.

Claims: CLM-UK-j0429516, CLM-UK-j0429517

Enforcement Activity IndexGreen

2026 enforcement actions include Reddit (£14.47m, Feb 2026), MediaLab/Imgur (£247,590, Feb 2026), South Staffordshire Water (£963,900, May 2026) and KRA Consultancy (£300,000, May 2026), reflecting a heavy focus on children's data and security/PECR marketing breaches.

Claims: CLM-UK-j0429518, CLM-UK-j0429519, CLM-UK-j0429520, CLM-UK-j0429521

Regulator Funding And CapacityAmber

The ICO is transitioning from a corporation-sole structure to a chair/CEO/board governance model as part of DUAA reforms intended to provide greater institutional continuity and resilience, though the final transition timeline remained unconfirmed as of mid-2026.

Claims: CLM-UK-j0429522, CLM-UK-a1f30b23

Collective Redress And Class ActionsAmber

The UK lacks a general opt-out class action mechanism for data protection claims; the Supreme Court's Lloyd v Google ruling held that a representative action under the (then) Data Protection Act failed because damages require individualised proof of material damage or distress, not mere loss of control of data.

Claims: CLM-UK-j0429523, CLM-UK-j0429524

Private Right Of ActionGreen

Individuals have a direct right to claim compensation from a controller in court for material or non-material damage suffered from a UK GDPR/DPA 2018 breach, though the ICO itself cannot award compensation.

Claims: CLM-UK-j0429525

Recent Developments 180DAmber

Within the last 180 days, the DUAA reached full commencement (19 June 2026) requiring all organisations to have a complaints-handling process; the ICO fined South Staffordshire Water (May 2026) and KRA Consultancy (May 2026); and the ICO published its AI and Biometrics strategy update (March 2026) alongside ADM hiring guidance.

Claims: CLM-UK-j0429526, CLM-UK-j0429520, CLM-UK-j0429521

Category narrative87 words

The ICO can issue fines of up to £17.5m or 4% of global annual turnover for UK GDPR/DPA 2018 breaches, with the DUAA also raising PECR fines to the same ceiling. 2026 enforcement activity has been intense, including Reddit (£14.47m), South Staffordshire Water (£963,900), MediaLab (£247,590) and KRA Consultancy (£300,000). Private compensation claims exist under UK GDPR/DPA 2018, but the Supreme Court's Lloyd v Google ruling constrains representative 'class action' style claims absent individualised proof of damage. The ICO itself is mid-transition to a board-governed Information Commission.

No periodic updates recorded against this sub-brief.

Sources and claims (11)
  1. ConfirmedInformation Commissioner's OfficeUnder UK GDPR and the DPA 2018, the ICO can issue fines of up to £17.5 million or 4% of an organisation's annual worldwide turnover, whichever is higher.
  2. ConfirmedInformation Commissioner's OfficeThe DUAA gives the ICO new powers, including the ability to compel witnesses to attend interviews and request technical reports, and raises the PECR maximum fine to £17.5 million or 4% of global turnover.
  3. ConfirmedInformation Commissioner's OfficeOn 23 February 2026, the ICO imposed a £14,472,500 penalty on Reddit, Inc. for infringing UK GDPR Articles 5(1)(a), 6, 8 and 35.
  4. ConfirmedInformation Commissioner's OfficeOn 26 February 2026, the ICO published a £247,590 monetary penalty notice against MediaLab for unlawful processing of children's data on the Imgur platform.
  5. ConfirmedInformation Commissioner's OfficeOn 7 May 2026, the ICO fined South Staffordshire Plc and South Staffordshire Water Plc £963,900 for infringing UK GDPR Articles 5(1)(f) and 32(1) following a cyber incident.
  6. ConfirmedInformation Commissioner's OfficeOn 20 May 2026, the ICO fined KRA Consultancy Ltd £300,000 for breaching PECR regulations 22 and 23 through mass unsolicited marketing texts.
  7. ConfirmedIAPPThe DUAA-driven governance reform moves the ICO from a corporation-sole structure to a traditional chair, CEO and board model intended to provide institutional continuity and resilience.
  8. ConfirmedDataGuidanceIn Lloyd v Google LLC [2021] UKSC 50, the UK Supreme Court held that damages under the (then) Data Protection Act require proof of material damage or distress caused by unlawful processing, not merely the unlawful processing (loss of control) itself, precluding the proposed representative 'class action' claim.
  9. ProbableIAPPFollowing Lloyd v Google, claimant law firms pursuing UK data-breach mass actions face the requirement that individual class members evidence the damage or distress they personally suffered, constraining opt-out-style collective redress.
  10. ConfirmedInformation Commissioner's OfficeUK GDPR gives individuals a right to claim compensation from an organisation in court for both material damage (e.g., financial loss) and non-material damage (e.g., distress) suffered from a breach of data protection law, though the ICO cannot itself award compensation.
  11. ConfirmedInformation Commissioner's OfficeAs of 19 June 2026, all data protection provisions of the DUAA 2025 are in force, including a new mandatory requirement for all organisations to have a data protection complaints-handling process in place.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United Kingdom
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 65 claim(s), 52 source(s) in the cumulative register.