#
Framework is comprehensive and stable, but amber reflects the live institutional transition (ICO to Information Commission) with an unconfirmed final transition date, plus DUAA phased commencement concluding only in June 2026.
Sub-modules (5)
Regulator And AuthorityAmber
The ICO is the UK's independent regulator for data protection and information rights, with responsibilities under DPA 2018, UK GDPR, FOIA, EIR and PECR, among other statutes. The DUAA abolishes the office of Information Commissioner and transfers its functions to a new corporate body, the Information Commission, moving from a corporation-sole model to a chair/CEO/board structure.
Claims: CLM-UK-a1f30b21, CLM-UK-a1f30b22, CLM-UK-a1f30b23
Act And InstrumentsGreen
The operative instruments are UK GDPR, DPA 2018 and PECR 2003, amended but not replaced by the DUAA 2025.
Claims: CLM-UK-a1f30b24
Material ScopeGreen
UK GDPR/DPA 2018 apply to processing of personal data by controllers and processors; the DUAA makes targeted amendments to purpose limitation, research processing and lawful bases without expanding core material scope.
Claims: CLM-UK-a1f30b25
Territorial ScopeGreen
UK GDPR has extraterritorial reach equivalent to EU GDPR Article 3(2): non-UK controllers/processors offering goods/services to, or monitoring the behaviour of, UK data subjects fall within scope and generally must appoint a UK representative.
Claims: CLM-UK-a1f30b26
Regulator Registration And FilingGreen
Controllers processing personal data must generally pay an annual data protection fee to the ICO under the Data Protection (Charges and Information) Regulations 2018, across three tiers (£52/£78/£3,763), with over one million controllers on the public register.
Claims: CLM-UK-a1f30b27, CLM-UK-a1f30b28
No periodic updates recorded against this sub-brief.
Sources and claims (8)
- ConfirmedInformation Commissioner's Office — The Information Commissioner's Office (ICO) is the UK's independent regulator for data protection and information rights law, with statutory responsibilities under the DPA 2018, UK GDPR, FOIA, EIR and PECR, among other acts.
- ConfirmedInformation Commissioner's Office — The DUAA 2025 abolishes the office of Information Commissioner and transfers its functions to a new body, the Information Commission, replacing the corporation-sole structure with a board-governed model.
- ProbableIAPP — As of mid-2026, the ICO's transition to the board-governed Information Commission structure has not been assigned a confirmed final transition date; the current Commissioner is expected to become Chair, with a CEO and non-executive board being appointed.
- ConfirmedInformation Commissioner's Office — The DUAA 2025 amends, but does not replace, UK GDPR, the DPA 2018 and PECR 2003.
- ConfirmedInformation Commissioner's Office — The DUAA restructures rather than materially changes the scope of what personal information organisations may use, clarifying legitimate interests, research processing and purpose limitation while preserving core UK GDPR/DPA 2018 material scope.
- ConfirmedIAPP — A UK company with active business ties to EU member states (and no EU establishment) may need to appoint an EU GDPR representative where its processing meets the Article 3(2)-equivalent destination-principle criteria, and the same logic applies to non-UK controllers targeting or monitoring UK data subjects under UK GDPR.
- ConfirmedInformation Commissioner's Office — Under the Data Protection (Charges and Information) Regulations 2018, organisations processing personal information must pay an annual data protection fee to the ICO across three tiers ranging from £52 to £3,763, unless exempt.
- ConfirmedInformation Commissioner's Office — The ICO maintains a public register of more than one million fee-paying data controllers, and failure to pay the required fee can result in a fixed penalty of up to £4,000.