Where the budget actually differs in 2026.
UK GDPR and EU GDPR remain 90-95% identical on the substantive regulation. The Data (Use and Access) Act 2025 (Royal Assent 19 June 2025; the main data protection changes commenced 5 February 2026) introduced targeted UK divergences that move the budget on cookie consent, data subject access, and international transfers. It carried through reforms first proposed in the Data Protection and Digital Information Bill, which fell before the July 2024 general election. Operators in both regimes face a 20-30% uplift over single-regime cost.
The 90-95% identical baseline
UK GDPR is, in substance, EU GDPR retained in domestic law via the Data Protection Act 2018 and amendments. The lawful bases, the rights of data subjects, the controller and processor obligations, the breach notification mechanism, and the Article 83 penalty structure are aligned. The 5-10% divergence is concentrated in three areas: cookie consent and PECR / soft opt-in, recognised legitimate interests, and international data transfers.
What the Data (Use and Access) Act 2025 changed
- Recognised legitimate interests (RLI): a defined list of processing purposes (national security, public security, emergencies, safeguarding) where the legitimate interests balancing test does not need to be conducted afresh. Reduces the documentation burden for in-scope processing.
- Cookie consent softening for analytics: certain low-risk analytics and service-improvement cookies move into a soft opt-out / opt-in regime, away from strict prior consent for all non-essential cookies. The CMP configuration implications are real but modest.
- “Stop the clock” for DSARs: the controller can pause the one-month response clock to seek clarification from the data subject in defined circumstances. The economic effect is to reduce DSAR fully-loaded cost in organisations handling complex requests.
- Data protection test for transfers: the test for adequacy and Article 46 transfer mechanisms moves from “essentially equivalent” (the Schrems II test) to a UK-defined “data protection test”. Same compliance stack (IDTA / UK Addendum, transfer impact assessment), reformed test.
- Senior responsible individual: the DPO concept remains for mandatory cases, with the option of naming a senior responsible individual for accountability where the mandatory triggers do not apply.
Where the budget actually differs
Translating the regulatory divergence into a budget delta:
- CMP configuration: UK-only operators can lighten cookie banners for low-risk analytics. The cost impact is modest (CMP itself remains; the configuration scope shrinks).
- DSAR handling: the “stop the clock” provision reduces DSAR fully loaded cost for complex requests by 10-25%. For high-volume B2C, this is meaningful.
- Transfer mechanism upkeep: UK uses IDTA / UK Addendum; EU uses 2021 SCCs. Operating in both requires both, plus parallel TIAs. The duplication cost is real.
- Supervisory authority engagement: UK = ICO. EU = lead DPA plus concerned authorities under one-stop-shop. Multi-jurisdiction breach engagement is materially more expensive.
Adequacy decision status
The European Commission renewed its two UK adequacy decisions on 19 December 2025, confirming that personal data may continue to flow freely from the EEA to the UK following the Data (Use and Access) Act 2025. The renewed decisions run for six years, to 27 December 2031, with a mid-point review after four years. If adequacy were to lapse at a future review, UK organisations receiving personal data from EU controllers would need to fall back on Article 46 mechanisms (SCCs, BCRs) and TIAs, materially increasing transfer mechanism upkeep cost.
ICO fee schedule
| Tier | Description | Standard | Direct debit |
|---|---|---|---|
| Tier 1 | Micro: turnover ≤ £632k or ≤ 10 staff | £52 | £47 |
| Tier 2 | SME: turnover ≤ £36m or ≤ 250 staff | £78 | £73 |
| Tier 3 | Large: above tier 2 thresholds | £3,763 | £3,758 |
Source: Data Protection (Charges and Information) Regulations 2018, as amended by SI 2025/63 (in force 17 February 2025). The ICO fee is a statutory charge, not a fine. Civil monetary penalties apply for non-payment by organisations subject to the duty.
Dual-regime operator uplift
A UK organisation subject to both UK GDPR and EU GDPR (e.g. UK headquartered, EU customers and EU establishment) faces a 20-30% uplift on year 1 implementation and ongoing budget over a single-regime peer. The uplift breaks into:
- Twin transfer-mechanism upkeep (IDTA + SCCs).
- Twin lead supervisory engagement (ICO + EU lead DPA, plus concerned authorities).
- CMP configuration parity for the stricter regime (typically EU, given the UK’s DUAA analytics-cookie softening).
- Documentation duplication where UK and EU diverge on RLI, consent, or rights-handling timeframes.