Framework module · uk-gdpr
UK GDPR
The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock.
UK GDPR + DPA 2018 (as amended by DUAA 2025) · UK Information Commissioner's Office · published 2025-06-19
Standing today
Catalog only
01Standing
Catalog only
A directory entry — authority, version ledger, verification — not a workspace you can open.
UK GDPR is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.
Freely published; obligations not modelled as a control catalog.
02Registry record
checked 2026-08-06
- Registry status
- Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Lawfulness · Data subject rights · Controller obligations · Security of processing · International transfers
- Applies to
- all sectors · UK
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- DUAA data protection provisions commence in stages. The regulations published 2026-01-29 brought further changes into force from 2026-02-05; later tranches remain outstanding.Expected: Staged commencement through 2026
03Version ledger
2 editions
| UK GDPR + DPA 2018 | Superseded | date not published |
| UK GDPR + DPA 2018 (as amended by DUAA 2025) | Current edition · supersedes UK GDPR + DPA 2018 | 2025-06-19 |