Skip to main content
—
Framework library
Framework module · uk-gdpr

UK GDPR

The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.

UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82) · UK Information Commissioner's Office · published 2025-06-19

Standing today
Directory entry

00Answer

from the registry record
What is UK GDPR?
The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.
Who does UK GDPR apply to?
UK GDPR applies to all sectors, UK, per UK Information Commissioner's Office.
What is the current version of UK GDPR?
The current edition is UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82), issued by UK Information Commissioner's Office and published 2025-06-19. Source: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/.
What does an assessment under UK GDPR require?
No control catalog has been ingested for UK GDPR yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

UK GDPR is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Lawfulness · Data subject rights · Controller obligations · Security of processing · International transfers
Applies to
all sectors · UK
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06

03Version ledger

2 editions
UK GDPR + DPA 2018Supersededdate not published
UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82)Current edition · supersedes UK GDPR + DPA 20182026-02-05

05Change history

06Related frameworks

scored from registry facts
  1. GDPRRegulation (EU) 2016/679

    Also applies to all sectors · The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.

  2. Also applies to all sectors · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

  3. Texas Data Privacy and Security ActHB 4 (Texas Business and Commerce Code Chapter 541)

    Also applies to all sectors · Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.

  4. CCPA/CPRA + US state privacyCCPA/CPRA with 2026 CPPA regulations

    Also applies to all sectors · California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.

UK GDPR | ControlFrame