UK GDPR
The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.
UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82) · UK Information Commissioner's Office · published 2025-06-19
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
UK GDPR is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely published; obligations not modelled as a control catalog.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Lawfulness · Data subject rights · Controller obligations · Security of processing · International transfers
- Applies to
- all sectors · UK
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
03Version ledger
| UK GDPR + DPA 2018 | Superseded | date not published |
| UK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82) | Current edition · supersedes UK GDPR + DPA 2018 | 2026-02-05 |
05Change history
06Related frameworks
- GDPRRegulation (EU) 2016/679
Also applies to all sectors · The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.
- ISO/IEC 270182025
Also applies to all sectors · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.
- Texas Data Privacy and Security ActHB 4 (Texas Business and Commerce Code Chapter 541)
Also applies to all sectors · Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.
- CCPA/CPRA + US state privacyCCPA/CPRA with 2026 CPPA regulations
Also applies to all sectors · California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.