Compliance
UK GDPR
UK General Data Protection Regulation
UK GDPR is the United Kingdom's own data protection law, sitting alongside the amended Data Protection Act 2018, that governs personal data processing, individual rights, lawful bases for processing, the respective duties of data controllers and processors, and organisational accountability for data protection within the UK specifically, following the UK's departure from the European Union.
Why UK GDPR matters in a Microsoft estate
UK GDPR matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.
How UK GDPR shows up in practice
UK GDPR was created by incorporating the EU GDPR directly into UK domestic law at the point of departure, so its core principles, individual rights, and structure remain closely aligned with the EU version data protection professionals are already familiar with: the same lawfulness, fairness, transparency, purpose limitation, data minimisation, and storage limitation principles apply, and individuals retain broadly the same rights of access, rectification, erasure, and data portability. The practical consequence organisations most need to understand is that UK GDPR and EU GDPR are now legally separate, independently enforced instruments rather than one single law applied in two places.
That matters directly for any organisation, such as a UK business serving EU customers, or an EU business handling UK residents' personal data, operating across both jurisdictions simultaneously, since compliance with one does not automatically guarantee compliance with the other if the two frameworks diverge through separate future amendment, which remains a genuine possibility now that they are governed independently. International transfers of personal data out of the UK are a specific area requiring active attention: transferring personal data to a country outside the UK generally requires an adequacy decision recognising that country's data protection standards as sufficient, or another approved transfer mechanism such as UK-specific standard contractual clauses.
These UK transfer mechanisms are not automatically identical to the equivalent EU mechanisms, so they need checking independently for UK-outbound transfers specifically rather than assumed to mirror EU practice. The UK's Information Commissioner's Office, the ICO, is the supervisory authority responsible for UK GDPR enforcement, separate from EU data protection authorities. Organisations processing personal data in a UK context should look to ICO guidance specifically as the primary and most current authoritative reference for UK compliance obligations, rather than relying solely on EU-focused GDPR guidance that may not reflect current UK-specific requirements or ICO regulatory positions.