Regulation & Policy
UK GDPR
Also known as: UK General Data Protection Regulation, Data Protection Act 2018
UK GDPR is the United Kingdom's data protection regime, based on the EU General Data Protection Regulation and retained in domestic law after the UK left the EU. It operates alongside the Data Protection Act 2018 and is enforced by the Information Commissioner's Office. It sets the rules for how organisations collect, use and store personal data about people in the UK.
What it is
UK GDPR keeps the core structure of the EU regulation, including lawful bases for processing, data subject rights, accountability duties and requirements around international transfers. The Data Protection Act 2018 supplements it with UK specific detail and exemptions. Rules on cookies and similar technologies sit in separate privacy and electronic communications regulations, which work alongside it.
Why it matters
Almost every marketing activity involving identifiable people falls under it, from email lists and CRM records to analytics identifiers and advertising audiences. Non-compliance carries enforcement action and fines, and poor handling of consent or transparency damages trust. It also shapes what data you can legitimately use to personalise content and measure performance.
How it works
Practitioners identify a lawful basis for each processing activity, publish clear privacy information, honour rights requests such as access and erasure, and maintain records of processing. Consent for marketing messages and non-essential cookies must be freely given, specific, informed and as easy to withdraw as to give. Vendor contracts, retention schedules and transfer safeguards are reviewed as part of routine governance.
When it applies
It applies to organisations established in the UK and to those outside the UK that offer goods or services to, or monitor the behaviour of, people in the UK.
Examples
- A B2B marketing team documents legitimate interests as the basis for prospect outreach and records a balancing assessment.
- An ecommerce brand sets a retention period for abandoned basket data rather than keeping records indefinitely.
- A publisher builds a workflow so subject access and erasure requests reach the data team within the statutory deadline.
How it is measured
- Number of data subject requests received and share resolved within the statutory time limit
- Proportion of processing activities with a documented lawful basis in the record of processing
- Marketing consent rate and unsubscribe rate for UK contacts
- Number of processors under signed data processing terms with transfer safeguards in place
Related terms in Regulation & Policy
- AI complianceAI compliance is the work of making sure AI systems meet the laws, regulations, standards and internal policies that apply to them. It spans data protection, transparency, risk classification, documentation, human oversight and record keeping across the life of a system. In practice it combines legal interpretation, engineering controls and ongoing evidence gathering.
- AI governanceAI governance is the set of policies, roles, controls and review processes an organisation uses to manage how AI systems are built, bought and used. It covers risk assessment, documentation, human oversight, data handling and accountability. It applies both to AI a company develops and to third-party AI tools used by staff.
- AI privacyAI privacy is the set of practices, rights and obligations that govern how personal data is collected, used, stored and exposed when building or using AI systems. It covers training data, prompts and outputs, retention by AI vendors, and the transparency and control offered to the people whose data is involved. For marketing teams it shapes what customer data can safely be put into AI tools and what must be disclosed.
- AI safetyAI safety is the practice of designing, testing and operating AI systems so they cause less harm, behave predictably and resist misuse. It covers alignment with intended behaviour, evaluation and red teaming, content guardrails, and monitoring once a system is live. For marketers it shapes what models will say, how assistants handle brands, and what compliance teams expect before AI tools go into production.
- AI transparencyAI transparency is the practice of making clear how an AI system works, what sits behind it, and when content or an interaction involves AI. It covers regulatory disclosure duties as well as voluntary explanations such as model cards, labels on synthetic media and citations in AI generated answers. For publishers and marketers it sets expectations about when AI involvement should be declared and how clearly.
- Competition and Markets AuthorityThe Competition and Markets Authority (CMA) is the United Kingdom's competition and consumer protection regulator. It investigates mergers, anti-competitive conduct and market practices, and it holds specific powers over large digital firms under the Digital Markets, Competition and Consumers Act 2024. Its decisions shape how search engines, app stores and AI assistants operate in the UK market.