All terms

Regulation & Policy

UK GDPR

Also known as: UK General Data Protection Regulation, Data Protection Act 2018

UK GDPR is the United Kingdom's data protection regime, based on the EU General Data Protection Regulation and retained in domestic law after the UK left the EU. It operates alongside the Data Protection Act 2018 and is enforced by the Information Commissioner's Office. It sets the rules for how organisations collect, use and store personal data about people in the UK.

What it is

UK GDPR keeps the core structure of the EU regulation, including lawful bases for processing, data subject rights, accountability duties and requirements around international transfers. The Data Protection Act 2018 supplements it with UK specific detail and exemptions. Rules on cookies and similar technologies sit in separate privacy and electronic communications regulations, which work alongside it.

Why it matters

Almost every marketing activity involving identifiable people falls under it, from email lists and CRM records to analytics identifiers and advertising audiences. Non-compliance carries enforcement action and fines, and poor handling of consent or transparency damages trust. It also shapes what data you can legitimately use to personalise content and measure performance.

How it works

Practitioners identify a lawful basis for each processing activity, publish clear privacy information, honour rights requests such as access and erasure, and maintain records of processing. Consent for marketing messages and non-essential cookies must be freely given, specific, informed and as easy to withdraw as to give. Vendor contracts, retention schedules and transfer safeguards are reviewed as part of routine governance.

When it applies

It applies to organisations established in the UK and to those outside the UK that offer goods or services to, or monitor the behaviour of, people in the UK.

Examples

  • A B2B marketing team documents legitimate interests as the basis for prospect outreach and records a balancing assessment.
  • An ecommerce brand sets a retention period for abandoned basket data rather than keeping records indefinitely.
  • A publisher builds a workflow so subject access and erasure requests reach the data team within the statutory deadline.

How it is measured

  • Number of data subject requests received and share resolved within the statutory time limit
  • Proportion of processing activities with a documented lawful basis in the record of processing
  • Marketing consent rate and unsubscribe rate for UK contacts
  • Number of processors under signed data processing terms with transfer safeguards in place

Related terms in Regulation & Policy

Primary research · August 2026

How ChatGPT Shortlists Software Brands

An audit across 10 categories and 60 buying questions. I recorded what ChatGPT reads, throws away and links to when a buyer asks it which software to buy, and what that decides.

60
Questions asked
10
Software markets
2,680
Results read
367
Links shown
Free35 pages · PDF · 536 KBDiscovery Digest every Friday

Free download

Get the full report

35 pages · PDF · 536 KB. Enter your details and it downloads straight away.

How ChatGPT Shortlists Software Brands downloads straight away. No spam, unsubscribe anytime.