Reform UK has proposed replacing the United Kingdom’s existing data protection regime with a “light-touch” privacy law modeled on New Zealand’s Privacy Act, arguing that the UK GDPR imposes unnecessary costs on small businesses and technology companies.
The proposal forms part of Reform UK’s broader plan for small businesses and represents one of the clearest calls by a major British political party to dismantle the post-Brexit privacy framework inherited from the European Union.
Reform UK leader Nigel Farage has characterized the current rules as a continuation of burdensome European regulation that the United Kingdom should have left behind after Brexit. The party maintains that a New Zealand-inspired system could preserve essential privacy protections while reducing documentation, legal expenses and compliance obligations for ordinary businesses.
The political appeal is straightforward: replace a detailed, prescriptive and heavily enforceable regime with a shorter, principles-based law.
The legal and commercial consequences would be considerably more complicated.
Abolishing the UK GDPR would affect individual rights, online advertising, artificial intelligence, international data transfers, breach response, regulatory enforcement and the ability of British companies to exchange personal information with European customers and business partners.
Reform UK Says GDPR Has Become a Burden on Small Businesses
Reform UK argues that privacy compliance has become disproportionately difficult for companies without dedicated legal, cybersecurity or data-protection teams.
A small business operating exclusively within the United Kingdom may still be expected to identify a lawful basis for processing personal information, publish an appropriate privacy notice, respond to individual rights requests, maintain security protections, manage vendors and assess whether a breach must be reported.
Depending on its activities, an organization may also need to maintain records of processing, conduct data protection impact assessments, appoint a data protection officer, complete international transfer assessments and document its legitimate-interest decisions.
Supporters of the existing system argue that many of these obligations are risk-based and do not apply equally to every organization. Critics respond that determining which requirements apply often requires the same legal or professional assistance that small businesses cannot afford.
Reform UK believes a New Zealand-style model would preserve basic privacy expectations while giving organizations more flexibility in how they satisfy them.
The UK Has Already Relaxed Parts of Its Privacy Framework
The proposal arrives after the United Kingdom enacted the Data (Use and Access) Act 2025, which amended—but did not replace—the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations.
The reforms were intended to make portions of British data law easier to apply while preserving a level of protection sufficient to maintain public trust and international data flows.
Among other changes, the legislation:
- Clarified that organizations need only conduct reasonable and proportionate searches when responding to subject access requests.
- Created recognized legitimate interests for certain processing activities.
- Expanded circumstances in which some further uses of personal information may be treated as compatible with the original purpose.
- Introduced additional flexibility for certain automated decisions.
- Extended the electronic marketing soft opt-in to qualifying charities.
- Required organizations to establish procedures for handling data-protection complaints.
- Strengthened regulatory powers and modernized the structure of the UK’s privacy regulator.
Reform UK’s plan would go considerably further. Rather than continuing to amend the UK GDPR, the party proposes replacing it with a different legislative model.
At this stage, however, “New Zealand-style” describes a political direction rather than a complete statutory proposal. The eventual effect would depend on which elements of New Zealand’s law were adopted, which existing British protections were retained and how the new system interacted with electronic marketing, online tracking, surveillance and sector-specific rules.
How New Zealand’s Privacy Act Works
New Zealand’s Privacy Act 2020 is built around 13 information privacy principles governing the lifecycle of personal information.
Those principles address:
- Why personal information may be collected.
- Where information should be collected from.
- What people should be told when information is collected.
- How information must be collected.
- Storage and security protections.
- Access to personal information.
- Correction of inaccurate information.
- Accuracy before information is used or disclosed.
- Retention of personal information.
- Limits on using information for new purposes.
- Limits on disclosure.
- Disclosure outside New Zealand.
- Use of unique identifiers.
The New Zealand framework is not a privacy-free alternative to the GDPR. Organizations must still collect information for lawful purposes connected with their functions, limit collection to what is necessary, provide appropriate notice, maintain reasonable security and restrict incompatible uses and disclosures.
New Zealand organizations must also appoint at least one privacy officer. That obligation applies more broadly than the UK GDPR’s requirement to appoint a formal data protection officer, which is triggered only in specified circumstances.
The principal difference is in legislative architecture and enforcement. New Zealand relies more heavily on broad principles, regulator engagement, dispute resolution, compliance notices and tribunal proceedings. The UK GDPR establishes more detailed duties, a broader catalogue of individual rights and substantially greater administrative penalties.
UK GDPR and New Zealand Privacy Law Compared
| Issue | UK GDPR | New Zealand Privacy Act 2020 |
|---|---|---|
| Regulatory structure | A detailed accountability framework organized around data-protection principles, lawful bases, individual rights and specific controller and processor duties. | A principles-based framework centered on 13 information privacy principles governing collection, use, storage, access, disclosure and retention. |
| Legal justification for collection and use | Organizations generally must identify a lawful basis, such as consent, contract, legal obligation, vital interests, public task or legitimate interests. | Collection must serve a lawful purpose connected with the organization’s functions or activities and must be necessary for that purpose. It does not use the GDPR’s six-lawful-bases structure. |
| Individual rights | Provides rights involving notice, access, correction, erasure, restriction, portability, objection and certain automated decisions. | Provides important access and correction rights but does not reproduce the full collection of standalone GDPR rights. |
| Right to deletion | Recognizes a right to erasure in specified circumstances, subject to exemptions. | Does not provide a general GDPR-equivalent right to erasure, although retention and correction principles may require action in particular circumstances. |
| Data portability | Provides a right to receive qualifying personal data in a structured, commonly used and machine-readable format. | Does not contain a directly equivalent general portability right. |
| Automated decision-making | Includes specific protections and safeguards for certain significant decisions involving solely automated processing, as amended by the Data (Use and Access) Act. | Does not establish the same standalone automated-decision framework, although the privacy principles continue to apply to information used by automated systems. |
| Sensitive information | Applies additional restrictions to special-category data, including health, biometric, genetic, religious and political information. | Does not use the same general special-category structure, although sensitivity affects how the principles apply and sector-specific privacy codes impose additional rules. |
| Privacy leadership | A formal data protection officer is mandatory only for certain public bodies and specified high-risk processing activities. | Every covered organization must have at least one privacy officer, although the role can be assigned internally or externally. |
| Impact assessments | A data protection impact assessment is required when processing is likely to create a high risk to individuals. | Privacy impact assessments are encouraged as good practice but are not imposed through an equivalent general statutory requirement. |
| Breach notification | Organizations generally must notify the regulator within 72 hours when a breach is likely to create a risk to people’s rights and freedoms. Individuals must be notified when the risk is high. | Notification is required as soon as practicable when a breach has caused or is likely to cause serious harm. The regulator generally expects notification within approximately 72 hours. |
| Maximum regulatory exposure | Serious violations can produce fines of up to £17.5 million or 4% of worldwide annual turnover, whichever is higher. | Does not currently contain an equivalent turnover-based administrative fine regime. Enforcement relies more heavily on regulatory directions, compliance notices, tribunal remedies and more limited statutory offences. |
| International transfers | Requires an adequacy mechanism, appropriate safeguards or an applicable exception for restricted transfers. | Principle 12 restricts offshore disclosures but provides a more flexible framework based on authorization, comparable safeguards and other permitted circumstances. |
| Online tracking | Works alongside the UK’s electronic communications rules, which impose additional requirements on cookies and similar technologies. | The Privacy Act regulates the collection and use of information but does not create a directly equivalent comprehensive cookie-consent regime. |
The UK GDPR Provides a Broader Set of Individual Rights
One of the most consequential differences concerns the rights available to individuals.
Under the UK GDPR, a person may have the right to:
- Receive information about how personal data is used.
- Obtain access to personal data and related processing information.
- Correct inaccurate or incomplete information.
- Request erasure in qualifying circumstances.
- Restrict certain processing.
- Receive portable data in an appropriate format.
- Object to certain uses, including direct marketing.
- Receive safeguards relating to certain automated decisions and profiling.
These rights are not absolute, but they create a detailed system through which individuals can question and sometimes stop an organization’s use of their information.
New Zealand provides meaningful rights of access and correction. Its other privacy protections are expressed more frequently as duties placed on organizations rather than as a separate catalogue of individual rights.
For example, New Zealand organizations should not retain personal information longer than necessary. That obligation can produce a deletion outcome, but it is not identical to giving every person a standalone right to erasure modeled on Article 17 of the UK GDPR.
A UK law closely following New Zealand’s approach could therefore simplify rights administration for businesses while reducing the number of mechanisms individuals can invoke directly.
New Zealand’s System Is Lighter on Fines, Not Necessarily on Responsibility
The largest practical difference may be enforcement exposure.
The UK regulator can impose penalties linked to worldwide annual turnover. That structure allows a serious privacy violation to produce a penalty proportionate to the size of a multinational company.
New Zealand does not currently have a comparable civil administrative penalty regime. Its Privacy Commissioner has publicly called for stronger financial consequences, arguing that existing enforcement tools may be insufficient for large organizations and modern data practices.
The absence of GDPR-level fines does not mean New Zealand organizations can ignore privacy requirements. The Privacy Commissioner can investigate complaints, issue compliance notices and direct agencies to provide access to information. Individuals can pursue qualifying claims before the Human Rights Review Tribunal, which may grant declarations, orders and damages.
Failure to notify a qualifying serious privacy breach can also constitute an offense.
Nevertheless, the financial risk facing a major technology company under New Zealand law is substantially different from the potential exposure under the UK GDPR.
That difference helps explain why the model appeals to politicians seeking to reduce business compliance costs. It also raises the question of whether the law would remain sufficiently deterrent when applied to global companies processing information about millions of people.
New Zealand’s Privacy Law Still Imposes Some Broad Business Duties
Calling the New Zealand system “light-touch” can obscure several obligations that British businesses may not expect.
Every New Zealand agency must appoint a privacy officer. The law has broad application to organizations carrying on business in New Zealand, including qualifying overseas organizations. Serious breaches must be reported, and organizations remain responsible for protecting personal information sent to service providers or disclosed overseas.
The law also requires organizations to consider necessity before collecting information. An agency should not collect personal information merely because it might become useful later.
New Zealand’s principles can be flexible, but flexibility does not eliminate accountability. Instead of satisfying a highly specified European requirement, an organization may need to demonstrate that its conduct was reasonable, necessary and consistent with the purposes for which information was obtained.
What Would Happen to Cookie Consent?
A decision to repeal the UK GDPR would not automatically eliminate every cookie banner in Britain.
Online tracking in the United Kingdom is also governed by the Privacy and Electronic Communications Regulations. Those rules address the storage of information on a device and access to information already stored there, including through cookies and comparable tracking technologies.
Reform UK would therefore need to determine whether it intended to retain, amend or repeal those separate requirements.
New Zealand does not operate an equivalent general cookie-consent framework. Cookies, pixels, analytics tools and advertising identifiers are instead evaluated primarily through general privacy principles and other applicable laws.
If Britain adopted that approach, organizations might have greater freedom to use lower-risk analytics and similar technologies without obtaining the same form of prior consent. Collection would still need to be lawful, necessary, transparent and appropriately protected.
Separate rules could remain necessary for behavioral advertising, sensitive profiling, children’s data and technologies capable of monitoring people across unrelated services.
EU Adequacy Would Become the Central Economic Question
Reform UK argues that a New Zealand-style law should allow the United Kingdom to maintain its European Union adequacy status because New Zealand itself is recognized by the European Commission as providing adequate data protection.
That conclusion is possible, but it is not automatic.
An adequacy decision does not require a country to copy the GDPR word for word. The European Commission instead evaluates whether the country’s overall legal system provides protection that is essentially equivalent to the European standard.
That assessment considers more than the wording of the principal privacy statute. It can include:
- Individual rights and available remedies.
- The independence and powers of the national regulator.
- Government access to personal information.
- National-security and surveillance laws.
- Judicial oversight.
- International transfer restrictions.
- Enforcement practices.
- The broader constitutional and legal environment.
New Zealand’s adequacy status demonstrates that a principles-based system can satisfy the European standard. It does not guarantee that every law described as New Zealand-style would produce the same result.
The precise details would matter. A British replacement that retained effective oversight, enforceable rights and international-transfer protections might preserve adequacy. A more aggressive deregulation that substantially reduced protections could lead the European Commission to reconsider.
The UK’s Adequacy Decision Was Renewed Through 2031
The European Commission renewed the United Kingdom’s GDPR adequacy decision in December 2025 after assessing the country’s amended legal framework, including the Data (Use and Access) Act.
The renewed decision allows personal data to continue flowing from the European Economic Area to the United Kingdom without each organization implementing a separate transfer mechanism. It is scheduled to remain in effect until December 2031, subject to continued monitoring and the Commission’s authority to amend, suspend or repeal the decision if British protections materially change.
Replacing the UK GDPR would represent a much larger departure than the reforms already assessed by the Commission.
If adequacy were lost, affected companies could still receive European personal data through mechanisms such as standard contractual clauses. Those mechanisms, however, introduce additional contracts, assessments, vendor reviews and administrative work—the very type of burden Reform UK says it wants to reduce.
The adequacy question therefore sits at the center of the proposal’s commercial viability.
British Companies Could Still Be Subject to the EU GDPR
Repealing the UK GDPR would not necessarily free every British company from European privacy law.
The EU GDPR can apply to an organization outside the European Union when it offers goods or services to people in the EU or monitors their behavior there.
A UK retailer selling to European consumers, a software company tracking users in France or Germany, or an advertising platform profiling people across the EU could remain directly subject to the EU GDPR even if British domestic law changed.
International businesses might therefore face two regimes:
- A lighter domestic law for UK activities.
- The EU GDPR for activities involving people in the European Union.
That division could reduce obligations for local businesses operating only in Britain. For companies serving both markets, it could create additional complexity because systems, policies and vendor arrangements would need to distinguish between different populations and legal requirements.
Many companies may decide that maintaining a GDPR-level privacy program across all operations is simpler than creating separate standards for UK and European users.
Would a New Zealand Model Actually Help Small Businesses?
A principles-based law could reduce some costs. Small organizations might no longer need to navigate the same lawful-basis terminology, portability requests, detailed impact-assessment requirements or extensive accountability records.
The risk is that flexible principles can replace specific rules with uncertain judgment calls.
A business might no longer need to complete a formal GDPR analysis, but it would still need to decide whether collecting information was necessary, whether an additional use was sufficiently connected to the original purpose and whether an overseas recipient provided comparable protection.
Without clear regulatory guidance, those questions can also require professional advice.
The success of any replacement would therefore depend on more than shortening the legislation. A genuinely small-business-friendly system would need:
- Clear and practical regulator guidance.
- Simple templates and compliance tools.
- Proportionate obligations based on risk and organizational size.
- Predictable enforcement.
- Safe harbors for businesses following approved practices.
- Stronger requirements for companies conducting high-risk processing.
- Rules capable of addressing artificial intelligence, profiling and behavioral advertising.
Replacing one law with another will not eliminate the underlying responsibilities created when businesses collect, analyze and monetize personal information.
UK GDPR Reform Announcement
Reform UK’s announcement is a policy proposal, not an immediate change in the law. Organizations remain subject to the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the applicable electronic communications rules.
Businesses should watch for additional detail concerning:
- Whether Reform UK would repeal the entire UK GDPR or retain selected provisions.
- How existing privacy rights would be translated into the new law.
- Whether the UK’s cookie and electronic marketing rules would also change.
- What enforcement powers and penalties the regulator would retain.
- How the law would address artificial intelligence and automated decisions.
- Whether sector-specific rules would apply to health, financial and children’s information.
- How the government would seek to preserve EU adequacy.
- Whether businesses operating in Europe would need separate UK and EU compliance programs.
Britain’s Next Privacy Debate Will Be About More Than GDPR
The argument over the UK GDPR reflects a wider disagreement about what privacy law should accomplish.
One view treats privacy regulation primarily as a check on institutional power. Under this approach, detailed rights, documentation requirements and substantial penalties are necessary because individuals cannot realistically negotiate with governments, employers, banks or global technology platforms.
The competing view sees the existing regime as overly procedural. It argues that organizations spend too much time producing notices, assessments and internal records that do not necessarily prevent meaningful harm.
New Zealand offers Reform UK a politically useful example because it protects personal information without reproducing every feature of the GDPR. But the comparison also reveals that the policy choice is not simply between privacy regulation and no regulation.
New Zealand still requires purpose limitation, collection necessity, security, breach reporting, privacy officers, access rights and controls on overseas disclosure. Its model is lighter in some respects and unexpectedly demanding in others.
The most consequential question is therefore not whether Britain can abolish the UK GDPR. Parliament could replace it.
The real question is whether a successor law could reduce unnecessary compliance costs without weakening individual rights, disrupting European data flows or leaving the United Kingdom with a privacy regime poorly equipped for artificial intelligence and data-intensive business models.
Until Reform UK publishes detailed legislation, its New Zealand proposal should be understood as the beginning of that debate—not its final answer.