UK GDPR PRivacy Software – GDPR didn’t leave with Brexit.
After leaving the EU, Britain kept GDPR almost word for word as the UK GDPR, paired it with the Data Protection Act 2018, and handed the ICO real enforcement teeth. PECR still governs cookies. We tune your whole stack to the UK regime, and track the DUAA reforms as they land.
Close to GDPR, but not identical.
Or 4% of global turnover — the ICO has used it against adtech and data brokers.
Prior consent for non-essential cookies sits in PECR, not the UK GDPR itself.
Report a notifiable personal-data breach to the ICO within 72 hours.
The Data (Use and Access) Act adjusts cookies, PECR fines and legitimate interests.
Built for the ICO, not just “the EU”.
Most vendors ship one EU banner and call it UK-ready. We separate the regimes: UK GDPR lawful bases, PECR cookie rules, and ICO-tested copy.
PECR cookie consent
Prior-consent banners that meet PECR and the ICO’s guidance, with reject-all as prominent as accept.
UK-tuned privacy notice
Lawful-basis disclosures, ICO contact and complaint routes, generated for your site.
DSAR fulfilment
One-month statutory response with the UK GDPR exemptions and extension rules baked in.
UK IDTA transfers
International Data Transfer Agreement and the UK Addendum to the EU SCCs, tracked per vendor.
ROPA & accountability
Records of processing and the accountability evidence the ICO asks for in an audit.
DUAA change tracking
We watch the Data (Use and Access) Act and flag what shifts for cookies and legitimate interests.
One program for both sides of the Channel.
If you serve the EU and the UK, you don’t want two disconnected setups. We run a single consent and rights program that applies UK GDPR and PECR to UK visitors and EU GDPR to EU visitors, from the same tag and the same dashboard.
Book a UK readiness review- Day 1 — PECR-compliant banner live, reject-all surfaced
- Week 1 — UK privacy notice generated and hosted
- Week 2 — DSAR portal wired with one-month SLA clock
- Week 3 — IDTA / Addendum attached to each sub-processor
- Ongoing — ICO guidance and DUAA changes tracked weekly
What changes when the UK program is on.
- One EU banner assumed to cover the UK
- Cookies treated under GDPR, PECR ignored
- No UK transfer mechanism on vendors
- DSAR deadlines tracked by hand
- Reforms like DUAA missed until enforcement
- Separate UK GDPR + PECR logic per visitor
- PECR prior-consent banner, reject-all equal
- UK IDTA / Addendum attached automatically
- One-month DSAR clock with exemptions built in
- DUAA and ICO guidance surfaced as diffs
UK GDPR, answered plainly.
Is UK GDPR really different from EU GDPR?+
Do cookies fall under UK GDPR or PECR?+
What is the UK IDTA?+
What is the DUAA and should we care?+
Get UK-ready without a second stack.
Run UK GDPR and PECR from the same tag you use for the EU. Start free and we’ll apply the right regime per visitor.
Start free trial See pricing