Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / UK GDPR
UK GDPR · DPA 2018 · PECR

UK GDPR PRivacy Software – GDPR didn’t leave with Brexit.

After leaving the EU, Britain kept GDPR almost word for word as the UK GDPR, paired it with the Data Protection Act 2018, and handed the ICO real enforcement teeth. PECR still governs cookies. We tune your whole stack to the UK regime, and track the DUAA reforms as they land.

ICO-tested patternsPECR cookie consentUK IDTA transfers

Close to GDPR, but not identical.

£17.5M
Top-tier fine

Or 4% of global turnover — the ICO has used it against adtech and data brokers.

PECR
Governs cookies

Prior consent for non-essential cookies sits in PECR, not the UK GDPR itself.

72h
Breach window

Report a notifiable personal-data breach to the ICO within 72 hours.

DUAA
Reform incoming

The Data (Use and Access) Act adjusts cookies, PECR fines and legitimate interests.

Built for the ICO, not just “the EU”.

Most vendors ship one EU banner and call it UK-ready. We separate the regimes: UK GDPR lawful bases, PECR cookie rules, and ICO-tested copy.

C

PECR cookie consent

Prior-consent banners that meet PECR and the ICO’s guidance, with reject-all as prominent as accept.

N

UK-tuned privacy notice

Lawful-basis disclosures, ICO contact and complaint routes, generated for your site.

D

DSAR fulfilment

One-month statutory response with the UK GDPR exemptions and extension rules baked in.

T

UK IDTA transfers

International Data Transfer Agreement and the UK Addendum to the EU SCCs, tracked per vendor.

R

ROPA & accountability

Records of processing and the accountability evidence the ICO asks for in an audit.

A

DUAA change tracking

We watch the Data (Use and Access) Act and flag what shifts for cookies and legitimate interests.

One program for both sides of the Channel.

If you serve the EU and the UK, you don’t want two disconnected setups. We run a single consent and rights program that applies UK GDPR and PECR to UK visitors and EU GDPR to EU visitors, from the same tag and the same dashboard.

Book a UK readiness review
Rollout · typical UK site
  • Day 1 — PECR-compliant banner live, reject-all surfaced
  • Week 1 — UK privacy notice generated and hosted
  • Week 2 — DSAR portal wired with one-month SLA clock
  • Week 3 — IDTA / Addendum attached to each sub-processor
  • Ongoing — ICO guidance and DUAA changes tracked weekly

What changes when the UK program is on.

Without a program
  • One EU banner assumed to cover the UK
  • Cookies treated under GDPR, PECR ignored
  • No UK transfer mechanism on vendors
  • DSAR deadlines tracked by hand
  • Reforms like DUAA missed until enforcement
With Captain Compliance
  • Separate UK GDPR + PECR logic per visitor
  • PECR prior-consent banner, reject-all equal
  • UK IDTA / Addendum attached automatically
  • One-month DSAR clock with exemptions built in
  • DUAA and ICO guidance surfaced as diffs

UK GDPR, answered plainly.

Is UK GDPR really different from EU GDPR?+
The text is nearly identical, but enforcement, transfer mechanisms and cookie rules diverge. The ICO is your regulator, transfers use the UK IDTA or Addendum, and cookies fall under PECR. We apply the UK-specific pieces rather than assuming an EU setup covers you.
Do cookies fall under UK GDPR or PECR?+
PECR governs the act of storing or reading cookies and requires prior consent for non-essential ones; UK GDPR governs the personal data you then process. You need both, which is why our banner and notice are wired together.
What is the UK IDTA?+
It is the UK’s International Data Transfer Agreement, the post-Brexit replacement for relying on EU SCCs. There is also an Addendum that bolts onto EU SCCs. We attach the right instrument to each sub-processor automatically.
What is the DUAA and should we care?+
The Data (Use and Access) Act reforms parts of the UK regime, including some cookie consent exceptions, PECR fine levels and legitimate-interest grounds. We track it and flag exactly what changes for your configuration.

Get UK-ready without a second stack.

Run UK GDPR and PECR from the same tag you use for the EU. Start free and we’ll apply the right regime per visitor.

Start free trial See pricing