Skip to the content
Global Data RulesData governance rules, country by country

United Kingdom

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in the United Kingdom — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.

Data governance in the United Kingdom

The eight things that decide how you handle data about people in the United Kingdom. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom. It also applies if you watch what they do online. There is no size or revenue floor to hide under. If the law catches you and you have no British office, you usually have to name a representative in the United Kingdom. You are excused if you are a public body, or if you only handle data rarely and at low risk.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra. Send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. We found no location rule for banking, payments, insurance, securities, education, online gambling or mapping.

What you have to do here:
Keep the data in the country

What to do: Get the paperwork for one of the routes below signed before any data leaves United Kingdom.

Sending data out of the country

You can send data freely only to countries on the government's approved list. If the destination is on that list, you need no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is long. It covers the whole European Economic Area. It also covers Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay. Canada, Japan and the United States are covered in part.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The regulator is the Information Commissioner's Office, and it is very much working. It fined Capita 14 million pounds (about 18 million US dollars) in October 2025. It fined Reddit 14.47 million pounds (about 18.5 million US dollars) in February 2026. It fined the owner of Imgur in the same month. It issues smaller marketing fines almost monthly. There is one oddity. A replacement body called the Information Commission legally exists. It had no staff and did no work in its first financial year. So the old office is still the one that acts.

How long you must keep it — and when to delete it

There is no single deletion deadline. You keep personal data only as long as you actually need it. You must be able to explain the period you chose. Pulling the other way are minimum keeping periods. Company and tax records: six years. Telecoms connection records: up to twelve months, if the government serves a notice. Telecoms security data: thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Allowed because the law requires it

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach. You must also tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules. That used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things. (1) A child can consent at 13 here, not 16. But the children's design code covers everyone under 18. The regulator fined Reddit 14.47 million pounds (about 18.5 million US dollars) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security. Apple is fighting one of those orders right now.

What you have to do here:
Get a parent's consent for children
What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

Two things to watch in the next twelve months. A cyber security bill is going through Parliament. It will widen incident reporting to data centres and managed service suppliers. It is not law yet, so do not plan as if it were. The privacy regulator is also due to be replaced by a new body called the Information Commission. That only happens once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.

What to do: Diarise 27 December 2031 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries7 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Telecoms

Telecoms rules

Official name: The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1) · SI 2022/933, made under the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021 · Directly binding regulation

In forceA copy must stay

This is the one real keep-a-copy-here rule in British law. Telecoms network providers must hold certain backup information inside the United Kingdom. They must also be able to keep the network running without depending on people, equipment or data abroad. A revised statutory code of practice was published on 14 July 2026.

In force since 1 October 2022

Enforced by Office of Communications

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Telecoms

Telecoms rules (Telecoms)

Official name: Investigatory Powers Act 2016 · 2016 c. 25, sections 87 and following; technical capability notices under Part 9 · Act of parliament

In forceYes — store it anywhere

This is a secret, on-demand power rather than a standing rule. The government can order a telecoms or internet company to keep connection records for up to twelve months. It can separately order a company to build a way to hand data over. Neither kind of order is published, so no public list exists.

In force since 31 December 2018

Enforced by Home Office

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.
Health and social care

Cloud and outsourcing rules

Official name: NHS and social care data: off-shoring and the use of public cloud services · NHS England Digital guidance, last updated 7 February 2023 · Regulator guideline

In forceYes, with paperwork

Health and social care records may be held in public cloud. But they may only sit inside the United Kingdom, the European Economic Area, or a country the United Kingdom has formally approved. That is narrower than the general law. The standard contract route other industries rely on is not offered here. A senior information risk owner must sign it off.

In force since 19 January 2018

Enforced by NHS England

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Not fully verified — see “What we're not sure about” below.

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Europe's main privacy law

Official name: UK General Data Protection Regulation and Data Protection Act 2018 · Regulation (EU) 2016/679 as assimilated into UK law; Data Protection Act 2018 c. 12 · Act of parliament

In forceYes, with paperwork

This is the general privacy law. Data may leave the United Kingdom to an approved country with no paperwork. It may go anywhere else under a government-published contract plus a risk assessment. The law reaches foreign companies that target or monitor people in the United Kingdom. There is no size threshold. Those companies usually have to name a representative here.

In force since 25 May 2018

Enforced by Information Commissioner's Office

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

General data protection law

Official name: Data (Use and Access) Act 2025 · 2025 c. 18; commenced by SI 2026/31 and SI 2026/82 · Act of parliament

Partly in forceYes, with paperwork

This is the 2025 reform act. Most privacy changes started on 5 February 2026. The duty to run a complaints procedure started on 19 June 2026. Several parts are still waiting for ministers to switch them on, including the creation of a new regulator. It also raised marketing and cookie fines to the same level as privacy fines.

In force since 20 August 2025Enforced from 19 June 2026

Enforced by Information Commissioner's Office

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Telecoms

Telecoms rules (2025)

Official name: The Privacy and Electronic Communications (EC Directive) Regulations 2003 · SI 2003/2426, as amended by the Data (Use and Access) Act 2025 · Directly binding regulation

In forceYes — store it anywhere

These are the marketing, cookies and communications-security rules. Two things changed recently and a lot of advice is out of date. The breach deadline for communications providers moved from 24 to 72 hours on 20 August 2025. And on 5 February 2026 the maximum fine jumped from 500,000 pounds to 17.5 million pounds (about 23 million US dollars). It can also be 4% of worldwide turnover.

In force since 11 December 2003Enforced from 20 August 2025

Enforced by Information Commissioner's Office

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Data protection, electronic marketing and cookies, freedom of information

    Fully working and issuing fines. Capita, 14 million pounds in October 2025. Reddit, 14.47 million pounds, and Imgur's owner MediaLab, both in February 2026. South Staffordshire Water in May 2026. Plus regular marketing fines. It is still the acting regulator, because the secondary legislation transferring functions to the Information Commission has not been laid.

  • Successor body to the Information Commissioner's Office

    Set up on 20 August 2025 but not yet working. Its own first annual report records no activity between 20 August 2025 and 31 March 2026. It had no employees. Its interim chief executive designate is employed by the old office. The transfer of functions needs secondary legislation, which had not been laid as at July 2026.

  • Ofcom

    Telecoms security, online safety and age assurance

    Running an active enforcement programme on age checks and supervising the telecoms security duties.

  • Financial services conduct, outsourcing and operational resilience, critical third parties

    Began direct oversight of four designated cloud providers on 13 July 2026, jointly with the Bank of England.

  • Health and social care information governance, offshoring and cloud policy

  • Government data classification, cloud and cyber security policy

  • Data protection policy, telecoms security code of practice, cyber resilience legislation

  • Investigatory powers, retention notices and technical capability notices

    Notices are secret and not published, so activity cannot be observed directly.

  • Remote and land-based gambling licensing

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the National Health Service offshoring guidance still represents current policy in August 2026

    We could not confirm this against anything newer. The guidance page's own last-reviewed date is 7 February 2023. We found nothing newer on the NHS England Digital site. A three-year-old page in a fast-moving area may have been overtaken by procurement rules we did not see. Confidence lowered to medium for that rule.

  • The exact scope of the telecoms 'retain within the United Kingdom' backup duty

    We could not confirm exactly which backup information this covers. The duty clearly exists. Check the full text before you rely on the detail.

  • Current status of the Apple technical capability notice litigation

    We could not confirm this against the Investigatory Powers Tribunal's own site, which we could not read. Reports of a second challenge in August 2026 come from legal trade press only. No official source supports that part.

  • That the December 2023 Court of Appeal ruling again held the immigration exemption unlawful

    We could not confirm this against an official court source. We checked it only against professional commentary and the March 2024 remedial regulations.

  • The five-year anti-money-laundering record retention period

    We could not confirm this against an official source. We state it with a hedge and leave it out of the rules list.

  • That no mapping or geospatial keeping data in the country rule exists in the United Kingdom

    We found no such rule, checked 18 August 2026. Searches turned up licensing terms only, not location rules. Finding nothing is not proof that nothing exists. Confidence medium. If you work in gambling, check before you rely on it.

  • Whether any further Data (Use and Access) Act commencement regulations were made between 19 June and 18 August 2026

    We confirmed Commencement Regulations No. 5 and No. 6. A later one made in the past few weeks might not be indexed yet, so we could not rule that out.

  • The precise incident reporting deadlines proposed in the Cyber Security and Resilience Bill

    We could not confirm the hour figures. The Lords Library briefing confirms the wider coverage but does not state them. We did not read the bill text line by line.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.