Skip to the content
Global Data RulesData governance rules, country by country

United Kingdom

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.

Eight questions about the United Kingdom

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do the United Kingdom's rules apply to my company?

Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom, or watches what they do online. There is no size or revenue floor to hide under. If you are caught and have no British office, you generally have to name a representative in the United Kingdom, unless you are a public body or your processing is rare and low risk.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside the United Kingdom?

Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra; send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. Banking, payments, insurance, securities, education, online gambling and mapping have no location rule that we could find.

High confidenceYes, with paperworkAllowlistKeep the data in the country

What do I need in place before data leaves the United Kingdom?

The model is an approved-list one. If the destination is on the government's approved list you may send data with no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is well populated: the whole European Economic Area plus Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay, with partial cover for Canada, Japan and the United States.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesPut a transfer safeguard in place

Who enforces the rules in the United Kingdom, and what can they do?

The Information Commissioner's Office, and it is very much working. It fined Capita fourteen million pounds (about $18 million) in October 2025, Reddit £14.47 million (about $18.5 million) in February 2026, and the owner of Imgur in the same month, and it issues smaller marketing fines almost monthly. Watch a quirk: a replacement body called the Information Commission legally exists but had no staff and did no work in its first financial year, so the old office is still the one that acts.

High confidenceActive

How long do I have to keep the data?

There is no single deletion deadline. The rule is that you keep personal data only as long as you actually need it, and you must be able to explain the period you chose. Pulling the other way are minimum keeping periods: company and tax records for six years, telecoms connection records for up to twelve months if the government serves a notice, and telecoms security data for thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logsAllowed because the law requires it

What happens if there is a breach?

Count at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach, and must tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules — that used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in the United Kingdom?

Five. (1) A child can consent at 13 here, not 16 — but the children's design code covers everyone under 18, and the regulator fined Reddit £14.47 million (about $18.5 million) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security, and Apple is fighting one of those orders right now.

Medium confidenceGet a parent's consent for childrenKeep the data in the countryCriminal liabilityUnenforceable

What is changing soon in the United Kingdom?

Two things to watch in the next twelve months. A cyber security bill is going through Parliament and will widen incident reporting to data centres and managed service suppliers — it is not law yet, so do not plan as if it were. And the privacy regulator is due to be replaced by a new body called the Information Commission, but only once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.

High confidenceProposedPartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules4 rules

UK General Data Protection Regulation and Data Protection Act 2018

Act of parliament · Regulation (EU) 2016/679 as assimilated into UK law; Data Protection Act 2018 c. 12

In forceYes, with paperwork

The general privacy law. Data may leave the United Kingdom to an approved country with no paperwork, or anywhere else under a government-published contract plus a risk assessment. It reaches foreign companies that target or monitor people in the United Kingdom, with no size threshold, and usually requires them to name a representative here.

In force since 25 May 2018

Enforced by Information Commissioner's Office

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

Data (Use and Access) Act 2025

Act of parliament · 2025 c. 18; commenced by SI 2026/31 and SI 2026/82

Partly in forceYes, with paperwork

The 2025 reform act. Most privacy changes started on 5 February 2026 and the duty to run a complaints procedure started on 19 June 2026, but several parts — including the creation of a new regulator — are still waiting for ministers to switch them on. It also raised marketing and cookie fines to the same level as privacy fines.

In force since 20 August 2025But only enforceable from 19 June 2026

Enforced by Information Commissioner's Office

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

The Privacy and Electronic Communications (EC Directive) Regulations 2003

Directly binding regulation · SI 2003/2426, as amended by the Data (Use and Access) Act 2025 · Telecoms

In forceYes — store it anywhere

The marketing, cookies and communications-security rules. Two things changed recently and a lot of advice is out of date: the breach deadline for communications providers moved from 24 to 72 hours on 20 August 2025, and the maximum fine jumped from £500,000 to £17.5 million (about $23 million) or 4% of worldwide turnover on 5 February 2026.

In force since 11 December 2003But only enforceable from 20 August 2025

Enforced by Information Commissioner's Office

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules7 rules

The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1)

Directly binding regulation · SI 2022/933, made under the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021 · Telecoms

In forceA copy must stay

The one genuine keep-a-copy-here rule in British law. Telecoms network providers must hold certain backup information inside the United Kingdom and must be able to keep the network running without depending on people, kit or data abroad. A revised statutory code of practice was published on 14 July 2026.

In force since 1 October 2022

Enforced by Office of Communications

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Investigatory Powers Act 2016

Act of parliament · 2016 c. 25, sections 87 and following; technical capability notices under Part 9 · Telecoms

In forceYes — store it anywhere

A secret, on-demand power rather than a standing rule. The government can order a telecoms or internet company to keep connection records for up to twelve months, and can separately order a company to provide a technical capability to hand over data. Neither kind of order is published, so no public list exists.

In force since 31 December 2018

Enforced by Home Office

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

NHS and social care data: off-shoring and the use of public cloud services

Regulator guideline · NHS England Digital guidance, last updated 7 February 2023 · Health and social care

In forceYes, with paperwork

Health and social care records may be held in public cloud, but only inside the United Kingdom, the European Economic Area, or a country the United Kingdom has formally approved. That is narrower than the general law, because the standard contract route other industries rely on is not offered here. A senior information risk owner must sign it off.

In force since 19 January 2018

Enforced by NHS England

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

Medium confidence

Who you would hear from

  • Data protection, electronic marketing and cookies, freedom of information

    Fully operational and issuing fines: Capita £14m in October 2025, Reddit £14.47m and Imgur's owner MediaLab in February 2026, South Staffordshire Water in May 2026, plus regular marketing fines. It remains the acting regulator because the statutory instrument transferring functions to the Information Commission has not been laid.

  • Successor body to the Information Commissioner's Office

    Incorporated on 20 August 2025 but not yet functioning. Its own first annual report records no operational activity between 20 August 2025 and 31 March 2026, no employees, and an interim chief executive designate employed by the old office. The transfer of functions requires secondary legislation that had not been laid as at July 2026.

  • Ofcom

    Telecoms security, online safety and age assurance

    Running an active enforcement programme on age checks and supervising the telecoms security duties.

  • Financial services conduct, outsourcing and operational resilience, critical third parties

    Began direct oversight of four designated cloud providers on 13 July 2026, jointly with the Bank of England.

  • Health and social care information governance, offshoring and cloud policy

  • Government data classification, cloud and cyber security policy

  • Data protection policy, telecoms security code of practice, cyber resilience legislation

  • Investigatory powers, retention notices and technical capability notices

    Notices are secret and not published, so activity cannot be observed directly.

  • Remote and land-based gambling licensing

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the National Health Service offshoring guidance still represents current policy in August 2026

    The guidance page's own last-reviewed date is 7 February 2023. Nothing newer was found on the NHS England Digital site during this run, but a three-year-old page in a fast-moving area may have been superseded by procurement-level rules we did not see. Confidence lowered to medium for that rule.

  • The exact scope of the telecoms 'retain within the United Kingdom' backup duty

    Regulation 9(2)(a) was read via an automated fetch of the statutory instrument rather than a full manual reading of regulation 9 in context. The duty clearly exists; which categories of backup information it covers should be confirmed against the full text before relying on it.

  • Current status of the Apple technical capability notice litigation

    The Investigatory Powers Tribunal's own site returned a JavaScript redirect and could not be read. Reports of a second challenge in August 2026 come from legal trade press only, so no official backlink supports that part.

  • That the December 2023 Court of Appeal ruling again held the immigration exemption unlawful

    Verified only against professional commentary and the March 2024 remedial regulations. The judgment itself was not opened on an official court site during this run.

  • The five-year anti-money-laundering record retention period

    Not verified against an official source in this run; stated with a hedge and excluded from the rules array.

  • That no mapping or geospatial data localisation rule exists in the United Kingdom

    No rule found, checked 18 August 2026. This is a negative and cannot be proved; searches surfaced only licensing terms, not location rules. Confidence medium.

  • Whether any further Data (Use and Access) Act commencement regulations were made between 19 June and 18 August 2026

    Commencement Regulations No. 5 and No. 6 were confirmed; a later instrument made in the last few weeks would not necessarily be indexed yet.

  • The precise incident reporting deadlines proposed in the Cyber Security and Resilience Bill

    The Lords Library briefing confirms the scope expansion but does not state the hour figures, and the bill text was not read line by line.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.