United Kingdom
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in the United Kingdom — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.
Data governance in the United Kingdom
The eight things that decide how you handle data about people in the United Kingdom. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom. It also applies if you watch what they do online. There is no size or revenue floor to hide under. If the law catches you and you have no British office, you usually have to name a representative in the United Kingdom. You are excused if you are a public body, or if you only handle data rarely and at low risk.
- What you have to do here:
- Appoint a representative
The reach comes from Article 3 of the UK GDPR, Britain's main privacy law. The duty to name a representative is Article 27. The regulator's own guidance stresses that a website simply being reachable from Britain is not enough. It looks for deliberate targeting. Examples are pricing in pounds, a .co.uk address, British marketing or British delivery. Watching what people do is read broadly. It covers one-off profiling, not just continuous tracking. The regulator also says the representative is not the target of enforcement. It goes after the overseas company itself. The February 2026 fine against Reddit, a United States company, shows this really happens.
Sources
- Official sourceInformation Commissioner's OfficeTerritorial scope of the UK GDPR — ICO knowledge hub note
ico.org.uk
“generally need to appoint someone to act as their representative in the UK”
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeReddit issued with £14.47m fine for children's privacy failures, 24 February 2026
ico.org.uk
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra. Send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. We found no location rule for banking, payments, insurance, securities, education, online gambling or mapping.
- What you have to do here:
- Keep the data in the country
Industry by industry, checked on 18 August 2026. TELECOMS. The strictest layer. The Electronic Communications (Security Measures) Regulations 2022 apply here. A network provider must be able to run its network without relying on people, equipment or stored data outside the United Kingdom. Regulation 9(2)(a) also requires certain backup information to be kept within the United Kingdom. That is a real must-stay-here copy rule. HEALTH. National Health Service and social care data, including confidential patient information, may be held in public cloud. But it may only sit in the United Kingdom, the European Economic Area, or a country the United Kingdom has formally approved as safe enough. That removes the standard contract route other industries can use. GOVERNMENT. Data marked OFFICIAL may sit overseas. The Cabinet Office guidance says plainly that there is no universal requirement to keep it in the United Kingdom. But public cloud is not allowed for SECRET or TOP SECRET at all. FINANCE. The regulators require access, audit, resilience and exit arrangements. From 13 July 2026 four cloud providers are supervised directly. But there is no requirement to keep the data in Britain. GAMBLING. A common myth. Putting remote gambling equipment in Great Britain means you need a licence. It is not a rule that the equipment must be there. MAPPING AND GEOSPATIAL. We found no location rule, checked 18 August 2026, confidence medium.
Sources
- Official sourceThe National Archives / UK GovernmentThe Electronic Communications (Security Measures) Regulations 2022, regulations 3 and 9
legislation.gov.uk
“able, without reliance on persons, equipment or stored data located outside the United Kingdom, to identify the risks of security compromises”
Link checked 18 August 2026
- Official sourceNHS England DigitalNHS and social care data: off-shoring and the use of public cloud services — guidance
digital.nhs.uk
“NHS and social care organisations can safely locate health and care data, including confidential patient information, in the public cloud”
Link checked 18 August 2026
- Official sourceCentral Digital and Data Office, Cabinet OfficeMulti-region cloud and software-as-a-service, 5 February 2025
gov.uk
“there is no universal requirement for government data classified as OFFICIAL to be physically located in the UK”
Link checked 18 August 2026
- Official sourceGambling CommissionRemote gambling equipment — Gambling Commission guidance
gamblingcommission.gov.uk
“If an operator providing facilities for remote gambling locates any 'remote gambling equipment' ... in Great Britain that operator is required to hold a form of remote gambling licence”
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves United Kingdom.
Sending data out of the country
You can send data freely only to countries on the government's approved list. If the destination is on that list, you need no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is long. It covers the whole European Economic Area. It also covers Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay. Canada, Japan and the United States are covered in part.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules
There are three routes. One, the destination is covered by official regulations saying it is safe enough. The government calls these data bridges. Two, you put approved safeguards in place. Three, a narrow exception applies. The main safeguard is the International Data Transfer Agreement. You can also use the Addendum that bolts onto the European standard clauses. Group-wide binding corporate rules are available too. Some approvals are partial. Canada is covered only for private-sector bodies under its federal privacy law. Japan is covered only for private-sector bodies under its own act. The United States is covered only through the UK Extension to the EU-US Data Privacy Framework. That means only certified American organisations. The Data (Use and Access) Act 2025 replaced the old 'essentially equivalent' test with a lower 'not materially lower' test. It also wrote a risk-based approach into the exporter's own assessment. The regulator refreshed its transfer guidance on 15 January 2026. Flows the other way, from the European Union into the United Kingdom, depend on the European Commission's renewed decisions of 19 December 2025. Those run to 27 December 2031.
Sources
- Official sourceInformation Commissioner's OfficeIs the restricted transfer covered by adequacy regulations? — list of covered countries, updated 15 January 2026
ico.org.uk
“not materially lower”
Link checked 18 August 2026
- Official sourceEuropean Commission / EUR-LexCommission Implementing Decision (EU) 2025/2574 of 19 December 2025 renewing UK adequacy under the GDPR (valid to 27 December 2031)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentData (Use and Access) Act 2025 (c. 18), Part 5 — data protection and privacy
legislation.gov.uk
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The regulator is the Information Commissioner's Office, and it is very much working. It fined Capita 14 million pounds (about 18 million US dollars) in October 2025. It fined Reddit 14.47 million pounds (about 18.5 million US dollars) in February 2026. It fined the owner of Imgur in the same month. It issues smaller marketing fines almost monthly. There is one oddity. A replacement body called the Information Commission legally exists. It had no staff and did no work in its first financial year. So the old office is still the one that acts.
The Information Commission was set up on 20 August 2025 under the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Its own first annual report says there was 'no operational activity during the period from 20 August 2025 to 31 March 2026'. It had no employees. The report also says the secondary legislation transferring functions to it 'has not yet been laid'. Until that transfer happens, every notice, fine and decision comes from the Information Commissioner. Industry regulators are separately active. The Financial Conduct Authority and the Bank of England's Prudential Regulation Authority began direct oversight of designated cloud providers on 13 July 2026. The communications regulator Ofcom is running an enforcement programme on age checks under the Online Safety Act. Ofcom also supervises telecoms security under the Communications Act.
Sources
- Official sourceInformation Commissioner's OfficeCapita plc and Capita Pension Solutions Ltd — enforcement action, October 2025
ico.org.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeReddit issued with £14.47m fine for children's privacy failures, 24 February 2026
ico.org.uk
“failed to apply any robust age assurance mechanism and therefore did not have a lawful basis for processing the personal information of children under the age of 13”
Link checked 18 August 2026
- Official sourceInformation Commission (laid before Parliament)Information Commission Annual Report and Accounts 2025-26, HC 531, July 2026
assets.publishing.service.gov.uk
“there was no operational activity during the period from 20 August 2025 to 31 March 2026”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is no single deletion deadline. You keep personal data only as long as you actually need it. You must be able to explain the period you chose. Pulling the other way are minimum keeping periods. Company and tax records: six years. Telecoms connection records: up to twelve months, if the government serves a notice. Telecoms security data: thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Allowed because the law requires it
The maximum comes from the storage limitation rule in the UK GDPR, Britain's main privacy law. There is no fixed number. You need a period you have written down and can justify. The minimums we verified. Company accounting records must be kept for six years from the end of the financial year they relate to. Keep them longer if a tax enquiry is open. A retention notice under the Investigatory Powers Act 2016 can require a telecoms operator to hold communications data. The maximum is twelve months. This includes internet connection records. The telecoms security regulations require access data to be 'held securely for at least 13 months', and other security records for at least three years. Anti-money-laundering records are generally kept five years, but we did not verify that against an official source. The clash is settled by the legal duty ground. Where another law requires you to keep data, that law is your legal reason for holding it. The duty to delete does not apply until the statutory period ends.
Sources
- Official sourceGOV.UKCompany and accounting records — how long to keep them
gov.uk
“You must keep records for 6 years from the end of the last company financial year they relate to”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentInvestigatory Powers Act 2016, section 87 — retention notices, 12-month maximum
legislation.gov.uk
“A retention notice must not require any data to be retained for more than 12 months”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentElectronic Communications (Security Measures) Regulations 2022, regulations 3(4) and 6(3)(e)
legislation.gov.uk
“held securely for at least 13 months”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentUK General Data Protection Regulation, Article 5(1)(e) — storage limitation
legislation.gov.uk
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach. You must also tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules. That used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one. British privacy law: 72 hours from becoming aware, to the Information Commissioner. Clock two. The Privacy and Electronic Communications Regulations, which apply to providers of public electronic communications services. The regulator's own guidance now says you must notify the Information Commissioner's Office within 72 hours of becoming aware of the essential facts of the breach. The Data (Use and Access) Act 2025 made that change on 20 August 2025. The old rule was 24 hours, and a great deal of stale advice still says so. A separate fixed penalty of 1,000 pounds applies if you fail to file that notification at all. Clock three. Regulation 11 of the Network and Information Systems Regulations 2018: 'without undue delay and in any event no later than 72 hours' to the relevant competent authority. Financial firms have a fourth, vaguer clock. Tell the Financial Conduct Authority about anything significant without delay. The overlap is where people fail. One incident can be reportable to the privacy regulator, to an industry regulator, and, for designated cloud providers, under the critical third parties rules.
Sources
- Official sourceInformation Commissioner's OfficeGuide to PECR — security breaches, 72-hour notification
ico.org.uk
“You must notify the ICO within 72 hours of becoming aware of the essential facts of the breach”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentNetwork and Information Systems Regulations 2018, regulation 11 — incident notification
legislation.gov.uk
“without undue delay and in any event no later than 72 hours after the operator is aware that a NIS incident has occurred”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things. (1) A child can consent at 13 here, not 16. But the children's design code covers everyone under 18. The regulator fined Reddit 14.47 million pounds (about 18.5 million US dollars) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security. Apple is fighting one of those orders right now.
- What you have to do here:
- Get a parent's consent for children
- What it costs if you get it wrong:
- Criminal liability
(1) The children's code is a statutory code made under section 123 of the Data Protection Act 2018. It applies to any online service likely to be accessed by children in the United Kingdom. People often cite section 9 of the Data Protection Act 2018 for the age of consent. That section was deleted on 31 December 2020. The 13-year rule now lives in Article 8 of the UK GDPR. Separately, the Online Safety Act has required 'highly effective age assurance' for pornographic content since July 2025. Ofcom polices that. It is a different regulator with different powers. (2) Regulation 9(2)(a) of the telecoms security regulations. (3) National Health Service and social care guidance permits only the United Kingdom, the European Economic Area, and countries the United Kingdom has formally approved. (4) The Data Protection Act 2018 creates criminal offences. One is knowingly obtaining or disclosing personal data without the consent of the company that decides how the data is used. Another is altering records to frustrate a request for a copy of someone's data. These offences attach to individuals as well as companies. (5) Technical capability notices under the Investigatory Powers Act 2016 are secret. They are not published, and they can reach companies outside the United Kingdom. Apple's challenge is before the Investigatory Powers Tribunal. A second challenge was reported in August 2026. BONUS TRAP. The immigration exemption in Schedule 2 to the Data Protection Act 2018 was held incompatible by the Court of Appeal in 2021. It was suspended, then rewritten twice, most recently in March 2024. Treat any reliance on it as legally fragile.
Sources
- Official sourceInformation Commissioner's OfficeAge appropriate design: a code of practice for online services — about this code
ico.org.uk
“This is a statutory code of practice prepared under section 123 of the DPA 2018”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentData Protection Act 2018, section 9 — omitted on 31 December 2020
legislation.gov.uk
“S. 9 omitted (31.12.2020)”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentThe Data Protection Act 2018 (Amendment of Schedule 2 Exemptions) Regulations 2024 — second rewrite of the immigration exemption
legislation.gov.uk
Link checked 18 August 2026
- Official sourceUK ParliamentData protection regulations and the immigration exemption — House of Lords Library
lordslibrary.parliament.uk
“incompatible with retained EU law”
Link checked 18 August 2026
What's changing next
Two things to watch in the next twelve months. A cyber security bill is going through Parliament. It will widen incident reporting to data centres and managed service suppliers. It is not law yet, so do not plan as if it were. The privacy regulator is also due to be replaced by a new body called the Information Commission. That only happens once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.
PENDING LEGISLATION. The Cyber Security and Resilience (Network and Information Systems) Bill is House of Lords Bill 32 of 2026-27. It had its second reading in the Lords on 14 July 2026. It expands the 2018 rules to data centres, electrical load control and third-party information technology suppliers. Much of the detail is left to later secondary legislation. THINGS THAT COULD CHANGE WITH NO CONSULTATION. (1) The Secretary of State can serve a retention notice on a telecoms operator at any time, covering up to twelve months of data. The notice is not published. (2) Technical capability notices under the same Act are secret and have already been used against a major cloud provider. (3) HM Treasury can designate further critical third parties by secondary legislation. It did so for four cloud providers on 8 July 2026, taking effect five days later. (4) The European Commission's renewed decision on the United Kingdom runs to 27 December 2031. It can be suspended if British law drifts away from European standards. (5) Ministers can switch on the remaining parts of the Data (Use and Access) Act 2025 by regulations alone. That includes transferring the regulator's functions.
Sources
- Official sourceUK ParliamentCyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026-27 — Lords Library briefing
lordslibrary.parliament.uk
“data centres, electrical load control, and third-party IT products”
Link checked 18 August 2026
- Official sourceInformation CommissionInformation Commission Annual Report and Accounts 2025-26 — transfer of functions not yet laid
assets.publishing.service.gov.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeOne year on: marking the 12-month commencement of the Data (Use and Access) Act, June 2026
ico.org.uk
“starting work on a new statutory code of practice on artificial intelligence”
Link checked 18 August 2026
What to do: Diarise 27 December 2031 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries7 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Telecoms rules
Official name: The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1) · SI 2022/933, made under the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021 · Directly binding regulation
This is the one real keep-a-copy-here rule in British law. Telecoms network providers must hold certain backup information inside the United Kingdom. They must also be able to keep the network running without depending on people, equipment or data abroad. A revised statutory code of practice was published on 14 July 2026.
Enforced by Office of Communications
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryBackup information must be kept within the United Kingdom. You must also be able to run the network without relying on people, equipment or stored data outside the United Kingdom.
- Keep logs — 13 monthsData supporting monitoring of privileged access must be held securely for at least 13 months.
- Keep data for a minimum period — 3 yearsSecurity assessment records must be kept at least three years.
- Secure the data
- Independent auditRisk assessment at least once every 12 months.
What it costs if you get it wrong
- Percentage of global turnover: 10% of turnover, or £100,000 per day for continuing contraventionBreach of the security duties, enforced by Ofcom under the Communications Act
Sources
- Official sourceThe National Archives / UK GovernmentThe Electronic Communications (Security Measures) Regulations 2022, regulations 3, 6 and 9
legislation.gov.uk
“to be created or acquired ... and to retain within the United Kingdom”
Link checked 18 August 2026
- Official sourceDepartment for Science, Innovation and TechnologyTelecommunications Security Code of Practice 2026 (version 1.1), published 14 July 2026
gov.uk
“able, without reliance on persons, equipment or stored data located outside the United Kingdom, to identify the risks of security compromises”
Link checked 18 August 2026
Telecoms rules (Telecoms)
Official name: Investigatory Powers Act 2016 · 2016 c. 25, sections 87 and following; technical capability notices under Part 9 · Act of parliament
This is a secret, on-demand power rather than a standing rule. The government can order a telecoms or internet company to keep connection records for up to twelve months. It can separately order a company to build a way to hand data over. Neither kind of order is published, so no public list exists.
Enforced by Home Office
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 1 yearOnly where the Secretary of State serves a retention notice. Notices are not published.
- Keep logs — 1 yearCan include internet connection records.
- Do not hand data to foreign authorities on demandThis works the other way round. The state can force a company to build or keep the ability to hand data over. That includes companies outside the United Kingdom.
What it costs if you get it wrong
- Criminal liabilityUnlawfully disclosing the existence of a notice
Sources
- Official sourceThe National Archives / UK GovernmentInvestigatory Powers Act 2016, section 87 — retention notices
legislation.gov.uk
“A retention notice must not require any data to be retained for more than 12 months”
Link checked 18 August 2026
- Official sourceLink may be brokenInvestigatory Powers TribunalApple Inc v Secretary of State for the Home Department — Investigatory Powers Tribunal
investigatorypowerstribunal.org.uk
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: NHS and social care data: off-shoring and the use of public cloud services · NHS England Digital guidance, last updated 7 February 2023 · Regulator guideline
Health and social care records may be held in public cloud. But they may only sit inside the United Kingdom, the European Economic Area, or a country the United Kingdom has formally approved. That is narrower than the general law. The standard contract route other industries rely on is not offered here. A senior information risk owner must sign it off.
Enforced by NHS England
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Assess high-risk projectsYou need this before you decide to move data abroad.
- Secure the data
- Written vendor contract
- Hold a security certificateData Security and Protection Toolkit completion is expected of suppliers handling health and care data.
What it costs if you get it wrong
- Order to stopContractual and regulatory consequences rather than a statutory fine; the privacy regulator can still act under the general law
Sources
- Official sourceNHS England DigitalNHS and social care data: off-shoring and the use of public cloud services — guidance
digital.nhs.uk
“Senior Information Risk Owners (SIROs) locally should be satisfied about appropriate security arrangements”
Link checked 18 August 2026
Cloud and outsourcing rules (Finance)
Official name: The Critical Third Parties (Designation) Regulations 2026, with FCA policy statement PS24/16 and Bank of England supervisory statement SS6/24 · SI 2026/777, made under section 312L(1) of the Financial Services and Markets Act 2000 · Directly binding regulation
British financial regulators do not require customer data to stay in the country. They require you to keep control of it. That means access and audit rights, resilience testing and a real exit plan. Since 13 July 2026 four cloud providers are supervised directly: Amazon, Google, Microsoft and Oracle. That is new, and it changes who carries the risk.
Enforced by Financial Conduct Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the data
- Written vendor contractOutsourcing contracts must give the firm and the regulators access, audit and information rights, and a workable exit plan.
- Report cyber incidentsDesignated providers must report incidents affecting the financial sector to the regulators.
- Independent audit
- Register or notifyFirms must keep an outsourcing register and notify material outsourcing.
What it costs if you get it wrong
- Order to stopDirection to a designated provider, including a direction to stop providing services to the financial sector
- Loss of your licenceRegulatory action against the regulated firm for failed outsourcing controls
Sources
- Official sourceThe National Archives / UK GovernmentThe Critical Third Parties (Designation) Regulations 2026
legislation.gov.uk
“Amazon Web Services EMEA SARL from 13th July 2026; Google Cloud EMEA Limited from 13th July 2026; Microsoft Ireland Operations Limited from 13th July 2026; Oracle Corporation UK Limited from 13 July 2026”
Link checked 18 August 2026
- Official sourceFinancial Conduct AuthorityCritical third parties: strengthening UK financial services
fca.org.uk
Link checked 18 August 2026
- Official sourceFinancial Conduct AuthorityOutsourcing and operational resilience — FCA guidance, referencing FG16/5
fca.org.uk
“implement an appropriate level of security to protect outsourced data”
Link checked 18 August 2026
Government data must stay in the country
Official name: Multi-region cloud and software-as-a-service; Government Security Classifications Policy · Central Digital and Data Office guidance, 5 February 2025; Government Cyber Security Policy Handbook principle B3, updated 28 January 2026 · Government policy document
British government data marked OFFICIAL, which is most of it, may be stored overseas. The legal, data protection and security checks have to stack up. The guidance says plainly that there is no blanket United Kingdom-only rule. Anything classified SECRET or above cannot go in public cloud at all.
Enforced by Central Digital and Data Office and Government Security Group, Cabinet Office
How this country controls where data goes: Approval each time · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Assess high-risk projects
- Secure the dataMust meet the national cyber centre's cloud security principles and the Government Cyber Security Standard.
- Keep the data in the country — applies at: SECRET and TOP SECRET onlyPublic cloud is not permitted for these classifications, including software-as-a-service built on public cloud.
- Prove the data stays under local controlDepartments must assess legal risk, including foreign government access, before choosing an overseas region.
What it costs if you get it wrong
- Order to stopPolicy and accreditation consequences rather than fines; a system can be refused approval to operate
Sources
- Official sourceCentral Digital and Data Office, Cabinet OfficeMulti-region cloud and software-as-a-service, 5 February 2025
gov.uk
“Public Cloud is not designed to protect SECRET and TOP SECRET information, including SaaS deployments using Public Cloud for hosting”
Link checked 18 August 2026
- Official sourceGovernment Security Group, Cabinet OfficeGovernment Cyber Security Policy Handbook, principle B3 data security, updated 28 January 2026
security.gov.uk
“there is no universal requirement for government data classified as OFFICIAL to be physically located in the UK”
Link checked 18 August 2026
Cyber security rules
Official name: The Network and Information Systems Regulations 2018 · SI 2018/506 · Directly binding regulation
These are the cyber security rules for water, energy, transport, health and digital infrastructure. They run a separate 72-hour incident clock to a separate regulator. That is why one incident often has to be reported twice. A bill to widen them to data centres and managed service providers is going through Parliament.
Enforced by Department for Science, Innovation and Technology
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 72 hoursTo the sector's competent authority, not to the privacy regulator.
- Secure the data
- Register or notify — applies at: Relevant digital service providers must register
What it costs if you get it wrong
- Fixed maximum fine: £17 million — about $22 millionIncident causing an immediate threat to life or significant harm to the economy
Sources
- Official sourceThe National Archives / UK GovernmentNetwork and Information Systems Regulations 2018, regulation 11
legislation.gov.uk
“without undue delay and in any event no later than 72 hours after the operator is aware that a NIS incident has occurred”
Link checked 18 August 2026
Children's data rules
Official name: Age appropriate design: a code of practice for online services (the children's code) · Statutory code under section 123 of the Data Protection Act 2018 · Statutory code of practice
This is a statutory code covering any online service children in Britain are likely to use. It includes services run from abroad. The consent age is 13, lower than most of Europe. But the design duties run to 18. The regulator is enforcing it. Reddit was fined 14.47 million pounds (about 18.5 million US dollars) in February 2026 for relying on users to declare their own age.
Enforced by Information Commissioner's Office
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Get a parent's consent for children — applies at: under 13 for consent-based servicesThe design code itself covers everyone under 18.
- No tracking or ads to childrenProfiling and geolocation off by default for children.
- Assess high-risk projectsMandatory for services likely to be accessed by children.
- Tell people what you doExplained in language a child can understand.
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionSerious breach of the underlying privacy law, or 4% of worldwide turnover if higher
Sources
- Official sourceInformation Commissioner's OfficeAge appropriate design code — about this code
ico.org.uk
“This is a statutory code of practice prepared under section 123 of the DPA 2018”
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeReddit issued with £14.47m fine for children's privacy failures, 24 February 2026
ico.org.uk
“relying on users to declare their age themselves is not enough when children may be at risk”
Link checked 18 August 2026
- Official sourceOfcomAge checks to protect children online — Online Safety Act duties
ofcom.org.uk
“all services which allow pornography must have highly effective age assurance processes in place by July 2025 at the latest”
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Europe's main privacy law
Official name: UK General Data Protection Regulation and Data Protection Act 2018 · Regulation (EU) 2016/679 as assimilated into UK law; Data Protection Act 2018 c. 12 · Act of parliament
This is the general privacy law. Data may leave the United Kingdom to an approved country with no paperwork. It may go anywhere else under a government-published contract plus a risk assessment. The law reaches foreign companies that target or monitor people in the United Kingdom. There is no size threshold. Those companies usually have to name a representative here.
Enforced by Information Commissioner's Office
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Tell people what you do
- Secure the data
- Keep records of how you use data
- Assess high-risk projectsYou need this where using the data is likely to be high risk for people.
- Let people see their dataYou have one month to respond. You can extend that by two months. You can now pause the clock while you seek clarification.
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Report breaches to the regulator — within 72 hours
- Tell affected peopleOnly where the risk to individuals is high.
- Appoint a representative — applies at: Organisations with no UK establishment that target or monitor people in the UKPublic authorities are exempt. So are you if you only handle data occasionally and at low risk.
- Appoint a data protection officer — applies at: Public authorities, large-scale monitoring, large-scale special category data
- Written vendor contract
- Put a transfer safeguard in place
- Delete data after a periodNo fixed period. You must justify the period you choose.
- Register or notifyMost companies must pay an annual data protection fee to the regulator.
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionSerious breach of the main obligations, or 4% of worldwide annual turnover if higher
- Percentage of global turnover: 4% of worldwide annual turnoverSerious breach of the main obligations
- Order to stopEnforcement notice requiring processing to stop
- Criminal liabilityKnowingly obtaining or disclosing personal data without the controller's consent; altering records to defeat a subject access request
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceThe National Archives / UK GovernmentData Protection Act 2018 (c. 12)
legislation.gov.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeTerritorial scope of the UK GDPR — ICO knowledge hub note
ico.org.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeCountries covered by UK adequacy regulations, updated 15 January 2026
ico.org.uk
Link checked 18 August 2026
General data protection law
Official name: Data (Use and Access) Act 2025 · 2025 c. 18; commenced by SI 2026/31 and SI 2026/82 · Act of parliament
This is the 2025 reform act. Most privacy changes started on 5 February 2026. The duty to run a complaints procedure started on 19 June 2026. Several parts are still waiting for ministers to switch them on, including the creation of a new regulator. It also raised marketing and cookie fines to the same level as privacy fines.
Enforced by Information Commissioner's Office
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Publish a complaints contact — from 19 June 2026Organisations must run a formal complaints procedure and acknowledge a complaint within 30 days.
- Document a legitimate interest — from 5 February 2026New list of 'recognised legitimate interests' that do not need a balancing test.
- Limit automated decisions — from 5 February 2026The rules on automated decision-making are looser now. That does not apply where you use sensitive data.
- Put a transfer safeguard in place — from 5 February 2026New test: protection in the destination must not be 'materially lower' than UK standards.
- Let people see their data — from 5 February 2026Your search only has to be reasonable and proportionate. You can pause the response clock to seek clarification.
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionBreach of the electronic communications rules, now aligned to privacy-law levels
- Percentage of global turnover: 4% of worldwide annual turnoverBreach of the electronic communications rules
Sources
- Official sourceThe National Archives / UK GovernmentThe Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026
legislation.gov.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeStatement on the commencement of the Data (Use and Access) Act, 5 February 2026
ico.org.uk
“issue fines of up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR)”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentThe Data (Use and Access) Act 2025 (Commencement No. 5) Regulations 2026
legislation.gov.uk
Link checked 18 August 2026
Telecoms rules (2025)
Official name: The Privacy and Electronic Communications (EC Directive) Regulations 2003 · SI 2003/2426, as amended by the Data (Use and Access) Act 2025 · Directly binding regulation
These are the marketing, cookies and communications-security rules. Two things changed recently and a lot of advice is out of date. The breach deadline for communications providers moved from 24 to 72 hours on 20 August 2025. And on 5 February 2026 the maximum fine jumped from 500,000 pounds to 17.5 million pounds (about 23 million US dollars). It can also be 4% of worldwide turnover.
Enforced by Information Commissioner's Office
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report breaches to the regulator — within 72 hours, from 20 August 2025Was 24 hours until 20 August 2025. Applies to providers of public electronic communications services.
- Tell affected people
- Get consentCookies and similar technologies, with narrow new exemptions for statistical and appearance-setting uses.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionSerious breach, since 5 February 2026
- Percentage of global turnover: 4% of worldwide annual turnoverSerious breach, since 5 February 2026
- Fixed maximum fine: £1,000 — about $1 thousandFailing to file a breach notification
Sources
- Official sourceInformation Commissioner's OfficeGuide to PECR — security breaches
ico.org.uk
“You must notify the ICO within 72 hours of becoming aware of the essential facts of the breach”
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeStatement on the commencement of the Data (Use and Access) Act, 5 February 2026
ico.org.uk
Link checked 18 August 2026
Cyber security rules (House of Lords Bill 32 of 2026-27)
Official name: Cyber Security and Resilience (Network and Information Systems) Bill · House of Lords Bill 32 of 2026-27 · Draft law
A bill, not law. It would extend the 2018 cyber rules to data centres, managed service providers and third-party technology suppliers, and widen what has to be reported. It had its second reading in the House of Lords on 14 July 2026. Do not plan as though it binds you yet.
Enforced by Department for Science, Innovation and Technology
How this country controls where data goes: No restriction
What you have to do
- Report cyber incidentsProposed only. Scope would widen to data centres, managed service providers and electrical load control.
Sources
- Official sourceHouse of Lords Library, UK ParliamentCyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026-27
lordslibrary.parliament.uk
Link checked 18 August 2026
- Official sourceHansard, UK ParliamentSecond reading debate, House of Lords, 14 July 2026
hansard.parliament.uk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the National Health Service offshoring guidance still represents current policy in August 2026
We could not confirm this against anything newer. The guidance page's own last-reviewed date is 7 February 2023. We found nothing newer on the NHS England Digital site. A three-year-old page in a fast-moving area may have been overtaken by procurement rules we did not see. Confidence lowered to medium for that rule.
The exact scope of the telecoms 'retain within the United Kingdom' backup duty
We could not confirm exactly which backup information this covers. The duty clearly exists. Check the full text before you rely on the detail.
Current status of the Apple technical capability notice litigation
We could not confirm this against the Investigatory Powers Tribunal's own site, which we could not read. Reports of a second challenge in August 2026 come from legal trade press only. No official source supports that part.
That the December 2023 Court of Appeal ruling again held the immigration exemption unlawful
We could not confirm this against an official court source. We checked it only against professional commentary and the March 2024 remedial regulations.
The five-year anti-money-laundering record retention period
We could not confirm this against an official source. We state it with a hedge and leave it out of the rules list.
That no mapping or geospatial keeping data in the country rule exists in the United Kingdom
We found no such rule, checked 18 August 2026. Searches turned up licensing terms only, not location rules. Finding nothing is not proof that nothing exists. Confidence medium. If you work in gambling, check before you rely on it.
Whether any further Data (Use and Access) Act commencement regulations were made between 19 June and 18 August 2026
We confirmed Commencement Regulations No. 5 and No. 6. A later one made in the past few weeks might not be indexed yet, so we could not rule that out.
The precise incident reporting deadlines proposed in the Cyber Security and Resilience Bill
We could not confirm the hour figures. The Lords Library briefing confirms the wider coverage but does not state them. We did not read the bill text line by line.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.