United Kingdom
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Data can leave the United Kingdom, but you need the right paperwork first. Sending it to Europe or to about fifteen other approved places needs nothing extra. Anywhere else needs a government-published contract and a risk check. No general law forces data to stay in Britain. The privacy regulator is busy and its fines are getting bigger.
Eight questions about the United Kingdom
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do the United Kingdom's rules apply to my company?
Yes. British privacy law reaches a company anywhere in the world if it deliberately offers goods or services to people in the United Kingdom, or watches what they do online. There is no size or revenue floor to hide under. If you are caught and have no British office, you generally have to name a representative in the United Kingdom, unless you are a public body or your processing is rare and low risk.
Territorial reach comes from Article 3 of the UK GDPR; the representative duty is Article 27. The regulator's own guidance stresses that a website merely being reachable from Britain is not enough — it looks for deliberate targeting such as pricing in pounds, a .co.uk address, British marketing or British delivery. 'Monitoring behaviour' is read broadly and covers one-off profiling, not just continuous tracking. The regulator also notes that the representative is not itself the enforcement target: it pursues the overseas company. The February 2026 fine against Reddit, a United States company, shows this is not theoretical.
Sources
- Official sourceInformation Commissioner's OfficeTerritorial scope of the UK GDPR — ICO knowledge hub note
ico.org.uk
“generally need to appoint someone to act as their representative in the UK”
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeReddit issued with £14.47m fine for children's privacy failures, 24 February 2026
ico.org.uk
Link checked 18 August 2026
Can I store my users' data outside the United Kingdom?
Yes, with paperwork. The United Kingdom has no general law forcing data to stay in the country. Send it to the European Economic Area or another approved country and you need nothing extra; send it anywhere else and you need an approved contract plus a written risk assessment. Three industries are stricter: telecoms, the health service and classified government work. Banking, payments, insurance, securities, education, online gambling and mapping have no location rule that we could find.
Sector by sector, checked on 18 August 2026. TELECOMS — the strictest layer. The Electronic Communications (Security Measures) Regulations 2022 require a network provider to be able to run its network 'without reliance on persons, equipment or stored data located outside the United Kingdom', and regulation 9(2)(a) requires certain backup information to be retained within the United Kingdom. That is a genuine copy-must-stay rule. HEALTH — National Health Service and social care data, including confidential patient information, may be held in public cloud, but only in the United Kingdom, the European Economic Area, or a country the United Kingdom has declared adequate. In practice that removes the standard-contract route that other industries can use. GOVERNMENT — data marked OFFICIAL may sit overseas; the Cabinet Office guidance says in terms that there is no universal requirement for it to be in the United Kingdom. But public cloud is not permitted for SECRET or TOP SECRET at all. FINANCE — the regulators impose access, audit, resilience and exit requirements, and from 13 July 2026 four cloud providers are directly supervised, but there is no requirement to keep the data in Britain. GAMBLING — a common myth. Putting remote gambling equipment in Great Britain triggers a licensing requirement; it is not a rule that the equipment must be there. MAPPING AND GEOSPATIAL — no location rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceThe National Archives / UK GovernmentThe Electronic Communications (Security Measures) Regulations 2022, regulations 3 and 9
legislation.gov.uk
“able, without reliance on persons, equipment or stored data located outside the United Kingdom, to identify the risks of security compromises”
Link checked 18 August 2026
- Official sourceNHS England DigitalNHS and social care data: off-shoring and the use of public cloud services — guidance
digital.nhs.uk
“NHS and social care organisations can safely locate health and care data, including confidential patient information, in the public cloud”
Link checked 18 August 2026
- Official sourceCentral Digital and Data Office, Cabinet OfficeMulti-region cloud and software-as-a-service, 5 February 2025
gov.uk
“there is no universal requirement for government data classified as OFFICIAL to be physically located in the UK”
Link checked 18 August 2026
- Official sourceGambling CommissionRemote gambling equipment — Gambling Commission guidance
gamblingcommission.gov.uk
“If an operator providing facilities for remote gambling locates any 'remote gambling equipment' ... in Great Britain that operator is required to hold a form of remote gambling licence”
Link checked 18 August 2026
What do I need in place before data leaves the United Kingdom?
The model is an approved-list one. If the destination is on the government's approved list you may send data with no extra paperwork. If it is not, you must sign the government's own contract template and run a risk assessment first. The list is well populated: the whole European Economic Area plus Andorra, Argentina, the Faroe Islands, Gibraltar, Guernsey, the Isle of Man, Israel, Jersey, New Zealand, South Korea, Switzerland and Uruguay, with partial cover for Canada, Japan and the United States.
Three routes: adequacy regulations (the 'data bridges'), appropriate safeguards, or a narrow exception. The main safeguard is the International Data Transfer Agreement, or the Addendum that bolts onto the European standard clauses. Group-wide binding corporate rules are also available. Canada is covered only for private-sector bodies under its federal privacy law, Japan only for private-sector bodies under its own act, and the United States only through the UK Extension to the EU-US Data Privacy Framework, which means only certified American organisations. The Data (Use and Access) Act 2025 replaced the old 'essentially equivalent' test with a lower 'not materially lower' standard, and codified a risk-based approach to the exporter's own assessment. The regulator refreshed its transfer guidance on 15 January 2026. Flows the other way — from the European Union into the United Kingdom — depend on the European Commission's renewed adequacy decisions of 19 December 2025, which run to 27 December 2031.
Sources
- Official sourceInformation Commissioner's OfficeIs the restricted transfer covered by adequacy regulations? — list of covered countries, updated 15 January 2026
ico.org.uk
“not materially lower”
Link checked 18 August 2026
- Official sourceEuropean Commission / EUR-LexCommission Implementing Decision (EU) 2025/2574 of 19 December 2025 renewing UK adequacy under the GDPR (valid to 27 December 2031)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentData (Use and Access) Act 2025 (c. 18), Part 5 — data protection and privacy
legislation.gov.uk
Link checked 18 August 2026
Who enforces the rules in the United Kingdom, and what can they do?
The Information Commissioner's Office, and it is very much working. It fined Capita fourteen million pounds (about $18 million) in October 2025, Reddit £14.47 million (about $18.5 million) in February 2026, and the owner of Imgur in the same month, and it issues smaller marketing fines almost monthly. Watch a quirk: a replacement body called the Information Commission legally exists but had no staff and did no work in its first financial year, so the old office is still the one that acts.
The Information Commission was incorporated on 20 August 2025 under the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025. Its own first annual report says there was 'no operational activity during the period from 20 August 2025 to 31 March 2026', that it had no employees, and that the secondary legislation transferring functions to it 'has not yet been laid'. Until that transfer happens, every notice, fine and decision comes from the Information Commissioner. Sector regulators are separately active: the Financial Conduct Authority and the Bank of England's Prudential Regulation Authority began direct oversight of designated cloud providers on 13 July 2026; the communications regulator Ofcom is running an enforcement programme on age checks under the Online Safety Act; and the telecoms security regime is supervised by Ofcom under the Communications Act.
Sources
- Official sourceInformation Commissioner's OfficeCapita plc and Capita Pension Solutions Ltd — enforcement action, October 2025
ico.org.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeReddit issued with £14.47m fine for children's privacy failures, 24 February 2026
ico.org.uk
“failed to apply any robust age assurance mechanism and therefore did not have a lawful basis for processing the personal information of children under the age of 13”
Link checked 18 August 2026
- Official sourceInformation Commission (laid before Parliament)Information Commission Annual Report and Accounts 2025-26, HC 531, July 2026
assets.publishing.service.gov.uk
“there was no operational activity during the period from 20 August 2025 to 31 March 2026”
Link checked 18 August 2026
How long do I have to keep the data?
There is no single deletion deadline. The rule is that you keep personal data only as long as you actually need it, and you must be able to explain the period you chose. Pulling the other way are minimum keeping periods: company and tax records for six years, telecoms connection records for up to twelve months if the government serves a notice, and telecoms security data for thirteen months. Where a minimum and a maximum clash, the legal duty to keep wins and you keep the data.
The ceiling is the storage limitation principle in Article 5(1)(e) of the UK GDPR — no fixed number, a documented and justified period. The floors we verified: company accounting records must be kept for six years from the end of the financial year they relate to, longer if a tax enquiry is open; a retention notice under the Investigatory Powers Act 2016 may require a telecoms operator to hold communications data, including internet connection records, for a maximum of twelve months; the telecoms security regulations require access data to be 'held securely for at least 13 months' and other security records for at least three years. Anti-money-laundering record keeping is generally five years, but we did not verify that against an official source in this run. The conflict is resolved by the lawful-obligation basis: where another law requires retention, that is the legal ground for continuing to hold the data, and the deletion duty does not bite until the statutory period ends.
Sources
- Official sourceGOV.UKCompany and accounting records — how long to keep them
gov.uk
“You must keep records for 6 years from the end of the last company financial year they relate to”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentInvestigatory Powers Act 2016, section 87 — retention notices, 12-month maximum
legislation.gov.uk
“A retention notice must not require any data to be retained for more than 12 months”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentElectronic Communications (Security Measures) Regulations 2022, regulations 3(4) and 6(3)(e)
legislation.gov.uk
“held securely for at least 13 months”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentUK General Data Protection Regulation, Article 5(1)(e) — storage limitation
legislation.gov.uk
Link checked 18 August 2026
What happens if there is a breach?
Count at least three clocks. Any organisation has 72 hours to tell the privacy regulator about a personal data breach, and must tell the affected people if the risk to them is high. Telecoms and internet providers also have 72 hours under the electronic communications rules — that used to be 24 hours and quietly changed on 20 August 2025. Operators of essential services such as water, energy and transport have their own 72-hour clock to their own regulator.
Clock one: UK GDPR Article 33, 72 hours from becoming aware, to the Information Commissioner. Clock two: the Privacy and Electronic Communications Regulations, which apply to providers of public electronic communications services. The regulator's own guidance now states 'You must notify the ICO within 72 hours of becoming aware of the essential facts of the breach', a change made by the Data (Use and Access) Act 2025 on 20 August 2025; the old rule was 24 hours and a great deal of stale advice still says so. A separate fixed £1,000 penalty applies for failing to file that notification at all. Clock three: regulation 11 of the Network and Information Systems Regulations 2018 — 'without undue delay and in any event no later than 72 hours' to the relevant competent authority. Financial firms have a fourth, less precise clock: notify the Financial Conduct Authority of anything significant without delay. The overlap is where people fail: the same incident can be reportable to the privacy regulator, a sector regulator and, for designated cloud providers, under the critical third parties regime.
Sources
- Official sourceInformation Commissioner's OfficeGuide to PECR — security breaches, 72-hour notification
ico.org.uk
“You must notify the ICO within 72 hours of becoming aware of the essential facts of the breach”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentNetwork and Information Systems Regulations 2018, regulation 11 — incident notification
legislation.gov.uk
“without undue delay and in any event no later than 72 hours after the operator is aware that a NIS incident has occurred”
Link checked 18 August 2026
What trips people up in the United Kingdom?
Five. (1) A child can consent at 13 here, not 16 — but the children's design code covers everyone under 18, and the regulator fined Reddit £14.47 million (about $18.5 million) for weak age checks. (2) Telecoms firms must keep some backup data physically in Britain. (3) Health service data can only go to approved countries, so the standard contract does not help you. (4) Misusing personal data can be a crime, not just a fine. (5) The government can secretly order a company to weaken its security, and Apple is fighting one of those orders right now.
(1) The children's code is a statutory code made under section 123 of the Data Protection Act 2018 and applies to any online service likely to be accessed by children in the United Kingdom. Note also that the age-of-consent provision people cite, section 9 of the Data Protection Act 2018, was deleted on 31 December 2020; the 13-year rule now lives in Article 8 of the UK GDPR. Separately, the Online Safety Act requires 'highly effective age assurance' for pornographic content since July 2025, policed by Ofcom, which is a different regulator with different powers. (2) Regulation 9(2)(a) of the telecoms security regulations. (3) National Health Service and social care guidance permits only the United Kingdom, the European Economic Area and countries with UK adequacy. (4) The Data Protection Act 2018 creates criminal offences, including knowingly obtaining or disclosing personal data without the controller's consent and altering records to frustrate a subject access request; these attach to individuals as well as companies. (5) Technical capability notices under the Investigatory Powers Act 2016 are secret, are not published, and can reach companies outside the United Kingdom; Apple's challenge is before the Investigatory Powers Tribunal and a second challenge was reported in August 2026. Bonus trap: the immigration exemption in Schedule 2 to the Data Protection Act 2018 was held incompatible by the Court of Appeal in 2021, suspended, and rewritten twice, most recently in March 2024 — treat any reliance on it as legally fragile.
Sources
- Official sourceInformation Commissioner's OfficeAge appropriate design: a code of practice for online services — about this code
ico.org.uk
“This is a statutory code of practice prepared under section 123 of the DPA 2018”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentData Protection Act 2018, section 9 — omitted on 31 December 2020
legislation.gov.uk
“S. 9 omitted (31.12.2020)”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentThe Data Protection Act 2018 (Amendment of Schedule 2 Exemptions) Regulations 2024 — second rewrite of the immigration exemption
legislation.gov.uk
Link checked 18 August 2026
- Official sourceUK ParliamentData protection regulations and the immigration exemption — House of Lords Library
lordslibrary.parliament.uk
“incompatible with retained EU law”
Link checked 18 August 2026
What is changing soon in the United Kingdom?
Two things to watch in the next twelve months. A cyber security bill is going through Parliament and will widen incident reporting to data centres and managed service suppliers — it is not law yet, so do not plan as if it were. And the privacy regulator is due to be replaced by a new body called the Information Commission, but only once ministers lay the paperwork, which had not happened by mid-2026. The regulator is also writing a statutory code on artificial intelligence.
Pending legislation: the Cyber Security and Resilience (Network and Information Systems) Bill, House of Lords Bill 32 of 2026-27, had its second reading in the Lords on 14 July 2026. It expands the 2018 regime to data centres, electrical load control and third-party information technology suppliers, with much of the detail left to later secondary legislation. Dormant switches that could change the picture with no consultation: (1) the Secretary of State may serve a retention notice on a telecoms operator at any time, up to twelve months of data, and the notice is not published; (2) technical capability notices under the same Act are secret and have already been used against a major cloud provider; (3) HM Treasury can designate further critical third parties by statutory instrument, as it did for four cloud providers on 8 July 2026 with effect five days later; (4) the European Commission's renewed adequacy decision for the United Kingdom runs to 27 December 2031 but can be suspended if British law diverges; (5) ministers can commence the remaining parts of the Data (Use and Access) Act 2025, including the transfer of the regulator's functions, by regulations alone.
Sources
- Official sourceUK ParliamentCyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026-27 — Lords Library briefing
lordslibrary.parliament.uk
“data centres, electrical load control, and third-party IT products”
Link checked 18 August 2026
- Official sourceInformation CommissionInformation Commission Annual Report and Accounts 2025-26 — transfer of functions not yet laid
assets.publishing.service.gov.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeOne year on: marking the 12-month commencement of the Data (Use and Access) Act, June 2026
ico.org.uk
“starting work on a new statutory code of practice on artificial intelligence”
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules4 rules
UK General Data Protection Regulation and Data Protection Act 2018
Act of parliament · Regulation (EU) 2016/679 as assimilated into UK law; Data Protection Act 2018 c. 12
The general privacy law. Data may leave the United Kingdom to an approved country with no paperwork, or anywhere else under a government-published contract plus a risk assessment. It reaches foreign companies that target or monitor people in the United Kingdom, with no size threshold, and usually requires them to name a representative here.
Enforced by Information Commissioner's Office
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Tell people what you do
- Secure the data
- Keep records of processing
- Assess high-risk projectsRequired where processing is likely to result in a high risk to people.
- Let people see their dataOne month to respond, extendable by two months; the clock can now be paused while you seek clarification.
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Report breaches to the regulator — within 72 hours
- Tell affected peopleOnly where the risk to individuals is high.
- Appoint a local representative — applies at: Organisations with no UK establishment that target or monitor people in the UKPublic authorities and occasional low-risk processing are exempt.
- Appoint a data protection officer — applies at: Public authorities, large-scale monitoring, large-scale special category data
- Written vendor contract
- Put a transfer safeguard in place
- Delete data after a periodNo fixed period. You must justify the period you choose.
- Register or notifyMost controllers must pay an annual data protection fee to the regulator.
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionSerious breach of the main obligations, or 4% of worldwide annual turnover if higher
- Percentage of global turnover: 4% of worldwide annual turnoverSerious breach of the main obligations
- Order to stopEnforcement notice requiring processing to stop
- Criminal liabilityKnowingly obtaining or disclosing personal data without the controller's consent; altering records to defeat a subject access request
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceThe National Archives / UK GovernmentData Protection Act 2018 (c. 12)
legislation.gov.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeTerritorial scope of the UK GDPR — ICO knowledge hub note
ico.org.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeCountries covered by UK adequacy regulations, updated 15 January 2026
ico.org.uk
Link checked 18 August 2026
Data (Use and Access) Act 2025
Act of parliament · 2025 c. 18; commenced by SI 2026/31 and SI 2026/82
The 2025 reform act. Most privacy changes started on 5 February 2026 and the duty to run a complaints procedure started on 19 June 2026, but several parts — including the creation of a new regulator — are still waiting for ministers to switch them on. It also raised marketing and cookie fines to the same level as privacy fines.
Enforced by Information Commissioner's Office
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Publish a complaints contact — from 19 June 2026Organisations must run a formal complaints procedure and acknowledge a complaint within 30 days.
- Document a legitimate interest — from 5 February 2026New list of 'recognised legitimate interests' that do not need a balancing test.
- Limit automated decisions — from 5 February 2026Automated decision-making loosened, except where special category data is used.
- Put a transfer safeguard in place — from 5 February 2026New test: protection in the destination must not be 'materially lower' than UK standards.
- Let people see their data — from 5 February 2026Searches need only be reasonable and proportionate; the response clock can be paused for clarification.
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionBreach of the electronic communications rules, now aligned to privacy-law levels
- Percentage of global turnover: 4% of worldwide annual turnoverBreach of the electronic communications rules
Sources
- Official sourceThe National Archives / UK GovernmentThe Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026
legislation.gov.uk
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeStatement on the commencement of the Data (Use and Access) Act, 5 February 2026
ico.org.uk
“issue fines of up to £17.5 million or 4% of global turnover under the Privacy and Electronic Communications Regulations (PECR)”
Link checked 18 August 2026
- Official sourceThe National Archives / UK GovernmentThe Data (Use and Access) Act 2025 (Commencement No. 5) Regulations 2026
legislation.gov.uk
Link checked 18 August 2026
The Privacy and Electronic Communications (EC Directive) Regulations 2003
Directly binding regulation · SI 2003/2426, as amended by the Data (Use and Access) Act 2025 · Telecoms
The marketing, cookies and communications-security rules. Two things changed recently and a lot of advice is out of date: the breach deadline for communications providers moved from 24 to 72 hours on 20 August 2025, and the maximum fine jumped from £500,000 to £17.5 million (about $23 million) or 4% of worldwide turnover on 5 February 2026.
Enforced by Information Commissioner's Office
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report breaches to the regulator — within 72 hours, from 20 August 2025Was 24 hours until 20 August 2025. Applies to providers of public electronic communications services.
- Tell affected people
- Get consentCookies and similar technologies, with narrow new exemptions for statistical and appearance-setting uses.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionSerious breach, since 5 February 2026
- Percentage of global turnover: 4% of worldwide annual turnoverSerious breach, since 5 February 2026
- Fixed maximum fine: £1,000 — about $1 thousandFailing to file a breach notification
Sources
- Official sourceInformation Commissioner's OfficeGuide to PECR — security breaches
ico.org.uk
“You must notify the ICO within 72 hours of becoming aware of the essential facts of the breach”
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeStatement on the commencement of the Data (Use and Access) Act, 5 February 2026
ico.org.uk
Link checked 18 August 2026
Cyber Security and Resilience (Network and Information Systems) Bill
Draft law · House of Lords Bill 32 of 2026-27
A bill, not law. It would extend the 2018 cyber rules to data centres, managed service providers and third-party technology suppliers, and widen what has to be reported. It had its second reading in the House of Lords on 14 July 2026. Do not plan as though it binds you yet.
Enforced by Department for Science, Innovation and Technology
Transfer model: No restriction
What it makes you do
- Report cyber incidentsProposed only. Scope would widen to data centres, managed service providers and electrical load control.
Sources
- Official sourceHouse of Lords Library, UK ParliamentCyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 of 2026-27
lordslibrary.parliament.uk
Link checked 18 August 2026
- Official sourceHansard, UK ParliamentSecond reading debate, House of Lords, 14 July 2026
hansard.parliament.uk
Link checked 18 August 2026
Industry rules7 rules
The Electronic Communications (Security Measures) Regulations 2022, with the Telecommunications Security Code of Practice 2026 (version 1.1)
Directly binding regulation · SI 2022/933, made under the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021 · Telecoms
The one genuine keep-a-copy-here rule in British law. Telecoms network providers must hold certain backup information inside the United Kingdom and must be able to keep the network running without depending on people, kit or data abroad. A revised statutory code of practice was published on 14 July 2026.
Enforced by Office of Communications
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryBackup information must be retained within the United Kingdom, and the provider must be able to run the network without relying on people, equipment or stored data outside the United Kingdom.
- Keep logs — 13 monthsData supporting monitoring of privileged access must be held securely for at least 13 months.
- Keep data for a minimum period — 3 yearsSecurity assessment records must be kept at least three years.
- Secure the data
- Independent auditRisk assessment at least once every 12 months.
What it costs if you get it wrong
- Percentage of global turnover: 10% of turnover, or £100,000 per day for continuing contraventionBreach of the security duties, enforced by Ofcom under the Communications Act
Sources
- Official sourceThe National Archives / UK GovernmentThe Electronic Communications (Security Measures) Regulations 2022, regulations 3, 6 and 9
legislation.gov.uk
“to be created or acquired ... and to retain within the United Kingdom”
Link checked 18 August 2026
- Official sourceDepartment for Science, Innovation and TechnologyTelecommunications Security Code of Practice 2026 (version 1.1), published 14 July 2026
gov.uk
“able, without reliance on persons, equipment or stored data located outside the United Kingdom, to identify the risks of security compromises”
Link checked 18 August 2026
Investigatory Powers Act 2016
Act of parliament · 2016 c. 25, sections 87 and following; technical capability notices under Part 9 · Telecoms
A secret, on-demand power rather than a standing rule. The government can order a telecoms or internet company to keep connection records for up to twelve months, and can separately order a company to provide a technical capability to hand over data. Neither kind of order is published, so no public list exists.
Enforced by Home Office
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 1 yearOnly where the Secretary of State serves a retention notice. Notices are not published.
- Keep logs — 1 yearCan include internet connection records.
- Do not hand data to foreign authorities on demandInverted here: the state can compel a company to build or keep a capability to hand data over, including companies outside the United Kingdom.
What it costs if you get it wrong
- Criminal liabilityUnlawfully disclosing the existence of a notice
Sources
- Official sourceThe National Archives / UK GovernmentInvestigatory Powers Act 2016, section 87 — retention notices
legislation.gov.uk
“A retention notice must not require any data to be retained for more than 12 months”
Link checked 18 August 2026
- Official sourceLink may be brokenInvestigatory Powers TribunalApple Inc v Secretary of State for the Home Department — Investigatory Powers Tribunal
investigatorypowerstribunal.org.uk
Link checked 18 August 2026
NHS and social care data: off-shoring and the use of public cloud services
Regulator guideline · NHS England Digital guidance, last updated 7 February 2023 · Health and social care
Health and social care records may be held in public cloud, but only inside the United Kingdom, the European Economic Area, or a country the United Kingdom has formally approved. That is narrower than the general law, because the standard contract route other industries rely on is not offered here. A senior information risk owner must sign it off.
Enforced by NHS England
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Assess high-risk projectsRequired before any offshoring decision.
- Secure the data
- Written vendor contract
- Hold a security certificateData Security and Protection Toolkit completion is expected of suppliers handling health and care data.
What it costs if you get it wrong
- Order to stopContractual and regulatory consequences rather than a statutory fine; the privacy regulator can still act under the general law
Sources
- Official sourceNHS England DigitalNHS and social care data: off-shoring and the use of public cloud services — guidance
digital.nhs.uk
“Senior Information Risk Owners (SIROs) locally should be satisfied about appropriate security arrangements”
Link checked 18 August 2026
The Critical Third Parties (Designation) Regulations 2026, with FCA policy statement PS24/16 and Bank of England supervisory statement SS6/24
Directly binding regulation · SI 2026/777, made under section 312L(1) of the Financial Services and Markets Act 2000 · Finance
British financial regulators do not require customer data to stay in the country. They require you to keep control of it: access and audit rights, resilience testing and a real exit plan. Since 13 July 2026 four cloud providers — Amazon, Google, Microsoft and Oracle — are supervised directly, which is new and changes who carries the risk.
Enforced by Financial Conduct Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the data
- Written vendor contractOutsourcing contracts must give the firm and the regulators access, audit and information rights, and a workable exit plan.
- Report cyber incidentsDesignated providers must report incidents affecting the financial sector to the regulators.
- Independent audit
- Register or notifyFirms must keep an outsourcing register and notify material outsourcing.
What it costs if you get it wrong
- Order to stopDirection to a designated provider, including a direction to stop providing services to the financial sector
- Loss of your licenceRegulatory action against the regulated firm for failed outsourcing controls
Sources
- Official sourceThe National Archives / UK GovernmentThe Critical Third Parties (Designation) Regulations 2026
legislation.gov.uk
“Amazon Web Services EMEA SARL from 13th July 2026; Google Cloud EMEA Limited from 13th July 2026; Microsoft Ireland Operations Limited from 13th July 2026; Oracle Corporation UK Limited from 13 July 2026”
Link checked 18 August 2026
- Official sourceFinancial Conduct AuthorityCritical third parties: strengthening UK financial services
fca.org.uk
Link checked 18 August 2026
- Official sourceFinancial Conduct AuthorityOutsourcing and operational resilience — FCA guidance, referencing FG16/5
fca.org.uk
“implement an appropriate level of security to protect outsourced data”
Link checked 18 August 2026
Multi-region cloud and software-as-a-service; Government Security Classifications Policy
Government policy document · Central Digital and Data Office guidance, 5 February 2025; Government Cyber Security Policy Handbook principle B3, updated 28 January 2026 · Government
British government data marked OFFICIAL, which is most of it, may be stored overseas if the legal, data protection and security checks stack up — the guidance says plainly there is no blanket United Kingdom-only rule. Anything classified SECRET or above cannot go in public cloud at all.
Enforced by Central Digital and Data Office and Government Security Group, Cabinet Office
Transfer model: Approval each time · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Assess high-risk projects
- Secure the dataMust meet the national cyber centre's cloud security principles and the Government Cyber Security Standard.
- Keep the data in the country — applies at: SECRET and TOP SECRET onlyPublic cloud is not permitted for these classifications, including software-as-a-service built on public cloud.
- Prove the data stays under local controlDepartments must assess legal risk, including foreign government access, before choosing an overseas region.
What it costs if you get it wrong
- Order to stopPolicy and accreditation consequences rather than fines; a system can be refused approval to operate
Sources
- Official sourceCentral Digital and Data Office, Cabinet OfficeMulti-region cloud and software-as-a-service, 5 February 2025
gov.uk
“Public Cloud is not designed to protect SECRET and TOP SECRET information, including SaaS deployments using Public Cloud for hosting”
Link checked 18 August 2026
- Official sourceGovernment Security Group, Cabinet OfficeGovernment Cyber Security Policy Handbook, principle B3 data security, updated 28 January 2026
security.gov.uk
“there is no universal requirement for government data classified as OFFICIAL to be physically located in the UK”
Link checked 18 August 2026
The Network and Information Systems Regulations 2018
Directly binding regulation · SI 2018/506 · Government
The cyber security regime for water, energy, transport, health and digital infrastructure. It runs a separate 72-hour incident clock to a separate regulator, which is why one incident often has to be reported twice. A bill to widen it to data centres and managed service providers is going through Parliament.
Enforced by Department for Science, Innovation and Technology
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 72 hoursTo the sector's competent authority, not to the privacy regulator.
- Secure the data
- Register or notify — applies at: Relevant digital service providers must register
What it costs if you get it wrong
- Fixed maximum fine: £17 million — about $22 millionIncident causing an immediate threat to life or significant harm to the economy
Sources
- Official sourceThe National Archives / UK GovernmentNetwork and Information Systems Regulations 2018, regulation 11
legislation.gov.uk
“without undue delay and in any event no later than 72 hours after the operator is aware that a NIS incident has occurred”
Link checked 18 August 2026
Age appropriate design: a code of practice for online services (the children's code)
Statutory code of practice · Statutory code under section 123 of the Data Protection Act 2018 · Social media and online platforms
A statutory code covering any online service children in Britain are likely to use, including services run from abroad. The consent age is 13, lower than most of Europe, but the design duties run to 18. The regulator is enforcing it: Reddit was fined £14.47 million (about $18.5 million) in February 2026 for relying on users to declare their own age.
Enforced by Information Commissioner's Office
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Get a parent's consent for children — applies at: under 13 for consent-based servicesThe design code itself covers everyone under 18.
- No tracking or ads to childrenProfiling and geolocation off by default for children.
- Assess high-risk projectsMandatory for services likely to be accessed by children.
- Tell people what you doExplained in language a child can understand.
What it costs if you get it wrong
- Fixed maximum fine: £17.5 million — about $23 millionSerious breach of the underlying privacy law, or 4% of worldwide turnover if higher
Sources
- Official sourceInformation Commissioner's OfficeAge appropriate design code — about this code
ico.org.uk
“This is a statutory code of practice prepared under section 123 of the DPA 2018”
Link checked 18 August 2026
- Official sourceInformation Commissioner's OfficeReddit issued with £14.47m fine for children's privacy failures, 24 February 2026
ico.org.uk
“relying on users to declare their age themselves is not enough when children may be at risk”
Link checked 18 August 2026
- Official sourceOfcomAge checks to protect children online — Online Safety Act duties
ofcom.org.uk
“all services which allow pornography must have highly effective age assurance processes in place by July 2025 at the latest”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the National Health Service offshoring guidance still represents current policy in August 2026
The guidance page's own last-reviewed date is 7 February 2023. Nothing newer was found on the NHS England Digital site during this run, but a three-year-old page in a fast-moving area may have been superseded by procurement-level rules we did not see. Confidence lowered to medium for that rule.
The exact scope of the telecoms 'retain within the United Kingdom' backup duty
Regulation 9(2)(a) was read via an automated fetch of the statutory instrument rather than a full manual reading of regulation 9 in context. The duty clearly exists; which categories of backup information it covers should be confirmed against the full text before relying on it.
Current status of the Apple technical capability notice litigation
The Investigatory Powers Tribunal's own site returned a JavaScript redirect and could not be read. Reports of a second challenge in August 2026 come from legal trade press only, so no official backlink supports that part.
That the December 2023 Court of Appeal ruling again held the immigration exemption unlawful
Verified only against professional commentary and the March 2024 remedial regulations. The judgment itself was not opened on an official court site during this run.
The five-year anti-money-laundering record retention period
Not verified against an official source in this run; stated with a hedge and excluded from the rules array.
That no mapping or geospatial data localisation rule exists in the United Kingdom
No rule found, checked 18 August 2026. This is a negative and cannot be proved; searches surfaced only licensing terms, not location rules. Confidence medium.
Whether any further Data (Use and Access) Act commencement regulations were made between 19 June and 18 August 2026
Commencement Regulations No. 5 and No. 6 were confirmed; a later instrument made in the last few weeks would not necessarily be indexed yet.
The precise incident reporting deadlines proposed in the Cyber Security and Resilience Bill
The Lords Library briefing confirms the scope expansion but does not state the hour figures, and the bill text was not read line by line.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- United Kingdom versus Bulgaria
- United Kingdom versus Canada
- United Kingdom versus China
- United Kingdom versus France
- United Kingdom versus Germany
- United Kingdom versus Greece
- United Kingdom versus Hungary
- United Kingdom versus India
- United Kingdom versus Italy
- United Kingdom versus Japan
- United Kingdom versus Slovakia
- United Kingdom versus United States