UK GDPR
UK General Data Protection Regulation (with the Data Protection Act 2018)
The UK's data protection law — substantively parallel to EU GDPR but separately enforced, with its own guidance on AI and automated decision-making.
30 individual requirements seeded and assessable in AIXYRA.
After Brexit, the UK retained GDPR as 'UK GDPR', operating alongside the Data Protection Act 2018 and enforced by the Information Commissioner's Office. The core obligations mirror the EU regime — lawful basis, transparency, impact assessments, automated decision-making safeguards — but they are a distinct legal framework with distinct guidance, and organizations serving both markets must evidence compliance with each.
The ICO has been notably active on AI, publishing guidance on AI and data protection, explainability, and automated decision-making. For organizations running AI across both EU and UK markets, the practical need is one assessment process that maps to both regimes without duplicating work.
Who it applies to
Organizations processing personal data of people in the UK — including non-UK organizations offering goods or services to, or monitoring, UK residents.
Key requirement themes
Parallel-but-separate compliance
UK GDPR mirrors EU GDPR but is separately enforced — dual-market organizations must evidence both.
ICO AI guidance
The ICO expects demonstrable accountability for AI: documented risk assessment, explainability, and human oversight.
Automated decision-making
Significant automated decisions carry safeguard and transparency duties parallel to EU Article 22.
International transfers
Data flows between the UK, EU, and third countries need mapped transfer mechanisms — which requires knowing where AI data flows.
Orientation for evaluators — not legal advice. Consult counsel for obligations specific to your organization.
How AIXYRA helps
- UK GDPR ships as its own seeded framework, so UK obligations are assessed and evidenced distinctly from EU GDPR
- One assessment pass maps an AI system to UK GDPR, EU GDPR, and the EU AI Act together — no duplicate programs
- Data source registry and dependency graphs give transfer and flow analysis a factual basis
- Obligation calendar tracks UK-specific deadlines alongside every other framework's
UK GDPR FAQ
Is UK GDPR different from EU GDPR?
The obligations are substantively parallel, but UK GDPR is a separate legal framework enforced by the ICO, with its own guidance — including active AI-specific guidance. Organizations serving both markets need to evidence compliance with each regime separately.
Does AIXYRA treat UK GDPR as a separate framework?
Yes — UK GDPR is one of the thirteen built-in frameworks, with its own seeded articles. Assessments can map an AI system to UK GDPR and EU GDPR in the same pass, so shared evidence is captured once and reported per framework.
Assess your AI systems against UK GDPR
UK GDPR ships built into AIXYRA — and the same assessment maps to every other enabled framework at once.