Smarter compliance for UK GDPR

The UK’s data rules have split from the EU. Cookie exemptions, whitelisted marketing, and complaint rules mean you’ll need to adapt. We keep your policies, consents, and records in line, so you don’t have to chase every change.


Brexit split UK GDPR from the EU’s rulebook. The Data (Use and Access) Act 2025 introduced analytics cookie exemptions, stricter complaint handling, and changes to how businesses can use and share data. iubenda keeps pace with these updates, so you can stay aligned with the latest regulations without having to start from scratch.

You’re in good company

150,000+ businesses rely on iubenda to adapt to changing UK and global data laws.

What UK GDPR means for you

The framework started out similar to the EU’s GDPR, but the 2025 Act added new obligations. If you process personal data and any of these apply, UK GDPR rules apply to you.


Checklist icon

You’re based in the UK

Every organisation must comply, regardless of size.

Checklist icon

You target UK users

Offering services (free or paid) triggers the rules.

What happens when you skip compliance?

UK GDPR enforcement is active, and the fallout goes beyond fines. Missed complaints, cookie issues, or cross-border mismatches can all cost you time, trust, and money.


Judge hammer

Fines

Up to £17.5M or 4% of global turnover.

Cookie Policy

Cookie rules

Analytics may be exempt, but users must have clear opt-out options.

Papers and Docs

Complaint handling

Miss the 30-day acknowledgement window and you’re on the regulator’s radar.

Feature Item 11

Cross-border divergence

The EU and UK frameworks no longer align, so if you operate in both, you need coverage for each.

Key requirements under the UK Act

The 2025 Act refined core GDPR duties. Here’s what businesses now need to cover:


Cookie Policy

Cookie consent

Analytics and optimisation cookies are exempt, but you must inform users clearly and offer a free opt-out.

Feature Item 10

Legitimate interests

Certain activities (marketing, network security, intra-group transfers) are now whitelisted.

Full Legal Text

Complaint handling

Electronic complaint forms and 30-day acknowledgements are mandatory.

Automatic Updates

Automated decisions

Restrictions now focus only on special category data.

Auto Configuration Wizard

Data transfers & AI

A risk-based test for cross-border transfers, plus definitions for research and AI processing.

  • Privacy and Cookie Policy

  • Cookie & Consent Banner

  • Marketing Consent

  • Data Processing Activities

  • Data Subject Rights

Your questions, answered


Do I still need a DPO?
What’s changed with cookies?
What’s this about smart data schemes?
How does iubenda help with all this?