Skip to main content
Compliance & Law

UK GDPR

The UK GDPR is the UK's post-Brexit version of the EU General Data Protection Regulation. It applies alongside the Data Protection Act 2018 and is enforced by the Information Commissioner's Office (ICO).

Definition

The UK GDPR is the retained EU GDPR after Brexit, modified by the Data Protection Act 2018 (UK) and the Data (Use and Access) Act 2025 (DUAA). It applies to all processing of personal data of UK data subjects, regardless of where the controller or processor is based.

DUAA 2025 Changes

The Data (Use and Access) Act 2025 introduced the first material UK divergence from EU GDPR: lighter cookie-consent rules, an expanded list of "recognised legitimate interests" and new rules on solely automated decision-making. teamly applies the stricter standard of UK and EU GDPR by default.

Employee Data Specifics

Processing of staff data needs a lawful basis, usually Article 6(1)(b) (performance of contract) or 6(1)(f) (legitimate interest). For special category data (e.g. health) you additionally need an Article 9 condition. The ICO has issued specific employer guidance on monitoring at work.

Employee App Requirements

A documented lawful basis, a Data Processing Agreement under Article 28 with the vendor, technical and organisational measures, documented purpose limitation, retention and deletion policy, and ICO-aligned monitoring policy. teamly provides this stack as standard.

FAQ

Frequently asked questions about UK GDPR

What HR leads, IT managers and compliance officers ask most often.

Is the EU/UK data adequacy decision still in place?
The European Commission adopted an adequacy decision for the UK in June 2021, valid for four years, then extended in 2025. EU to UK transfers remain straightforward as a result. teamly hosts in Germany, so EU GDPR applies directly.
What are the ICO's rules on monitoring employees?
The ICO's Employment Practices guidance requires transparency, proportionality and a clear lawful basis. Covert monitoring is rarely justified. teamly's read receipts and analytics are designed to avoid individual performance monitoring.
Can I be fined under UK GDPR?
Yes. Maximum fines are £17.5 million or 4 percent of global annual turnover, whichever is higher. The ICO has issued multiple six-figure fines for employer-related processing.

Considering an employee app?

teamly is the European employee app for mid-market companies. Go-live in 3 to 6 months, your own branded app, UK and EU GDPR compliant.