Skip to content

UK vs EU After DUAA: Where the Data Paths Diverged

UK GDPR vs EU GDPR differences 2026: what the Data (Use and Access) Act changed for marketers, with a comparison table and the cookie banner question answered.

28 Aug 202610 min read
  • Privacy

Verified as of August 2026: EU and UK rules are actively changing, and some widely-shared claims are out of date. This is operational orientation, not legal advice; confirm with official sources or your data protection adviser.

The UK's Data (Use and Access) Act 2025 received Royal Assent in 2025 and was phased in, with all data protection provisions active as of 19 June 2026. For marketers this is the most concrete UK-EU divergence available: the UK now permits certain analytics and appearance/functionality cookies to be set without consent under amended PECR, has extended the soft opt-in to charities, has introduced "recognised legitimate interests" as a lawful basis that removes the balancing-test requirement for listed purposes, and has raised PECR penalties toward GDPR-level maximums. The EU has proposed comparable cookie reforms in the Digital Omnibus: but those remain under negotiation and are not law. So yes, you can now run a lighter cookie banner for UK traffic than for EU traffic. Whether you should is a different question.

Key Takeaways

  • UK GDPR and EU GDPR still share the same architecture. Divergence so far is at the edges, but the edges are exactly where marketing operates.
  • New PECR exemptions let certain cookies be set without consent in the UK. Verify the exact scope against ICO guidance before switching anything off.
  • "Recognised legitimate interests" is a new UK lawful basis for a defined list of purposes, removing the balancing test for those purposes. Direct marketing is not on that list.
  • Soft opt-in now extends to charities in the UK: a genuine, immediate operational change for non-profits.
  • PECR fines have been raised toward GDPR-level maximums. Lighter rules, heavier penalties.
  • UK adequacy from the EU side remains the strategic variable underneath all of this.
  • Running two banner configurations is legally permitted and operationally non-trivial. Decide deliberately.
Same architecture, different fittings. The divergence is narrow but lands squarely on marketing operations.

What DUAA Actually Did

The Data (Use and Access) Act 2025 amended the UK GDPR, the Data Protection Act 2018 and PECR rather than replacing them. There is no new UK data protection regime to learn. There is a set of targeted amendments, most of which reduce friction for defined low-risk activities while increasing the consequences of getting the high-risk ones wrong.

The phased commencement completed for data protection provisions on 19 June 2026, which is why this became a live operational question in the middle of 2026 rather than in 2025 when the Act passed.

The Comparison Table

AreaEU position (August 2026)UK position (August 2026)Marketing consequence
Core GDPR principles, lawful bases, rightsGDPR as adoptedUK GDPR, substantively alignedNo divergence to manage
Cookie consent triggerePrivacy Directive as nationally transposed; consent required for non-essential storage/accessPECR as amended by DUAA, new exemptions for certain statistical/analytics and appearance/functionality purposesUK can drop specific categories from the banner; EU cannot
Analytics without consentOnly via narrow national exemptions (e.g. CNIL's audience-measurement carve-out), conditions attachedPermitted for defined statistical purposes subject to conditions, check ICO guidance for scopeCleanest single divergence for a growth team
New lawful basisNone added"Recognised legitimate interests": listed purposes, no balancing test requiredUseful for safeguarding, emergencies, public interest tasks; not a direct-marketing shortcut
Legitimate interest for direct marketingRecital 47 acknowledges it may apply; balancing test requiredBalancing test still required; direct marketing sits in ordinary legitimate interestsLittle practical change
Soft opt-in for email marketingExisting-customer soft opt-in under national ePrivacy transposition; commercial contextExtended to charities and non-commercial purposesImmediate operational win for UK non-profits
PECR/ePrivacy penaltiesSet nationally; varies widelyRaised toward GDPR-level maximumsUK enforcement exposure materially increased
Automated decision-makingArticle 22 restrictions as adoptedReframed with a more permissive structure for non-special-category data, safeguards retainedRelevant to lead scoring and automated qualification
Subject access requestsOne month, extendable"Reasonable and proportionate" search standard clarified; stop-the-clock for clarificationSlightly reduced operational burden
International transfersChapter V; adequacy decisions; SCCs plus TIARevised "data protection test" for adequacy assessment; UK IDTA/AddendumTwo transfer paperwork sets if you serve both
Representative requirementArticle 27 EU representative where applicableUK representative under UK GDPR where applicableNon-UK/non-EU firms may need both
Cookie reform statusProposed only: Digital Omnibus under negotiation, Council text reportedly weakenedIn force since 19 June 2026Do not build EU strategy on proposed EU reforms
DSA-type platform dutiesDSA in force: obligations on platforms/VLOPsOnline Safety Act regime, different architectureBoth felt indirectly via platform ad policy

The Question Nobody Answers: Can You Run a Lighter UK Banner?

Legally: yes

Nothing requires you to apply the strictest applicable regime globally. If a visitor is in the UK, UK law governs, and UK law now exempts certain cookie categories from consent. You may serve a UK configuration that sets those cookies without asking, and an EU configuration that asks.

Practically: three considerations

One: the exemptions are conditional, not categorical. The statistical/analytics exemption comes with conditions around purpose, scope and what happens to the data. The appearance-and-functionality exemption is about remembering user preferences, not about anything that improves the site commercially. Read the ICO's guidance on storage and access technologies and map your actual cookies against it, tag by tag. Most analytics implementations carry advertising integrations that break the exemption.

Two: geolocation is imperfect. Your CMP decides which configuration to serve using IP geolocation, which is wrong some of the time. A German visitor served the UK configuration is a compliance failure, and PECR penalties are now high enough that the failure is expensive on the UK side too.

Three: measurement inconsistency. If UK analytics captures near-100% of sessions and EU analytics captures whatever consent rate you achieve, every cross-market comparison in your reporting becomes misleading. Teams routinely fail to adjust for this and then conclude the UK market is outperforming.

My recommendation

If the UK is a major market for you and you have the CMP sophistication to segment reliably, take the exemption for genuine first-party analytics, the data quality improvement is real and it is the single biggest measurement win available in Europe right now.

If the UK is a secondary market, or your analytics stack is entangled with ad platforms, run one strict configuration. The complexity cost exceeds the benefit, and a single configuration is easier to defend and easier to keep correct as rules move.

Either way, document the decision and the reasoning. That document is the thing a regulator asks for.

Recognised Legitimate Interests: What It Is and Isn't

DUAA introduced a category of "recognised legitimate interests": a defined list of purposes where a controller may rely on legitimate interests without conducting the usual balancing assessment. The list covers things like national security, emergencies, safeguarding, crime prevention and certain public-interest disclosures.

Direct marketing is not on that list. Marketing to your own contacts under legitimate interests still requires the ordinary Article 6(1)(f) analysis and a documented balancing test. Any content telling you DUAA made B2B marketing easier through this route is misreading it.

What DUAA did do for marketing is at the ePrivacy layer, the cookie exemptions and the charity soft opt-in, not at the lawful-basis layer.

Two configurations is legal. It is also two things to keep correct forever.

The Charity Soft Opt-In

Previously, the soft opt-in under PECR: allowing email marketing to people whose contact details you obtained in the course of a sale or negotiations for a sale, for similar products, with a clear opt-out at every stage, was tied to a commercial context. That excluded charities in most of their fundraising activity.

DUAA extended it. UK charities can now use the soft opt-in for contacts obtained in the course of the person expressing interest in or offering support for the charity's purposes, subject to the same conditions: clear opt-out at the point of collection and in every message.

This is the most immediately actionable change in the Act for a whole sector, and it is under-covered because the charity marketing press and the data protection press don't overlap much.

Adequacy: The Thing Underneath

The EU's adequacy decision for the UK is what allows personal data to flow from the EEA to the UK without additional safeguards. It has been extended once and remains subject to review, with the European Commission monitoring UK divergence.

The strategic implication for a marketing team is simple: your UK-EU data flows currently work on adequacy, and if adequacy lapsed you would need SCCs and transfer impact assessments for flows you currently treat as domestic. Know which of your systems those are before you need to know.

Practical Divergence Checklist

  1. Map your cookies against the UK exemptions, tag by tag, not category by category.
  2. Decide banner strategy, one configuration or two, and write down why.
  3. Test geolocation accuracy in your CMP. Ask the vendor for their accuracy figures.
  4. Separate UK and EU analytics reporting so you are not comparing consented data to near-complete data.
  5. Review lawful basis documentation, recognised legitimate interests may cover some non-marketing processing you were over-documenting.
  6. Charities: implement the soft opt-in and update collection-point wording.
  7. Check representative obligations, you may need both an EU Article 27 representative and a UK representative.
  8. Re-read PECR penalty exposure. The numbers changed. Your risk register probably didn't.

What Hasn't Diverged

Worth stating, because divergence coverage tends to overstate it. Transparency obligations, data subject rights, security requirements, breach notification, DPIA triggers, processor obligations under Article 28, and the core lawful bases are all substantively aligned. If your compliance programme is sound, it remains sound in both jurisdictions. What you're managing is a set of specific, marketing-adjacent deltas, not two regimes.

Frequently Asked Questions

Is UK GDPR still basically the same as EU GDPR?

Structurally yes. DUAA amended rather than replaced it. The divergences are targeted: cookies, a new recognised-legitimate-interests category, automated decision-making framing, SAR handling, and penalties.

When did DUAA fully take effect?

Royal Assent was in 2025, with phased commencement. All data protection provisions were active as of 19 June 2026.

For defined statistical purposes, subject to conditions, yes. The exemption is conditional and narrower than headlines suggest: verify your specific configuration against current ICO guidance, particularly if your analytics shares data with advertising platforms.

Does the EU allow the same thing?

Not as a general rule. Some member states operate narrow national exemptions, CNIL's audience-measurement carve-out is the best-known, but there is no EU-wide equivalent. The Digital Omnibus proposes something in this direction; it is not law.

No. Direct marketing is not among the recognised legitimate interests. Ordinary legitimate interests analysis still applies for processing, and PECR still governs the sending.

You may. You are not required to. Weigh the data-quality gain against geolocation risk and reporting complexity.

Have UK marketing penalties gone up?

Yes. DUAA raised PECR penalties toward GDPR-level maximums, which is a substantial increase from the previous PECR ceiling.

Do I need both an EU and a UK representative?

Potentially, if you are established outside both and target individuals in both. Article 27 applies for the EU; the UK GDPR equivalent applies for the UK. Exemptions exist for occasional, low-risk processing.

What happens if UK adequacy is not renewed?

EEA-to-UK transfers would need Chapter V safeguards, SCCs plus transfer impact assessments, for flows currently treated as free. Know which systems that would affect.

Did DUAA change the rules for charity fundraising emails?

Yes: the soft opt-in was extended to charities, subject to the usual conditions including a clear opt-out at collection and in every message. This is the clearest immediate win in the Act.

Should a business serving both markets just apply the stricter rule everywhere?

It's the low-complexity answer and often the right one. But if the UK is a primary market, the analytics exemption is a genuine measurement advantage and worth the operational effort to take properly.

Further Reading


If you run growth across both UK and EU markets and want the divergence handled as an operational design question rather than a legal memo, that's work I do. More at younusfardeen.com.