UK
Summary
Law: Data Protection Act 2018 (the Data Protection Act) and the UK General Data Protection Regulation (Regulation (EU) 2016/679) (UK GDPR)
Regulator: The Information Commissioner's Office (ICO)
Summary: As the UK is no longer an EU Member State, from January 1, 2021, the UK's data protection regime has been regulated by the Data Protection Act 2018 (the Data Protection Act) and the UK GDPR, which is broadly similar to the EU GDPR. As a result, the European Commission adopted two adequacy decisions for the UK, one under the GDPR and one under the Data Protection Directive with Respect to Law Enforcement (Directive (EU) 2016/680).
In addition, on September 21, 2023, the Department of Science, Innovation and Technology (DSIT) published the Data Protection (Adequacy) (United States of America) Regulations 2023, also known as the UK-US Data Bridge, for the UK Extension to the EU-US Data Privacy Framework, designating the US as a jurisdiction that ensures an adequate level of personal data protection for data transfers in specified circumstances.