Website Rules in the United Kingdom
UK websites operate under the UK GDPR and PECR. The ICO enforces privacy rules with fines up to £17.5 million. Companies House registration must be displayed.
Data protection authority:
Information Commissioner's Office
(ICO)
Requirements
4
country-specific rules
Guides
12
guides available
Specific requirements for United Kingdom
Companies House number
UK limited companies must display their company registration number, registered office address, and place of registration on their website.
UK GDPR
The UK retained GDPR after Brexit as UK GDPR. Requirements are mostly the same as EU GDPR, but the supervisory authority is the ICO, not an EU DPA.
PECR (cookies and email)
The Privacy and Electronic Communications Regulations govern cookies and electronic marketing. Fines can reach up to £500,000 (separate from UK GDPR fines).
Accessibility
Public sector websites must meet WCAG 2.1 AA. The EAA does not apply in the UK post-Brexit, but the Equality Act 2010 requires reasonable adjustments for disabled users.
Enforcement in United Kingdom
The ICO fined British Airways £20 million for a 2018 data breach affecting 400,000 customers. For smaller organisations, the ICO has issued enforcement notices to businesses failing to respond to subject access requests within the 30-day deadline, with penalties starting at £500 for repeat offenders.
Official resources
UK data protection in 2026, three laws that matter
The UK has three active instruments that govern personal data on websites. Knowing which applies saves time when something goes wrong.
The UK GDPR. This is the retained EU GDPR as it stood at the end of the Brexit transition, amended since. The substance is identical to the EU version for most website operations. If you're compliant with EU GDPR, you're 95% of the way there.
The Data Protection Act 2018. Fills in the national bits: age of consent for online services, law enforcement processing, immigration exemptions. Most of it doesn't touch a typical Irish business selling into Britain.
The Data (Use and Access) Act 2025. Passed after the Data Protection and Digital Information Bill collapsed in 2024. It relaxes some record-keeping duties and clarifies lawful bases for research and public interest processing. Critically for website operators, it did not remove the cookie consent requirement. UK cookie rules still live in PECR.
The UK supervisory authority is the Information Commissioner's Office (ICO). John Edwards has been Commissioner since January 2022. The ICO website at ico.org.uk publishes every monetary penalty notice, every enforcement notice, every reprimand.
PECR, the UK cookie regime that survives data reform
Privacy and Electronic Communications Regulations 2003, usually just PECR, is where UK cookie law lives. Regulation 6 is the one to bookmark. It requires clear and comprehensive information about any cookie placed on a user's device and consent for non-essential cookies.
The ICO guidance from 2019, reconfirmed in 2023, mirrors the EDPB line. No pre-ticked boxes. Reject must be as prominent as accept. No cookie walls unless the site has a genuine paid alternative. Analytics cookies need consent.
The ICO has been publicly sharper than some EU regulators on cookie banners. In November 2023 the ICO warned the top 100 UK websites that their banners were non-compliant. In 2024 it followed up with commitments from most of those sites to redesign. The ICO publishes the list of companies that refused to comply.
For an Irish business with UK customers, the practical rule is simple. If your cookie banner complies with Irish DPC guidance, it complies with ICO PECR. The inverse isn't always true because the ICO has accepted some formulations on analytics cookies that the DPC treats more cautiously.
UK-EU adequacy and what it means for Irish data flows
The European Commission granted the UK adequacy status on 28 June 2021, under GDPR Article 45. That means personal data can flow from Ireland to the UK without Standard Contractual Clauses, Binding Corporate Rules, or any other Article 46 safeguard.
The 2021 decision had a four-year sunset. It was renewed in late 2025 for a further period, conditional on the UK maintaining broadly equivalent standards. The Data (Use and Access) Act 2025 survived this review without triggering a loss of adequacy.
For Irish businesses this means three things. You can use UK-based hosting, CRM, analytics or payment processors without extra transfer paperwork. Your UK customers' data still counts as personal data protected by the UK GDPR on the UK side, the EU GDPR on the Irish side. Contracts still need to name the right controller and processor under each regime.
If adequacy is ever lost, the fallback is Standard Contractual Clauses approved by the Commission. You'd need to renegotiate contracts with every UK processor. It's a real risk but not immediate.
For a full UK compliance check use our free scanner. For country-specific guidance on France see our France page.
Guides for United Kingdom
GDPR Compliance Checklist for Your Website (2026)
A practical GDPR checklist for small business websites. Check cookies, privacy policy, consent forms, and tracking scripts.
Does the European Accessibility Act Apply to Your Business?
The EAA became enforceable in June 2025. Find out if it applies to your business, what it requires and what happens if you don't comply.
Cookie Banner Requirements Under EU Law (2026 Guide)
Cookie banner requirements in the EU 2026: reject equal to accept, no dark patterns, prior consent. EDPB Guidelines 05/2020 explained.
Website Security Checklist: 10 Things to Check Today
A practical security checklist for small business websites. 10 things you can check and fix today without technical expertise.
GDPR for accountants in the UK: ICAEW, ACCA & AML
GDPR for UK accountants. ICAEW/ACCA/AAT standards, MLR 2017 anti-money laundering, client confidentiality, ICO breach notification, and website rules.
GDPR for estate agents in the UK: Propertymark & AML
GDPR for UK estate agents. Propertymark, MLR 2017 anti-money laundering, viewings, photography, tenancy data, ICO breach notification, and website rules.
GDPR for hair & beauty salons in the UK: NHBF guide
GDPR for UK hair and beauty salons. Treatwell, Phorest, Fresha booking platforms, patch-test records, ICO breach rules, and website compliance.
GDPR for physiotherapists in the UK: CSP & HCPC
GDPR for UK physiotherapy practices. CSP, HCPC, ICO data fee, patient-record retention, online booking, and ICO breach notification under UK GDPR.
GDPR for veterinary practices in the UK: RCVS & ICO
GDPR for UK veterinary practices. RCVS Code, pet-owner data, clinical-record retention, online booking, payment, and breach notification under UK GDPR.
AI-Built Website Liability Under UK Law
ICO enforces UK GDPR, PECR and Equality Act against the site owner, not Cursor, Lovable or the developer. EU PLD doesn't apply post-Brexit.
AI-Generated Code and Open-Source Licences (UK)
Copilot or Cursor wrote GPL code into your site. UK Consumer Protection Act, not the EU PLD. What Doe v. GitHub decided and what to do about it.
AI-Generated Images on UK Business Websites (2026)
Getty v Stability AI was narrower than the headlines. The four risk layers a UK SMB owner should check before publishing AI-generated images.
Check your website for United Kingdom requirements
Our scanner checks for United Kingdom-specific requirements automatically.
I understand this is a technical scan, not legal advice, and I accept the Terms.