• Home
  • 5
  • Industry News
  • 5
  • Reform UK’s Proposal to Replace UK GDPR: What It Means for Businesses and Privacy Rights

Reform UK’s Proposal to Replace UK GDPR: What It Means for Businesses and Privacy Rights

Share this Article:

Reform UK has announced that it would repeal the UK General Data Protection Regulation (UK GDPR) and replace it with a “light-touch” privacy law modelled on New Zealand’s approach. The pledge was briefed on the evening of 25 August 2026 and formed part of a wider package of measures aimed at small businesses, announced on 26 August.

Party leader Nigel Farage said small businesses had been “suffocated” by “EU red tape”, and Treasury spokesperson Robert Jenrick said the GDPR had “strangled small businesses and tech firms alike in a web of unnecessary regulation”. Reform’s press material states that a New Zealand style framework would preserve the UK’s EU adequacy status, so that personal data could continue to flow between the UK and Europe.

No draft legislation, consultation or policy paper has been published. Critics, including Conservative shadow chancellor Sir Mel Stride, have noted that there is “little detail on how their proposals to scrap GDPR would work”.

Sources: PoliticoThe Independent

First, some context that has been missing from the coverage

UK data protection law has already been reformed. The Data (Use and Access) Act 2025 amended the UK GDPR and the Data Protection Act 2018, introducing recognised legitimate interests, changes to automated decision-making and research provisions, a reformed regulator and a new duty on organisations to have a complaints handling process, which came into force on 19 June 2026.

That matters for two reasons. It shows that targeted, adequacy-safe reform is possible and is already happening. It also means any future government proposing to “scrap GDPR” would be unpicking a framework that Parliament amended only last year, and which the European Commission has just assessed.

How different is New Zealand’s law?

New Zealand’s Privacy Act 2020 is a principles based regime built around thirteen Information Privacy Principles. It is genuinely lighter in several places, but it is not the absence of privacy law that some of the coverage implies.

AreaUK GDPR (current)New Zealand Privacy Act 2020
StructurePrescriptive articles plus DPA 2018 and DUAA 2025Thirteen Information Privacy Principles
Maximum penalty£17.5m or 4% of global turnoverStatutory fines up to NZ$10,000 (~£4500) for specified offences
plus compensation awards up to NZ$350,000 via the HRRT.
Lawful basisSix lawful bases, consent rules, special category conditionsPurpose and necessity based collection under IPP1 to IPP4
Right of accessYes, Article 15Yes, IPP6, a well established right
Right to erasureYesNo standalone right to be forgotten
Right to correctionYesYes, IPP7
DPO requirementMandatory in defined casesNo equivalent mandatory DPO, but a privacy officer must be appointed
DPIAsMandatory for high risk processingNot mandated by statute
Breach notification72 hours to the ICO where reportableNotify the Privacy Commissioner and affected people
as soon as practicable for notifiable privacy breaches
International transfersChapter V, adequacy, IDTA, addendum, TRAsIPP12, comparable safeguards test
EU adequacyHeld, renewed December 2025Held since 2012, reconfirmed January 2024

 

The honest conclusion is more nuanced than either side of the debate suggests. New Zealand does hold EU adequacy, so a principles based model is not automatically incompatible with adequacy. But New Zealand achieved that from a standing start, having never been part of the EU framework, and adequacy is assessed on the whole legal environment, including national security and law enforcement access to data, not on the privacy statute alone. Reproducing the outcome in the UK would be a far more complicated exercise than copying the drafting.

Sources: Office of the Privacy Commissioner, New Zealand and Buddle Findlay on New Zealand’s adequacy decision.

The adequacy question

The UK’s adequacy position is currently stable. On 19 December 2025 the European Commission renewed the UK’s two adequacy decisions following its assessment of the Data (Use and Access) Act 2025. The renewed decisions run to 27 December 2031, with a review after four years and a sunset clause at the end.

Two points follow from that. Adequacy is not permanent, it is a rolling assessment that the Commission can review, suspend or repeal if UK law diverges materially. And the four year review date gives a practical yardstick for any incoming government: significant divergence would land squarely inside that review window.

If adequacy were lost, transfers of personal data from the EEA to the UK would need Article 46 safeguards such as standard contractual clauses and transfer risk assessments, for every affected data flow. For UK businesses with European customers, suppliers, group companies or cloud arrangements, that is a substantial contracting and documentation exercise, and the cost would fall on exactly the small businesses the policy is intended to help.

What would actually change for your business, and what would not

Even if a proposal of this kind became law, the following obligations would be untouched.

  • EU GDPR would still apply to you if you offer goods or services to people in the EU, or monitor their behaviour. Its extraterritorial reach under Article 3 does not depend on UK law. See our EU and international support services if this applies to you.
  • PECR would still apply. Cookies, tracking and electronic marketing are governed by the Privacy and Electronic Communications Regulations, which are separate from UK GDPR. Most of the compliance work businesses find visible and irritating, such as cookie banners and marketing consent, sits here.
  • Employment, financial services and sector rules would still apply. Confidentiality duties, FCA and other regulator expectations, safeguarding requirements and professional obligations are not GDPR creations.
  • Your existing contracts would still bind you. Data processing agreements with EU and UK customers commit you to specific standards by contract. Those survive changes in statute until renegotiated.
  • Your customers’ expectations would not reset. Breach and misuse of data remain reputationally and commercially damaging regardless of the statutory maximum fine.

The realistic change for a typical UK SME would be lighter documentation and governance, and a much lower ceiling on regulatory penalties. That is not nothing. But it is a long way from “there is nothing to do”.

How likely is this to happen?

We take no political position, and we make no prediction about elections. On the mechanics alone, this is a long road.

  • There is no bill, no consultation and no published policy detail.
  • Repeal would require unpicking the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025, along with a large body of sector specific and secondary legislation that cross refers to them.
  • The ICO’s statutory functions, codes of practice and enforcement powers would need rebuilding around a new framework.
  • Any material divergence would need to be squared with the Commission’s four year review of UK adequacy.
  • Businesses would need a transition period, which in practice means running two regimes for a time.

Realistically, no organisation should expect its data protection obligations to reduce inside the next few years, and any change that did arrive would come with a lead in period and consultation. Planning your compliance programme on the assumption that GDPR is about to disappear would be a serious mistake.

What we are telling our clients this week

  1. Do not pause your compliance programme. Nothing has changed in law. Deferring work now simply means doing it later under time pressure.
  2. Prioritise your complaints handling process if you have not already. That duty is live under the Data (Use and Access) Act 2025 and is enforceable today.
  3. Keep your records of processing current. A records of processing exercise is the one piece of work that retains its value under any framework, including a principles based one. It is also what you would need if adequacy were ever lost and you had to paper transfers at speed.
  4. If you sell into the EU, treat EU GDPR as your baseline. Building to the higher standard means UK reform becomes an opportunity to simplify, not a compliance emergency.
  5. Do not over correct. We have already had clients ask whether they can stand down data protection work. The answer today is no.

Our view

Concern about regulatory burden is legitimate, and much of the compliance industry has earned some of the criticism by turning proportionate obligations into unnecessary paperwork. Where we agree with the direction of travel is that the aim of good reform should be to make compliance simpler to achieve, not to remove the protections themselves.

Where we would urge caution is the assumption that a lighter statute means a lighter workload. For most UK organisations of any size, the obligations that actually take time, understanding what data you hold, why you hold it, who you share it with, keeping it secure and answering people who ask about it, exist under every credible privacy framework in the world, including New Zealand’s. A change of statute changes the paperwork. It does not change the job.

Key takeaways

  • Reform UK has proposed replacing UK GDPR with a lighter-touch framework modelled on New Zealand’s Privacy Act 2020. No legislation has been published.
  • New Zealand’s law is genuinely lighter in penalties, DPO and DPIA requirements and the right to erasure, but it is still a full privacy regime and it does hold EU adequacy.
  • The UK’s own adequacy decisions were renewed on 19 December 2025 and run to 27 December 2031, with a review after four years. Adequacy is a rolling assessment, not a permanent status.
  • UK data protection law has already been reformed by the Data (Use and Access) Act 2025, including a complaints handling duty in force since 19 June 2026.
  • EU GDPR, PECR, sector rules and existing contracts would all continue to apply regardless of UK reform.
  • Nothing has changed today. Compliance programmes should continue as planned.

Not sure how exposed your organisation would be to a change in the UK framework, or whether your current programme is proportionate in the first place? Our Data Protection Gap Analysis gives you a clear picture of what you hold, where the real risk sits and what you can safely stop doing. If you would rather have that judgement on tap, our Outsourced DPO service puts a qualified, certified practitioner alongside your team. Get in touch.

About the Author:

Explore More Articles