UK GDPR: same structure, different regulator
The UK GDPR keeps the Article 13 and 14 information duties, with the ICO as the supervisory authority and PECR governing cookies and electronic marketing. Practical differences for a UK business are mostly about naming: reference the ICO for complaints, use UK transfer mechanisms such as the IDTA or the UK Addendum when sending data abroad, and remember that some organisations must register and pay the ICO data protection fee.
- ICO as the route for complaints
- UK international transfer agreement or Addendum for overseas providers
- PECR rules for cookies and marketing email, including the soft opt-in
- Whether ICO registration applies to you