When the UK began legislating to reform its data protection regime after leaving the EU, a particular expectation took hold in parts of the business community: that the UK would diverge meaningfully from the UK GDPR, lighten the compliance burden, and create a more permissive data environment. The Data (Use and Access) Act was read, in anticipation, as the instrument that would deliver this divergence, a GDPR replacement that would free UK organisations from the more onerous requirements of the European framework.
This reading is wrong, and acting on it is a mistake with real consequences. The Act reforms specific aspects of the UK data regime; it does not replace the UK GDPR, does not abandon its core principles, and does not deliver the wholesale divergence that some anticipated. More importantly, the UK's data protection framework remains tied to a consideration that constrains how far divergence can go regardless of domestic political preference: EU adequacy. Organisations that treat the Act as a GDPR replacement, and that relax their data protection posture accordingly, are exposing themselves to compliance risk under a regime that has changed less than they believe and to a strategic risk that the framing entirely obscures.
What the Act Actually Does
The Data (Use and Access) Act makes targeted reforms to the UK data protection and broader data framework, and the targeted nature of the reforms is the point that the GDPR-replacement framing misses.
The Act addresses specific areas: it makes provision for digital verification services, reforms aspects of the regime around automated decision-making, adjusts certain requirements around data subject rights and the handling of requests, establishes frameworks for smart data schemes, reforms the regulator, and makes various other specific changes. These are real reforms with real effects in their specific domains. They are not a replacement of the UK GDPR, and they do not alter its fundamental architecture.
The core of the UK GDPR remains. The lawful basis requirements, the data protection principles, the accountability obligations, the data subject rights, the international transfer rules, the enforcement framework, these continue substantially as before, modified at the edges by the Act's specific reforms but not replaced or fundamentally lightened. An organisation's core data protection obligations under the UK regime after the Act are recognisably the same obligations it had before, adjusted in particular respects rather than transformed.
This means the organisation that anticipated a GDPR replacement and prepared to operate under a significantly lighter regime has prepared for a regime that does not exist. The Act delivers specific reforms, some of which are genuinely useful, within a framework that remains fundamentally a GDPR-derived data protection regime. The compliance burden is adjusted, not removed, and an organisation that relaxes its compliance posture on the assumption of removal is non-compliant under the regime that actually applies.
The Adequacy Constraint
The deeper reason the UK cannot diverge as far as some anticipated, regardless of the contents of any particular Act, is EU adequacy, and this is the strategic consideration that the GDPR-replacement framing obscures entirely.
The EU has granted the UK an adequacy decision, which permits personal data to flow freely from the EU to the UK on the basis that the UK provides a level of data protection essentially equivalent to the EU's. This adequacy decision is enormously valuable to the UK economy, because it allows the vast flows of personal data between the EU and UK, on which a great deal of commercial activity depends, to continue without the friction and cost of alternative transfer mechanisms. For UK CNI operators and the broader economy, EU adequacy is a critical piece of infrastructure that most organisations never think about because it operates invisibly in the background.
EU adequacy is conditional on the UK maintaining data protection that the EU regards as essentially equivalent to its own. If the UK diverges too far from the EU framework, the EU can review and potentially revoke the adequacy decision, which would impose significant cost and friction on EU-UK data flows and damage the UK economy. This creates a hard constraint on UK data protection divergence that operates regardless of domestic political preference for a lighter regime. The UK can reform at the edges, as the Act does, but it cannot diverge fundamentally without jeopardising adequacy, and the value of adequacy means that fundamental divergence is not, in practice, available.
The adequacy decision is itself subject to periodic review, and the review assesses whether the UK regime, including reforms like the Act, has maintained essential equivalence. This means the Act and any future UK data reform operate under the watchful assessment of whether they have gone too far for adequacy to survive. The constraint is live and consequential, and it is the reason that the GDPR-replacement framing was always a misreading: the UK was never free to replace the GDPR, because adequacy required it not to.
The Strategic Risk the Framing Obscures
The GDPR-replacement framing does not just produce compliance risk through relaxation. It obscures a strategic risk that CNI operators in particular need to understand.
The strategic risk is adequacy itself. EU-UK data flows are critical infrastructure for the UK economy and for individual CNI operators with EU operations, EU customers, or EU supply chains. The continued free flow of that data depends on the survival of the adequacy decision, and the survival of adequacy depends on the UK maintaining essential equivalence as both the UK and EU frameworks evolve. This is not a static condition. The EU framework is developing, the UK framework is being reformed, and adequacy survives only as long as the two remain close enough in the EU's assessment.
For a CNI operator, this means EU adequacy is a strategic dependency that should be actively monitored, not a settled background fact. A future divergence, whether through subsequent UK reform or through the UK framework failing to keep pace with EU developments, could put adequacy at risk, and the consequences for an operator dependent on EU-UK data flows would be significant. The operator that understands this monitors the adequacy position as it would monitor any other critical dependency, factors adequacy risk into its strategic planning, and is prepared for the possibility, however currently remote, that adequacy could be reviewed.
The GDPR-replacement framing obscures all of this. It encourages organisations to think of UK data reform as a matter of domestic compliance burden, lighter or heavier, rather than as a matter bound up with a critical strategic dependency on EU data flows. An organisation focused on whether the Act lightens its compliance burden is asking the small question. The large question is whether the trajectory of UK data reform preserves the adequacy that its EU data flows depend on, and that question is invisible from within the GDPR-replacement frame.
The Data (Use and Access) Act is a reform of the UK data regime, useful in its specifics, and constrained by an adequacy requirement that prevents it from being the GDPR replacement some anticipated. Organisations should comply with the regime as it actually is, which remains substantially GDPR-derived, rather than the lighter regime they imagined. And CNI operators should look past the compliance question to the strategic one: EU adequacy is critical infrastructure, its survival is conditional and monitored, and the trajectory of UK data reform is a dependency worth watching closely. The Act changed less than the framing suggested, and the thing worth attending to is not what it changed but what it must not be allowed to break.
