Reform UK Plan to Scrap GDPR Threatens EU Data Flow

Reform UK proposes replacing the UK's GDPR-based data protection with a lighter framework, risking its EU data adequacy and cross-border digital trade.

Lauren Collins ·

Reform UK Plan to Scrap GDPR Threatens EU Data Flow

Reform UK has put forward a proposal to repeal the United Kingdom's current data protection framework, which is presently rooted in the European Union’s General Data Protection Regulation (GDPR). The political party's stated objective is to substitute these existing regulations with a more streamlined approach, drawing inspiration from New Zealand’s Privacy Act. This move aims to alleviate the administrative burden on small and medium-sized enterprises (SMEs) within the UK.

This potential policy shift could introduce considerable institutional risks for the UK’s data adequacy status with the European Union. The European Commission grants adequacy decisions exclusively to jurisdictions that maintain data protection standards deemed essentially equivalent to those mandated by EU law. A transition to a less rigorous regulatory environment could imperil the uninterrupted flow of personal data between the UK and the European Economic Area (EEA).

Potential Impact on Data Adequacy

In the past, the UK implemented incremental legislative adjustments to ease privacy requirements. However, a complete overhaul of the existing framework would signify a substantial departure from European standards. Such a transition would necessitate intricate legal negotiations with the EU, potentially imposing significant compliance costs on firms operating across both the UK and EU markets, thereby disrupting cross-border digital trade flows.

A primary concern revolves around whether the European Commission would consider a New Zealand-style framework as providing 'essentially equivalent' data protection to the GDPR. The New Zealand Privacy Act, while robust, operates under a different legal philosophy and may not meet the EU's stringent equivalence criteria, particularly concerning individual rights and data transfer mechanisms.

Business Implications and Compliance

The proposed changes, if enacted by Reform UK, could simplify regulations for domestic small businesses, potentially reducing red tape and compliance costs for those operating solely within the UK. However, this simplification for British firms might result in increased complexity and heightened compliance burdens for companies involved in data transfers with EU entities.

Businesses would face the challenge of navigating two distinct and potentially conflicting data protection environments. Should the European Commission determine that the new UK regime is insufficient, it could revoke the UK's data adequacy status. This action would then compel businesses to adopt more complex and costly alternative mechanisms, such as standard contractual clauses (SCCs) or binding corporate rules (BCRs), for transferring data from the EU to the UK, adding layers of legal and operational overhead.

This situation highlights the delicate balance between domestic regulatory autonomy and the necessity of maintaining international data flow agreements, particularly with a major trading partner like the EU. The long-term implications could reshape the digital economy for UK firms engaged in international commerce.

More stories