EU warns UK not to abandon GDPR post-Brexit

GDPR
(Image credit: Shutterstock / Vector Image Plus)

The European Union has officially classified UK data protection practices as “adequate” under GDPR, permitting the free flow of data between the pair after the temporary post-Brexit arrangement comes to an end this week.

However, the new agreement will expire in four years’ time, after which it will need to be renegotiated. This sunset clause acts as insurance for Brussels, which has warned it will rescind the ruling should the UK diverge from GDPR in years to come.

“The UK has left the EU but today its legal regime of protecting personal data is as it was. Because of this, we are adopting these adequacy decisions today,” said Věra Jourová, VP for Values and Transparency at the European Commission (EC).

“[However], we have significant safeguards and if anything changes on the UK side, we will intervene,” she added.

GDPR post-Brexit

The EU decision will be met with relief by businesses on both sides of the equation, who could have faced a host of challenges if an agreement was not reached.

If the EU ruling had not been favorable, UK businesses would have had to make costly arrangements with European partners to ensure data could still be passed to and fro, and the exchange of data would likely have slowed to a crawl for a period, impeding collaboration and innovation.

“After months of careful assessments, today we can give EU citizens certainty that their personal data will be protected when it is transferred to the UK,” explained Didier Reynders, EC Commissioner for Justice.

“This is an essential component of our new relationship with the UK. It is important for smooth trade and the effective fight against crime.”

Oliver Dowden, the UK Culture Secretary, also expressed his delight with the outcome of negotiations, citing similar benefits.

However, pro-Brexit commentators are less enamored with the arrangement. The British government enshrined GDPR into UK law in an effort to secure the adequacy ruling, but some have suggested the country has wasted an opportunity to gain a competitive business advantage by cutting away GDPR red tape.

“The fact is that GDPR doesn’t work in Europe, it doesn’t work here,” asserted Iain Duncan Smith, Conservative MP.

“If the EU doesn’t watch out it’s going to get left behind as the rest of the world has a more flexible form of regulation over data, while the EU becomes almost impossible to do business with.”

Via The Telegraph

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
European Union
European Commission hit by EU court fine after breaking own data privacy rules
Microsoft
Microsoft completes EU cloud sovereignty project, letting Europe-based cloud customers store and process data in the EU
Racks of servers inside a data center.
Companies say data sovereignty is important, yet many businesses see it as a burden
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
NIS2: the GDPR of cybersecurity
Conceptual image with a bunch of floating eyeballs in different sizes overlooking a red computer, could symbolize ideas around malware and computer viruses
Accept all or bust: how cookie walls are creating a two-tier internet
Cloud, networking and internet
Under the hood of data sovereignty
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning