UK GDPR is the United Kingdom's retained version of the EU General Data Protection Regulation, which became UK law after Brexit on January 1, 2021. It mirrors the EU GDPR in most respects — applying the same principles, legal bases, data subject rights, and controller/processor obligations — but is enforced by the UK Information Commissioner's Office (ICO) rather than EU supervisory authorities. Organizations serving both EU and UK users must comply with both frameworks separately. Data transfers between the EU and UK are currently covered by a UK adequacy decision, though this is subject to periodic review and could change.