🇬🇧 United Kingdom · Privacy & Data Protection
Data-protection regime (GDPR/CCPA/PIPL and local laws), registration duties, and the official supervisory authority.
The UK's data-protection regime is the UK GDPR together with the Data Protection Act 2018, regulated by the Information Commissioner's Office (ICO). Organisations must have a lawful basis to process personal data, uphold individuals' rights, keep data secure, and report serious personal-data breaches to the ICO (generally within 72 hours).
- You need a lawful basis (e.g. consent, contract, legitimate interests) to process personal data.
- Individuals have rights (access, rectification, erasure, etc.) that you must honour.
- Report serious personal-data breaches to the ICO, generally within 72 hours.
Official authorities
- Information Commissioner's Office (ICO)
Official UK data-protection regulator.
Official-information aggregation, not legal advice. Always verify on the authority's own site.
Government portals
- UK Government (GOV.UK) — UK's unified government services portal — visas, taxes, driving licences, benefits and more
- UK Visas and Immigration — UK visa applications, Biometric Residence Permits (BRP), and work authorization
- HM Revenue & Customs — Self Assessment tax returns, National Insurance, VAT registration and payment