Does UK GDPR apply to businesses outside the UK?
Yes, if you offer goods or services to people in the UK or monitor their behaviour. Organisations without a UK establishment may also need a UK representative.
What did the Data (Use and Access) Act 2025 change?
Among other things: recognised legitimate interests, relaxed consent for some low-risk cookies, clearer rules for subject access searches, reformed automated decision-making rules, a duty to handle data protection complaints, and PECR fines raised to UK GDPR levels.
We are already GDPR compliant for the EU. Is that enough?
Mostly, but UK and EU rules are now diverging. UK-specific changes to cookies, legitimate interests, complaints handling and international transfers need their own review.
Do we need a Data Protection Officer?
Only public authorities and organisations whose core activities involve large-scale monitoring or special category data must appoint one. Everyone else still needs someone accountable for data protection.
Is this legal advice?
No. Stratgik is a technology firm. We implement notices, workflows, consent, logging and security in your systems, and work alongside your solicitor where a legal opinion is needed.
Are prices fixed?
Yes, for organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before any work starts. VAT is added where applicable.