GDPR Day 2024: A Look at Past, Present and Future Developments in the UK

By Deborah Margolis and Sanika Karandikar on May 30, 2024

Share this page

May 25th marked six years since the General Data Protection Regulation has been in effect.

Since it was implemented, GDPR has been regarded as the gold standard for data protection legislation across the world. The implementation of GDPR signaled the European Union鈥檚 firm stance on data privacy and security, demonstrated by the large fines introduced for businesses that violate GDPR standards. The GDPR is retained in the UK鈥檚 domestic law as UK GDPR, which sits alongside the Data Protection Act 2018.

In this article we look back at the most important recent developments in data protection law, and look ahead to the developments that will impact UK employers in the coming years.

  • The EU AI Act聽鈥 the EU AI Act (鈥淎I Act鈥) was approved by the European Parliament on March 13, 2024 and will be the world鈥檚 first comprehensive law regulating AI. The AI Act imposes large fines (nearly double those under GDPR) and will have extra-territorial scope meaning international companies, even if they are not based in the EU, may still find themselves subject to the AI Act. Read our more detailed analysis about the AI Act聽.
  • UK regulation of AI聽鈥 in contrast to the EU鈥檚 approach, the UK has taken a more 鈥渋nnovation鈥-led approach, introducing sector-specific regulation and guidance. There are some rumblings of potential regulation in this area, including a bill which aims to regulate AI in employment and to establish a central AI Authority in the UK. Read more about this聽
  • Potential shift away from UK GDPR聽鈥 after Brexit, the UK government proposed new legislation to simplify the UK鈥檚 data protection framework, reducing the compliance burden on organizations. The Data Protection and Digital Information Bill is still being reviewed by the House of Lords in the UK. Read our more detailed analysis of the bill聽.
  • More ICO guidance聽鈥 as we see more technological and legal developments, we can expect to see more guidance published by the Information Commissioner in the UK. The ICO published its聽聽in March 2023.
  • European Commission review of GDPR聽鈥 we are expecting the European Commission to publish its review of EU GDPR in 2024.
  • Areas of regulatory focus聽鈥 as part of its strategic plans, the ICO has committed to focus its attention on the use of AI in recruitment and data protection compliance within the financial services industry.
  • Labour Government and change in policy聽鈥 it remains to be seen whether we will have a Labour government later this year or early next, and what a Labour government will do in relation to data protection legislation. Early indications show that Labour may be more willing to regulate AI in the UK than the current Conservative government.