Skip to main content
Two abstract privacy frameworks connected by a protected data bridge

Reform UK's GDPR replacement pledge leaves the most important privacy details open

The party wants a lighter law modelled on New Zealand, but has not published a bill defining rights, enforcement or safeguards for EU data flows.

Published

02 Sep 2026

Reading Time

4 min read

Share this article:

Contents

Reform UK has pledged to repeal the UK General Data Protection Regulation and replace it with what the party calls a light-touch privacy law modelled on New Zealand. The Next Web reported the proposal on August 31, 2026; Reform's own policy announcement was published on August 26 as part of a package aimed at small businesses.

A pledge, not a draft law

Reform's announcement says the replacement would reduce regulatory burdens while preserving data protection and EU adequacy. It does not publish legislative text, define which UK GDPR rights would remain, identify enforcement powers or explain how existing contracts, complaints and investigations would transition.

That missing detail is decisive. The UK's current regime is not a single document that can be swapped without related changes. The Information Commissioner's Office explains that the Data (Use and Access) Act 2025 amended, but did not replace, the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations. Any replacement would need to address how those laws interact.

What the New Zealand model contains

New Zealand's Privacy Act 2020 is not an absence of privacy rules. Its Office of the Privacy Commissioner describes 13 information privacy principles covering collection purpose, source and notice, fairness, security, access, correction, accuracy, retention, use, disclosure, overseas transfers and unique identifiers. A new principle 3A concerning indirect collection took effect in May 2026.

The New Zealand framework uses principles and sector-specific codes rather than reproducing the UK GDPR article by article. That may offer a different compliance structure, but the phrase “modelled on New Zealand” does not tell UK residents which rights or remedies they would receive. Nor does it explain whether the UK would copy the entire framework, selected principles or only its regulatory approach.

EU adequacy cannot be assumed

Both New Zealand and the United Kingdom currently appear on the European Commission's list of jurisdictions recognized as providing adequate data protection in the relevant scope. This allows personal data to flow from the European Economic Area without each transfer needing another safeguard.

That does not mean one country can adopt fragments of another's law and automatically keep its own decision. Adequacy is an assessment of the complete legal framework, enforcement, oversight and remedies. The Commission renewed the UK's adequacy decisions in December 2025. A material future change would need to be evaluated on its actual text and operation.

If adequacy were lost, many organizations would need other transfer mechanisms and additional legal work. Reform says its approach would preserve adequacy, but the published announcement does not provide enough detail to test that claim.

Rights and enforcement are the practical test

For individuals, the useful questions are concrete: can a person learn what data an organization holds, correct it, object to particular uses, obtain deletion where applicable, challenge automated decisions and secure an effective remedy after misuse? For organizations, the questions include lawful bases, record-keeping, breach duties, international transfers and regulator expectations.

A lighter compliance process can coexist with meaningful protection, but only if the law clearly assigns duties and supplies credible enforcement. Conversely, changing labels without simplifying overlapping obligations would not deliver the promised reduction in burden.

What to watch next

The next meaningful evidence would be a draft bill, an impact assessment and a clause-by-clause comparison with the current regime. It should specify the regulator's independence and powers, individual rights, rules for children and sensitive data, automated decision-making, international transfers and transitional arrangements.

The European Commission's response would matter for adequacy, while the ICO and Parliament would assess domestic operation. Until those details exist, this is a political direction rather than an implementable privacy framework.

Sources and methodology

Tags:

#UK GDPR #Reform UK #privacy law #New Zealand Privacy Act #EU adequacy #data protection #regulation

46

views

0

shares

0

likes

Related Articles