Reform UK has pledged to repeal the UK General Data Protection Regulation and replace it with what the party calls a light-touch privacy law modelled on New Zealand. The Next Web reported the proposal on August 31, 2026; Reform's own policy announcement was published on August 26 as part of a package aimed at small businesses.
A pledge, not a draft law
Reform's announcement says the replacement would reduce regulatory burdens while preserving data protection and EU adequacy. It does not publish legislative text, define which UK GDPR rights would remain, identify enforcement powers or explain how existing contracts, complaints and investigations would transition.
That missing detail is decisive. The UK's current regime is not a single document that can be swapped without related changes. The Information Commissioner's Office explains that the Data (Use and Access) Act 2025 amended, but did not replace, the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations. Any replacement would need to address how those laws interact.
What the New Zealand model contains
New Zealand's Privacy Act 2020 is not an absence of privacy rules. Its Office of the Privacy Commissioner describes 13 information privacy principles covering collection purpose, source and notice, fairness, security, access, correction, accuracy, retention, use, disclosure, overseas transfers and unique identifiers. A new principle 3A concerning indirect collection took effect in May 2026.
The New Zealand framework uses principles and sector-specific codes rather than reproducing the UK GDPR article by article. That may offer a different compliance structure, but the phrase “modelled on New Zealand” does not tell UK residents which rights or remedies they would receive. Nor does it explain whether the UK would copy the entire framework, selected principles or only its regulatory approach.
EU adequacy cannot be assumed
Both New Zealand and the United Kingdom currently appear on the European Commission's list of jurisdictions recognized as providing adequate data protection in the relevant scope. This allows personal data to flow from the European Economic Area without each transfer needing another safeguard.
That does not mean one country can adopt fragments of another's law and automatically keep its own decision. Adequacy is an assessment of the complete legal framework, enforcement, oversight and remedies. The Commission renewed the UK's adequacy decisions in December 2025. A material future change would need to be evaluated on its actual text and operation.
If adequacy were lost, many organizations would need other transfer mechanisms and additional legal work. Reform says its approach would preserve adequacy, but the published announcement does not provide enough detail to test that claim.
Rights and enforcement are the practical test
For individuals, the useful questions are concrete: can a person learn what data an organization holds, correct it, object to particular uses, obtain deletion where applicable, challenge automated decisions and secure an effective remedy after misuse? For organizations, the questions include lawful bases, record-keeping, breach duties, international transfers and regulator expectations.
A lighter compliance process can coexist with meaningful protection, but only if the law clearly assigns duties and supplies credible enforcement. Conversely, changing labels without simplifying overlapping obligations would not deliver the promised reduction in burden.
What to watch next
The next meaningful evidence would be a draft bill, an impact assessment and a clause-by-clause comparison with the current regime. It should specify the regulator's independence and powers, individual rights, rules for children and sensitive data, automated decision-making, international transfers and transitional arrangements.
The European Commission's response would matter for adequacy, while the ICO and Parliament would assess domestic operation. Until those details exist, this is a political direction rather than an implementable privacy framework.
Sources and methodology
The Next Web: Reform UK wants to scrap the UK GDPR and copy New Zealand’s privacy law
Reform UK: Reform's plan to rescue Britain's small businesses
New Zealand Office of the Privacy Commissioner: Privacy Act 2020 principles
ICO: What the Data Use and Access Act means for organisations
European Commission: Data protection adequacy for non-EU countries