Could the UK Really Scrap GDPR and Keep EU Adequacy?
Reform UK wants a New Zealand-style privacy regime. Would that actually reduce the compliance burden for UK businesses?
Written by Mark Farrell and Gbenga Onojobi.
Reform UK has proposed replacing the UK GDPR with what it describes as a “light-touch” privacy law modelled on New Zealand. The pledge forms part of its Contract with Small Business, published on 26 August 2026, and is presented as a way of reducing the regulatory burden for smaller firms and technology businesses.
At this stage, however, there is no detailed Bill setting out what a replacement regime would contain. The proposal therefore raises more questions than answers. In particular, would a New Zealand-style model significantly reduce compliance costs for UK businesses, what would the wider implications be for data protection in the UK, and could the UK make such a change without putting its EU adequacy status at risk?
What Is Actually Being Proposed?
The proposal is not to remove privacy law altogether. New Zealand has a comprehensive privacy regime under the Privacy Act 2020, but it is structured differently from the UK GDPR.
Rather than using the GDPR’s detailed framework of lawful bases and accountability requirements, New Zealand’s legislation is built around Information Privacy Principles governing how personal information is collected, stored, used, disclosed and transferred. Individuals have rights of access and correction, organisations must report serious privacy breaches, and the regime includes regulatory and enforcement powers.
New Zealand has also continued to develop its privacy framework. Since 1 May 2026, Information Privacy Principle 3A has introduced additional transparency requirements where organisations collect personal information indirectly.
Therefore, “light-touch” should not be read as meaning little or no regulation. New Zealand takes a less prescriptive approach in some areas, but organisations still have legal duties and individuals still have enforceable privacy rights.
Could a New Zealand-Style Model Work in the UK?
In principle, yes. GDPR is not the only possible model for regulating personal information. The fact that the UK recognises New Zealand as offering adequate protection shows that the standard is recognised as sufficient overall.
One reason New Zealand has featured so prominently in the proposal is that it already benefits from an EU adequacy decision. In January 2024, the European Commission concluded that New Zealand continued to provide an adequate level of protection for personal data transferred from the EU. However, New Zealand’s adequacy status does not mean that the UK could simply adopt parts of its legislation and automatically retain its own adequacy decision.
The Commission assesses a country’s framework as a whole. This includes individual rights, regulatory oversight and enforcement, international transfers, and the circumstances in which public authorities may access personal data.
The UK’s own adequacy decision was renewed in December 2025, after the Commission considered the reforms introduced by the Data (Use and Access) Act 2025. The current decision runs until December 2031, subject to continued monitoring.
For UK businesses, adequacy has a clear practical benefit. It allows personal data to flow from the EEA to the UK without organisations having to put additional transfer safeguards in place. If adequacy were lost, many businesses would instead need to rely on mechanisms such as Standard Contractual Clauses.
A reform intended to reduce domestic compliance costs could therefore create a different set of costs if UK-EU data transfers became more complicated.
The UK Has Already Been Reforming GDPR
The Data (Use and Access) Act 2025 has already changed significant parts of the UK data protection framework without replacing the UK GDPR. Its reforms include changes to rules around automated decision-making, recognised legitimate interests, international transfers, subject access, and storage and access technologies such as cookies.
This raises a fair policy question: if the aim is to reduce unnecessary compliance burdens, does that require wholesale replacement of the UK GDPR, or can the UK continue making targeted changes within the existing framework?
In our view, the evidence on burden is mixed. The UK Business Data Survey 2026 found that 90% of businesses handling digitised personal data said data protection law had not prevented them from carrying out any of the activities surveyed. Only 1% specifically reported being prevented from introducing a new or significantly improved product, process or business model. At the same time, 19% said their compliance burden had increased, while 76% said it had remained broadly the same.
Reframing Data Protection as Red Tape Overlooks What the Law Is Actually For
The language used to introduce Reform UK’s pledge, including businesses being “suffocated” and “strangled” by regulation, is entirely cost-focused. It says nothing about what the UK GDPR secures for the people it protects. Some of what could be lost is not simply paperwork.
Of the potential losses should the UK mimic New Zealand’s approach, the right to erasure is perhaps the most significant, as New Zealand’s Privacy Act has no direct equivalent. This is an important privacy remedy that allows individuals to compel the removal of inaccurate or unwanted personal data in many circumstances. It is not merely a compliance formality.
The same is true of mandatory DPIAs, which require organisations to assess risk before deploying high-risk processing. Framing these protections purely as a burden for organisations ignores the imbalance of power they exist to address.
Individuals generally cannot negotiate terms with a bank, employer or advertising technology platform. Rights of access, rectification and erasure are among the main tools available to them. A reform proposal that focuses only on costs to businesses, without considering what protections individuals may lose, fails to engage with an important underlying purpose of data protection law.
A Lighter Penalty Regime May Cost More Than It Saves
The gap between the fine structures of the UK GDPR and New Zealand’s regime is significant, ranging from a ceiling of £17.5 million or 4% of global turnover under the UK GDPR to fines of approximately £4,500 in New Zealand, alongside compensation awards capped at NZ$350,000.
Such a significant reduction in monetary sanctions could weaken the deterrent effect provided by larger fines. This may lead some organisations to take a more relaxed approach to data protection, including slower breach responses, reduced investment in security and less appetite for proactive risk assessment.
Organisations may make compliance savings, but there is a risk that the cost would be passed to individuals through lower standards of protection.
The argument that the EU’s adequacy decision for New Zealand means the UK would retain adequacy if it proceeded with Reform UK’s proposal is not without merit. However, adequacy is monitored continually and should not be treated as a foregone conclusion.
If UK law diverged sufficiently to place adequacy at risk, businesses could lose frictionless data flows with the EU and would need to invest in appropriate safeguards and transfer risk assessments for affected transfers. That cost could fall hardest on the small businesses the policy is intended to help.
Weakening the Regime Now Is a Mistimed Bet Against Emerging Technology
Notably absent from the debate so far is consideration of artificial intelligence and its associated risks, which a robust data protection framework can help to address. This is significant because the safeguards a lighter regime might lack are precisely those increasingly needed for AI-era processing.
Mandatory DPIAs require organisations to scrutinise automated decision-making, profiling and biometric systems before they go live. Removing that requirement would reduce oversight at the same time these systems are scaling rapidly.
The right to erasure also raises new and unresolved questions in an AI context, including whether a person can have their data removed not only from a database but also from a trained model. A regime without a standalone right to erasure may be less equipped to address that question.
A significantly reduced penalty ceiling may also be poorly matched to AI-driven harm, which can affect large numbers of people simultaneously in ways that a relatively small fixed fine cannot reflect.
The more defensible path, and one the UK has already demonstrated through the Data (Use and Access) Act 2025’s changes to automated decision-making provisions, is targeted adaptation within the existing framework rather than a wholesale switch to a lighter regime developed before AI-scale processing existed.
Would Scrapping GDPR Remove Cookie Banners?
Not by itself.
The specific UK rules governing cookies and similar technologies sit mainly within the Privacy and Electronic Communications Regulations 2003, commonly known as PECR. The UK GDPR applies alongside PECR and provides the standard for valid consent where consent is required.
The Data (Use and Access) Act 2025 has already introduced additional exceptions for certain low-risk storage and access technologies. However, removing the UK GDPR alone would not automatically remove cookie consent requirements unless PECR were also changed.
Would UK Businesses Really Leave GDPR Behind?
Not necessarily.
A UK business offering goods or services to individuals in the EU, or monitoring their behaviour there, may still fall directly within the territorial scope of the EU GDPR.
For some internationally active businesses, replacing the UK GDPR could therefore mean complying with a new domestic privacy regime while continuing to meet EU GDPR requirements separately. This is an important part of the wider debate. Simplifying domestic rules does not necessarily mean simplifying compliance for every UK business.
There is also the question of potential cost savings. The idea that a simpler regime would automatically mean lower costs overlooks the fact that the EU GDPR would continue to apply to many UK businesses.
Those businesses may gain little practical or financial relief from a lighter UK regime. Instead, they could be required to meet two distinct standards, potentially at a greater cost than satisfying one.
Where This Leaves Businesses
For now, nothing changes. The UK GDPR, Data Protection Act 2018 and PECR remain the applicable framework, as amended by the Data (Use and Access) Act 2025.
New Zealand demonstrates that GDPR is not the only privacy model capable of receiving an EU adequacy decision. However, replacing the UK GDPR would involve much more than removing lawful-basis assessments or simplifying privacy notices.
Any future regime would still need to answer the same practical questions: what personal information organisations may collect, what they can use it for, how it must be protected, what rights individuals should have, and how personal data can continue to move between the UK and other countries.
The bigger question is therefore not simply whether the UK could scrap the UK GDPR, but whether doing so would actually make compliance simpler for the businesses expected to operate under whatever comes next.
Sources
Reform UK: Reform’s Plan to Rescue Britain’s Small Businesses
Politico: Nigel Farage Wants to Scrap GDPR for the UK
New Zealand: Privacy Act 2020
European Commission: Report on the First Review of Adequacy Decisions, January 2024
European Commission: UK Adequacy Decision Renewal, December 2025
GOV.UK: Data (Use and Access) Act 2025 – Data Protection and Privacy Changes
GOV.UK: UK Business Data Survey 2026
ICO: Guidance on Cookies and Storage and Access Technologies