I want to start this post off with a small warning - the subject matter we’ll be discussing today is, to be very honest about it, boring. It is not sexy, entertaining or in any way something that will get you tumescent with excitement.
But. It is important - as so many, many deeply unsexy but vital things in life are.
I am, of course, talking about the General Data Protection Regulation or GDPR, an acronym that’s both ubiquitous in our national vocabulary and at the same time very, very bland.
The obvious place to start with this is what GDPR actually is, so in short, it’s a set of regulations that govern how exactly your data can and can’t be used. It specifically regulates things like:
Why a company should be allowed to collect your data.
What they can collect.
How long they’re allowed to keep it.
Who exactly they can share it with.
How securely they have to store it.
Your right to see or correct it.
The final part of what GDPR does though is quite important, and hence why it is being pulled out of the bullets and put in bold below:
GDPR regulations say exactly what needs to happen when your data is breached or misused in any way.
What GDPR does, in essence, is create a protective framework for your data, and by doing so, your privacy, and allows for recourse when that has been fucked around with by what I’m sure are completely well meaning massive corporate entities.
Now, there is incredible technical detail that goes into the subject of GDPR (special-category data, lawful bases and numerous other bits and pieces), but for the purposes of this post, we’ll not be doing a two hour mandatory training session on these.
How is Reform Distracting Us Today?
You may be quietly sitting and muttering at your mobile the question of why am I today venturing in this landscape of beigeness?
Well, largely because GDPR is yet another one of those subjects that our dear friends at Reform UK have taken one look at, and decided that this is something that they can drag kicking and screaming into their non-stop culture war and make it look like they’re doing something while actually just wildly flailing about.
In the news this morning, there was the announcement of what exactly Robert “Generic” Jenrick would be contributing today to throw some more distraction over all the rising financial questions surrounding Reform UK, and GDPR is what the big old spinner fell on.
The plan, according to Jenrick, is that Reform will be scrapping GDPR and replacing it with a “light-touch” law that is meant to boost innovation and ease regulation for entrepreneurs. They are doing this on the back of research by a Washington DC based think tank that suggests that EU laws have cut venture capital investment by 20% and led to a third of apps on the Google Play Store being removed.
They will, according to the City AM, be looking at a “light touch” approach based on “privacy laws in New Zealand, which involves smaller fines and has broader definitions around anonymity in data collection.”
GDPR is a bit shit.
Now, I have to confess here, GDPR, something which forms a huge part of my day to day work, very roundly deserves legitimate criticism, and there are small business that complain about the complexity that’s involved with it. I recently dealt with an issue that resulted in an email chain with our DPO that would have made James Joyce feel that the piss was being taken.
And this is where, as usual, Reform has latched onto something that is an issue, and pulled it into their repertoire of grievance.
So what are the complaints about GDPR from SMEs? According to a report authored by RSM:
They find it to be considerable additional work.
There is a lot of effort that goes into keeping up to date with GDPR related changes and updates.
There are ongoing expenses related to maintaining good practice.
There is, quite often, uncertainty about exactly what is and isn’t required.
These are absolutely legitimate issues, and they’re ones that I’ve personally felt working in both the private and public sectors. I can’t count the number of times that a project has been delayed because we had to figure out how a controller fits into things, or where there have been delays with getting a DPIA or a DSA set up. GDPR is incredibly complex, and I would absolutely welcome more clarity and clearer guidance on a wide range of issues.
However, identifying an issue and getting an actual workable solution to it are two very different things, and when it comes to the gang at Reform UK’s policy factory, we have a lot of experience already to know that this is not something that’s going to be particularly well considered.
The Gigantic Brexit Shaped Problem: Europe
Now, with having Brexited, there is again a valid question on why exactly we’re holding on to an EU regulation. Because as it stands, we are still, with our current setup, EU adequate when it comes to handling data - and this was actually renewed in 2025 by the commission.
That adequacy basically means that the EU considers current UK Data protections to be sufficiently robust and comparable to EU protections that they allow, in general, for personal information to flow between the EEA and the UK without business having to bolt additional safeguards onto every transaction.
That data flow is what allows businesses and UK entities to receive and send to the EEA things like:
Customer records
Mailing lists
Employee information
Analytics information
Account details
Healthcare information
Health research data
Bookings
These data flows underpin a gigantic part of what makes up the modern services trade - one of the only parts of the UK that have shown actual stability since we decided to fuck-off out of the EU. The UK government itself has described that free flow of cross-border data as being foundational to “almost all economic activity”.
Pretty important, I think we can all agree, yes?
At this point, it is also worth pointing out that the UK diverging from EU regulation would not necessarily mean that we lose full access to data flows. Losing our adequacy wouldn’t mean a full cut off. Businesses could still transfer data cross border, however, instead of a standardised agreement on how exactly that’s done, there would be massive additional work.
Instead of that adequacy, business, individually, would need to rely on things like:
Standard contractual clauses
Transfer-risk assessments
Additional contractual safeguards
Ad hoc legal and compliance advice
Potentially additional technical safeguards.
This is all becoming very technical, so to sum up what it would result in:
Reforms divergence and deregulation could leave a UK based company who wants EU customers complying with both the fancy new “light touch” British rules AND still have to comply with EU transfer requirements instead of a single aligned system.
That, to my mind, sounds like duplication, not deregulation - and it also sounds like even more data related busy work.
But We’re Outside the EU!
There will now be a contingent of people who are going to grasp aggressively at this particular straw, and again, understandably so. We left the EU in 2020, so an open question is why we still need to hold onto this foreign muck.
Ultimately, it’s a relatively easy question to answer - because we still want to sell things to people living in Europe, and EU GDPR does have extraterritorial reach in certain circumstances.
An organisation based in the United States can still be subject to EU GDPR regulations where it offers anything for sale to people in the EU, or even monitors their behaviour there.
So even if we had to abolish UK GDPR, we would still need to comply with EU GDPR for any UK based company that, again, wants to sell things.
We also need to start drawing a distinction here between two separate entities, one we’ll call MEGACORP DATA MARKETING INC and one we’ll call Wolverhampton Dave’s Software Emporium Ltd.
Now, for the former, MEGACORP, you will generally find that it has access to things like lawyers, compliance departments, DPOs, technical teams and European subsidiaries that they can reach to.
Wolverhampton Dave’s Software Emporium Ltd might know a bloke who travels to France a few times a year and a wifi connection.
With those two in mind, who will be the one unshackled?
It’s most certainly not going to be Dave frantically googling how to set up a cross border data sharing agreement.
But New Zealand!
The reporting this morning mentioned that Reform would be looking at New Zealand for inspiration of their policy, which has been described as light touch.
Except, that’s just not the case - because, New Zealand, that Social Democratic little island in the Pacific that regularly gives anxiety attacks to conservatives all over the world on just how progressive they tend to skew actually has quite substantial data protection regulation.
Its Privacy Act 2020, brought in under then PM Jacinda Ardern, also not exactly a hero on the right of politics, has 13 information privacy principles that govern:
The purposes for collection
Where the information comes from
Transparency
How information is stored and the security around it.
Access of that information
Correction of incorrect information
The accuracy of information held
Retention of information
The use of information
Disclosure of information
Overseas transfers
Unique identifiers
As a rule, Kiwis are fully entitled to demand access to personal information and ask for inaccurate data to be corrected, and since May 2026, there has actually been an expansion on the policy that adds additional protections in the form of introducing new requirements to notify people even when their data is indirectly collected.
The hilarious bit of it all though?
New Zealand itself holds EU adequacy.
The question here then becomes, if the gold-standard example that Reform is using is a country with comprehensive privacy legislation which the EU itself considers accurate - what exactly are we actually abolishing or scrapping or ripping up?
What GDPR Actually Protects YOU From
This rambling big explainer has so far looked a fair bit at national regulation, a few concepts and businesses, but there is an incredibly important aspect to this - and that’s how you as a human person is protected by GDPR.
It’s at this stage that I want you to quickly imagine all the data out there about you. Imagine the data about your medical records, racial or ethnic origin, political opinions, religious and philosophical beliefs, trade-union membership, genetic data, biometric data, health, sex-life and sexual orientation.
Rather a lot that, isn’t there? And all of it living on the internets in some way or form.
These little bits of data that make up who you are as a person are, under GDPR, especially strongly protected as special-category data.
This is partly because this is supported by your human right to privacy, but also for another very important reason.
That data is insanely valuable.
One of the biggest impacts around taking the culture war shears to something like data privacy isn’t just that business might be regulated less, we also have to consider that your right as an individual in relation to businesses that possess this data about you may be substantially weakened.
We already find ourselves in a situation where our data is constantly being used in various ways to manipulate us - whether that’s through targeted marketing that we constantly see on the interwebs or what your favourite social media site’s algorithm is going to choose to send your way to keep you glued to your phone.
Cambridge Analytica already gave us a spectacular demonstration of exactly what can happen when enormous datasets, behavioural profiling and political persuasions are weaponised - do we really want to be in a position where we give even more latitude to tech companies to get away with what amounts to incredible mass manipulation?
From my side, that’s a massive, huge, hard no-fucking-thank-you.
Who Would Actually Benefit
Earlier in this post we discussed who would have the resource to deal with a divergent regulatory system when it comes to data, and we already know that Wolverhampton Dave’s Software Emporium Ltd would be on the backfoot - but the more important question is, who would actually benefit most from this type of deregulation?
If you guessed that it isn’t Wolverhampton Dave’s Software Emporium Ltd and more likely to be MEGACORP DATA MARKETING INC, you would be absolutely correct and can collect your prize at the end of this essay1.
The hard truth of the matter is that the SMEs that Reform UK are touting may face some benefit, but the biggest winners by far would be advertising platforms, social media networks, data brokers, AI developers, large online retailers that with names that rhyme with Shmamazon and financial/data analytics companies.
And I don’t know about you, but I certainly wouldn’t trust these people to have even more freedom to do with my data what they want.
Reform Do Not Care About You
To close this conversation off with - yes, there is absolutely a conversation to be had about GDPR. It is a thing in my life that has caused me to swear far too viciously at my computer when I get waylaid on a project by a DPIA that wasn’t done quite right.
It can be confusing, cumbersome and for smaller businesses, like the one I work for, it can take up an insane amount of time, a lot of paperwork and very expensive advice to ensure you don’t run afoul of the ICO and I firmly believe it could do with at least some simplification.
However. The simplification of a process is not the same thing as weakening it.
If Reform genuinely wanted to make GDPR an easier concept to understand, they would be talking about simplifying the guidance around it, reducing the unnecessary duplication that happens, providing better and more affordable support to SMEs and making compliance proportionate to the size and risk profile of the organisation in question.
What you simply don’t do is just chuck the entire framework in a bin, set it on fire and vaguely point at an island in the Pacific.
There has to be an understanding on their behalf, and I’m not sure that there is, that if we substantially diverge from Europe, business in the UK do not become magically unshackled to shout RULE BRITANNIA at the top of their voices and then charge into the world with their goods and services.
The only thing that will happen is that instead of one set of regulations, they will now find themselves complying with both British AND European requirements at the same time.
And while this is all happening to Wolverhampton Dave’s Software Emporium Ltd trying to sell an App to track how many cans of baked beans you’ll eat over your lifetime to a man in Antwerp and having to figure out contractual ways to be compliant with EU regulations, MEGACORP DATA MARKETING INC who have the money, lawyers, compliance teams and EU subsidiaries get to run with far fewer restrictions on exploiting one of the most valuable commodities on earth:
You.
This is what’s getting lost whenever there’s another regulation that gets chucked onto the flaming pyre that is the continued Brexit culture war.
There are absolutely times when regulation is unnecessary bureaucracy. There are also other times when that annoying piece of regulation is the only thing standing between you and a multi-national corporation doing whatever the fuck it wants.
GDPR needs to be simplified. Your right to privacy does not need to be abolished to achieve that.
There is no prize, I’m very sorry.


Morning Bear.
The commercial world regards data as an asset. Without regulation they or at least a fair proportion of them will exploit the resource for commercial gain if robust restrictions are not in place.
That is before we consider the other actors who will be keen to exploit data for their own dubious ends.
Once again Reform reveal themselves to be on the side of corrupt or illegal practice. Must be a bung in it for them somewhere.
I would genuinely like to see legislation changes to reduce the GDPR burden for Wolverhampton Dave’s Software Emporium, but I agree that Reform's plan isn't the answer.
At the moment, many small organisations appear to ignore GDPR because it's too difficult. Perhaps reducing the requirements for small businesses and non-profits which hold data about fewer than 500 data subjects would be desirable, and a genuine Brexit benefit (which, let's face it, have been pretty limited so far).