Nigel Farage's Reform UK party has outlined plans to scrap the United Kingdom's data protection regime, arguing that the General Data Protection Regulation has "strangled small businesses and tech firms." The proposal, unveiled Tuesday night as part of a broader policy package, would replace the UK's version of GDPR with what the party describes as a "light-touch" privacy law modeled on New Zealand's approach to data protection.
The pledge arrives alongside other measures in Reform UK's package, including an expanded venture capital scheme offering tax relief to investors. Together, the proposals frame data protection reform as part of a wider push to cut regulatory burdens on British businesses, particularly smaller firms and tech startups that Reform UK says have struggled under the current rules.
Why GDPR Became a Target
GDPR, first introduced across the EU in 2018 and carried into UK law after Brexit, sets strict rules on how organizations collect, store, and process personal data. It requires companies to justify why they collect information, gives individuals rights to access or delete their data, and imposes significant fines for violations. Supporters credit it with giving ordinary people meaningful control over their digital footprint for the first time.
Critics, including Reform UK, argue the rules impose disproportionate compliance costs on smaller organizations that lack the legal and technical resources of larger tech companies. That tension between consumer protection and business flexibility is not new, but Farage's proposal marks one of the most direct political challenges yet to the UK's post-Brexit data protection framework.
New Zealand's Privacy Act, the model Reform UK points to, takes a more principles-based approach than GDPR. It relies less on prescriptive rules and more on general obligations for organizations to handle information responsibly, with enforcement handled through a Privacy Commissioner rather than the kind of large-scale fines associated with GDPR enforcement in Europe.
What Scrapping GDPR Could Mean for Privacy
Any move to unwind UK GDPR would raise immediate questions about what protections replace it. GDPR currently underpins rights that many UK residents may not think about until they need them: the right to know what data a company holds on you, the right to request deletion, and the right to be informed when your data is involved in a breach. A lighter regulatory model could reduce compliance friction for businesses, but it could also narrow the legal tools individuals rely on to challenge misuse of their personal information.
There's also a practical dimension for UK businesses that operate internationally. The EU's own GDPR still applies to any UK company handling the personal data of EU residents, regardless of domestic UK law. A significant divergence between UK and EU privacy standards could complicate data transfers and force companies to maintain two separate compliance systems, one for UK customers and another for EU customers.
This debate is unfolding as European policymakers continue to wrestle with their own contentious privacy proposals. The ongoing discussion around Chat Control legislation in the EU illustrates how difficult it is to balance enforcement goals against individual privacy rights, a tension that any UK replacement framework would also need to navigate.
What This Means for You
Reform UK's proposal is currently a policy pledge, not enacted law, and any change to the UK's data protection framework would require legislation and parliamentary debate. Still, the announcement is a signal that data protection rules are back on the political agenda in Britain, and it's worth watching how the conversation develops.
For now, UK residents' rights under GDPR remain unchanged. Organizations still must justify their data collection practices, respond to access requests, and report significant breaches. If a replacement law like the one Reform UK describes were eventually adopted, it could shift how much control individuals have over their personal information and how strictly companies are held to account for mishandling it.
Regardless of how the political debate plays out, individuals concerned about their personal data exposure don't need to wait on legislation to take basic protective steps. Being selective about which apps and services receive personal information, reviewing privacy settings regularly, and understanding what a company's privacy policy actually promises are habits that remain useful under any regulatory framework.
Key Takeaways
- Reform UK has pledged to scrap UK GDPR in favor of a "light-touch" law modeled on New Zealand's Privacy Act, as part of a broader business-focused policy package.
- The proposal is not yet law and would require parliamentary action to take effect.
- Any UK departure from GDPR standards would not remove obligations for UK companies handling EU residents' data, since EU GDPR would still apply separately.
- Readers should keep monitoring how this policy develops, since it could eventually affect data access rights, breach notification rules, and consumer recourse in the UK.
- In the meantime, practicing good personal data hygiene, limiting unnecessary data sharing and reviewing app permissions, remains a sound strategy no matter which regulatory framework is in place.




