Reform UK's Contract Targets UK GDPR

Reform UK has released a policy paper aimed at the country's 5.7 million small businesses, and one of its headline pledges is a full repeal of the UK GDPR. The document proposes scrapping the current data protection framework and replacing it with rules modeled on New Zealand's privacy law, which is built around 13 broad principles rather than the UK's system of "lawful bases" for processing personal data.

This is not the first time Reform UK has floated tearing up GDPR. The party has previously pitched a "light-touch" alternative to the existing framework, a proposal that data protection experts and legal analysts have already criticized as unworkable. The new small business contract folds that ambition into a broader pitch to cut regulatory burdens for firms that make up the vast majority of the UK's private sector.

Principles Versus Lawful Bases: What Actually Changes

The UK GDPR, inherited from the EU version after Brexit, requires organizations to identify a specific "lawful basis" before processing anyone's personal data, options like consent, contractual necessity, legal obligation, or legitimate interest. Each basis comes with its own conditions and documentation requirements, and businesses are expected to justify their choice if challenged.

New Zealand's Privacy Act takes a different approach. Rather than forcing organizations to slot data processing into predefined legal categories, it sets out 13 information privacy principles covering things like collection, storage, use, and disclosure of personal information. Compliance is judged against these broader standards rather than a checklist of lawful bases, and the maximum penalties under the New Zealand model are comparatively modest.

Supporters of this approach argue it reduces paperwork and legal uncertainty for smaller organizations that lack dedicated compliance teams. Critics counter that principles-based systems can be harder to enforce consistently and may leave individuals with less clarity about their rights, since there's no single lawful basis a person can point to when asking why their data was processed a certain way.

The EU Adequacy Question Looms Large

The most consequential issue in Reform UK's proposal isn't really about domestic compliance costs. It's about what happens to the UK's data adequacy agreement with the European Union if the underlying law changes this dramatically.

The UK currently holds an adequacy decision from the European Commission, which allows personal data to flow freely between the UK and EU member states without additional legal safeguards. That decision exists because the UK's post-Brexit data protection rules were judged sufficiently similar to EU standards. Swapping a lawful-bases system for a New Zealand-style principles model would represent a significant departure from that baseline, and adequacy decisions are reviewed periodically, not granted permanently.

If the UK lost adequacy status, businesses that transfer personal data to or from the EU, which includes a large share of UK companies trading with European customers or using European cloud services, would need to rely on alternative legal mechanisms such as standard contractual clauses. That would add complexity and cost, potentially undercutting the very simplification Reform UK is promising to small firms.

What This Means For You

For now, this is a policy pledge in an opposition party's contract, not enacted law. Nothing changes immediately for how your personal data is collected, stored, or shared by UK businesses. UK GDPR remains fully in force, and companies are still obligated to meet its current requirements around consent, data subject rights, and breach notification.

That said, the debate is worth watching if you run a small business or care about how your data is handled online. A repeal of this scale would touch nearly every website, app, and service that processes UK residents' information, and any transition period would likely bring its own confusion as businesses adjust to new rules while EU-facing companies wait to see whether adequacy survives.

If you're concerned about how your personal data is used regardless of which framework eventually applies, tools like reputable VPNs, privacy-focused browsers, and careful review of app permissions remain useful ways to limit unnecessary data exposure. Legal frameworks set the floor for what companies must do, but individual privacy habits still matter on top of that.

Key Takeaways

Reform UK's GDPR repeal pledge for small firms is a political proposal, not current law, so no immediate compliance changes apply. The New Zealand-style model would swap lawful bases for 13 broader principles, a shift that experts have already flagged as difficult to implement cleanly. The biggest risk isn't domestic red tape, it's whether the UK could keep its EU data adequacy status under a substantially different privacy law. Anyone running a UK business with EU customers, or anyone simply following UK privacy policy, should keep an eye on how this debate develops rather than assume UK GDPR is going anywhere soon.