Reform UK Unveils Plan to Scrap UK GDPR

Reform UK has announced its intention to abolish the UK's General Data Protection Regulation (GDPR) and replace it with a lighter privacy law modelled on New Zealand's. The pledge was unveiled by party leader Nigel Farage and economy chief Robert Jenrick on Tuesday evening as part of a broader package of measures aimed at small businesses.

In a statement, Farage framed the proposal as a rescue mission for British enterprise. "Small businesses are the beating heart of our economy, yet they have been suffocated by years of punishing taxes, suffocating EU red tape and a big-state obsession that rewards dependency over hard work," he said, in remarks carried by the PA news agency.

Jenrick was more direct about the regulation itself. "GDPR has strangled small businesses and tech firms alike in a web of unnecessary regulation," he said. "Ten years after the Brexit referendum, we should not still be following ridiculous EU privacy laws that hurt British businesses," he added.

The UK GDPR, which replaced the pre-Brexit Data Protection Act 2018 in 2021, is an amended version of the EU regulation written into domestic law after Brexit. Reform UK's plan would unwind that arrangement, according to a report by Politico.

Politico's report also noted that Reform UK's press release asserts the New Zealand model would meet the EU's adequacy standard, but did not explain how. The party has not specified which regulator would enforce the replacement, and few technology policies have been published beyond an ambition to make Britain an AI leader.

The New Zealand Model: Key Differences

The gap between the UK and New Zealand regimes lies primarily in enforcement and individual rights. Under the UK GDPR, the Information Commissioner can issue multi-million-pound fines. In contrast, New Zealand's Privacy Act 2020 caps penalties at NZ$50,000, as noted by The Register.

The EU GDPR grants individuals a wider set of rights, including the right to be forgotten, which the New Zealand law does not match. On the mechanics of handling and transferring data, the two regimes sit closer than the rhetoric suggests.

Data Adequacy and EU Relations

The UK currently holds an EU data adequacy decision, extended until 2031, which allows data to flow freely between the UK and the EU. The European Commission grants adequacy only to countries with essentially equivalent data protection. Reform UK's proposal to adopt a New Zealand-style regime raises questions about whether the UK would retain this status, given the significant differences in enforcement and rights.

Reactions from Labour and Conservatives

The proposal has drawn sharp criticism from political opponents. A Labour government spokesperson called Reform's pledges "unworkable and unserious" and accused the party of trying to undo the Online Safety Act.

Shadow chancellor Sir Mel Stride said Reform's pledges "collapse on contact with reality" and would cost billions. He also noted that there was little detail on how scrapping GDPR would work in practice.

Additional Proposals in the Package

The small-business package includes several other measures: reversing the National Insurance increase announced in 2024 by Rachel Reeves, scrapping income tax on overtime (which the party calls a "hard work bonus"), loosening inheritance tax on farms, raising the VAT threshold to £150,000, and scrapping the 2035 Zero Emission Vehicle mandate.

Legal Challenges and Context

Reform UK faces ongoing legal pressure over its handling of personal data. The Good Law Project sued Reform UK in March 2025, claiming the party failed to comply with the UK GDPR by not disclosing data it held and not deleting it on request. A High Court judge ruled in June that the case should proceed to trial.

The announcement comes amid broader debates about data protection and online regulation in the UK. The Dutch data protection authority recently used the EU GDPR to fine Uber €290 million over automated driver monitoring, illustrating the enforcement powers that Reform UK's proposal would seek to reduce. In the UK, NHS England admitted in July that its paperwork hid a disclosure about who could see identifiable patient data.

As the party moves forward with its pledge, the details of how it would replace the UK GDPR remain unclear, and the compatibility with EU adequacy requirements is a key question that has yet to be answered by Reform UK.