REFNATION
RightsEnded 14 Sept

Should the UK replace GDPR with a less onerous data protection regime?

Yes 51%No 49%848 votes cast

The UK incorporated an amended version of the EU's GDPR into domestic law after Brexit. In 2025 Parliament passed the Data (Use and Access) Act, which amended UK GDPR to reduce burdens on business while keeping core principles, with most changes taking effect from February 2026. Reform UK has proposed scrapping the UK GDPR entirely in favour of a New Zealand-style light-touch privacy law to ease compliance for small firms and tech companies.

Jump to opinions· 20

Small firms got the lighter rule they wanted, but the margin left no room for triumphalism. The floor’s highest-respected Yes voice framed the issue as sovereignty by way of a joke about “some Brussels Eurocrat” whose exposed details had left the country suffering.

The substantive Yes case was that compliance has become an innovation tax: one developer said, “Half a dozen promising app ideas are dead in the water”, while others described GDPR as overcomplex, costly and hostile to smaller firms and AI. The appeal ran from simpler domestic rules to a broader complaint that “The UK should have its own, simpler data protection rules”, with even the lighter voices conceding that firms serving Europe would still face the EU regime.

No voters answered with two anxieties the Yes side never quite resolved. One warned of “two completely separate regulatory nightmares instead of one”, while another argued that, with AI scraping the internet, “we need more control of our data, not less”; alongside them came the quieter case that the current system is established, supported by guidance, and not obviously broken.

That left the debate talking past itself: Yes treated privacy law chiefly as a burden on enterprise, sovereignty and new technology, while No treated it as infrastructure for trust, trade and personal confidentiality. The question also exposed the practical limit of regulatory divergence — adequacy, parity and European market access mattered even to a Yes voter who urged, “Do not pretend the export lane comes free.”

The verdict was permission to lighten the domestic rulebook, not a blank cheque to abandon the protections or the trading relationships around it.

We're still suffering because some Brussels Eurocrat had his details exposed on a porn site.

YES case · Jonathan · 3 respects

Brilliant plan: let’s scrap GDPR so the EU immediately revokes our data adequacy status, forcing every British business that trades with Europe to comply with two completely separate regulatory nightmares instead of one.

NO case · BenL · 2 respects

LeftCentreRight
51%
Yes · 433 votes
49%
No · 415 votes
Spread the wordShare
Debate

20 Opinions

Sign in and vote to share your opinion.
The Peacemaker
Voted noLeft lean

What we have now does not appear to be broken, therefore does not need fixing.

The Tax-Raising Reformer
Voted noLeft lean

With the rise of AI and what it drives privacy is important. In terms of trade it is important that we keep parity with other nations (like it or not the EU is important for trade. Sometimes having different laws make them more difficult to train, understand and enforce in a trading nation

The Constituent
Voted noC. Left lean

Trade is vital to this country especially outside the EU, so unless we return to the EU it must be kept as it is until we find another way to also maintain trade and keep privacy protections.

The Green Labourist
Voted noLeft lean

Reform the current system. Protection of people's information data & confidentiality in a digital age is paramount

Astobie1· 442
The Institutional Taskmaster
Voted yesRight lean

What has GDPR ever done for us? Certainly no viaducts

The Diplomat
Voted noH. Left lean

If anything in an age where AI is scraping every corner of the internet we need more control of our data, not less

The Polymath
Voted yesRight lean

I returned to software development a year ago. Before that, I was a freelancer in internal systems, with a department handling GDPR. Half a dozen promising app ideas are dead in the water because AI can do them with a single prompt and the right connectors. Another half-dozen, because the obscene risks, eye-watering fines and nit-picking compliance associated with GDPR can only be tolerated by massive corporate concerns with deep pockets.

JohnnyBoy· 303
The Motorist Statist
Voted yesRight lean

It’s an EU top down imposition & hinders rather than helps businesses. Like many things some say “better the devil” but why is it always like this. Bad law, badly thought out & implemented & then those who are to blame’s just want to forget & move on. I think all laws should be forensically reviewed - not by Civil Servants - after say 3 years of operation and if found wanting are repealed. Maybe more effort can then be employed at outset. Improve this & improve our economy.

Bigden40· 330
The Unifier
Voted noRight lean

No. GDPR is well established and companies already know what they’re doing in relation to it. Other OECD nations have broadly similar regulation, even the US, and the simplification isn’t really that big a prize. In this AI age data protection is actually even more important.

HNTRJ· 338
Policy Maker
Voted yesC. Right lean

The UK should have its own, simpler data protection rules that reduce costs for British businesses. Other countries have their own systems and still trade successfully with the EU.