Nigel Farage Proposes Scrapping UK GDPR for Simpler Privacy Rules
Reform UK leader Nigel Farage proposes replacing UK GDPR with a streamlined data privacy framework in 2026.
Why it matters: Legal teams managing UK and international data must track this proposal closely, as changes could reshape compliance and risk management. The move threatens to alter how personal data is regulated, impacting contract clauses, cross-border data flows, and enforcement strategies.
- Nigel Farage criticizes UK GDPR as 'suffocating businesses' and promotes a 'light-touch' privacy regime.
- Reform UK aims to repeal the UK GDPR, which replaced the EU GDPR post-Brexit and governs personal data use in the UK.
- Critics argue the proposal lacks a detailed framework and timeline, making practical effects unclear.
- The contest over UK data privacy laws highlights tensions between regulatory easing and protecting individual rights.
In August 2026, Nigel Farage, leader of Reform UK, advocated for scrapping the United Kingdom's General Data Protection Regulation (UK GDPR), seeking to replace it with a simpler, more business-friendly data privacy law. The UK GDPR, which closely mirrors the European Union's GDPR, was adopted after Brexit to maintain high data protection standards across the UK.
Farage contends that the current UK GDPR imposes excessive regulatory burdens that hinder business innovation and economic growth. He argues for a 'light-touch' privacy framework that would reduce compliance obligations and costs for companies handling personal data.
However, the proposal has met sharp criticism from political opponents and some legal experts. Critics note that Reform UK has not published a concrete legislative plan or timeline, leaving questions about how rights protections and enforcement mechanisms would be maintained or altered. As The Register reported, opponents emphasize the lack of specific details undermines the feasibility of the plan.
For legal professionals advising UK-based or globally operating companies, the proposal signals potential shifts in data protection compliance requirements. The UK GDPR currently enforces strict rules on data processing, consent, transparency, and data subjects' rights. Any overhaul may require revising privacy notices, contractual provisions, and cross-border data transfer mechanisms.
Given both business pressures for deregulation and public interest in data privacy, this debate will shape UK regulatory policy in the coming years. Legal and compliance teams should monitor political developments and be prepared to update compliance programs accordingly.
For ongoing updates, see coverage in Financial Times and detailed analysis by the UK Information Commissioner's Office.
By the numbers:
- 2026 — Year Nigel Farage publicly proposed scrapping UK GDPR
- 2018 — Year UK GDPR came into effect post-Brexit, replicating EU GDPR standards
- £17bn — Estimated annual cost of GDPR compliance to UK businesses (according to UK government studies)
Yes, but: While reform proponents emphasize reducing compliance costs and boosting business competitiveness, data protection authorities and privacy advocates warn that weakening UK GDPR could undermine individuals' rights and increase data misuse risks.
What's next: Reform UK has not released a legislative timetable; however, data protection reform is expected to arise in parliamentary debates later in 2026. Legal professionals should watch closely for bill proposals and consultations.