Reform UK wants to reform GDPR by scrapping the U.K.’s data protection regime and replacing the U.K. version of GDPR with a light-touch privacy law. The party said the move would sit inside a broader package aimed at small businesses. The change would rewrite the rules for how U.K. firms handle personal data, with the clearest test being whether data can still move freely between the U.K. and EU.
Nigel Farage and Reform UK
Nigel Farage called the plan a "bold, common-sense rescue plan" and said small businesses have had to deal with "suffocating EU red tape". Robert Jenrick went further and said, "The GDPR has strangled small businesses and tech firms alike in a web of unnecessary regulation... Ten years after the Brexit referendum we should not still be following ridiculous EU privacy laws that hurt British businesses". Both remarks frame the proposal as a business deregulation drive, not a narrow privacy tweak.
New Zealand model and EU adequacy
Reform UK said the replacement law would follow New Zealand’s approach to data protection. The practical question is not the label but the structure. The European Commission grants adequacy only when a country offers an essentially equivalent level of data protection to the EU, so any U.K. rewrite would need to stay close enough on core safeguards to avoid disrupting data transfers.
The U.K. has already moved away from Brussels on privacy law through the Data (Use and Access) Act last year, which relaxed some parts of the U.K. GDPR to try to boost economic growth. Reform UK is now pushing that divergence much further, but it is also saying the New Zealand-style model would preserve U.K. EU data adequacy status. That is the central tension in the plan: less regulation for businesses, yet still enough legal protection to keep cross-border data flows intact.
What changes next
The announcement did not set out the exact legal clauses Reform UK would change, so businesses and privacy teams still do not know which parts of the current regime would survive intact. The immediate question is whether the party’s promised light-touch law would keep the same practical safeguards on consent, retention, and transfers while trimming the compliance burden that smaller firms say has become costly.







