PrivacyProof · UK sellers
GDPR + the cookie rules require a clear privacy policy, lawful opt-in for non-essential cookies, and a way for people to exercise their data rights. Check yours in 60 seconds.
🌍 Short answer: Since Brexit, UK businesses are treated as outside-the-EU sellers — so EU rules apply to you whenever you sell into the EU, on top of the UK's own (often closely-related) domestic regime.
Mind the two-tier picture: the UK usually has its own version for your domestic sales (e.g. UK GDPR, UK product-safety rules), while the EU version applies to your EU-facing sales. This page is about the EU rule — check the UK equivalent separately for domestic.
As a UK seller, this rule generally applies once you collect personal data from visitors in the EU or UK and sell to, ship to, or target customers in the EU. Collect data from EU/UK visitors? Check your privacy policy, cookie consent, and data-rights handling. Not sure? The free checker tells you in about a minute — no signup.
If you're in scope, you need to be able to answer "yes" to each of these — the points sellers most often get caught on:
⚠️ Exposure: up to €20M or 4% of global turnover (Art. 83) · Status: In force. EU regulators can act against non-EU sellers who reach EU customers.
Compare the penalty for every rule →
Since Brexit, UK businesses are treated as outside-the-EU sellers — so EU rules apply to you whenever you sell into the EU, on top of the UK's own (often closely-related) domestic regime.
If you serve EU/UK visitors and use any non-essential cookies (analytics, advertising), yes — they must load only after the visitor opts in, with a Reject option as easy as Accept.
What data you collect, why, the lawful basis, who you share it with, how long you keep it, international transfers, and how to exercise data rights — in plain language, available at collection.
Up to €20 million or 4% of global annual turnover, whichever is higher — plus regulator orders and reputational damage.
RuleGoose checks this against the EU GDPR (Reg. (EU) 2016/679), UK GDPR + ePrivacy/cookie rules. Read it yourself: EUR-Lex — Regulation (EU) 2016/679 →
or get one RuleGoose Score across every EU rule that reaches your business.
GDPR privacy & cookie consent is one of several EU rules that can reach a UK business. See the full EU compliance guide for UK sellers →, or read the platform-neutral GDPR privacy & cookie consent guide.
Informational only, not legal advice, and not affiliated with the EU. Territorial scope can be fact-specific — confirm against the cited source. Last reviewed 2026-06-30.