Following Brexit, the UK incorporated GDPR into domestic law as the UK GDPR, maintaining largely the same provisions while allowing for future divergence. Effective from January 1, 2021, it works alongside the Data Protection Act 2018 to form the UK’s data protection framework. Key differences include the ICO as the sole supervisory authority, specific provisions for UK-based organizations, and modified international transfer mechanisms. The UK has its own adequacy decisions and implements an International Data Transfer Agreement (IDTA) as an alternative to Standard Contractual Clauses. Penalties remain aligned with EU GDPR at up to £17.5 million or 4% of global turnover. The UK government has proposed reforms through the Data Protection and Digital Information Bill to reduce compliance burdens while maintaining high protection standards. For Indian organizations, UK GDPR compliance is required when processing UK residents’ data.
Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality,