# What applies in Europe and the UK?

**Short answer:** EU GDPR and UK GDPR, which track each other closely. The practical controls are the same; the main divergence is which instrument covers international transfers — EU SCCs versus the UK's IDTA or Addendum.

## The two regimes

| | EU GDPR | UK GDPR + DPA 2018 |
|---|---|---|
| **Supervisor** | National DPAs / EDPB | Information Commissioner's Office (ICO) |
| **Transfer instrument** | EU Standard Contractual Clauses | International Data Transfer Agreement, or UK Addendum to EU SCCs |
| **Principles, bases, processor duties** | Substantially identical | Substantially identical |

## What this means practically

Organizations operating in both must satisfy both, but the underlying controls overlap almost entirely. Vendor assessment work done for one carries over to the other with the transfer instrument swapped.

## Why this book's other regimes matter here too

GDPR is the template most of the world's newer data protection laws were built from. Bahrain and Oman mirror it closely; Kenya, Nigeria, and South Africa borrow its structure. Work done to satisfy GDPR is rarely wasted elsewhere — which is why organizations operating across several of these markets usually assess vendors against the strictest applicable regime rather than each one separately.

> Per-country detail is in **Country Compliance Guides**.