Reform UK's proposal to replace UK GDPR with a New Zealand-style privacy law raises an important question: which regulatory framework will govern your processing activities?
The answer isn't straightforward. Even if this proposal becomes law, most organizations will still operate under multiple regimes. Here's how to determine which path applies to your operations.
The Decision You're Facing
You need to establish whether a shift from UK GDPR to a New Zealand-modeled framework would:
- Reduce your compliance obligations
- Leave them unchanged
- Create dual-regime complexity
This decision isn't theoretical. Your answer determines budget allocation, tooling decisions, and whether your current privacy program needs restructuring or just minor adjustments.
Key Factors That Affect Your Choice
Factor 1: Your EU market exposure
Do you offer goods or services to data subjects in the EU? Article 3(2) of EU GDPR establishes extraterritorial reach based on targeting or monitoring EU individuals, regardless of where your entity is established.
Factor 2: Your processing volume and complexity
New Zealand's Privacy Act operates with 13 privacy principles rather than UK GDPR's detailed articles. This principles-based approach offers flexibility but less prescriptive guidance on technical implementation.
Factor 3: Your existing compliance infrastructure
You've built systems, policies, and training around UK GDPR's specific requirements: DSARs within one month, Article 30 records of processing, Data Protection Impact Assessments for high-risk processing. Can these assets translate to a different framework?
Factor 4: Your supervisory authority interactions
The Information Commissioner's Office has established enforcement patterns, guidance, and case law. A new regime means rebuilding that institutional knowledge.
Path A: You Continue Under EU GDPR (Full Compliance Required)
Choose this path if:
- You target EU customers through localized websites, EU-specific marketing, or EU payment options
- You monitor behavior of EU data subjects (web analytics, behavioral advertising, location tracking)
- You process EU employee data as part of an international group
- You operate as a processor for EU-based controllers
What this means operationally: Your compliance program doesn't change. You still need:
- GDPR-compliant lawful bases for each processing purpose
- Article 30 records documenting all processing activities
- DSAR responses within one month (extendable to three in complex cases)
- Personal data breach notifications within 72 hours to the relevant supervisory authority
- Data Protection Impact Assessments for high-risk processing
The New Zealand-style UK law becomes irrelevant to your core operations. You might face dual compliance if you also process UK-only data, but your baseline remains EU GDPR.
Your action: Audit your customer base and processing activities now. Document which processing falls under Article 3(2). Don't assume you're exempt because you lack an EU establishment; the extraterritorial effect is triggered by offering or monitoring, not by physical presence.
Path B: You Transition to New Zealand-Style Framework (Reduced Prescriptiveness)
Choose this path if:
- Your processing involves only UK data subjects
- You have no EU customer targeting or behavioral monitoring
- You're willing to rebuild compliance infrastructure around principles rather than detailed articles
What this means operationally: New Zealand's Privacy Act 2020 works through 13 Information Privacy Principles covering collection, use, disclosure, storage, and access. The framework is less prescriptive than GDPR but still requires:
- Purpose limitation and collection limitation
- Individual access rights (similar to DSARs but with different timelines)
- Security safeguards appropriate to the sensitivity of information
- Breach notification to affected individuals and the Privacy Commissioner
You'll lose some GDPR-specific structures:
- No Article 30 processing records requirement (though documentation remains prudent)
- No formal Data Protection Impact Assessment obligation
- Different consent standards (less stringent than GDPR's "freely given, specific, informed, unambiguous")
- Legitimate interests don't require formal assessments
Your action: Map your current GDPR controls to New Zealand's 13 principles. Identify which documentation you can simplify and which protections you'll maintain anyway for risk management. Don't dismantle your entire program; you've built institutional knowledge that remains valuable even under a lighter regime.
Path C: You Operate Dual Regimes (Maximum Complexity)
Choose this path if:
- You process both EU and UK-only data
- You can't cleanly separate processing activities by jurisdiction
- You serve both markets through integrated systems
What this means operationally: You maintain GDPR compliance for EU-related processing while adapting UK-only activities to the new framework. This creates:
- Split documentation requirements
- Different DSAR timelines depending on data subject location
- Dual training programs for staff handling both datasets
- Complex breach notification workflows
This is the highest-burden scenario. You're not reducing compliance costs; you're adding a second regime.
Your action: Consider whether you can segregate processing by jurisdiction. If your CRM, marketing automation, or analytics tools mix EU and UK data, you might default to GDPR compliance across the board rather than attempt separation. Sometimes the simplest path is maintaining the higher standard universally.
Summary Matrix
| Factor | EU GDPR Path | NZ-Style Path | Dual Regime |
|---|---|---|---|
| EU market presence | Yes | No | Mixed |
| Prescriptive requirements | High | Moderate | High (for EU data) |
| Documentation burden | Article 30 records, DPIAs | Principles-based | Both frameworks |
| DSAR timeline | One month | Different standard | Depends on requester location |
| Consent standard | Strict (freely given, specific, informed, unambiguous) | More flexible | Strict (for EU data) |
| Supervisory authority | EU authority (based on establishment or lead authority) | UK Privacy Commissioner | Multiple authorities |
| Implementation effort | Continue current program | Rebuild around principles | Maintain both |
The proposal to replace UK GDPR doesn't create a clean before-and-after. It creates a choice matrix where your EU exposure determines your actual obligations. Map your processing activities against Article 3(2) now, before any legislative change forces rushed decisions.



