"GDPR-compliant" stopped being a universal badge in 2026
The UK's Data (Use and Access) Act and a growing US state patchwork mean the same contact data can be compliant in one market and not another.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
For most of the GDPR era, “we’re GDPR-compliant” functioned as a rough, if imprecise, shorthand for “we take data protection seriously” everywhere a company operated — even outside the EU. That shorthand is losing its usefulness in 2026, and not because GDPR is weakening. It’s because the rest of the world stopped converging toward it and started diverging from it, in different directions, at different speeds, and a compliance posture built around one reference framework no longer maps cleanly onto where your contacts actually live.
The UK just proved the point
The clearest 2026 evidence is the UK’s own break from the EU model. The UK’s Data (Use and Access) Act 2025 (DUAA) began taking effect through 2026, and legal analysis has started describing it, without much hedging, as “the great GDPR divergence.” The UK and EU frameworks still share the same GDPR ancestry and core principles, but the DUAA introduces real, practical differences: it exempts certain analytics cookies from consent requirements when they only collect aggregate, non-identifying data, where EU ePrivacy rules still require consent for essentially all non-essential cookies. It replaces the EU’s “essential equivalence” test for international data transfers with a UK-specific “not materially lower” standard. And more broadly, it signals a shift from GDPR’s one-size-fits-all model toward a risk-based approach that gives UK controllers more discretion than their EU counterparts have.
The European Commission renewed the UK’s adequacy decision in December 2025 despite this divergence, so data can still flow between the two regimes for now. But “adequate” isn’t “identical” — a cookie-consent flow or a transfer justification built strictly to EU GDPR requirements can be simultaneously over-engineered for the UK and under-engineered for wherever else you operate, and the two rulebooks are drifting further apart, not closer together, as UK regulators use the discretion DUAA hands them.
The US isn’t converging either — it’s fragmenting further
Cross the Atlantic and the picture is a genuine patchwork rather than a single divergent pair. There’s still no comprehensive federal privacy law in the US, so individual states keep filling the gap on their own timelines and with their own rules. 2026 brings new comprehensive laws in Indiana, Kentucky, and Rhode Island, while California, Colorado, Connecticut, Oregon, and Utah are amending laws already on the books — meaning the compliance target in a majority of US states isn’t just present, it’s actively moving under a company’s feet within a single year.
The deeper structural mismatch isn’t the count of states, it’s the default. GDPR runs on opt-in — processing requires a lawful basis established before you act. Most US state laws run on the opposite default: process unless and until someone opts out. A system that only tracks “has this person consented” can’t correctly represent a US contact’s status, because the relevant question in that market is different — “has this person opted out” — and the two aren’t just phrased differently, they’re structurally incompatible with a single yes/no flag per contact. And unlike GDPR’s percentage-of-revenue penalty structure, several US state laws price violations per-incident — California’s CPRA, for instance, allows penalties per intentional violation with no aggregate cap, a different risk shape entirely from GDPR’s up-to-4%-of-turnover ceiling.
Add Brazil, Canada, and Australia and the picture gets clearer, not muddier
None of this is unique to the EU/UK/US triangle — it’s the general pattern globally. Brazil’s LGPD, Canada’s CASL, and Australia’s Spam Act each define consent, retention, and enforcement differently enough that a program compliant under one doesn’t automatically clear the bar under another. Norbelys has per-region breakdowns of each, worth treating as the actual reference rather than inferring rules from whichever country’s law you happen to know best: Australia’s Spam Act, Brazil’s LGPD, California’s CCPA/CPRA, Canada’s CASL, the EU’s GDPR, and the UK post-Brexit regime — plus a direct comparison of CAN-SPAM, GDPR, and CASL if you’re weighing three of the biggest frameworks against each other directly.
What “compliant everywhere” actually requires now
The operational implication for anyone selling or sending across borders is narrower than it sounds: stop treating compliance as a single global setting and start treating it as a per-region attribute of every contact. Concretely, that means tracking, at minimum:
- Which jurisdiction’s rules apply to this contact — usually based on residence, not just company location.
- What legal basis or consent status you’re actually relying on there — opt-in on file, legitimate interest documented, or opt-out honored, and which one applies depends on the jurisdiction, not on your default policy.
- What that jurisdiction’s specific retention, disclosure, and opt-out mechanics require — the per-country breakdowns above exist precisely because these details differ enough to matter.
A single “we’re compliant” banner was never fully accurate, but it was close enough to functional when most of the regulatory world was still converging on GDPR as the reference model. In 2026, with the UK actively diverging and US states actively multiplying, that banner is now doing less work than it looks like it’s doing. The businesses least exposed to a bad surprise are the ones tracking compliance per-region as a property of the contact, not as a single company-wide claim.
Where “per-contact, not per-company” has to actually be enforced
The hardest part of that shift isn’t deciding it’s the right model — it’s having a system that can act on it. When a GDPR erasure request and a CCPA opt-out request land on the same day for contacts in different jurisdictions, “we’re compliant” needs to resolve into two different, correct actions, not one shared response. That’s the concrete distinction behind Norbelys’s erasure endpoint: a regular archive is reversible and keeps the record intact, while an erasure request is a separate, audited action that destroys the contact’s PII permanently and adds the address to the suppression list — the difference between a convenience delete and a request that has to hold up under a regulator’s question later. Whichever jurisdiction’s rule triggered the request, the platform doesn’t need to know in advance which one applies; it just needs to give you the right two buttons and an audit trail proving which one got pressed, for which contact, when.