Accessibility

Font size

Filters

Highlight

Colour

Zoom

Draft UK-EU Agreement FAQ

In February 2026, the United Kingdom (UK) and the European Union (EU) published a draft agreement setting out bespoke arrangements for Gibraltar (the “Draft Agreement”). This draft still needs to complete its legal review and ratification process, but it gives a clear picture of how our relationship with the EU may look in the future, including how your personal data will be protected. We will provide further updates as the Draft Agreement progresses through legal review, translation and ratification, and as any implementing legislation is brought forward in Gibraltar.

The below FAQs explain what, according to the Draft Agreement, is changing and what will stay the same for data protection in Gibraltar.

If you have any further questions about how these developments may affect your organisation or your personal data rights, you can contact the Information Commissioner’s office using the details provided on this website.

After the UK left the EU, Gibraltar was not covered by the UK‑EU Trade and Cooperation Agreement. To make sure people’s information continued to be protected to a high standard, Gibraltar adopted the Gibraltar General Data Protection Regulation (“Gibraltar GDPR”) through our EU Withdrawal arrangements.

The Gibraltar GDPR is based very closely on the EU’s General Data Protection Regulation (“EU GDPR”). In practice, this means:

  • Your privacy rights are very similar to those in the EU (for example, rights of access, rectification, and erasure).
  • Organisations in Gibraltar must follow rules that largely mirror those in the EU, with only limited local differences.

The Draft Agreement contains a specific article (Article 14) dealing with personal data protection. In simple terms, it would:

  • Re‑embed the EU GDPR into Gibraltar law, again with some limited local differences.
  • Keep Gibraltar aligned with the high standards that apply within the EU.

Some of the EU GDPR provisions on how supervisory authorities in different EU countries work together will not apply in the same way to Gibraltar. This reflects Gibraltar’s particular position and the fact that we have a single Information Commissioner, rather than being one of many EU data protection authorities.

The European Data Protection Board (EDPB) is the body that issues guidance, decisions, and opinions on how EU data protection law should be interpreted.

Under the Draft Agreement:

  • The guidance, decisions, and opinions of the EDPB will apply in Gibraltar, helping ensure that the rules are interpreted in a consistent way with the EU.
  • However, the Information Commissioner for Gibraltar will not be a regular member of the EDPB like EU countries’ data protection authorities.

Instead:

  • The Information Commissioner may be invited to attend EDPB meetings when:
    • a decision is addressed specifically to the Information Commissioner, or
    • the Information Commissioner’s presence is needed and in the interest of the EU to help ensure the rules are applied in the same way.
  • In those cases, the Information Commissioner will attend as an expert or guest and only for the relevant parts of the agenda.

This approach allows Gibraltar to follow EU data protection standards closely, while respecting our distinct constitutional position.

Data protection law is not static. The EU regularly updates and develops its rules, and the Draft Agreement creates a structured way for Gibraltar to stay aligned.

Under Article 19 of the Draft Agreement:

  • When the EU updates its data protection rules (including those listed in Annex 3 of the Draft Agreement), Gibraltar will need to decide within 30 days whether to adopt those changes.
  • If Gibraltar decides to adopt the new rules, they become binding obligations for Gibraltar.
  • If Gibraltar does not adopt them within that time, the Draft Agreement could, in principle, come to an end, unless the parties agree otherwise.
  • While Gibraltar completes any necessary constitutional or legislative processes, the new EU rules would apply provisionally.

For individuals and organisations, this is designed to provide continuity: it helps ensure that Gibraltar’s data protection framework remains closely aligned with the EU over time.

A key point for people and businesses is how Gibraltar is treated when personal data is transferred from the EU.

Under the Draft Agreement:

  • Gibraltar will not be treated as a “third country” for the purposes of EU data protection law, as long as certain compliance conditions are met.
  • This means there is no need for a separate EU “adequacy decision” for Gibraltar, unlike many non‑EU countries.
  • Personal data should be able to flow between Gibraltar and the EU without the additional transfer tools (such as standard contractual clauses) that are often needed for third countries.

The EU will also be required to keep the UK, in respect of Gibraltar, informed when it prepares new adequacy decisions relating to data protection. This helps ensure transparency and allows Gibraltar to understand how wider EU decisions may affect its position.

For most people and organisations in Gibraltar, the practical message is one of continuity and stability:

  • The strong data protection standards you are familiar with under the Gibraltar GDPR will continue, and in some respects will be further anchored to EU rules.
  • If you do business with partners in the EU, the Draft Agreement is designed to support the free flow of personal data, reducing complexity and cost.
  • Individuals can expect their rights, safeguards, and protections to remain closely aligned with those enjoyed by individuals in the EU.