Reform UK, the political party led by Nigel Farage, published a policy document in August 2026 promising that if it forms a government, it would scrap the UK version of the GDPR and replace it with a lighter privacy law modelled on New Zealand's rules. This matters to anyone running a website, an ad campaign, or a small business in Britain, because GDPR compliance currently shapes cookie banners, consent forms, and how customer data gets collected and used. Nothing changes for advertisers or publishers today: this is an opposition party's policy pledge, not a bill before Parliament, and Reform UK would need to win a general election and then legislate before any of it took effect.

Where the plan comes from

Reform UK published a 20-page policy document titled "Contract with Small Business" in August 2026, setting out what the party says it would do for Britain's small and medium enterprises if it won power. The document carries signatures from party leader Nigel Farage, deputy leader Richard Tice, and shadow chancellor Robert Jenrick. Among five headline commitments covering tax, hiring costs, energy prices, and access to finance, the fifth promises to "ease the regulatory burden" by repealing the UK's retained version of the General Data Protection GDPR and replacing it with a New Zealand-style privacy law, alongside scrapping electric vehicle sales mandates for cars and vans.

The pledge sits inside a broader argument the document makes about the state of British small business. According to the document, the United Kingdom's 5.7 million small and medium enterprises employ 16.9 million people. The same document states that less than a fifth of small businesses expect to grow over the next 12 months, which it describes as the lowest share on record, with almost twice as many expecting to shrink, sell up, or close entirely.

The GDPR repeal sits alongside a wider basket of proposals: raising the VAT registration threshold from £90,000 to £150,000, cutting employer National Insurance back from 15% to 13.8%, reversing inheritance tax changes affecting family farms and businesses, introducing wage credits for apprentices, and scrapping so-called Net Zero policies the party blames for high energy costs. None of the other four pillars touch advertising or data directly. The GDPR section does, and that is where the marketing and ad-tech relevance of this document concentrates.

What the document proposes to replace

The core of Reform UK's data protection argument rests on a comparison with New Zealand's Privacy Act 2020. According to the document, "under New Zealand's Privacy Act 2020, there is no GDPR-style requirement to fit every act of processing into one of a prescribed set of 'lawful bases'." Instead, the document states, that law is "built around 13 broad privacy principles," under which businesses "may collect personal information that they need, but they must collect it fairly and keep it secure, and generally must use or disclose it only for the purpose for which it was obtained or a directly related purpose."

The document does not claim the New Zealand model abandons enforcement altogether. It notes that the regime "still requires firms to notify people of serious data breaches and to give them (reasonable) access to their own information." What it removes, according to Reform UK, is "the GDPR's elaborate system of legal bases and turnover-linked administrative penalties." The pitch is one of compliance simplicity rather than an absence of privacy protection, at least as the party frames it.

Reform UK anticipates the most obvious objection to this plan: that stripping GDPR-equivalent protections could threaten the UK's data adequacy status with the European Union, the mechanism that currently allows personal data to flow between the EU and UK without additional safeguards. The document addresses this directly, noting that the European Commission itself recognises fifteen countries, New Zealand among them, as having "adequate" data protection despite not running GDPR-equivalent regimes. On that basis, the document states its expectation that "the UK's adequacy decisions would be maintained" under a New Zealand-style framework.

That claim will likely draw scrutiny if the policy ever moves beyond a party position paper. Adequacy decisions are assessed by the European Commission on the substance of a country's data protection regime rather than by analogy to a third country's arrangement, and the UK's own current adequacy decision, last extended by the Commission in 2025, would presumably need to be reassessed against whatever replacement law actually passed rather than against New Zealand's separate framework.

The economic case Reform UK makes for repeal

The document leans on academic research to argue that GDPR has depressed European technology investment. It cites a finding that "economists have found that the GDPR cut venture investment in European tech firms by a full 25%, compared to their American competitors," attributing this to research by Jian Jia and co-authors on transatlantic venture investment following GDPR's introduction. It also cites separate research claiming GDPR "halved the number of new apps being added to the Google Play Store from Europe, including the UK," referencing a paper by Rebecca Janßen and colleagues on what they term a "lost generation" of European apps.

These figures are consistent with a body of economic literature examining GDPR's effect on the European technology sector that has circulated since the regulation took effect in 2018, though the scale of the estimated impact varies across studies depending on methodology and time period examined. Reform UK's document does not cite counter-studies or acknowledge methodological debate within that literature, presenting the figures as settled findings rather than contested estimates.

More broadly, the document frames GDPR compliance as a disproportionate burden specifically on small businesses without dedicated legal or compliance teams. It states that "more than half of Britain's 'innovative' small businesses say they struggle with the GDPR," attributing the figure to the Department for Business and Trade's 2024 Business Perceptions Survey. The document argues that under GDPR, "every company - no matter how small or low-tech - has to identify the 'lawful basis' on which it collects or processes information," and that even compiling a public list of prospective business customer emails "can be considered 'data processing' and create privacy obligations."

How this connects to the ongoing Brussels debate

Reform UK's proposal arrives as the European Union runs its own, separate process to simplify the same regulation that Reform wants to abolish outright in Britain. The European Commission published its Digital Omnibus package on 19 November 2025, proposing amendments that would narrow the definition of personal data, expand exemptions for AI training, and raise breach notification thresholds, while leaving the GDPR's core architecture, including its lawful-basis requirement, intact.

That EU process has proven contentious in its own right. The European Data Protection Board and European Data Protection Supervisor jointly rejected key elements of the Digital Omnibus on 10 February 2026, warning the changes would weaken privacy rights rather than simplify compliance as intended. A survey of privacy professionals published by noyb in March 2026 found that the articles the Commission proposed restricting were often not the ones generating the most compliance work in practice, suggesting a mismatch between the EU's simplification target and where the actual burden sits. Separately, the EU Council removed a proposed automated consent signal, Article 88b, from its compromise text on 18 June 2026 following industry lobbying, leaving the European Parliament as the only remaining route to restore it.

The contrast is instructive for anyone tracking European data policy. Brussels is attempting incremental amendment within the existing GDPR framework, arguing over specific articles and thresholds, while facing resistance from its own data protection authorities. Reform UK's proposal, by comparison, would discard the framework entirely and start from a different legal architecture built on broad principles rather than enumerated lawful bases. The UK already operates a version of this simplification debate through its own domestic legislation. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 under the current government, amending the UK GDPR and the Data Protection Act 2018 in ways the government described as modernising automated decision-making rules and reducing compliance burdens, without replacing the underlying regulation. Reform UK's proposal goes considerably further than that existing reform, treating amendment as insufficient and proposing wholesale replacement instead.

What the document does not specify

The Reform UK document is a party policy paper rather than draft legislation, and several practical questions a repeal would raise are not addressed in the text. It does not specify a timeline for repeal beyond the general condition of forming a government. It does not detail what would happen to guidance, case law, and enforcement precedent built up under UK GDPR and its predecessor regime since 2018. It does not address whether a New Zealand-style law would apply the same territorial scope as GDPR, which currently extends to non-UK organisations that monitor the behaviour of, or offer goods and services to, people in the UK regardless of where the organisation is based.

For an advertising and marketing audience specifically, the document does not mention the ePrivacy regime that separately governs cookie consent and direct electronic marketing in the UK, distinct from data protection law proper. GDPR governs what happens to personal data once collected; the UK's Privacy and Electronic Communications Regulations govern the act of placing cookies or sending marketing messages in the first place. A repeal of UK GDPR alone would not necessarily touch that separate framework unless legislated together, and the document does not address the relationship between the two.

Context for the marketing and ad tech sector

For programmatic buyers, publishers, and agencies operating in the UK, the practical relevance of this document today is limited: it is a policy position from a party that does not currently hold government, published roughly a year ahead of no confirmed general election date. Its significance lies less in immediate compliance implications and more in signalling where UK data protection policy could move if political conditions shift. Reform UK has grown its parliamentary and local government presence since the 2024 general election, and its formal policy documents increasingly read as governing platforms rather than opposition rhetoric.

The document's framing of GDPR as a barrier specifically to small business growth, rather than to large platforms with dedicated compliance functions, echoes a distinction the marketing industry has debated for years: that uniform data protection obligations under GDPR apply the same lawful-basis and documentation requirements to a five-person agency as to a global advertising network, regardless of relative compliance capacity. The European Union's own Digital Omnibus process has faced similar criticism in reverse, with noyb's survey work suggesting that the EU's proposed simplifications may not target the provisions actually causing the most friction for smaller operators.

Whether a New Zealand-style principles-based regime would in practice reduce compliance costs for UK small businesses, or simply shift ambiguity from statutory lawful-basis tests to more open-ended fairness and purpose-limitation principles enforced case by case, remains untested in the UK context. New Zealand's Privacy Act 2020 has operated for a smaller population and a different regulatory culture than the UK's, and transplanting a framework across jurisdictions of very different scale carries its own uncertainties that the policy document does not explore in detail.

Timeline

  • 19 June 2025 - The Data (Use and Access) Act, the UK government's own amendment to UK GDPR, receives Royal Assent.
  • 19 November 2025 - The European Commission publishes the Digital Omnibus proposal to amend GDPR at EU level, a separate and more incremental reform track than Reform UK's proposal.
  • 10 February 2026 - The EDPB and EDPS jointly reject key elements of the EU's Digital Omnibus proposal.
  • March 2026 - noyb publishes survey findings suggesting the EU's proposed GDPR restrictions do not match where compliance burden actually falls.
  • 18 June 2026 - The EU Council removes the automated consent signal provision from its Digital Omnibus compromise text.
  • August 2026 - Reform UK publishes "Contract with Small Business," pledging to repeal UK GDPR and replace it with a New Zealand-style privacy law.

Summary

Who: Reform UK, the political party led by Nigel Farage, with signatures from deputy leader Richard Tice and shadow chancellor Robert Jenrick.

What: Published a policy document, "Contract with Small Business," pledging to repeal the UK's retained General Data Protection Regulation and replace it with a New Zealand-style privacy law built on broad principles rather than enumerated lawful bases, as part of a wider package of small-business tax, hiring, and energy proposals.

When: August 2026, according to the document's cover date.

Where: The United Kingdom, targeting the country's 5.7 million small and medium enterprises, though the proposal would also affect any organisation processing the personal data of people in the UK.

Why: Reform UK argues that GDPR imposes disproportionate compliance costs on small businesses without dedicated legal teams, citing research linking the regulation to reduced venture investment and fewer new apps from European developers, and proposes New Zealand's lighter, principles-based framework as an alternative it believes would preserve the UK's EU data adequacy status.