SOVEREIGNTY LAW ATLAS — UK
United Kingdom
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04post-Brexit the UK runs a near-copy of the EU transfer regime — divergence is watchable, not yet material.
ATLAS RECOMMENDATION — DOCUMENTED CONTROL · UK–US access agreement — local runtime, no overflow path. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
The Data Protection Act 2018 together with the retained UK GDPR forms the regime: transfers to third countries require adequacy regulations or appropriate safeguards (the IDTA or the UK addendum to EU SCCs).1 There is no localization mandate. EU adequacy decisions for the UK were extended to December 2025; their renewal is the divergence watchpoint. (REPORTED)
D2 — AI-specific regulation
The 2023 white paper chose a sectoral, non-statutory path: existing regulators apply cross-cutting principles rather than a single AI act.2 As of capture no AI statute is in force.
D3 — Cloud & procurement sovereignty
Public-sector cloud procurement runs through Crown Commercial Service frameworks (G-Cloud). There is no certification scheme comparable to France's SecNumCloud or Germany's C5; sovereignty requirements appear as contract terms, not qualifications.
D4 — Export & access
The UK–US Data Access Agreement (2019, under the CLOUD Act) allows reciprocal lawful demands directly to providers. The Investigatory Powers Act 2016 supplies domestic powers. Both make "UK region" a weaker sovereignty claim than "UK-controlled provider."
Extraterritorial exposure
Two-sided: US law reaches UK-hosted data at US-controlled providers (CLOUD Act), and UK law reaches outward via the IPA's extraterritorial warrants. A UK-incorporated, UK-controlled provider materially reduces the first; only data-location plus provider-control together address the second. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.
- Data Protection Act 2018 (c. 12) + UK GDPR (retained EU law) — legislation.gov.uk — vault
atlas-vault/uk/uk-dpa2018/2026-08-04.pdf, sha2568b6f3eef…, captured 2026-08-04. (VERIFIED) ↑ - A pro-innovation approach to AI regulation — DSIT white paper, 2023 — gov.uk, not vaulted (HTML source). (REPORTED) ↑
The instruments.
2 ON RECORD · 1 GAPSData Protection Act 2018 (c. 12) + UK GDPR (retained EU law)
VERIFIEDatlas-vault/uk/uk-dpa2018/2026-08-04.pdf · SHA256 8b6f3eef… · CAPTURED 2026-08-04A pro-innovation approach to AI regulation (white paper, 2023; sectoral implementation)
REPORTEDNo national sovereign-cloud certification scheme; procurement via CCS frameworks
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.