← SOVEREIGNTY LAW ATLAS

SOVEREIGNTY LAW ATLAS — UK

United Kingdom

TIER DEMO · STATUS PUBLISHED · LAST FULL REVIEW 2026-08-04 · 2 INSTRUMENTS ON RECORD

The verdict.

FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04
Data residency & localizationD1 — WHERE DATA MUST LIVE Transfer controls not localizationVERIFIED
AI-specific regulationD2 — AI ACTS & REGISTRATION DUTIES No instrumentVERIFIED
Cloud & procurement sovereigntyD3 — CERTIFICATION & MANDATES Procurement frameworkREPORTED
Export & access lawsD4 — EXTRATERRITORIAL REACH Bilateral access agreementJUDGMENT
Instruments on record 2
Last full review 2026-08-04
Status PUBLISHED
For a buyer

post-Brexit the UK runs a near-copy of the EU transfer regime — divergence is watchable, not yet material.

Configure your SovereigntyBox for United Kingdom →

ATLAS RECOMMENDATION — DOCUMENTED CONTROL · UK–US access agreement — local runtime, no overflow path. Seeded into the configurator; adjust anything.

The dossier.

SOURCES FOOTNOTED · EVIDENCE STATE LABELLED

Domains

D1 — Data residency & localization

The Data Protection Act 2018 together with the retained UK GDPR forms the regime: transfers to third countries require adequacy regulations or appropriate safeguards (the IDTA or the UK addendum to EU SCCs).1 There is no localization mandate. EU adequacy decisions for the UK were extended to December 2025; their renewal is the divergence watchpoint. (REPORTED)

D2 — AI-specific regulation

The 2023 white paper chose a sectoral, non-statutory path: existing regulators apply cross-cutting principles rather than a single AI act.2 As of capture no AI statute is in force.

D3 — Cloud & procurement sovereignty

Public-sector cloud procurement runs through Crown Commercial Service frameworks (G-Cloud). There is no certification scheme comparable to France's SecNumCloud or Germany's C5; sovereignty requirements appear as contract terms, not qualifications.

D4 — Export & access

The UK–US Data Access Agreement (2019, under the CLOUD Act) allows reciprocal lawful demands directly to providers. The Investigatory Powers Act 2016 supplies domestic powers. Both make "UK region" a weaker sovereignty claim than "UK-controlled provider."

Extraterritorial exposure

Two-sided: US law reaches UK-hosted data at US-controlled providers (CLOUD Act), and UK law reaches outward via the IPA's extraterritorial warrants. A UK-incorporated, UK-controlled provider materially reduces the first; only data-location plus provider-control together address the second. US reference record deferred to Phase 2.

Disclaimer

This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

  1. Data Protection Act 2018 (c. 12) + UK GDPR (retained EU law) — legislation.gov.uk — vault atlas-vault/uk/uk-dpa2018/2026-08-04.pdf, sha256 8b6f3eef…, captured 2026-08-04. (VERIFIED)
  2. A pro-innovation approach to AI regulation — DSIT white paper, 2023 — gov.uk, not vaulted (HTML source). (REPORTED)

The instruments.

2 ON RECORD · 1 GAPS

Data Protection Act 2018 (c. 12) + UK GDPR (retained EU law)

VERIFIED
TYPE STATUTESTATUS IN-FORCEENACTED 2018-05-23 · IN FORCE 2018-05-25
EvidenceVAULT atlas-vault/uk/uk-dpa2018/2026-08-04.pdf · SHA256 8b6f3eef… · CAPTURED 2026-08-04
RAGblocked — parser staging 401

A pro-innovation approach to AI regulation (white paper, 2023; sectoral implementation)

REPORTED
TYPE POLICY-FRAMEWORKSTATUS NON-STATUTORY
AuthorityDSIT
Evidencenot-vaulted — HTML-only source
RAGnot-submitted
GAP — D3 · VERIFIED 2026-08-04VERIFIED ABSENCE

No national sovereign-cloud certification scheme; procurement via CCS frameworks

This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.

SBX CONCIERGEnothing leaves this page