background image blur
background image
  • Blog
    >
  • News
    >
  • Nigel Farage Says GDPR Strangled Business. Here's What It Actually Does

Nigel Farage Says GDPR Strangled Business. Here's What It Actually Does

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 26 August, 2026
A grey-haired man using his tablet on a sofa

Key Takeaways

  • Reform UK has proposed replacing the UK's data protection framework — currently based on an amended version of the EU's GDPR — with a "light-touch" privacy law modeled on New Zealand's Privacy Act.
  • Reform UK leader Nigel Farage and MP Robert Jenrick framed the proposal as cutting "suffocating EU red tape" that has "strangled small businesses and tech firms."
  • New Zealand's Privacy Act provides a significantly narrower set of individual rights than GDPR, including no "right to be forgotten" and generally weaker enforcement mechanisms.
  • Reform UK claims the New Zealand model would preserve the UK's EU data adequacy status, but experts note the European Commission only grants adequacy to countries providing "essentially equivalent" data protection to EU standards — a bar New Zealand's framework may not meet under current GDPR interpretation.

Reform UK unveiled plans on Tuesday to scrap the UK's data protection framework — currently based on an amended version of the EU's General Data Protection Regulation — and replace it with what the party describes as a "light-touch" privacy law modeled on New Zealand's Privacy Act, according to reporting by Politico

The proposal is part of a broader package of small business support measures. Reform UK leader Nigel Farage called it a "bold, common-sense rescue plan," and MP Robert Jenrick said GDPR has "strangled small businesses and tech firms alike in a web of unnecessary regulation."

The framing is familiar: data protection law as bureaucratic burden rather than individual right. The argument has political appeal, particularly to small businesses that experience GDPR's compliance requirements as genuinely onerous without always having clear sight of what those requirements actually protect.

The UK has already been moving in this direction. The Data (Use and Access) Act, passed last year, relaxed some aspects of UK GDPR in a bid to boost economic growth — a policy direction Reform UK is now proposing to accelerate significantly.

What GDPR Actually Does — and What New Zealand's Framework Doesn't

The political case against GDPR focuses on compliance costs. The individual rights case for it is less often made in these discussions, so it's worth being clear about what's at stake.

GDPR gives EU and UK individuals specific named rights: the right to access data held about them, the right to have inaccurate data corrected, the right to erasure (the "right to be forgotten"), the right to data portability, and the right to object to processing — including for direct marketing and profiling. 

It requires companies to have a legal basis for processing personal data, to obtain genuine consent where consent is the basis, and to report data breaches within 72 hours. Enforcement is backed by fines of up to 4% of global annual turnover.

New Zealand's Privacy Act, which Reform UK is proposing as the model, provides a substantially narrower set of rights. There is no right to erasure. Enforcement mechanisms are generally weaker. The Privacy Commissioner has fewer investigative powers and smaller sanction capacity than GDPR enforcement bodies.

Reform UK's press release argues that following the New Zealand model would preserve the UK's EU data adequacy status — the designation that allows personal data to flow freely between the UK and EU. This is where the proposal runs into a structural problem. The European Commission grants adequacy only to countries providing "essentially equivalent" data protection to EU standards. 

The UK's current adequacy status was granted on the basis of its GDPR-derived framework. A move to a significantly lighter regime — one without a right to erasure, with weaker enforcement, and modeled on a country the EU has not itself granted full adequacy to — would put that status at risk.

Why This Matters for Internet Freedom

Data protection law and internet freedom occupy the same territory. GDPR is, among other things, the legal basis on which Europeans can demand that data brokers delete their records, challenge algorithmic profiling, and require platforms to justify what they collect and why. 

We covered California's DROP tool, which lets users opt out of 614 data brokers at once, as a meaningful step toward making privacy rights exercisable. GDPR is a more comprehensive version of that framework, applied by law rather than by opt-in.

Scrapping it in favor of a lighter framework doesn't primarily benefit ordinary users. It primarily benefits the companies whose business models depend on collecting and processing personal data with minimal friction. 

The small business compliance burden is real, but the solution to that is targeted reform of compliance requirements for small operators — not replacing the rights framework with one that gives individuals less recourse when those rights are violated.

We're tracking a week in which Brazil fined TikTok $30 million for collecting children's data without a legal basis, Russia launched a registry stripping digital service access from political dissidents, and France's court struck down an age verification law as a disproportionate privacy burden. 

Data protection law is doing genuine work in all three of those stories. Reform UK's proposal would weaken the UK's version of that framework at precisely the moment when its importance is most visible.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"