The UK government is proposing significant reforms to its data protection and corporate governance landscape. A new Data Reform Bill is set to replace the UK GDPR, aiming to reduce the compliance burden on businesses. This includes removing mandatory requirements for Records of Processing Activities (ROPA) and Data Protection Impact Assessments (DPIA), leaving it to firms' discretion. Additionally, consent requirements for analytical cookies are proposed to be removed. The government estimates these changes could provide a net direct monetized benefit of $1.04 billion over 10 years, rising to $1.45 billion if EU adequacy is maintained. However, privacy experts are concerned that these changes could lead to confusion and increase operational burdens for financial firms operating in both the UK and the EU.

Alongside data protection reforms, the UK is scaling back planned corporate governance changes following pushback from businesses. Proposals to make directors personally liable for internal controls, similar to the US Sarbanes-Oxley Act, have been dropped. Instead, a provision will be added to the corporate governance code for the largest listed companies, which boards can opt out of if they provide an explanation. The expansion of companies falling under stricter regulatory oversight has also been significantly reduced, with only an estimated 600 additional private companies (those with over 750 employees and over $750 million annual turnover) now designated as "public interest entities," compared to an original plan that could have included up to 4,000.

These reforms are intended to streamline regulations, reduce business burdens, and enhance the UK's position as an attractive global data marketplace. However, the watering down of corporate governance reforms has drawn criticism. Sir Jon Thompson, chief executive of the Financial Reporting Council, called the failure to introduce Sarbanes-Oxley-style rules a "missed opportunity." Similarly, Michael Izza of the ICAEW stated the package had a "halfhearted and lopsided feel to it," suggesting that lessons from company failures like Carillion have been ignored regarding internal controls and corporate governance. The government is also planning to replace the Financial Reporting Council with a more powerful regulator, the Audit, Reporting and Governance Authority (Arga).