There's the risk aspect and the regulation aspect. Personally I think there's something to be said for a country where your car can't collect data on your trade union membership and sex life and pass it on to your insurers. (The UK is no longer in the EU so it's not technically subject to GDPR anymore, but they "forked" that law when they left and it's now called the Data Protection Act (DPA).
It's worth noting that's Data Protection Act (2018), there was also Data Protection Act (1998) which predates GDPR and had many of the same laws. People outside of the UK only started caring when a regulator with enough teeth (and penalties harsh enough) took notice, but data protection has been a requirement in the UK long before GDPR and should hopefully continue long after it.
No, the Data Protection Act (2018) is just the legal instrument which sets out the (UK) GDPR. It is 'technically subject to GDPR anymore', it's just a different one (with essentially if not entirely the same contents).
>No, the Data Protection Act (2018) is just the legal instrument which sets out the (UK) GDPR.
That's not right either.
The GDPR is law because it's an EU Regulation that was made while we were part of the EU, and it became UK law automatically when it was passed, as regulations do.
The Data Protection Act 2018 augments the GDPR, but the GDPR would be the law of the land with or without the DPA.