Re: GDPR-exit
Several factors to consider here.
Firstly< offences committed after GDPR applied up until 31st Oct will presumably have to be dealt with under GDPR, just as offences committed pre-GDPR but dealt with after GDPR applied were fined under the old regulations.
Secondly, if HMG wants to avoid problems for businesses which need to process data of EU residents then they'll need to achieve equivalence which means keeping GDPR-equivalent regulation in place. Whether such sanity will prevail is anybody's guess.
Thirdly, the current DPA implements GDPR so if the numpty in residence, whoever he may be, doesn't like that he'll have to replace it or repeal it.
Fourthly, post-Brexit, I presume any fines won't be shared with other EU countries so they may be less to take into account of fines which an EU regulator might apply. Alternatively the maximum sum of EU & UK fines could be 8%. That should make boards think.