Surely you don't have to degrade your security to a lower UK standard, you can still meet GDPR and make it clear on your website, "Do you conform to GDPR?", "Yes we do. Although the UK have a lower standard of data protection, we still meet the stricter standard"
If UK law would require backdoors in a way that conflicts with GDPR, how could they remain compliant?