Artifact GuideUKApplicability Test

UK GDPR Applicability Test

UK GDPR applies activity by activity. Test the data and processing under Article 2, the UK connection under Article 3, any exclusion, and whether each organisation acts as controller or processor.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

Apply this test to one processing activity. Identify , the form of processing, the UK establishment or UK-targeting connection, the relevant controller or processor, and any Article 2 exclusion before mapping obligations. Do not decide scope from the organisation's headquarters alone.

Section 1

What should the UK GDPR Applicability Test decide?

Article 2 covers processed wholly or partly by automated means and non-automated personal data that forms, or is intended to form, part of a filing system. It also covers manual unstructured personal data held by an FOI public authority. A name, device identifier, location, or pseudonymous record can be personal data when it relates to an identified or identifiable person.

Article 3 applies where processing occurs in the context of a UK establishment, even if the processing itself takes place elsewhere. It can also apply to a non-UK controller or processor whose relevant processing concerns people in the UK and relates to offering them goods or services, whether paid or free, or monitoring their behaviour in the UK. Mere website availability or having UK customers does not by itself answer the targeting question; record the features that connect the activity to the UK.

Purely personal or household activity is excluded. Competent-authority law-enforcement processing and intelligence-services processing instead fall under separate Data Protection Act 2018 regimes. Anonymous information is outside UK GDPR, but pseudonymised information remains where it can be attributed using additional information.

  • Describe the processing activity, the , the people concerned, and whether processing is automated, structured, or held by an FOI public authority.
  • Record the UK establishment activity or the facts showing an offer to people in the UK or monitoring of behaviour in the UK.
  • Test the personal or household, competent-authority law-enforcement, and intelligence-services exclusions separately.
  • Identify each controller, joint controller, and processor from who decides the purposes and essential means, not from contract labels alone.
  • Record the conclusion, facts, source provision, owner, reviewer, and change triggers. Reassess when the purpose, market, user group, system, or supplier changes.
Section 2

Who should own the UK GDPR applicability test, and what evidence should prove the decision?

The business or product owner should describe the activity and UK market facts. Privacy or legal should review the Article 2 and 3 analysis and exclusions. Procurement and engineering should confirm supplier roles, hosting, data flows, and whether a non-UK provider processes data in the context of a UK offer or monitoring activity.

The scope record should show the activity, data and people, automation or filing-system status, UK connection, exclusions considered, role analysis, systems and recipients, conclusion, date, reviewer, and events that require reassessment. Lawful basis, notices, rights, security, and transfers follow only after this threshold decision.

  • Business or product owner: describe the purpose, users, market, collection points, systems, disclosures, and intended changes.
  • Engineering and procurement: provide the data-flow map, filing-system or automation facts, supplier instructions, hosting locations, access paths, and contract roles.
  • Privacy or legal reviewer: record the Article 2 result, Article 3 connection, exclusions, controller and processor analysis, assumptions, and any separate EU GDPR or PECR workstream.
  • Approver: date the conclusion, list missing evidence, and set event-based review triggers rather than treating scope as a one-time corporate decision.
Section 3

Which edge cases should teams check before relying on a UK GDPR applicability test decision?

At a boundary, identify which instrument supplies the rule: UK GDPR for general processing, the Data Protection Act 2018 for UK conditions, exemptions, law-enforcement processing, and intelligence-services processing, and PECR for electronic communications and access to terminal equipment. EU GDPR may apply independently to the same activity under its own territorial scope; UK GDPR coverage does not displace that separate analysis.

Review this section before approving a new processing purpose, vendor, transfer, profiling flow, DSAR workflow, breach process, or child-facing product change.

  • A spreadsheet, paper index, or other organised manual record can be a filing system; unstructured paper held by a private organisation is not brought into scope by Article 2 on that basis alone.
  • Pseudonymisation reduces attribution risk but does not make data anonymous when additional information can reconnect it to a person.
  • A non-UK website being reachable in the UK does not by itself prove an offer to people in the UK; document pricing, delivery, language, marketing, user references, and other targeting facts.
  • Employee, customer, or device monitoring can satisfy Article 3(2)(b) when the relevant behaviour takes place in the UK; record what is observed and how the observations are used.
  • A household user may fall within the personal-activity exclusion while a platform, employer, service provider, or other organisation processing the same data does not.
Section 4

How should teams operationalize the UK GDPR applicability test with proportionate controls?

Use a decision record with four gates: and covered processing; Article 2 exclusions; Article 3 UK connection; and controller or processor role. A 'yes' at the scope gate starts the obligation map. It does not establish a lawful basis or prove compliance.

If the facts are incomplete, record a conditional conclusion and the missing evidence. Typical open points are whether data is truly anonymous, whether a service is directed at people in the UK, whether online activity amounts to behavioural monitoring, and which party determines the purposes and essential means.

  • Gate 1 - data and processing: identify an identifiable person and automated or structured processing, or manual unstructured data held by an FOI public authority.
  • Gate 2 - exclusion: test purely personal or household activity, competent-authority law-enforcement processing, and intelligence-services processing.
  • Gate 3 - UK connection: identify a UK establishment activity, a documented offer to people in the UK, monitoring of behaviour in the UK, or the public-international-law connection in Article 3(3).
  • Gate 4 - role and outcome: identify every controller, joint controller, processor, and any required UK representative, then open the applicable lawful-basis, transparency, rights, accountability, security, breach, and transfer work.
  • Conditional outcome: state which gate cannot yet be answered, the missing evidence, who will obtain it, and whether processing may proceed pending review.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • The consolidated UK GDPR text is the primary UK legal source for deciding whether processing is in scope and which controller, processor, lawful-basis, rights, and accountability duties apply.
legislation.gov.uk
Referenced sections
  • Binding source for UK-specific conditions and exemptions and the separate law-enforcement and intelligence-services regimes.
ico.org.uk
Referenced sections
  • ICO guidance on applying UK GDPR duties after deciding scope and organisational roles.
"UK GDPR guidance and resources"
ico.org.uk
Referenced sections
  • Regulator guidance for applying UK GDPR duties after the material, territorial, exclusion, and role tests are complete.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.