- Article 30 and supporting documentation guidance.
References and citations
- Accountability, records, and contracts guidance.
- Primary ICO guidance hub.
- UK legislative text.
Decide if UK GDPR applies and which obligations trigger first.
Use Article 3 scope tests, role mapping, and risk triggers to avoid shallow or overbroad scoping.
Structured answer sets in this page tree.
Cited legal and guidance references.
A good UK GDPR scope memo shows why the law applies, which entity acts as controller or processor, and which high risk workflows need follow up work.
UK GDPR has applied in the United Kingdom since January 1, 2021. Start with whether the processing is tied to a UK establishment, offering goods or services to people in the UK, or monitoring behaviour in the UK.
For each activity, decide whether the organisation is a controller, joint controller, or processor and note whether children, profiling, special category data, or transfers are involved.
An applicability decision is useful only if it can be defended later. Keep the output close to the processing inventory and vendor register.
Assessment Autopilot can take UK GDPR Applicability Test from deciding whether these obligations apply in practice to a reusable workflow inside Sorena. Teams working on UK GDPR can keep owners, evidence, and next steps aligned without copying this guide into separate documents.
Start from UK GDPR Applicability Test and turn the guidance into owned tasks, evidence requests, and review checkpoints.
Review your current process, evidence gaps, and next steps for UK GDPR Applicability Test.