Artifact GuideUKChecklist

UK GDPR Checklist

This checklist helps verify lawful basis, notices, rights handling, records, security, breaches, transfers, and review points under the UK GDPR before launch or review.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

This page turns UK GDPR into a practical checklist: confirm scope and roles, choose and record the lawful basis, give the required notices, protect the data, prepare rights, complaints, and breach workflows, and review DPIAs, transfers, and special cases before launch or material change.

Section 1

How should a Checklist workflow run under the UK GDPR?

Use the workflow as a pre-launch and change-review checklist: identify the processing, confirm the lawful basis, check special category or criminal-offence data, confirm notices, evidence, retention, security, and review triggers, then assign ownership and a next review date.

First confirm scope. The UK GDPR can apply to processing in the context of a UK establishment and to an organisation outside the UK that offers goods or services to, or monitors the behaviour of, people in the UK. Then identify the controller, any joint controllers, and each processor for the actual decisions and operations. The DPA 2018 supplies UK-specific conditions, restrictions, and exemptions; it is not a replacement for the UK GDPR.

A checklist item passes only when the live processing matches the recorded decision and the evidence can be inspected. Use 'not applicable' only with a reason and cited condition; use 'open' where facts, ownership, or remediation are missing. Distinguish binding duties from ICO guidance, optional certification, internal policy, and Sorena's suggested evidence fields.

  • Check whether the processing is lawful under Article 6 and whether any special category or criminal-convictions rule also applies.
  • Confirm the information given to people covers the identity of the controller, purposes, lawful basis, retention, rights, complaints, and transfers where relevant.
  • Confirm controller, joint-controller, and processor roles and that Article 28 terms or a joint-controller arrangement match the actual responsibilities.
  • Test rights intake, identity checks, searches, decisions, deadlines, communications, and exemptions with an auditable case record.
  • Maintain a clear data-protection complaints route for complaints received on or after 19 June 2026; acknowledge receipt within 30 days, investigate and keep the person informed without undue delay, and communicate the outcome without undue delay.
  • Confirm retention and deletion rules, access controls, resilience, incident detection, processor escalation, and the Article 33 and 34 breach decisions.
  • Record whether high-risk processing requires a DPIA before launch and whether unresolved high residual risk requires prior consultation.
  • Check whether Article 30 records are required. The fewer-than-250-person exception is narrow and does not cover processing that is more than occasional, is likely to risk people's rights and freedoms, or includes special category or criminal-conviction data.
  • Appoint a DPO where Article 37 requires one, including for a public authority or body other than a court acting judicially, or where core activities involve large-scale regular and systematic monitoring or large-scale special-category or criminal-conviction processing.
  • Check international transfers under Articles 44A-49A and apply the Children's Code and Article 25 children's higher-protection matters where relevant.
Section 2

What fields should the UK GDPR checklist template capture?

A useful template captures the processing and actor in scope, the control being checked, the binding rule or guidance relied on, the evidence, the owner, the due date, and the review outcome.

It should also show whether the item passed, failed, is not applicable for a recorded reason, or needs escalation. Keep a remediation owner and launch condition for failed controls rather than treating the checklist as a one-time attestation.

  • Processing purpose, lawful basis, and any linked special category or criminal-offence condition.
  • Notice content, recipient categories, retention period, and complaint route.
  • Record of processing, security measures, breach process, and DPIA or prior-consultation status.
  • Transfer mechanism, destination country or organisation, and supporting safeguards.
  • DPO status, processor and joint-controller arrangements, children's or automated-decision safeguards, and any DPA 2018 condition, restriction, or exemption.
  • Decision result, exception rationale, owner, reviewer, due date, evidence link, remediation, and escalation note.
Section 3

How should teams review and improve the UK GDPR checklist workflow?

Review the checklist when the purpose changes, a new data category is added, the legal basis changes, a transfer is introduced, a DPIA becomes necessary, a breach occurs, or rights requests and complaints show that controls are not working.

The review should retain the audit trail for superseded decisions, close gaps in evidence or ownership, and update the control before changed processing begins. Do not remove a legal check merely because it was not applicable to the previous version of the processing.

  • Check whether the notices, records, and retention periods still match the live processing.
  • Confirm the security, breach, and escalation steps are still current.
  • Review whether profiling, child-directed processing, special category data, or transfers require fresh assessment.
  • Update the checklist whenever binding law, regulator guidance, systems, vendors, data flows, or complaint patterns change.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for the principles, lawful bases, rights, controller and processor duties, security, breaches, DPIAs, automated decisions, and transfers covered by the checklist.
legislation.gov.uk
Referenced sections
  • UK-specific conditions, exemptions, enforcement provisions, and separate processing regimes that must be checked alongside UK GDPR.
ico.org.uk
Referenced sections
  • Regulator guidance on demonstrating compliance through appropriate measures, documentation, data protection by design, DPIAs, DPOs, and contracts.
ico.org.uk
Referenced sections
  • Source for reassessing the balancing test when circumstances change.
"You should consider exactly what you are trying to achieve with the particular processing activity."
legislation.gov.uk
Referenced sections
  • Core UK GDPR checklist obligations on lawfulness, transparency, records, security, breach notification, and DPIAs.
"The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1"
legislation.gov.uk
Referenced sections
  • Source for accountability, review, and operational change management.
"The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1"
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.