---
title: "UK GDPR Compliance Guide"
canonical_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/compliance"
source_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/compliance"
author: "Sorena AI"
description: "Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers."
published_at: "2026-05-09"
updated_at: "2026-07-27"
keywords:
  - "UK GDPR"
  - "Compliance"
  - "UK GDPR Compliance"
  - "Compliance checklist"
  - "practical guidance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# UK GDPR Compliance Guide

Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.

*Artifact Guide* *UK* *Compliance*

## UK GDPR Compliance

This implementation guide helps translate the UK GDPR duties into owned controls, evidence, review checkpoints, and escalation paths.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

The UK GDPR, supplemented by the Data Protection Act 2018, governs most general processing of personal data in the UK and can also reach an organisation outside the UK under Article 3. It has applied in its UK form since 1 January 2021, and the Data (Use and Access) Act 2025 amendments are now in force. This page maps the main duties to the decisions, owners, deadlines, and evidence a compliance programme needs.

## Definitions

### United Kingdom General Data Protection Regulation

**Term:** UK GDPR

The UK GDPR is the United Kingdom's general data-protection regulation. It governs most processing of personal data in the UK, works alongside the Data Protection Act 2018, and can also apply to an organisation outside the UK under the territorial tests in Article 3.

**Why it matters here:** This page uses the UK GDPR as the main source for general-processing duties. The Data Protection Act 2018 supplies additional UK conditions, exemptions, enforcement rules, and separate regimes, while PECR can add rules for electronic communications and device access.

Sources:

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io)

### Personal data

Personal data is information relating to an identified or identifiable living person. A person may be identifiable directly or indirectly, including through a name, identifier, location data, online identifier, or factors specific to their identity.

**Why it matters here:** The UK GDPR duties on this page apply only where the activity processes personal data. Genuinely anonymous information falls outside the UK GDPR, while pseudonymised information remains personal data when additional information can be used to attribute it to a person.

Sources:

- [UK GDPR Article 4 - Definitions](https://www.legislation.gov.uk/eur/2016/679/article/4?ref=sorena.io)

### Article 9 special-category data conditions

**Term:** Article 9

Article 9 prohibits processing specified sensitive categories of personal data unless one of its stated conditions applies. These categories include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, and data about a person's sex life or sexual orientation.

**Why it matters here:** An Article 6 lawful basis is not enough by itself when Article 9 applies. The controller must also identify an Article 9 condition and any additional Data Protection Act 2018 Schedule 1 condition or policy-document requirement that the chosen route requires.

Sources:

- [UK GDPR Article 9 - Processing of special categories of personal data](https://www.legislation.gov.uk/eur/2016/679/article/9?ref=sorena.io)
- [Data Protection Act 2018 Schedule 1](https://www.legislation.gov.uk/ukpga/2018/12/schedule/1?ref=sorena.io)

### Data protection impact assessment

**Term:** DPIA

A DPIA is the controller's documented assessment of planned processing that is likely to result in a high risk to people's rights and freedoms. It describes the processing and purposes, assesses necessity and proportionality, evaluates risks to people, and records measures to address those risks and demonstrate compliance.

**Why it matters here:** Complete a required DPIA before processing begins and while the design can still change. If the assessment shows that high risk would remain without measures to reduce it, the controller must consult the ICO before processing.

Sources:

- [UK GDPR Articles 35 and 36](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [ICO - Data protection impact assessments](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/data-protection-impact-assessments/?ref=sorena.io)

## How should privacy, product, and data teams structure a UK GDPR Compliance plan?

Build compliance around processing activities, not policies alone. For each activity, record scope and role, purpose and lawful basis, Article 9 or 10 condition, notice, data fields and recipients, retention, security, processor terms, rights handling, DPIA decision, transfer route, breach path, owner, and change trigger.

Accountability means being able to demonstrate why the activity is lawful, fair, transparent, necessary, proportionate, accurate, time-limited, and secure. A completed checklist is useful evidence only when it links to the actual system, decision, contract, test, approval, and operating record.

- Maintain an inventory that connects each purpose, system, data category, person, recipient, retention rule, and transfer to an accountable owner.
- Record the Article 6 basis before processing starts and any separate Article 9 condition or Article 10 authority. Necessity must be tested, not assumed.
- Give Articles 13 or 14 information in clear language and keep it aligned with the live activity and children's needs where relevant.
- Operate rights requests, security, breach assessment, DPIAs, processor oversight, and transfer controls as tested workflows with case records.
- Give people a way to make data protection complaints, accept complaints received through other channels, acknowledge receipt within 30 days, make appropriate enquiries, and communicate the outcome without undue delay.
- Review controls after a purpose, data, model, supplier, market, user group, or legal change; a policy review alone does not test the live processing.

Sources for this answer:

- [Consolidated UK GDPR Articles 5-6, 9-10, 12-14 and 24-36](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding source for principles, lawful processing, transparency, accountability, design, role arrangements, records, security, breaches, and DPIAs.
- [ICO guide to accountability and governance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/?ref=sorena.io) - Regulator guidance on demonstrating compliance through measures, documentation, design controls, DPIAs, DPOs, and contracts.
- [ICO guide to data security](https://ico.org.uk/for-organisations/uk-GDPR-guidance-and-resources/security/a-guide-to-data-security/?ref=sorena.io) - Regulator guidance on selecting and maintaining appropriate technical and organisational security measures.
- [ICO - Data (Use and Access) Act 2025 changes for organisations](https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/?ref=sorena.io) - Current ICO summary confirming that the data-protection amendments are in force and explaining the complaints-channel, 30-day acknowledgement, rights, cookie, automated-decision, and transfer changes.
- [ICO - How to deal with data protection complaints](https://ico.org.uk/for-organisations/how-to-deal-with-data-protection-complaints/?ref=sorena.io) - Current regulator guidance on recognising complaints, providing a complaint route, acknowledging within 30 days, making appropriate enquiries, responding without undue delay, and keeping records.

## Who should own the UK GDPR compliance, and what evidence should prove the decision?

Senior management remains responsible for the compliance framework. Processing owners make and maintain activity-level decisions; privacy or legal reviews legal interpretation; security owns technical and organisational safeguards; procurement manages processor terms and supplier evidence; service teams operate rights and incident channels. A DPO, where required, advises and monitors but does not take over the controller's responsibility.

Evidence should include the record of processing, role map, lawful-basis and necessity analysis, Article 9 or 10 condition, notice, retention decision, processor or joint-controller terms, security tests, DPIA, rights cases, complaint register, breach log, transfer route, training, review results, and remediation.

- Name one accountable owner and one reviewer for the Compliance workflow.
- Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
- Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
- Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.

Sources for this answer:

- [Consolidated UK GDPR Articles 24, 30, 35 and 37-39](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding source for controller accountability, records, DPIAs, and the DPO's advisory and monitoring tasks.
- [ICO guide to accountability and governance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/?ref=sorena.io) - Regulator guidance on governance roles, evidence, DPO independence, documentation, and contracts.

## Which edge cases should teams check before relying on a UK GDPR compliance decision?

At a boundary, identify which instrument supplies the rule: UK GDPR for general processing, the Data Protection Act 2018 for UK conditions, exemptions, and separate regimes, PECR for communications and device access, and EU GDPR where its territorial scope independently applies. Transfer instruments address Chapter V only.

The UK GDPR does not cover genuinely anonymous information or processing by a person in a purely personal or household activity with no professional or commercial connection. Part 3 of the Data Protection Act 2018 governs competent-authority law-enforcement processing and Part 4 governs intelligence-service processing. Pseudonymised data remains personal data when it can be attributed to a person using additional information.

Review this section before approving a new processing purpose, vendor, transfer, profiling flow, DSAR workflow, breach process, or child-facing product change.

- Check whether the rule changes for minors, consumers, business users, public-sector bodies, regulated sectors, high-risk services, or cross-border transfers.
- Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
- Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
- Track unresolved assumptions in an open-questions section and route legal interpretation points for review.

Sources for this answer:

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding general-processing rules and territorial-scope provisions.
- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io) - Binding source for UK conditions, exemptions, enforcement, and separate processing regimes.
- [Privacy and Electronic Communications Regulations 2003](https://www.legislation.gov.uk/uksi/2003/2426/contents?ref=sorena.io) - Binding separate rules for electronic communications, marketing, and storing or accessing information on terminal equipment.

## How should teams put UK GDPR controls into operation?

Use one control register that links each statutory duty to the processing activities it affects, the responsible owner, the operating procedure, the evidence location, exceptions, last test, and next trigger-based review. Sample completed cases and system behaviour, not only documents.

Record gaps as remediation with an owner and due date. Build statutory clocks into the workflow: give Article 14 information within its applicable window, answer rights requests within the Article 12A period, notify the ICO of a reportable breach without undue delay and where feasible within 72 hours, and acknowledge a data protection complaint within 30 days. If proposed processing is likely to create high risk, complete the DPIA before processing. If high residual risk remains after mitigation, assess whether Article 36 prior consultation is required before launch.

- Use intake questions that identify the purpose, role, data, people, systems, recipients, countries, technology, risk, and intended start date.
- Map each answer to the applicable duty or exception, required action, evidence field, owner, reviewer, due date, and reassessment event.
- Link every control to the live system, notice, contract, case record, or test that proves it operates.
- Update the workflow when the consolidated law or ICO guidance changes, or when case sampling exposes a recurring gap or exception.

Sources for this answer:

- [Consolidated UK GDPR Articles 24, 25, 35 and 36](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding source for accountable measures, review and updating, design controls, DPIAs, and prior consultation.
- [ICO guide to accountability and governance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/?ref=sorena.io) - Regulator guidance for turning accountability into operating controls and evidence.
- [UK ICO data protection audit framework](https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/?ref=sorena.io) - Operational implementation support for the UK GDPR compliance.
- [ICO - Data (Use and Access) Act 2025 changes for organisations](https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/?ref=sorena.io) - Current regulator summary for the complaint acknowledgement deadline and the amended rights, automated-decision, cookie, and transfer rules.

*Recommended next step*

*Placement: after the practical guidance*

## Turn UK GDPR Compliance into assigned work

Assign each live processing activity an owner, legal decision record, operating control, statutory clock, evidence location, and change-triggered review.

- [Open Assessment Autopilot for UK GDPR](/solutions/assessment.md): Turn Compliance into scoped questions, evidence fields, and review tasks.
- [Review UK GDPR source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next Compliance actions with Sorena.

## Primary sources

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding source for the principles, accountability, controller and processor obligations, rights, security, breaches, DPIAs, and international transfers.
- [ICO guide to accountability and governance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/?ref=sorena.io) - ICO guidance on appropriate technical and organisational measures, documentation, data protection by design, DPIAs, DPOs, and contracts. The ICO notes that parts of this guidance are under review following the Data (Use and Access) Act 2025.
- [ICO guide to data security](https://ico.org.uk/for-organisations/uk-GDPR-guidance-and-resources/security/a-guide-to-data-security/?ref=sorena.io) - ICO guidance on assessing risk and selecting, testing, and maintaining appropriate technical and organisational security measures.
- [ICO - Data (Use and Access) Act 2025 changes for organisations](https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/?ref=sorena.io) - Current ICO summary, updated 19 June 2026, confirming that all DUAA data-protection provisions are in force and identifying the operational changes.

## Related Topic Guides

- [How do you choose a lawful basis under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/lawful-bases.md): Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
- [UK Children's Code: Scope and 15 Standards](/artifacts/uk/general-data-protection-regulation/faq/children-s-code.md): Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
- [UK GDPR 72-hour Breach Reporting Guide](/artifacts/uk/general-data-protection-regulation/72-hour-breach-reporting.md): Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
- [UK GDPR 72-Hour Breach Reporting: Decision Guide](/artifacts/uk/general-data-protection-regulation/faq/72-hour-breach-reporting.md): Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
- [UK GDPR Adequacy Guide](/artifacts/uk/general-data-protection-regulation/adequacy.md): Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
- [UK GDPR Adequacy: When Can You Rely on It?](/artifacts/uk/general-data-protection-regulation/faq/adequacy.md): Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
- [UK GDPR AI and Automated Decisions Guide](/artifacts/uk/general-data-protection-regulation/ai-and-automated-decisions.md): Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
- [UK GDPR AI and Automated Decisions: Articles 22A-22D](/artifacts/uk/general-data-protection-regulation/faq/ai-and-automated-decisions.md): Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
- [UK GDPR Applicability Test Guide](/artifacts/uk/general-data-protection-regulation/applicability-test.md): Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
- [UK GDPR Article 30 Records Guide](/artifacts/uk/general-data-protection-regulation/article-30-records.md): Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
- [UK GDPR Article 30 Records: What to Document](/artifacts/uk/general-data-protection-regulation/faq/article-30-records.md): See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
- [UK GDPR Breach Notification Guide](/artifacts/uk/general-data-protection-regulation/breach-notification.md): Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
- [UK GDPR Breach Workflow Guide](/artifacts/uk/general-data-protection-regulation/breach-workflow.md): Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
- [UK GDPR Children and Age Appropriate Design Guide](/artifacts/uk/general-data-protection-regulation/children-and-age-appropriate-design.md): Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
- [UK GDPR Children's Code Guide](/artifacts/uk/general-data-protection-regulation/children-s-code.md): A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
- [UK GDPR Compliance Checklist](/artifacts/uk/general-data-protection-regulation/checklist.md): A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
- [UK GDPR Compliance FAQ: Duties, Rights, and Decisions](/artifacts/uk/general-data-protection-regulation/faq.md): Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
- [UK GDPR Controller and Processor Status Guide](/artifacts/uk/general-data-protection-regulation/controller-and-processor-status.md): Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
- [UK GDPR Controller or Processor: How to Decide](/artifacts/uk/general-data-protection-regulation/faq/controller-and-processor-status.md): Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
- [UK GDPR Data Subject Rights Guide](/artifacts/uk/general-data-protection-regulation/data-subject-rights.md): Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
- [UK GDPR Deadlines and Compliance Calendar Guide](/artifacts/uk/general-data-protection-regulation/deadlines-and-compliance-calendar.md): Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
- [UK GDPR DPIA Workflow Guide](/artifacts/uk/general-data-protection-regulation/dpia-workflow.md): Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
- [UK GDPR DPIA: When It Is Required and What to Record](/artifacts/uk/general-data-protection-regulation/faq/dpias.md): Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
- [UK GDPR DPIAs and DPOs Guide](/artifacts/uk/general-data-protection-regulation/dpias-and-dpos.md): Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
- [UK GDPR DPO: When Appointment Is Mandatory](/artifacts/uk/general-data-protection-regulation/faq/dpos.md): Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
- [UK GDPR DSAR Workflow Guide](/artifacts/uk/general-data-protection-regulation/dsar-workflow.md): Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
- [UK GDPR IDTA Addendum and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/idta-addendum-and-transfer-risk-assessment.md): Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
- [UK GDPR Lawful Bases Guide](/artifacts/uk/general-data-protection-regulation/lawful-bases.md): Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
- [UK GDPR PECR Cookies Guide](/artifacts/uk/general-data-protection-regulation/pecr-cookies.md): UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
- [UK GDPR Penalties and Fines: Maximums and ICO Factors](/artifacts/uk/general-data-protection-regulation/penalties-and-fines.md): Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
- [UK GDPR Requirements Guide](/artifacts/uk/general-data-protection-regulation/requirements.md): Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
- [UK GDPR Transfer Workflow Guide](/artifacts/uk/general-data-protection-regulation/transfer-workflow.md): Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
- [UK GDPR Transfers, IDTA, and UK Addendum Guide](/artifacts/uk/general-data-protection-regulation/transfers-idta-and-uk-addendum.md): Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
- [UK GDPR vs Data Protection Act 2018: How They Work Together](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-data-protection-act-2018.md): See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
- [UK GDPR vs EU GDPR: Scope, Regulators and Transfers](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-eu-gdpr.md): Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
- [UK IDTA vs EU SCCs: Which Transfer Contract to Use](/artifacts/uk/general-data-protection-regulation/idta-vs-eu-sccs.md): Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
- [UK IDTA, Addendum, and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/faq/idta-addendum-and-transfer-risk-assessment.md): Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
- [UK vs EU GDPR Differences After the 2025 UK Reforms](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-gdpr-differences.md): Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
- [UK vs EU GDPR Operations: Regulators, Breaches and Transfers](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-differences.md): Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
- [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md): Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/uk/general-data-protection-regulation/compliance.md
