Use the event that starts each UK GDPR clock. Rights requests usually run for one month, reportable breaches for no more than 72 hours, and privacy information has its own collection and disclosure triggers.
The UK GDPR does not set one annual compliance deadline. Put statutory clocks, pre-processing gates, and internal review dates in separate calendar fields.
UK GDPR deadlines start when a defined event occurs. Calculate rights requests from the ; acknowledge a data-protection complaint received on or after 19 June 2026 within 30 days; give privacy information when Articles 13 or 14 require it; notify the ICO of a reportable and, where feasible, within 72 hours of awareness; and complete a required or ICO consultation before the processing begins. Internal audits and policy reviews are useful controls, but the UK GDPR does not turn them into a universal annual deadline.
1
Section 1
Which UK GDPR deadlines should teams track in the compliance calendar?
Put the legal trigger beside every date. A calendar entry that says only "one month" or "72 hours" is unsafe because identity checks, clarification, risk thresholds, first communications, disclosures, and statutory exceptions can change the start point or the required action.
Rights requests under or by virtue of Articles 15 to 22D generally require action and before the end of one month beginning with the . A controller may extend by two further months when complexity or the number of that person's requests makes the extension necessary. It must notify the person within the first month and give reasons. For an Article 15 access request, time spent waiting for further information reasonably needed to identify the requested information or processing does not count; this clarification rule does not create a general pause for every type of rights request.
When personal data comes directly from the person, Article 13 generally requires privacy information at collection. When it comes from another source, Article 14 generally requires the information within a reasonable period and no later than one month, but an earlier deadline applies if the controller first communicates with the person or first discloses the data to another recipient. Both articles contain exceptions, including where the person already has the information, and Article 14 has additional conditions that must be assessed before relying on them.
The timing amendments apply to requests received on or after 5 February 2026. The commencement regulations preserve the previous time-limit rules for a request received before that date. Keep the request receipt date and the version of the law used in the calculation instead of retrofitting the new clarification pause or relevant-time rule to an older request.
Rights request: log receipt, any reasonable identity request, any permitted fee and payment, the resulting , the one-month due date, and any extension notice.
Article 15 clarification: record why clarification is reasonably needed, when it was requested, when it arrived, and the excluded period.
Direct collection: make the Article 13 information available when the personal data is obtained, and provide information about a new purpose before further processing unless a statutory exception applies.
Indirect collection: set the earliest applicable Article 14 deadline - no later than one month, first communication, or first disclosure - and record any exception and safeguards.
Which complaint-handling dates apply from 19 June 2026?
Section 164A of the Data Protection Act 2018 applies to a data-protection complaint submitted to a controller on or after 19 June 2026. The controller must make complaints easy to submit and acknowledge receipt within 30 days beginning with the day it receives the complaint. This is a 30-day clock, not the one-calendar-month clock used for rights requests.
The controller must also take appropriate steps to respond, including appropriate enquiries and progress information, and must tell the person the outcome without undue delay. The law gives no fixed outer number of days for investigation or outcome, so the calendar needs dated progress actions and an escalation target rather than an invented statutory deadline.
A message can contain both a rights request and a complaint. Track the response clock and the section 164A acknowledgement and complaint workflow separately. The new complaint duties do not apply retrospectively to complaints submitted before 19 June 2026.
Intake: record whether the person alleges an infringement of UK GDPR rights, the controller that received it, the exact receipt date, contact route, and any linked rights request.
Acknowledgement: send and retain evidence of acknowledgement within 30 days beginning with receipt.
Investigation: assign an owner, make enquiries appropriate to the subject matter, retain findings, and give progress information .
Outcome: communicate the result and next complaint or remedy routes , then record corrective action and closure.
Transition: apply section 164A only to a complaint submitted to the controller on or after 19 June 2026.
How should the calendar handle a personal data breach?
A processor must tell the controller after becoming aware of a . The controller must notify the ICO without undue delay and, where feasible, no later than 72 hours after awareness unless the breach is unlikely to result in a risk to people's rights and freedoms. A late notification must explain the delay. The 72-hour point is an outer limit for a reportable breach; it does not require reporting every security incident.
If all required information is not available at once, Article 33 allows phased reporting without undue further delay. The controller must document every , including the facts, effects, and remedial action, whether or not it reports the breach.
The threshold for telling affected people is higher: the breach must be likely to result in a high risk to their rights and freedoms. Article 34 then requires communication , unless effective protection made the data unintelligible, later measures removed the likely high risk, or individual communication would involve disproportionate effort and an equally effective public or similar communication is used.
Record the first facts that established awareness, the awareness timestamp, and who made the controller's risk decision.
Assess likely effects on people, including severity and likelihood; document why ICO notification is or is not required.
If notifying, submit within 72 hours where feasible and phase missing information rather than waiting for a complete investigation.
Run the separate high-risk test for affected-person communication and record any Article 34 exception.
Keep the incident record, notification, phased updates, affected-person message, containment evidence, and remedial actions together.
Article 35 requires a before processing that is likely to result in a high risk to people's rights and freedoms. Complete it before launch. The controller must review the DPIA when necessary, at least when the risk represented by the processing changes; the UK GDPR does not prescribe a universal annual DPIA review.
If the completed shows that the processing would remain high risk without measures to mitigate it, Article 36 requires the controller to consult the ICO before processing. The ICO has up to eight weeks after receiving the consultation request to provide written advice. It may extend that period by six weeks for complexity, must tell the controller about the extension within one month, and may suspend the periods while waiting for requested information.
These dates do not replace other regimes. PECR, sector rules, contracts, EU GDPR, or another regulator can impose a separate clock. Track each instrument and authority in its own calendar entry rather than assuming the UK GDPR deadline covers all notifications.
Screen before design approval for processing likely to result in high risk and complete any required before processing starts.
Record the residual-risk decision, planned mitigation, DPO advice where applicable, and whether ICO prior consultation is required.
Do not launch processing that requires Article 36 consultation while the consultation is unresolved.
Trigger a review when the nature, scope, context, purpose, technology, data, population, or risk changes.
Keep statutory due dates separate from internal target dates. For each event, record the governing article, controller or processor role, trigger and timestamp, calculation, owner, required action, evidence, exception or pause, escalation point, and completion timestamp.
Use internal targets earlier than the legal outer point where investigation, review, translation, or approval takes time. Label them as internal controls. Do not describe a quarterly audit, annual policy review, training date, retention review, or vendor check as a UK GDPR deadline unless a separate rule or commitment makes that date binding.
Does every UK GDPR rights request have a one-month deadline from the email date?
No. The general period is one month from the , which is the latest applicable date among receipt, receipt of reasonably requested identity information, and payment of a permitted fee. The controller may extend by two further months when the complexity or number of that person's requests makes this necessary, but it must notify the person within the first month and explain the delay. An Article 15 clarification period may also be excluded when further information is reasonably needed to identify the information or processing sought.
Must every security incident be reported to the ICO within 72 hours?
No. The controller reports a unless it is unlikely to result in a risk to people's rights and freedoms. If reportable, notification must be made and, where feasible, within 72 hours after awareness. Record the assessment and every personal data breach even when the decision is not to notify.
Is there an annual UK GDPR compliance deadline?
No universal annual deadline appears in the UK GDPR. The regulation uses event-driven duties and pre-processing gates. Organisations often set annual or quarterly reviews for governance, training, records, retention, security, vendors, and DPIAs, but those dates are internal controls unless another law, regulator, contract, or documented commitment sets a specific frequency.
Is a data-protection complaint due within one month?
No single one-month completion deadline applies. For a complaint submitted to a controller on or after 19 June 2026, section 164A DPA 2018 requires acknowledgement within 30 days beginning with receipt. The controller must investigate, keep the person informed, and communicate the outcome , but the statute does not set a fixed outer completion period. If the same message contains a rights request, calculate that separate clock as well.
Trigger: what happened, when it happened, and who confirmed it.
Rule: the UK GDPR article and any DPA 2018, PECR, sector, contractual, or non-UK rule that creates a separate obligation.
Calculation: start time, excluded periods, extension, time zone, legal due date, and earlier internal target.
The commencement and transitional provisions bring section 103 and Schedule 10 into force on 19 June 2026 and apply the new controller duties only to complaints submitted on or after that date.
ICO guidance explains high-risk screening, completing a DPIA before processing, residual high-risk consultation, and the expected consultation timetable.
Current ICO guidance explains awareness, risk assessment, the 72-hour reporting process, phased information, affected-person notice, and records for non-reportable breaches.