Artifact GuideUKDeadlines and Compliance Calendar

UK GDPR Deadlines and Compliance Calendar

Use the event that starts each UK GDPR clock. Rights requests usually run for one month, reportable breaches for no more than 72 hours, and privacy information has its own collection and disclosure triggers.

The UK GDPR does not set one annual compliance deadline. Put statutory clocks, pre-processing gates, and internal review dates in separate calendar fields.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

UK GDPR deadlines start when a defined event occurs. Calculate rights requests from the ; acknowledge a data-protection complaint received on or after 19 June 2026 within 30 days; give privacy information when Articles 13 or 14 require it; notify the ICO of a reportable and, where feasible, within 72 hours of awareness; and complete a required or ICO consultation before the processing begins. Internal audits and policy reviews are useful controls, but the UK GDPR does not turn them into a universal annual deadline.

Section 1

Which UK GDPR deadlines should teams track in the compliance calendar?

Put the legal trigger beside every date. A calendar entry that says only "one month" or "72 hours" is unsafe because identity checks, clarification, risk thresholds, first communications, disclosures, and statutory exceptions can change the start point or the required action.

Rights requests under or by virtue of Articles 15 to 22D generally require action and before the end of one month beginning with the . A controller may extend by two further months when complexity or the number of that person's requests makes the extension necessary. It must notify the person within the first month and give reasons. For an Article 15 access request, time spent waiting for further information reasonably needed to identify the requested information or processing does not count; this clarification rule does not create a general pause for every type of rights request.

When personal data comes directly from the person, Article 13 generally requires privacy information at collection. When it comes from another source, Article 14 generally requires the information within a reasonable period and no later than one month, but an earlier deadline applies if the controller first communicates with the person or first discloses the data to another recipient. Both articles contain exceptions, including where the person already has the information, and Article 14 has additional conditions that must be assessed before relying on them.

The timing amendments apply to requests received on or after 5 February 2026. The commencement regulations preserve the previous time-limit rules for a request received before that date. Keep the request receipt date and the version of the law used in the calculation instead of retrofitting the new clarification pause or relevant-time rule to an older request.

  • Rights request: log receipt, any reasonable identity request, any permitted fee and payment, the resulting , the one-month due date, and any extension notice.
  • Article 15 clarification: record why clarification is reasonably needed, when it was requested, when it arrived, and the excluded period.
  • Direct collection: make the Article 13 information available when the personal data is obtained, and provide information about a new purpose before further processing unless a statutory exception applies.
  • Indirect collection: set the earliest applicable Article 14 deadline - no later than one month, first communication, or first disclosure - and record any exception and safeguards.
Section 2

Which complaint-handling dates apply from 19 June 2026?

Section 164A of the Data Protection Act 2018 applies to a data-protection complaint submitted to a controller on or after 19 June 2026. The controller must make complaints easy to submit and acknowledge receipt within 30 days beginning with the day it receives the complaint. This is a 30-day clock, not the one-calendar-month clock used for rights requests.

The controller must also take appropriate steps to respond, including appropriate enquiries and progress information, and must tell the person the outcome without undue delay. The law gives no fixed outer number of days for investigation or outcome, so the calendar needs dated progress actions and an escalation target rather than an invented statutory deadline.

A message can contain both a rights request and a complaint. Track the response clock and the section 164A acknowledgement and complaint workflow separately. The new complaint duties do not apply retrospectively to complaints submitted before 19 June 2026.

  • Intake: record whether the person alleges an infringement of UK GDPR rights, the controller that received it, the exact receipt date, contact route, and any linked rights request.
  • Acknowledgement: send and retain evidence of acknowledgement within 30 days beginning with receipt.
  • Investigation: assign an owner, make enquiries appropriate to the subject matter, retain findings, and give progress information .
  • Outcome: communicate the result and next complaint or remedy routes , then record corrective action and closure.
  • Transition: apply section 164A only to a complaint submitted to the controller on or after 19 June 2026.
Section 3

How should the calendar handle a personal data breach?

A processor must tell the controller after becoming aware of a . The controller must notify the ICO without undue delay and, where feasible, no later than 72 hours after awareness unless the breach is unlikely to result in a risk to people's rights and freedoms. A late notification must explain the delay. The 72-hour point is an outer limit for a reportable breach; it does not require reporting every security incident.

If all required information is not available at once, Article 33 allows phased reporting without undue further delay. The controller must document every , including the facts, effects, and remedial action, whether or not it reports the breach.

The threshold for telling affected people is higher: the breach must be likely to result in a high risk to their rights and freedoms. Article 34 then requires communication , unless effective protection made the data unintelligible, later measures removed the likely high risk, or individual communication would involve disproportionate effort and an equally effective public or similar communication is used.

  • Record the first facts that established awareness, the awareness timestamp, and who made the controller's risk decision.
  • Assess likely effects on people, including severity and likelihood; document why ICO notification is or is not required.
  • If notifying, submit within 72 hours where feasible and phase missing information rather than waiting for a complete investigation.
  • Run the separate high-risk test for affected-person communication and record any Article 34 exception.
  • Keep the incident record, notification, phased updates, affected-person message, containment evidence, and remedial actions together.
Section 4

Which deadlines apply before processing starts?

Article 35 requires a before processing that is likely to result in a high risk to people's rights and freedoms. Complete it before launch. The controller must review the DPIA when necessary, at least when the risk represented by the processing changes; the UK GDPR does not prescribe a universal annual DPIA review.

If the completed shows that the processing would remain high risk without measures to mitigate it, Article 36 requires the controller to consult the ICO before processing. The ICO has up to eight weeks after receiving the consultation request to provide written advice. It may extend that period by six weeks for complexity, must tell the controller about the extension within one month, and may suspend the periods while waiting for requested information.

These dates do not replace other regimes. PECR, sector rules, contracts, EU GDPR, or another regulator can impose a separate clock. Track each instrument and authority in its own calendar entry rather than assuming the UK GDPR deadline covers all notifications.

  • Screen before design approval for processing likely to result in high risk and complete any required before processing starts.
  • Record the residual-risk decision, planned mitigation, DPO advice where applicable, and whether ICO prior consultation is required.
  • Do not launch processing that requires Article 36 consultation while the consultation is unresolved.
  • Trigger a review when the nature, scope, context, purpose, technology, data, population, or risk changes.
Section 5

What should each calendar record contain?

Keep statutory due dates separate from internal target dates. For each event, record the governing article, controller or processor role, trigger and timestamp, calculation, owner, required action, evidence, exception or pause, escalation point, and completion timestamp.

Use internal targets earlier than the legal outer point where investigation, review, translation, or approval takes time. Label them as internal controls. Do not describe a quarterly audit, annual policy review, training date, retention review, or vendor check as a UK GDPR deadline unless a separate rule or commitment makes that date binding.

Does every UK GDPR rights request have a one-month deadline from the email date?

No. The general period is one month from the , which is the latest applicable date among receipt, receipt of reasonably requested identity information, and payment of a permitted fee. The controller may extend by two further months when the complexity or number of that person's requests makes this necessary, but it must notify the person within the first month and explain the delay. An Article 15 clarification period may also be excluded when further information is reasonably needed to identify the information or processing sought.

Must every security incident be reported to the ICO within 72 hours?

No. The controller reports a unless it is unlikely to result in a risk to people's rights and freedoms. If reportable, notification must be made and, where feasible, within 72 hours after awareness. Record the assessment and every personal data breach even when the decision is not to notify.

Is there an annual UK GDPR compliance deadline?

No universal annual deadline appears in the UK GDPR. The regulation uses event-driven duties and pre-processing gates. Organisations often set annual or quarterly reviews for governance, training, records, retention, security, vendors, and DPIAs, but those dates are internal controls unless another law, regulator, contract, or documented commitment sets a specific frequency.

Is a data-protection complaint due within one month?

No single one-month completion deadline applies. For a complaint submitted to a controller on or after 19 June 2026, section 164A DPA 2018 requires acknowledgement within 30 days beginning with receipt. The controller must investigate, keep the person informed, and communicate the outcome , but the statute does not set a fixed outer completion period. If the same message contains a rights request, calculate that separate clock as well.

  • Trigger: what happened, when it happened, and who confirmed it.
  • Rule: the UK GDPR article and any DPA 2018, PECR, sector, contractual, or non-UK rule that creates a separate obligation.
  • Calculation: start time, excluded periods, extension, time zone, legal due date, and earlier internal target.
  • Decision evidence: identity check, clarification request, risk assessment, exception, , notice, response, or regulator submission.
  • Closure: action taken, communication or filing timestamp, approver, remaining follow-up, and lessons for the workflow.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for the event-driven rights, transparency, breach, DPIA, and prior-consultation duties summarised in this calendar.
ico.org.uk
Referenced sections
  • Current ICO guidance explains awareness, risk assessment, the 72-hour reporting process, phased information, affected-person notice, and records for non-reportable breaches.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.