Artifact GuideUKFAQ

UK GDPR Compliance FAQ

Start with the processing activity, the organisation's role, the people and data involved, and the decision or duty that has been triggered.

Read the UK GDPR with the Data Protection Act 2018. PECR, sector rules, contracts, and the EU GDPR may impose separate duties on the same activity.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
FAQ modules
11

Structured answer sets in this page tree.

Primary sources
12

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

The governs most general processing of personal data in the UK and applies alongside the Data Protection Act 2018. It can also apply to an organisation outside the UK under Article 3. The Data (Use and Access) Act 2025 amendments are now in force, including changes to lawful bases, rights timing, automated decisions, transfers, cookies, and complaints. This hub gives the decision sequence and standalone answers a product, legal, privacy, security, procurement, or compliance team needs.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items33
Focused FAQ modules
11
Showing 11 of 11
FAQ module

How do you choose a lawful basis under the UK GDPR?

Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.

3 items
FAQ module

UK Children's Code: Scope and 15 Standards

Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.

3 items
FAQ module

UK GDPR 72-Hour Breach Reporting: Decision Guide

Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.

3 items
FAQ module

UK GDPR Adequacy: When Can You Rely on It?

Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.

3 items
FAQ module

UK GDPR AI and Automated Decisions: Articles 22A-22D

Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.

3 items
FAQ module

UK GDPR Article 30 Records: What to Document

See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.

3 items
FAQ module

UK GDPR Controller or Processor: How to Decide

Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.

3 items
FAQ module

UK GDPR DPIA: When It Is Required and What to Record

Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.

3 items
FAQ module

UK GDPR DPO: When Appointment Is Mandatory

Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.

3 items
FAQ module

UK IDTA, Addendum, and Transfer Risk Assessment Guide

Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.

3 items
FAQ module

When do PECR cookie rules require consent?

Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.

3 items
Question 1

Where should a UK GDPR assessment start?

Describe the processing in concrete terms: who collects or receives which personal data, about whom, for what purpose, in which systems and countries, for how long, and with which recipients. Then classify each party as controller, joint controller, or processor for that activity. The role determines who selects the , gives privacy information, handles rights, completes DPIAs, reports breaches, and controls processors.

Choose an Article 6 before processing and make sure it fits the actual purpose. Consent is only one basis. If is used, identify both an Article 6 basis and an Article 9 condition, plus any Data Protection Act 2018 Schedule 1 condition and policy document that applies. Criminal-conviction and offence data has its own Article 10 and DPA 2018 requirements.

  • Record purpose, role, , data and people, sources, recipients, retention, security, transfers, rights, and owner.
  • Check transparency and fairness separately from whether a exists.
  • Use data protection by design and default throughout the processing lifecycle.
  • Reassess before a new purpose, dataset, model, vendor, recipient, market, or child-user journey goes live.
Question 2

Which governance duties need an early decision?

Screen for a before likely high-risk processing. Article 35 always captures specified forms of significant automated evaluation, large-scale sensitive-data processing, and large-scale public monitoring; ICO guidance identifies additional high-risk operations and indicators. Consult the ICO before processing if high residual risk cannot be reduced.

Check whether a is mandatory for a public authority or body, or because core activities involve large-scale regular and systematic monitoring or large-scale special-category or criminal-offence data. Whether or not a DPO is required, assign sufficient expertise, authority, resources, and management ownership.

  • Maintain current Article 30 records and connect them to notices, contracts, DPIAs, transfers, retention, and security evidence.
  • Use written Article 28 terms and prior authorisation for sub-processors.
  • Keep security proportionate to risk and test confidentiality, integrity, availability, resilience, and recovery.
  • Give people a way to make data protection complaints, accept complaints received through other channels, acknowledge receipt within 30 days, investigate and respond without undue delay, and retain the complaint and outcome.
  • Document decisions, control operation, exceptions, approvals, and review triggers rather than policy wording alone.
Question 3

How should teams handle rights, children, and automated decisions?

Give Article 13 privacy information when personal data is obtained from the person. For data from another source, Article 14 generally requires information within a reasonable period and no later than one month, but earlier deadlines apply at the first communication with the person or before the first disclosure. Check the stated exceptions rather than treating one month as universal.

Respond to rights requests without undue delay and within the Article 12A period. The one-month clock starts at the latest of receipt, receipt of reasonably requested identity information, or payment of a permitted fee. It can be extended by two months for complexity or number; only an access request has the separate clarification pause. For significant decisions without meaningful human involvement, current Articles 22A to 22C require information, representation, human-intervention, and contest safeguards and impose extra restrictions for special-category processing and recognised legitimate interests.

  • Treat the Children's Code as an under-18 online-design framework, distinct from the age-13 consent rule for information society services offered directly to a child.
  • Use concise, intelligible, accessible language, with child-appropriate presentation where relevant.
  • Verify identity proportionately and search for responsive personal data across the systems and processors in scope.
  • Make human review meaningful: the reviewer needs information, time, authority, and freedom to change the automated outcome.
Question 4

What are the main incident and international-transfer decisions?

For a , record when the controller became aware and assess risk to people. Notify the ICO unless the breach is unlikely to result in risk, without undue delay and, where feasible, within 72 hours. Tell affected people without undue delay when high risk is likely and no Article 34 exception applies. Document every personal data breach.

For an international disclosure or remote access, first decide whether it is a . Check current UK adequacy regulations. If none covers the transfer, use an Article 46 safeguard and complete the data protection test, which the ICO still calls a TRA, or rely on a specific Article 49 exception where its conditions are met.

  • Keep processor escalation separate from the controller's ICO and individual-notification decisions.
  • Do not wait for a complete investigation before making a required phased breach report.
  • Check partial adequacy conditions for the recipient, sector, data, and transfer rather than relying on the country name.
  • Do not treat signed transfer clauses as sufficient without the data protection test and necessary supplementary protections.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for territorial scope, principles, lawful bases, special-category processing, roles, rights, security, accountability, and transfers.
legislation.gov.uk
Referenced sections
  • Binding companion legislation for UK definitions, special-category and criminal-offence conditions, exemptions, the ICO, enforcement, and separate processing regimes.
ico.org.uk
Referenced sections
  • ICO guidance on transparency and the access, rectification, erasure, restriction, portability, objection, and automated-decision rights.
ico.org.uk
Referenced sections
  • Current ICO guidance hub for restricted transfers, adequacy, safeguards, the data protection test, and exceptions.
Related guides

Explore more topics

UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.