FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
33of33items
Across 11 modules • Updated Jul 27, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
UK GDPR Article 30 Records: What to Document

Who must keep Article 30 records?

Controllers and processors each have record-keeping duties. An organisation with 250 or more employees must document all processing activities. An organisation with fewer than 250 employees still needs to document any activity that is not occasional, is likely to result in a risk to people's rights and freedoms, or involves special-category data or criminal-conviction and offence data.

The three small-organisation conditions are alternatives. Routine payroll, customer management, service delivery, account administration, or monitoring is usually non-occasional even in a small business, so the exemption often removes little from the practical record.

  • List every processing activity and identify whether the organisation acts as controller, joint controller, or processor.
  • Apply the under-250 test to each activity rather than exempting the whole organisation.
  • Record the reason for excluding an activity and revisit it if frequency, data, scale, purpose, or risk changes.
  • Keep other DPA 2018 records required for special-category and criminal-offence processing where applicable.
Citations
UK GDPR Article 30 Records: What to Document

What must a controller or processor record?

A controller's record must identify the controller and relevant joint controllers, UK representative, and DPO; the purposes; categories of people and personal data; categories of recipients; international transfers and safeguards where applicable; envisaged erasure time limits where possible; and a general description of Article 32 security measures where possible.

A processor's record is narrower but still substantial. It must identify the processor and each controller it serves, relevant representatives and DPOs; the categories of processing carried out for each controller; international transfers and safeguards where applicable; and a general description of security measures where possible.

  • Use one row or connected record per meaningful processing activity, with a stable owner and system or data-flow reference.
  • Link purposes to data categories, people, recipients, retention, transfers, and security rather than keeping disconnected lists.
  • Add operational context such as lawful basis, Article 9 or 10 condition, data location, privacy notice, contract, DPIA, consent record, and breach record when it helps demonstrate compliance.
  • Do not copy controller fields into a processor record without identifying the controller and the processing performed for that controller.
Citations
ICO - Documentation

Lists the controller and processor record fields and distinguishes Article 30 requirements from useful linked accountability records.

UK GDPR Article 30 Records: What to Document

How should teams maintain the record?

The record must describe current processing, not the intended design or an old audit snapshot. Update it when a product adds a purpose, data category, recipient, vendor, transfer, retention rule, or material security change. Product, procurement, HR, security, and legal change processes should feed the record owner.

Article 30 does not prescribe a single template. A spreadsheet, governance tool, or connected register can work if the required information is written, understandable, current, and exportable for the ICO. Preserve approval and change history where it helps show when the record changed and why.

  • Reconcile the ROPA with system inventories, privacy notices, processor contracts, transfer records, DPIAs, retention rules, and live product behaviour.
  • Assign field owners so one privacy team is not guessing technical, vendor, or operational facts.
  • Review on material change and on a proportionate periodic schedule.
  • Keep enough granularity for a reviewer to understand what happens to the data without reading several unrelated records.
Citations
ICO - Documentation

States that records must be written, current, granular, meaningful, and regularly reviewed, and suggests information audits and data mapping.

UK GDPR Controller or Processor: How to Decide

How do we decide whether a party is a controller or processor?

Map the data flow and ask who decided to collect or use the personal data, the outcome the processing is meant to achieve, which people and data are in scope, who receives the data, and how long it is kept. Those purpose and essential-means decisions point to controller status. A provider may still be a processor while choosing practical technical details, such as the software or security method used to carry out the controller's instructions.

Two parties are joint controllers only when they jointly determine the purposes and means of the same processing. Parties are not joint controllers merely because they exchange the same data or work toward related commercial goals. Employees acting within their duties are part of the controller rather than separate processors.

  • Describe one processing activity and its purpose before assigning any role.
  • Record which party decides the purpose, data, people, recipients, retention, and essential processing method.
  • Compare the factual decision-making with the contract; amend the contract if the labels do not match the facts.
  • Repeat the analysis for secondary uses, product analytics, fraud prevention, legal compliance, and sub-processing.
Citations
UK GDPR Controller or Processor: How to Decide

What duties follow from the classification?

The controller is responsible for the lawfulness and fairness of the processing, transparency, rights handling, security, accountability, breach decisions, and choosing processors that give sufficient guarantees. Article 28 requires a binding processor contract or other legal act containing the required terms.

A processor has direct UK GDPR duties. It must follow documented instructions unless UK law requires otherwise, keep data confidential, apply Article 32 security, control sub-processors, assist the controller with rights, security, breach, DPIA, and prior-consultation duties, return or delete data at the end as instructed, and provide compliance information and allow audits. A processor needs the controller's prior specific or general written authorisation before appointing a sub-processor.

  • Controller evidence: role analysis, lawful basis, transparency material, processor due diligence, Article 28 terms, rights and breach ownership, and review date.
  • Processor evidence: instructions, confidentiality commitments, security controls, sub-processor approvals, assistance procedure, deletion or return record, and audit information.
  • Joint-controller evidence: an Article 26 arrangement that transparently allocates responsibilities and makes the essence available to individuals.
  • Mixed-role evidence: separate the processing performed for a customer's instructions from processing performed for the provider's own purposes.
Citations
UK GDPR Article 28 - Processor

Binding requirements for selecting processors, mandatory contract terms, sub-processor authorisation, assistance, deletion or return, and audits.

UK GDPR Controller or Processor: How to Decide

Which role mistakes should teams avoid?

Do not classify a cloud or professional-services provider once and reuse the answer for every feature. Hosting to a customer's instructions may be processor activity, while a provider's independent fraud, billing, product-development, or legal-compliance use may make it a controller for that separate processing. The answer depends on the actual facts and the authority each party exercises.

  • Calling every vendor a processor even where the vendor decides its own purpose.
  • Treating access to data, payment, or bargaining power as the role test.
  • Assuming two controllers are joint controllers without a joint decision about the same processing.
  • Allowing a processor to reuse data for an independent purpose without reclassifying and assessing that processing.
Citations
UK GDPR DPIA: When It Is Required and What to Record

When is a DPIA required?

Article 35 states that a DPIA is in particular required for systematic and extensive automated evaluation on which legal or similarly significant decisions are based; large-scale processing of special-category or criminal-conviction and offence data; and systematic monitoring of a publicly accessible area on a large scale.

Also check the ICO's Article 35(4) list and high-risk indicators. Relevant indicators include evaluation or scoring, significant automated decisions, systematic monitoring, sensitive or highly personal data, large scale, combining datasets, vulnerable people, innovative technology, and preventing access to a right, service, or contract. Two indicators often point to a DPIA, but that is not a strict threshold; one may be enough.

  • Screen every new or materially changed processing activity before launch.
  • Assess nature, scope, context, purposes, people affected, data, technology, scale, duration, and likely harm.
  • Document a decision not to conduct a DPIA when high-risk indicators exist but the controller concludes likely high risk is absent.
  • Use one DPIA for similar operations only when their risks and controls are genuinely similar.
Citations
UK GDPR DPIA: When It Is Required and What to Record

What must the DPIA contain?

At minimum, describe the processing and purposes, including any legitimate interest; assess necessity and proportionality; assess risks to people's rights and freedoms; and describe measures that address those risks, including safeguards, security, and mechanisms demonstrating compliance.

The controller remains responsible for the DPIA. Seek the DPO's advice where a DPO is designated, obtain processor and technical input, and consult affected people or their representatives where appropriate unless doing so would be disproportionate or prejudice commercial or public interests.

  • Map data sources, people, fields, inferences, systems, recipients, transfers, retention, deletion, and decision points.
  • Record lawful bases, Article 9 or 10 conditions, fairness, transparency, minimisation, accuracy, rights, security, and processor controls.
  • Describe each potential harm, who may experience it, likelihood, severity, existing controls, further action, owner, deadline, and residual risk.
  • Record DPO advice, stakeholder input, disagreements, approvals, and the decision to proceed, change, pause, or stop.
Citations
ICO - How do we do a DPIA?

ICO process for describing processing, consulting, assessing necessity and risk, identifying measures, sign-off, and integration into project plans.

UK GDPR DPIA: When It Is Required and What to Record

When must we consult the ICO or review the DPIA?

If the completed DPIA shows that processing would result in high risk in the absence of measures and the controller cannot reduce that risk, Article 36 requires prior consultation with the ICO before processing. Do not accept or sign off unresolved high residual risk as a business choice and launch anyway.

Review the DPIA when the risk represented by the processing changes. Triggers include new purposes, data, recipients, models, profiling, decisions, vulnerable groups, transfers, security architecture, incidents, complaints, or evidence that a control is ineffective.

Citations
UK GDPR DPO: When Appointment Is Mandatory

How do we apply the three DPO triggers?

The public-authority test uses section 7 of the Data Protection Act 2018. The other two triggers apply to core activities: primary operations needed to achieve the organisation's objectives, not routine ancillary functions such as most employers' internal payroll or HR administration.

Regular and systematic monitoring includes organised, recurring, or methodical tracking and profiling online or offline. To assess whether processing is large scale, consider the number of people, volume and range of data, geographical extent, and duration or permanence. No single numerical threshold decides the issue.

  • Apply the test to controllers and processors; both can have a mandatory appointment duty.
  • Describe the core activity, monitoring, data, people, scale factors, geography, and duration.
  • Distinguish an organisation's own ancillary HR processing from an HR service provider's core processing for clients.
  • Revisit the decision after acquisitions, new services, changed monitoring, wider geography, or increased sensitive-data processing.
Citations
ICO - Data protection officers

Explains public authority, core activities, regular and systematic monitoring, large scale, voluntary appointments, and documented decisions.

UK GDPR DPO: When Appointment Is Mandatory

How must the DPO role be set up?

Select the DPO for professional qualities and expert knowledge appropriate to the processing and protections required. A group may appoint one DPO if each establishment can easily access them, and a public body may share one where organisational structure and size allow. The DPO may be an employee or work under a service contract.

Involve the DPO properly and promptly in personal-data matters. Give them resources, access to data and processing, and support to maintain expertise. They must report directly to the highest management level, receive no instructions about how to perform their DPO tasks, and not be dismissed or penalised for performing those tasks.

  • Publish the DPO's contact details and communicate them to the ICO.
  • Give staff and data subjects a direct, usable route to contact the DPO.
  • Document budget, time, staff, training, system access, meeting access, and escalation arrangements.
  • Protect confidentiality or secrecy in the DPO's communications as required by law.
Citations
UK GDPR DPO: When Appointment Is Mandatory

What does the DPO do, and which conflicts must be avoided?

Article 39 minimum tasks are to inform and advise the controller or processor and staff; monitor compliance, responsibilities, awareness, training, and audits; advise on DPIAs and monitor their performance; cooperate with the ICO; and act as the ICO contact point. The DPO works with due regard to processing risk.

A DPO may perform other work only if it creates no conflict of interests. A role that decides the purposes and means of processing conflicts with independent oversight of those decisions. Assess the real authority of senior management, IT, security, HR, marketing, product, finance, and operational roles rather than relying on job titles.

  • Keep a written role description, task plan, reporting line, independence protections, resource record, and conflict assessment.
  • Record DPO advice and management decisions without making the DPO personally responsible for the controller's or processor's compliance.
  • Review conflicts after promotions, reorganisations, outsourcing, or new decision-making authority.
  • If a voluntary appointee is called the DPO, apply the same UK GDPR position and task requirements.
Citations
UK IDTA, Addendum, and Transfer Risk Assessment Guide

When should we use the IDTA or Addendum?

First confirm that your organisation initiates a restricted transfer and that current UK adequacy regulations do not cover it. Consider whether a specific Article 49 exception applies; for recurring or structured transfers, an Article 46 safeguard is normally the relevant route.

Choose either the IDTA or Addendum. The Addendum attaches UK requirements to the European Commission's 2021 EU SCCs and may suit organisations already using those clauses for EEA transfers. The EU SCCs alone do not support a UK restricted transfer. The IDTA is the standalone UK alternative.

  • Map each sender, recipient, role, location, onward transfer, data category, purpose, volume, frequency, and access method.
  • Select the correct instrument and complete its tables, modules, commercial references, security requirements, and optional clauses accurately.
  • Confirm the parties have legal authority to sign and that the instrument is legally binding before transfer.
  • Keep the transfer tool distinct from the Article 28 processor contract; one agreement may incorporate both sets of terms, but both duties must be met.
Citations
UK IDTA, Addendum, and Transfer Risk Assessment Guide

How do we complete the transfer risk assessment?

Assess the protection people receive after transfer, taking account of all relevant circumstances and acting reasonably and proportionately. Examine the information and transfer, the selected safeguard, destination laws and practices that may affect it, the likelihood and consequences of access or non-compliance, enforceability and redress, and the effect of contractual, technical, and organisational measures.

If the test identifies a gap, add effective supplementary measures, such as strong encryption with keys inaccessible to the importer or changes that reduce the transferred data, where those measures address the actual risk. If protection remains materially lower for some or all data, do not rely on the safeguard for that portion; use a valid exception if available or stop the transfer.

  • Record the evidence, assumptions, legal and practical analysis, risk reasoning, supplementary measures, residual issues, approver, and date.
  • Test whether technical measures remain effective against the access powers or practices identified.
  • Cover remote access and cloud administration as well as file transmission.
  • Use one assessment for similar transfers only when the parties, data, purposes, laws, practices, measures, and risk remain materially the same.
Citations
UK IDTA, Addendum, and Transfer Risk Assessment Guide

What evidence and review controls should we keep?

Keep the data-flow and role map, adequacy and exception checks, executed IDTA or Addendum and incorporated EU SCCs, completed TRA, importer information, destination-law and practices evidence, supplementary measures, approvals, and notices. Record which transfers and onward transfers the pack covers.

A TRA completed before 5 February 2026 does not need to be repeated merely because the legislation now calls it the data protection test. The ICO says a pre-commencement TRA that followed its guidance and concluded protection was sufficient meets the current test. Review it when the facts, law, measures, or risk change.

The ICO currently says to continue using IDTA A1.0 and Addendum B1.0 while it prepares updated instruments during 2026. The parties may choose the instruments' automatic-update mechanism. Also review on changes to the importer, sub-processors, destination, data, purpose, access pattern, security, government-access practices, legal challenge, or ICO guidance.

Citations
Page 2 of 3