---
title: "UK GDPR Compliance FAQ: Duties, Rights, and Decisions"
canonical_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/faq"
source_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/faq/items/page/3"
author: "Sorena AI"
description: "Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers."
published_at: "2026-05-09"
updated_at: "2026-07-27"
keywords:
  - "UK GDPR FAQ"
  - "UK data protection"
  - "lawful basis"
  - "data subject rights"
  - "breach reporting"
  - "international transfers"
  - "UK GDPR"
  - "Data Protection Act 2018"
  - "Privacy compliance"
  - "FAQ"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# UK GDPR Compliance FAQ: Duties, Rights, and Decisions

Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.

*Artifact Guide* *UK* *FAQ*

## UK GDPR Compliance FAQ

Start with the processing activity, the organisation's role, the people and data involved, and the decision or duty that has been triggered.

Read the UK GDPR with the Data Protection Act 2018. PECR, sector rules, contracts, and the EU GDPR may impose separate duties on the same activity.

The UK GDPR governs most general processing of personal data in the UK and applies alongside the Data Protection Act 2018. It can also apply to an organisation outside the UK under Article 3. The Data (Use and Access) Act 2025 amendments are now in force, including changes to lawful bases, rights timing, automated decisions, transfers, cookies, and complaints. This hub gives the decision sequence and standalone answers a product, legal, privacy, security, procurement, or compliance team needs.

## Definitions

### United Kingdom General Data Protection Regulation

**Term:** UK GDPR

The UK GDPR is the United Kingdom's general data-protection regulation. It governs most processing of personal data in the UK, works alongside the Data Protection Act 2018, and can apply to an organisation outside the UK under the territorial tests in Article 3.

**Why it matters here:** Use the UK GDPR for the general-processing questions on this page, then check the Data Protection Act 2018 for additional UK conditions, exemptions, enforcement rules, and separate regimes. PECR and sector rules can add separate duties.

Sources:

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io)

### Lawful basis for processing

**Term:** lawful basis

A lawful basis is the Article 6 condition that permits a specific processing purpose. The available bases are consent, contract, legal obligation, vital interests, public task, recognised legitimate interests, and ordinary legitimate interests, subject to the conditions and exclusions of each route.

**Why it matters here:** Choose and document the basis before processing. If special-category or criminal-offence data is involved, Article 6 is only the first step; a separate Article 9 or Article 10 route and any applicable Data Protection Act 2018 condition are also needed.

Sources:

- [UK GDPR Article 6 - Lawfulness of processing](https://www.legislation.gov.uk/eur/2016/679/article/6?ref=sorena.io)
- [ICO - A guide to lawful basis](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/?ref=sorena.io)

### Special-category personal data

**Term:** special-category data

Special-category data is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, or data about a person's sex life or sexual orientation.

**Why it matters here:** Processing this data requires both an Article 6 lawful basis and an Article 9 condition. Some Article 9 routes also require a Data Protection Act 2018 Schedule 1 condition and an appropriate policy document.

Sources:

- [UK GDPR Article 9 - Special categories of personal data](https://www.legislation.gov.uk/eur/2016/679/article/9?ref=sorena.io)
- [Data Protection Act 2018 Schedule 1](https://www.legislation.gov.uk/ukpga/2018/12/schedule/1?ref=sorena.io)

### Data protection impact assessment

**Term:** DPIA

A DPIA is the controller's documented assessment of planned processing that is likely to result in a high risk to people's rights and freedoms. It describes the processing and purposes, tests necessity and proportionality, assesses risks to people, and records measures to address those risks.

**Why it matters here:** Complete a required DPIA before processing begins. If the assessment indicates that high risk would remain without measures to reduce it, the controller must consult the ICO before processing.

Sources:

- [UK GDPR Articles 35 and 36](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [ICO - Data protection impact assessments](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/data-protection-impact-assessments/?ref=sorena.io)

### Data protection officer

**Term:** DPO

A DPO is an independent data-protection adviser and monitor appointed under Articles 37 to 39. The DPO advises on duties and DPIAs, monitors compliance, cooperates with the ICO, and acts as a contact point, but does not take over the controller's or processor's responsibility.

**Why it matters here:** Appointment is mandatory only when an Article 37 test applies, although an organisation may appoint a DPO voluntarily. The role requires independence, adequate resources, access, a direct reporting line to the highest management level, and protection from conflicting duties.

Sources:

- [UK GDPR Articles 37 to 39](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [ICO - Data protection officers](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/data-protection-officers/?ref=sorena.io)

### Personal data breach

A personal data breach is a security breach that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. It can affect confidentiality, integrity, or availability.

**Why it matters here:** The controller must document every personal data breach, notify the ICO unless the breach is unlikely to result in risk, and separately assess whether likely high risk requires communication to affected people.

Sources:

- [UK GDPR Articles 4(12), 33 and 34](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [ICO - Personal data breaches: a guide](https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/?ref=sorena.io)

### UK GDPR restricted transfer

**Term:** restricted transfer

A restricted transfer occurs when the UK GDPR applies to a sender's processing and the sender initiates and agrees to send personal information, or make it accessible, to a separate organisation outside the UK. Remote access can qualify; movement within the same legal entity does not qualify merely because it crosses a border.

**Why it matters here:** A restricted transfer needs coverage under current UK adequacy regulations, an Article 46 safeguard and data protection test, or a specific Article 49 exception. The exporter must identify the route before the transfer begins.

Sources:

- [ICO - Are we making a restricted transfer?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/are-we-making-a-restricted-transfer/?ref=sorena.io)
- [Consolidated UK GDPR Chapter V](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)

## Browse sub-FAQ modules

### [How do you choose a lawful basis under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/lawful-bases.md)

Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.

- 3 items

### [UK Children's Code: Scope and 15 Standards](/artifacts/uk/general-data-protection-regulation/faq/children-s-code.md)

Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.

- 3 items

### [UK GDPR 72-Hour Breach Reporting: Decision Guide](/artifacts/uk/general-data-protection-regulation/faq/72-hour-breach-reporting.md)

Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.

- 3 items

### [UK GDPR Adequacy: When Can You Rely on It?](/artifacts/uk/general-data-protection-regulation/faq/adequacy.md)

Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.

- 3 items

### [UK GDPR AI and Automated Decisions: Articles 22A-22D](/artifacts/uk/general-data-protection-regulation/faq/ai-and-automated-decisions.md)

Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.

- 3 items

### [UK GDPR Article 30 Records: What to Document](/artifacts/uk/general-data-protection-regulation/faq/article-30-records.md)

See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.

- 3 items

### [UK GDPR Controller or Processor: How to Decide](/artifacts/uk/general-data-protection-regulation/faq/controller-and-processor-status.md)

Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.

- 3 items

### [UK GDPR DPIA: When It Is Required and What to Record](/artifacts/uk/general-data-protection-regulation/faq/dpias.md)

Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.

- 3 items

### [UK GDPR DPO: When Appointment Is Mandatory](/artifacts/uk/general-data-protection-regulation/faq/dpos.md)

Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.

- 3 items

### [UK IDTA, Addendum, and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/faq/idta-addendum-and-transfer-risk-assessment.md)

Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.

- 3 items

### [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md)

Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.

- 3 items

Browse all indexed questions: [/artifacts/uk/general-data-protection-regulation/faq/items](/artifacts/uk/general-data-protection-regulation/faq/items.md)

## All FAQ items

*Page 3 of 3. Showing 3 of 33 items.*

### [What technologies and information does PECR cover?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md#what-technologies-and-information-does-pecr-cover)

*Module: [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md)*

Regulation 6 is broader than cookies and websites. It covers storage and access technologies that store information on or access information from terminal equipment such as computers, phones, tablets, smart TVs, wearables, connected vehicles, and other connected devices. Pixels, software development kits, local storage, scripts, tags, fingerprinting, and similar methods can all fall within scope.

- Inventory first-party and third-party technologies, including components loaded after login, media playback, or another user action.
- Record what each technology stores or accesses, each purpose, provider, recipients, duration, and device context.
- Test each purpose separately. A familiar label such as analytics, security, or preference does not establish an exception.
- Include technologies that operate in mobile apps and connected products, not only browser cookies.

Sources for this answer:

- [ICO - What are storage and access technologies?](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-storage-and-access-technologies/?ref=sorena.io) - Explains the technologies, devices, contexts, scripts, tags, pixels, fingerprinting, and other methods within regulation 6.
- [ICO - How PECR relates to the UK GDPR](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/how-do-the-pecr-rules-relate-to-the-uk-gdpr/?ref=sorena.io) - Explains that PECR applies to information, must be considered before the UK GDPR, and sits alongside UK data protection duties.

### [Which purposes can operate without consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md#which-purposes-can-operate-without-consent)

*Module: [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md)*

There are five purpose-specific exceptions. The communication exception covers storage or access whose sole purpose is transmitting a communication and without which transmission is impossible. The strictly necessary exception covers what is essential to provide the online service the user requested. The emergency assistance exception applies after a device sends a request or another indication that the subscriber or user needs emergency assistance, where the sole purpose of the storage or access is to identify their geographical position so that assistance can be provided.

- Communication: confirm that transmission is impossible without the technology and that transmission is its sole purpose.
- Strictly necessary: show which user-requested service would fail without the technology and why the chosen method is essential.
- Statistics or appearance: document every condition, keep use within the sole purpose, explain it clearly, and provide a simple, free objection route.
- Emergency assistance: confirm that the device sent a request or another indication that the subscriber or user needs emergency help, and limit use to identifying their geographical position so that assistance can be provided.
- No exception: block the technology by default and request valid consent for each purpose.

Sources for this answer:

- [ICO - What are the PECR exceptions?](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-exceptions/?ref=sorena.io) - Sets out the five current exceptions, their conditions, the objection requirements, and uses that remain subject to consent.
- [PECR regulation 6](https://www.legislation.gov.uk/uksi/2003/2426/regulation/6?ref=sorena.io) - Binding rule prohibiting storage or access without consent unless an exception applies.
- [Data (Use and Access) Act 2025, section 112](https://www.legislation.gov.uk/ukpga/2025/18/section/112?ref=sorena.io) - Binding amendment that expanded the exceptions to PECR regulation 6.
- [Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026](https://www.legislation.gov.uk/uksi/2026/82/regulation/2/made?ref=sorena.io) - Brought section 112 and the expanded regulation 6 exceptions into force on 5 February 2026.

### [What must the consent mechanism and evidence show?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md#what-must-the-consent-mechanism-and-evidence-show)

*Module: [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md)*

Before requesting consent, tell the subscriber or user which technologies will operate, their purposes, whether third parties store, access, or receive information, and how long the storage or access will last. Consent must result from a clear positive action. Continuing to use a service, silence, inactivity, or a pre-ticked control is not enough.

- Record the notice version, purposes offered, user's affirmative choice, timestamp, and later withdrawal or change.
- Verify that reject, object, and withdraw controls work and do not trigger the technologies they are meant to stop.
- Contract with third parties for the agreed purposes and confirm their deployed configuration and information use.
- Repeat the assessment after adding a tag, SDK, vendor, purpose, recipient, or materially different retention period.

Sources for this answer:

- [ICO - What are the PECR rules?](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-pecr-rules/?ref=sorena.io) - Explains clear and comprehensive information, third-party disclosure, duration, valid consent, refusal, withdrawal, and controls.
- [ICO - How to comply with the PECR rules](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/how-do-we-comply-with-the-pecr-rules/?ref=sorena.io) - Explains responsibility, design, third-party technologies, information, duration, and audit expectations.
- [ICO - How to manage consent in practice](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/how-do-we-manage-consent-in-practice/?ref=sorena.io) - Explains consent mechanisms, records, withdrawal, changing uses, and technologies serving multiple purposes.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/uk/general-data-protection-regulation/faq/items](/artifacts/uk/general-data-protection-regulation/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 3 of 3

Pages: [1](/artifacts/uk/general-data-protection-regulation/faq/items.md) | [2](/artifacts/uk/general-data-protection-regulation/faq/items/page/2.md) | [3](/artifacts/uk/general-data-protection-regulation/faq/items/page/3.md)

[Previous page](/artifacts/uk/general-data-protection-regulation/faq/items/page/2.md)

*Recommended next step*

*Placement: after the practical guidance*

## Turn each question into a recorded decision

Capture the processing facts, legal trigger, owner, required action, evidence, approval, and review date before implementation.

- [Open Assessment Autopilot for UK GDPR](/solutions/assessment.md): Turn UK GDPR questions into scoped evidence requests, owners, and actions.
- [Review UK GDPR source evidence](/solutions/research-copilot.md): Use Research Copilot to answer a follow-up question against legislation and ICO material.
- [Talk through implementation](/contact.md): Review the processing scope, decisions, evidence, and next actions with Sorena.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/uk/general-data-protection-regulation/faq/items/page/3.md
