---
title: "UK GDPR Penalties and Fines: Maximums and ICO Factors"
canonical_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/penalties-and-fines"
source_url: "https://www.sorena.io/artifacts/uk/general-data-protection-regulation/penalties-and-fines"
author: "Sorena AI"
description: "Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine."
published_at: "2026-05-09"
updated_at: "2026-07-25"
keywords:
  - "UK GDPR"
  - "penalties and fines"
  - "UK GDPR penalties and fines"
  - "compliance checklist"
  - "practical guidance"
  - "Compliance"
  - "Regulatory guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# UK GDPR Penalties and Fines: Maximums and ICO Factors

Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.

*Artifact Guide* *UK* *Penalties and Fines*

## UK GDPR Penalties and Fines

The two main UK GDPR ceilings are £8.7 million or 2% of worldwide annual turnover and £17.5 million or 4%, using the higher figure for an undertaking.

Those statutory maximums do not set automatic tariffs. The ICO decides whether to issue a penalty notice and sets the amount from the infringement, seriousness, turnover where relevant, and aggravating or mitigating factors.

ICO enforcement can include warnings about intended processing, reprimands for infringements, orders, processing restrictions, fines, or a combination permitted by law. The standard maximum amount and higher maximum amount are ceilings; they do not set default penalties. The ICO must assess the individual case, and the turnover percentage applies to an undertaking only when it produces a higher ceiling than the fixed sterling amount.

## Definitions

### Standard maximum amount

The standard maximum amount is £8.7 million. If the controller or processor is an undertaking, the ceiling is the higher of £8.7 million or 2% of the undertaking's total worldwide annual turnover in the preceding financial year.

**Why it matters here:** Article 83(4) applies this band to specified controller and processor obligations, including Articles 8, 11, 25 to 39, 42, and 43, as well as specified certification and code-monitoring duties.

Sources:

- [Consolidated UK GDPR, Article 83(4)](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [ICO guidance on maximum fine amounts](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018/?ref=sorena.io)

### Higher maximum amount

The higher maximum amount is £17.5 million. If the controller or processor is an undertaking, the ceiling is the higher of £17.5 million or 4% of the undertaking's total worldwide annual turnover in the preceding financial year.

**Why it matters here:** Article 83(5) applies this band to basic processing principles and consent, data-subject rights, restrictions and safeguards for specified automated decision-making, international-transfer duties, specified DPA 2018 obligations, and non-compliance with certain ICO powers or orders.

Sources:

- [Consolidated UK GDPR, Article 83(5)](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io)
- [ICO guidance on maximum fine amounts](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018/?ref=sorena.io)

### Undertaking for fine calculations

**Term:** undertaking

For UK GDPR fines, an undertaking is an entity engaged in economic activity and may include several legal or natural persons that form one economic unit. It is not necessarily the same as one registered company. A subsidiary and parent can form one undertaking where the parent exercises decisive influence.

**Why it matters here:** When a controller or processor forms part of a wider undertaking, the ICO calculates the percentage-based statutory maximum from the turnover of the undertaking as a whole. Group structure and autonomy therefore affect the ceiling.

Sources:

- [ICO guidance on the concept of an undertaking](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-concept-of-an-undertaking-for-the-purpose-of-imposing-fines/?ref=sorena.io)

### Penalty notice

A penalty notice is the Commissioner's formal notice requiring a person to pay a stated monetary penalty for an infringement that falls within the UK GDPR or Data Protection Act 2018 fining powers. A fine can be imposed instead of, or in addition to, other corrective measures where the law permits.

**Why it matters here:** Finding an infringement does not by itself set the amount. The Commissioner decides whether a penalty notice is appropriate and must apply the relevant statutory factors and maximum.

Sources:

- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io)
- [ICO guidance on fineable infringements](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-infringements-of-uk-gdpr-and-dpa-2018-for-which-the-commissioner-can-impose-a-fine/?ref=sorena.io)

## What should teams understand about UK GDPR penalties and fines?

Article 83 and section 157 DPA 2018 create two main ceilings. The standard band is £8.7 million or, for an undertaking, the higher of £8.7 million and 2% of total worldwide annual turnover in the preceding financial year. The higher band is £17.5 million or, for an undertaking, the higher of £17.5 million and 4% of that turnover.

The percentage does not automatically apply to every business. It produces the statutory ceiling only when it exceeds the fixed amount. The ICO gives the crossover figures as worldwide turnover above £435 million for the 2% band and above £437.5 million for the 4% band.

For example, an undertaking with £300 million in preceding-year worldwide turnover still has an £8.7 million standard ceiling because 2% is £6 million. At £500 million, the standard ceiling is £10 million and the higher ceiling is £20 million. These calculations identify only the maximum; they do not estimate the fine.

A statutory maximum does not predict the fine. The Commissioner must ensure that a fine is effective, proportionate, and dissuasive, and must consider the Article 83(2) factors that are relevant to the case. Article 83 and the DPA 2018 are binding law. The ICO's fining guidance explains its current evaluative approach but does not replace the statutory test or make the five steps a tariff.

- Standard band: specified controller and processor duties in Articles 8, 11, 25 to 39, 42, and 43, plus specified certification-body and code-monitoring duties.
- Higher band: processing principles and consent in Articles 5, 6, 7, and 9; rights in Articles 12 to 21; specified automated-decision safeguards in Articles 22B and 22C; international-transfer duties; specified DPA 2018 obligations; and non-compliance with certain ICO orders or access powers.
- Separate DPA 2018 powers also cover failures involving information notices, assessment notices, enforcement notices, and data-protection charges; the applicable provision determines the penalty route and maximum.
- Controllers, processors, certification providers, monitoring bodies, and other persons can face fines where the cited provisions apply. Identify the legal role before selecting a band.
- A fine is one possible corrective measure. The ICO may also use warnings, reprimands, orders to comply, rectification or erasure orders, processing restrictions, or suspension of data flows where its powers and the case permit.

Sources for this answer:

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Article 83 sets the two maximum bands, the provisions assigned to each band, the factors for individual cases, and the rule for same or linked processing operations.
- [ICO guidance on maximum fine amounts](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018/?ref=sorena.io) - Current ICO guidance confirms the £8.7 million or 2% and £17.5 million or 4% ceilings and explains when turnover produces the higher statutory maximum.
- [ICO guidance on fineable infringements](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-infringements-of-uk-gdpr-and-dpa-2018-for-which-the-commissioner-can-impose-a-fine/?ref=sorena.io) - ICO guidance identifies the UK GDPR and DPA 2018 infringements for which the Commissioner may impose a fine, including failures to comply with regulatory notices.

## Which facts can increase or reduce a UK GDPR fine?

Article 83(2) directs the Commissioner to consider the nature, gravity, and duration of the infringement; the processing purpose and scope; the number of people affected and their damage; whether conduct was intentional or negligent; mitigation; responsibility for technical and organisational measures; previous infringements; cooperation; data categories; how the ICO learned of the issue; compliance with earlier measures; approved codes or certification; and other aggravating or mitigating factors such as financial benefit or avoided loss.

Prompt remediation and cooperation can matter, but they do not erase the infringement or guarantee a reduced fine. Evidence should show what the organisation knew, what control failed, how quickly it contained and corrected the issue, how it protected people, and whether it complied with notification and ICO requests.

- Scope and impact: affected processing, duration, data categories, number and types of people affected, and evidence of actual or potential damage.
- State of mind and responsibility: decision records, risk assessments, warnings, budgets, control ownership, training, testing, and whether conduct was intentional or negligent.
- Response: containment, mitigation for people, correction, regulator and individual notifications, preservation of evidence, and recurrence prevention.
- Regulatory history: previous infringements, earlier ICO measures, compliance with those measures, and the completeness and timing of cooperation.
- Financial context: benefit gained or loss avoided, the legal-entity and group structure, economic activity, autonomy, and the preceding financial year's worldwide turnover.

Sources for this answer:

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Article 83(1) and (2) establish the effective, proportionate, and dissuasive requirement and the case-specific factors.
- [ICO guidance on statutory fine factors](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-factors-the-commissioner-will-take-into-account-when-deciding-whether-to-issue-a-penalty-notice-and-in-determining-the-amount/?ref=sorena.io) - ICO guidance lists the factors used to decide whether to issue a penalty notice and to determine its amount.
- [ICO guidance on the concept of an undertaking](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-concept-of-an-undertaking-for-the-purpose-of-imposing-fines/?ref=sorena.io) - ICO guidance explains when multiple legal persons can form one economic unit and why the wider undertaking's turnover can set the ceiling.

## How does the ICO calculate a fine?

The ICO's fining guidance uses five steps: assess seriousness; account for turnover where the controller or processor is part of an undertaking; calculate a starting point from seriousness and, where relevant, turnover; adjust for aggravating and mitigating factors; and check that the result is effective, proportionate, and dissuasive. The ICO says this is an evaluative process, not a mechanical formula.

Where the same or linked processing operations intentionally or negligently infringe several UK GDPR provisions, Article 83(3) caps the total at the maximum for the gravest infringement. That rule does not combine genuinely separate conduct into one ceiling. The ICO assesses whether operations are linked from the circumstances, including their purpose, affected people, and timing.

For example, the ICO guidance treats an Article 8 children's-consent failure and an Article 13 transparency failure arising from the same or linked processing as subject to the single gravest-infringement ceiling, even if separate amounts are identified. By contrast, a security failure involving employee salary and bank details and an unrelated transparency failure in direct marketing can be separate conduct, so each infringement has its own applicable maximum.

Financial hardship is not assumed from the size of a proposed fine. The ICO guidance says a reduction for inability to pay is available only in exceptional circumstances after the appropriate amount has been calculated.

- Map each alleged infringement to the exact UK GDPR or DPA 2018 provision and its maximum band.
- Separate the infringement decision from the seriousness assessment and the later calculation of amount.
- Determine whether the controller or processor forms part of a wider undertaking before using turnover.
- Identify whether multiple findings arise from the same or linked processing operations or from separate conduct.
- Retain the source financial statements, group and control analysis, factual chronology, mitigation record, and submissions relied on.

Sources for this answer:

- [ICO guidance on calculating the appropriate fine](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/calculation-of-the-appropriate-amount-of-the-fine/?ref=sorena.io) - ICO guidance sets out the five-step calculation, its non-mechanical nature, and the exceptional financial-hardship adjustment.
- [ICO guidance on multiple infringements](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-commissioner-s-approach-to-fines-where-there-is-more-than-one-infringement-by-a-controller-or-processor/?ref=sorena.io) - ICO guidance explains Article 83(3), the same-or-linked processing test, and the treatment of separate conduct.

## What should an organisation do when an infringement or ICO investigation is possible?

Contain continuing harm, preserve evidence, and identify the controller, processor, and undertaking before estimating exposure. Meet any separate breach-notification or rights-request deadline; responding to an investigation does not pause those duties.

Build a provision-by-provision record instead of multiplying turnover by a percentage. Include the alleged conduct, affected processing, dates, people and data, applicable maximum, Article 83 factors, remediation, regulatory correspondence, financial evidence, and unresolved factual or legal issues. Separate verified facts, the organisation's position, and assumptions. Obtain case-specific legal advice where liability, privilege, appeals, or representations on a proposed penalty are in issue.

- Stop or reduce continuing risk and keep a dated record of each containment and mitigation step.
- Preserve logs, notices, policies, DPIAs, contracts, decisions, tickets, complaints, communications, and financial records without altering the originals.
- Map each fact to the exact obligation, responsible role, maximum band, seriousness evidence, and aggravating or mitigating factor.
- Coordinate accurate, timely responses to ICO information, assessment, or enforcement notices and track every stated deadline.
- Keep public, customer, employee, insurer, board, and regulator communications consistent with the verified facts.
- Record the outcome separately for each alleged infringement: not established, established without a penalty notice, included in a penalty notice with the applicable maximum and amount, or addressed through another corrective measure.

### Is the maximum UK GDPR fine always 4% of turnover?

No. The infringement determines the band. The standard ceiling is £8.7 million or, for an undertaking, the higher of £8.7 million and 2% of worldwide annual turnover in the preceding financial year. The higher ceiling is £17.5 million or, for an undertaking, the higher of £17.5 million and 4%. The final fine can be lower, and the ICO assesses each case.

### Does a data breach automatically lead to a fine?

No. A security incident must first be assessed against the UK GDPR duties that apply, including security, processor escalation, ICO notification, affected-person communication, and recordkeeping. The ICO then decides which infringements, if any, are established and whether a penalty notice is appropriate. Other corrective measures can be used instead of or alongside a fine where the law permits.

### Is the turnover calculation based only on the UK company that committed the infringement?

Not necessarily. If the controller or processor is part of an undertaking, the ICO can calculate the statutory maximum from the undertaking's worldwide turnover as a whole. An undertaking can include a parent and subsidiary that form one economic unit. The result depends on autonomy, decisive influence, and the economic, organisational, and legal links in the specific group.

### Can remediation prevent a UK GDPR fine?

Remediation can be relevant mitigation, but it does not erase an infringement or guarantee that the ICO will avoid or reduce a fine. The Commissioner considers mitigation alongside seriousness, intent or negligence, responsibility, prior infringements, cooperation, affected data, notification, compliance with earlier measures, and other aggravating or mitigating factors.

Sources for this answer:

- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io) - Part 6 establishes the ICO's information, assessment, enforcement, and penalty-notice framework, together with appeal and enforcement provisions.
- [ICO guidance on fineable infringements](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-infringements-of-uk-gdpr-and-dpa-2018-for-which-the-commissioner-can-impose-a-fine/?ref=sorena.io) - ICO guidance explains which substantive infringements and failures to comply with regulatory notices can attract a fine.

*Recommended next step*

*Placement: after the practical guidance*

## Build the UK GDPR enforcement record

Map each alleged infringement to the responsible role, evidence, maximum band, Article 83 factors, remediation, and regulator correspondence.

- [Open Assessment Autopilot for UK GDPR](/solutions/assessment.md): Turn each potential infringement into scoped questions, evidence fields, and response tasks.
- [Review UK GDPR source evidence](/solutions/research-copilot.md): Use Research Copilot to answer follow-up questions with cited source material.
- [Talk through implementation](/contact.md): Review scope, evidence, owners, and the next compliance actions with Sorena.

## Primary sources

- [Consolidated UK GDPR](https://www.legislation.gov.uk/eur/2016/679/contents?ref=sorena.io) - Binding Article 83 text for fine factors, linked infringements, maximum bands, covered provisions, and non-compliance with ICO orders.
- [Data Protection Act 2018](https://www.legislation.gov.uk/ukpga/2018/12/contents?ref=sorena.io) - Binding UK framework for information, assessment, enforcement, and penalty notices, maximum amounts, appeals, and enforcement.
- [ICO guidance on maximum fine amounts](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-maximum-amount-of-a-fine-under-uk-gdpr-and-dpa-2018/?ref=sorena.io) - Current ICO guidance for the fixed and percentage ceilings and the turnover crossover figures.
- [ICO guidance on fineable infringements](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-infringements-of-uk-gdpr-and-dpa-2018-for-which-the-commissioner-can-impose-a-fine/?ref=sorena.io) - ICO guidance for the substantive duties, regulatory notices, and charge requirements that can attract monetary penalties.
- [ICO guidance on statutory fine factors](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-factors-the-commissioner-will-take-into-account-when-deciding-whether-to-issue-a-penalty-notice-and-in-determining-the-amount/?ref=sorena.io) - ICO guidance for the factors used to decide whether to issue a penalty notice and to determine its amount.
- [ICO guidance on the concept of an undertaking](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/statutory-background/the-concept-of-an-undertaking-for-the-purpose-of-imposing-fines/?ref=sorena.io) - ICO guidance for economic units, decisive influence, group turnover, and potential parent-company responsibility.
- [ICO guidance on calculating the appropriate fine](https://ico.org.uk/about-the-ico/our-information/policies-and-procedures/data-protection-fining-guidance/calculation-of-the-appropriate-amount-of-the-fine/?ref=sorena.io) - ICO guidance for the five-step, case-specific calculation and exceptional financial-hardship adjustment.

## Related Topic Guides

- [How do you choose a lawful basis under the UK GDPR?](/artifacts/uk/general-data-protection-regulation/faq/lawful-bases.md): Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
- [UK Children's Code: Scope and 15 Standards](/artifacts/uk/general-data-protection-regulation/faq/children-s-code.md): Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
- [UK GDPR 72-hour Breach Reporting Guide](/artifacts/uk/general-data-protection-regulation/72-hour-breach-reporting.md): Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
- [UK GDPR 72-Hour Breach Reporting: Decision Guide](/artifacts/uk/general-data-protection-regulation/faq/72-hour-breach-reporting.md): Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
- [UK GDPR Adequacy Guide](/artifacts/uk/general-data-protection-regulation/adequacy.md): Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
- [UK GDPR Adequacy: When Can You Rely on It?](/artifacts/uk/general-data-protection-regulation/faq/adequacy.md): Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
- [UK GDPR AI and Automated Decisions Guide](/artifacts/uk/general-data-protection-regulation/ai-and-automated-decisions.md): Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
- [UK GDPR AI and Automated Decisions: Articles 22A-22D](/artifacts/uk/general-data-protection-regulation/faq/ai-and-automated-decisions.md): Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
- [UK GDPR Applicability Test Guide](/artifacts/uk/general-data-protection-regulation/applicability-test.md): Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
- [UK GDPR Article 30 Records Guide](/artifacts/uk/general-data-protection-regulation/article-30-records.md): Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
- [UK GDPR Article 30 Records: What to Document](/artifacts/uk/general-data-protection-regulation/faq/article-30-records.md): See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
- [UK GDPR Breach Notification Guide](/artifacts/uk/general-data-protection-regulation/breach-notification.md): Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
- [UK GDPR Breach Workflow Guide](/artifacts/uk/general-data-protection-regulation/breach-workflow.md): Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
- [UK GDPR Children and Age Appropriate Design Guide](/artifacts/uk/general-data-protection-regulation/children-and-age-appropriate-design.md): Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
- [UK GDPR Children's Code Guide](/artifacts/uk/general-data-protection-regulation/children-s-code.md): A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
- [UK GDPR Compliance Checklist](/artifacts/uk/general-data-protection-regulation/checklist.md): A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
- [UK GDPR Compliance FAQ: Duties, Rights, and Decisions](/artifacts/uk/general-data-protection-regulation/faq.md): Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
- [UK GDPR Compliance Guide](/artifacts/uk/general-data-protection-regulation/compliance.md): Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
- [UK GDPR Controller and Processor Status Guide](/artifacts/uk/general-data-protection-regulation/controller-and-processor-status.md): Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
- [UK GDPR Controller or Processor: How to Decide](/artifacts/uk/general-data-protection-regulation/faq/controller-and-processor-status.md): Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
- [UK GDPR Data Subject Rights Guide](/artifacts/uk/general-data-protection-regulation/data-subject-rights.md): Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
- [UK GDPR Deadlines and Compliance Calendar Guide](/artifacts/uk/general-data-protection-regulation/deadlines-and-compliance-calendar.md): Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
- [UK GDPR DPIA Workflow Guide](/artifacts/uk/general-data-protection-regulation/dpia-workflow.md): Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
- [UK GDPR DPIA: When It Is Required and What to Record](/artifacts/uk/general-data-protection-regulation/faq/dpias.md): Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
- [UK GDPR DPIAs and DPOs Guide](/artifacts/uk/general-data-protection-regulation/dpias-and-dpos.md): Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
- [UK GDPR DPO: When Appointment Is Mandatory](/artifacts/uk/general-data-protection-regulation/faq/dpos.md): Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
- [UK GDPR DSAR Workflow Guide](/artifacts/uk/general-data-protection-regulation/dsar-workflow.md): Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
- [UK GDPR IDTA Addendum and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/idta-addendum-and-transfer-risk-assessment.md): Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
- [UK GDPR Lawful Bases Guide](/artifacts/uk/general-data-protection-regulation/lawful-bases.md): Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
- [UK GDPR PECR Cookies Guide](/artifacts/uk/general-data-protection-regulation/pecr-cookies.md): UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
- [UK GDPR Requirements Guide](/artifacts/uk/general-data-protection-regulation/requirements.md): Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
- [UK GDPR Transfer Workflow Guide](/artifacts/uk/general-data-protection-regulation/transfer-workflow.md): Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
- [UK GDPR Transfers, IDTA, and UK Addendum Guide](/artifacts/uk/general-data-protection-regulation/transfers-idta-and-uk-addendum.md): Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
- [UK GDPR vs Data Protection Act 2018: How They Work Together](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-data-protection-act-2018.md): See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
- [UK GDPR vs EU GDPR: Scope, Regulators and Transfers](/artifacts/uk/general-data-protection-regulation/uk-gdpr-vs-eu-gdpr.md): Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
- [UK IDTA vs EU SCCs: Which Transfer Contract to Use](/artifacts/uk/general-data-protection-regulation/idta-vs-eu-sccs.md): Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
- [UK IDTA, Addendum, and Transfer Risk Assessment Guide](/artifacts/uk/general-data-protection-regulation/faq/idta-addendum-and-transfer-risk-assessment.md): Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
- [UK vs EU GDPR Differences After the 2025 UK Reforms](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-gdpr-differences.md): Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
- [UK vs EU GDPR Operations: Regulators, Breaches and Transfers](/artifacts/uk/general-data-protection-regulation/uk-vs-eu-differences.md): Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
- [When do PECR cookie rules require consent?](/artifacts/uk/general-data-protection-regulation/faq/pecr-cookies.md): Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/uk/general-data-protection-regulation/penalties-and-fines.md
