Artifact GuideUKRequirements

UK GDPR Requirements

This page maps the UK GDPR Requirements into scope triggers, accountable owners, controls, evidence records, deadlines, and escalation points.

Use this guide for implementation planning, not as a substitute for checking the consolidated UK GDPR, applicable Data Protection Act 2018 provisions, current ICO guidance, contracts, and the facts of the processing.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The UK GDPR, supplemented by the Data Protection Act 2018, applies requirements to each processing activity according to scope, role, purpose, data, people, risk, technology, recipients, and transfers. It has applied in its UK form since 1 January 2021, and the Data (Use and Access) Act 2025 amendments are now in force. Use this map to connect each legal decision, deadline, exception, owner, control, and evidence record.

Section 1

How should teams map UK GDPR Requirements into owners, controls, and evidence?

Map the seven principles first, including . Then attach Article 6 and any Article 9 or 10 condition, privacy information, rights, privacy by design and default, processor and joint-controller arrangements, records, security, breach readiness, DPIA or DPO triggers, and Chapter V transfer controls.

Reflect the current consolidated UK text, including recognised legitimate interests, amended request timing and access searches, Articles 22A-22D, the revised transfer route, PECR storage-and-access exceptions, and the data protection complaints process. Legislation is binding; ICO material explains the regulator's interpretation and expected practice. Recheck older guidance and templates where the law has changed.

  • Scope and roles: record Article 2 and 3 coverage and who acts as controller, joint controller, or processor.
  • Lawfulness and purpose: document an Article 6 basis, necessity, purpose compatibility, and any Article 9 condition or Article 10 authority.
  • People and information: provide Articles 13 or 14 information and operate access, rectification, erasure, restriction, portability, objection, and automated-decision safeguards as applicable.
  • Governance and risk: implement data protection by design and default, records, processor terms, security, breach handling, DPIAs, DPO arrangements, children's higher-protection measures, and a data protection complaints process where triggered.
  • Transfers: use the Article 44A route map and record approval regulations, Article 46 safeguards, or the narrow Article 49 derogation relied on, including any Article 49A restriction.
Section 2

Who should own the UK GDPR requirements, and what evidence should prove the decision?

Assign each requirement to the actor that can perform it. Controllers decide purposes and essential means and remain responsible for compliance; processors act on documented instructions and have direct duties including security, records, cooperation, and breach escalation. Joint controllers must allocate responsibilities transparently, although people may exercise rights against either controller.

Evidence should show both the legal decision and operation: the processing record, notice, contract, system setting, access review, deletion result, request case, complaint case, security test, DPIA, breach assessment, transfer record, approval, and remediation. The evidence set must match the activity rather than repeat every possible document.

  • Name one accountable owner and one reviewer for the Requirements workflow.
  • Keep the legal source, decision note, system or contract evidence, implementation ticket, test result, exception, and approval together.
  • Use dated evidence for Article 14 delivery, Article 12A request handling, breach assessment and any 72-hour notification, 30-day complaint acknowledgement, notices, contracts, DPIAs, and transfer reviews.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which edge cases should teams check before relying on a UK GDPR requirements decision?

At a boundary, identify which instrument supplies the rule: UK GDPR for general processing, the Data Protection Act 2018 for UK conditions, exemptions, and separate regimes, PECR for communications and device access, and EU GDPR where its territorial scope independently applies. Transfer instruments address Chapter V only.

Exclude genuinely anonymous information and a person's purely personal or household activity with no professional or commercial connection. Pseudonymised information remains personal data when additional information can attribute it to a person. Use DPA 2018 Part 3 for competent-authority law-enforcement processing and Part 4 for intelligence-service processing instead of applying the general-processing map unchanged.

Review this section before approving a new processing purpose, vendor, transfer, profiling flow, DSAR workflow, breach process, or child-facing product change.

  • Check whether the rule changes for minors, consumers, business users, public-sector bodies, regulated sectors, high-risk services, or cross-border transfers.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams put the requirements into operation?

Start with an intake that identifies the processing, legal trigger, actor, data, people, risk, recipient, and country. Map a lawful-basis question to an Article 6 necessity note, a special-category question to Article 9 and any Schedule 1 condition, a transfer question to the Article 44A route, and a rights, complaint, or breach question to its own deadline and escalation path.

The decision record should state the action, legal reason, condition or exception, accountable actor, reviewer, evidence, due date, approval, residual risk, and reassessment event. A control is complete only when the live system, contract, notice, or case file matches the decision.

  • Rights: calculate the Article 12A relevant time, record any permitted extension or access clarification pause, search reasonably and proportionately, apply exemptions item by item, and retain the response evidence.
  • Incidents: record controller awareness, risk and high-risk decisions, processor escalation, phased notification, communication to people, containment, and remediation; notify the ICO where required without undue delay and, where feasible, within 72 hours.
  • Complaints: give people a way to complain, accept complaints received through other channels, acknowledge within 30 days, make appropriate enquiries, keep the person informed, communicate the outcome without undue delay, and retain the case record.
  • High-risk change: screen before design is fixed, complete any required DPIA before processing, consult the ICO before launch if high residual risk remains, and reopen the assessment when the nature, scope, context, purpose, technology, or risk changes.
  • Suppliers and transfers: confirm role, Article 28 terms and subprocessor controls, security evidence, restricted-transfer scope, adequacy or safeguard, data protection test, onward transfers, signed instrument version, and review triggers.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding source for mapping each processing trigger to the required action, responsible actor, evidence, and deadline.
legislation.gov.uk
Referenced sections
  • Binding source for material and territorial scope and the exclusions that separate general processing from other regimes.
legislation.gov.uk
Referenced sections
  • Binding source for controller accountability, joint-controller arrangements, processor duties and contracts, records, and cooperation.
legislation.gov.uk
Referenced sections
  • Binding source for UK conditions, exemptions, enforcement, and separate law-enforcement and intelligence-services processing.
ico.org.uk
Referenced sections
  • ICO guidance for mapping UK GDPR security requirements into proportionate technical and organisational measures.
gov.uk
Referenced sections
  • GOV.UK explainer for UK-US data bridge conditions and protection-level rationale under the UK GDPR.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.