UK GDPR (Data Protection Act 2018)
The UK GDPR sits alongside the Data Protection Act 2018 and is enforced by the ICO. Since Brexit it has diverged in small but real ways from the EU GDPR — most notably around international transfers (the UK IDTA) and the ICO's own guidance.
Who it applies to
Any organisation processing personal data of individuals in the UK.
How ISO-STANDARD.app helps with UK GDPR
10 in-depth articles
UK GDPR vs EU GDPR: the differences that matter
The regimes share DNA but diverge on transfers, age of consent, and enforcement posture. Here's the shortlist that changes your programme.
The high-level position
The UK GDPR is essentially the EU GDPR retained into UK law by the European Union (Withdrawal) Act. The principles, lawful bases, and data subject rights are identical. Where things differ is around international transfers, age of consent for information society services (13 in the UK, 16 by default in the EU), and how the ICO applies the law compared with continental DPAs.
International data transfers
You cannot rely on the same set of adequacy decisions blindly. The UK maintains its own list, and transfers out of the UK typically use the IDTA (International Data Transfer Agreement) or the UK Addendum to the EU SCCs. Any Transfer Risk Assessment must consider both routes if you serve UK and EU data subjects.
Enforcement flavour
The ICO has historically leaned pragmatic — engagement, warnings, then fines. That does not mean fines don't happen (British Airways, Marriott, Clearview AI) — it means a documented, defensible programme goes further than in some EU jurisdictions.
Records of processing (ROPA)
Article 30 obligations are unchanged. In practice a good ROPA also feeds your DPIAs, retention register and DSAR responses, so keep it in a system that can query it — not a spreadsheet the DPO owns alone.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR DPIA: when it's required and how to run one
The ICO publishes an explicit list of processing that requires a DPIA. Miss one and you're on the wrong side of the accountability principle.
The trigger list
The ICO requires a DPIA for: innovative use of technology (including AI), denial of service based on automated decisions, systematic profiling with legal effect, biometric data at scale, and combining/matching datasets across sources — among others. If any of these apply, a DPIA is not optional.
The nine components
A DPIA has a defined shape: description of processing, necessity/proportionality assessment, consultation with stakeholders, risk identification, risk mitigation, sign-off, and a plan for review. Use a template that forces you to complete every section — half-done DPIAs are how programmes fail an ICO audit.
Prior consultation
If residual risk stays high after mitigation, you must consult the ICO before processing. Very few organisations get to this stage, but it's a signal that the mitigation isn't yet strong enough — go back and strengthen controls before launching.
Living documents
DPIAs age. New features, new vendors, new data flows all reopen them. Version them like code, not like Word documents in a shared drive.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR DSAR response: a one-month playbook
One month to identify, retrieve, redact and deliver. Without a playbook, teams miss deadlines and invite complaints.
Day 1–3: verify identity and scope
The clock starts when the request is received, not when identity is verified — but you're allowed to pause it while you confirm the requester's identity. Confirm scope early: 'all my data' is rarely what they actually need.
Day 4–15: search and collect
Query every system that holds personal data on the subject. This is where your data map and ROPA earn their keep. Missing a system is the most common cause of complaint.
Day 16–25: redact and review
Third-party personal data must be redacted unless disclosure is reasonable. Legal privilege, negotiation privilege and confidential references have their own carve-outs — apply them carefully with a documented rationale.
Day 26–30: deliver and log
Deliver through a secure channel. Log every request, every extension used, and every exemption applied. This log is the first thing the ICO asks for if a complaint lands.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR international transfers using the IDTA
The IDTA replaced legacy SCCs for UK exports in March 2024. Legacy contracts need repapering.
Choose the instrument
You can use the standalone IDTA, or the UK Addendum to the EU SCCs when you're already using the EU version for the EU leg. The Addendum is often lighter-touch operationally.
Complete the tables
The IDTA relies on tables you fill in describing parties, transfer details, security requirements and commercial clauses. Empty tables are unenforceable — treat them as contract schedules, not annexes.
Transfer Risk Assessment
A TRA weighs the legal regime and practices of the destination country against the sensitivity and volume of data. The ICO's TRA tool is a reasonable starting point; document the reasoning, not just the conclusion.
Supplementary measures
Encryption in transit and at rest is table stakes. Additional measures (pseudonymisation, split processing, contractual right of audit) may be required for high-risk transfers — these are what the ICO looks for after a Schrems-style challenge.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR breach notification: 72 hours in practice
72 hours is not much time. The organisations that meet it are the ones with a rehearsed decision tree.
The threshold
You notify when a breach is likely to result in a risk to individuals. 'Likely to result' is a low bar — err on the side of notifying, and document your reasoning either way.
The clock
The 72-hour clock starts on 'awareness' — when someone in the organisation reasonably believes a breach has occurred. That's often earlier than teams admit. Train first-responders to escalate immediately.
What to include
Nature of breach, categories and approximate numbers, likely consequences, measures taken. If you don't have all the facts, notify with what you have and update the ICO — don't wait to build a perfect submission.
Notifying individuals
If the risk to individuals is high, you must also tell them without undue delay. Draft the notification template now, not in the middle of an incident. Practise it in a tabletop.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
Preparing for an ICO audit
ICO audits are collaborative, not punitive — but only if you show up prepared.
The scope letter
The audit starts with a scope letter listing the areas the ICO wants to see: ROPA, DPIAs, DSAR handling, breach log, training records, DPO reports. Have those ready before the meeting.
The interview
Auditors interview process owners, not just the DPO. Marketing, HR, engineering and vendor management will all be asked to describe their data handling in their own words. Rehearse.
Findings and action plan
Most audits produce recommendations, not enforcement. But recommendations get followed up — an unactioned recommendation from an old audit is a bad look in a new investigation.
The public report
Some audits are published (in redacted form). Assume yours will be — it's a good motivator for real fixes, not cosmetic ones.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
Choosing the right lawful basis (and sticking to it)
You must pick a lawful basis before you process — and switching mid-flight is a recognised complaint driver.
The six bases
Consent, contract, legal obligation, vital interests, public task, legitimate interests. Only one applies to any given processing activity — mixing them signals confused thinking to the ICO.
Legitimate interests assessment (LIA)
If you rely on legitimate interests, document the three-part test: purpose, necessity, balance. Without an LIA the basis is not defensible.
Special category data
Special category data (health, biometrics, political opinion, etc.) needs both an Article 6 basis and an Article 9 condition. Explicit consent is one option; there are ten in total.
Communicating it
Your privacy notice must state the lawful basis for each purpose. Vague statements like 'we may process your data for various business purposes' fail the transparency principle.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR vendor management: the processor relationship
Article 28 controls the shape of every processor contract. Most contracts you inherit are missing at least one required clause.
Article 28 clauses
The eight mandatory clauses: process on documented instructions, confidentiality, security, sub-processors, data subject rights assistance, breach assistance, return/deletion, audit rights. Absent any one and the contract is non-compliant.
Sub-processor management
You need to know who your processors use, and the processor needs your general or specific authorisation for changes. Most Article 28 disputes come from silent sub-processor swaps.
Audit rights
You have a right to audit — in practice this is nearly always satisfied by third-party assurance (ISO 27001, SOC 2, penetration test summaries). Accept those where they're solid; insist on more where they're not.
Deletion at end of contract
The processor must return or delete data at the end of the relationship. Make this a scheduled operational task, not a promise buried in the DPA.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR + PECR: marketing without breaching either
PECR is the UK's ePrivacy law. It governs cookies, direct marketing and online tracking — often more strictly than GDPR.
Cookies
Non-essential cookies need consent — a genuine opt-in, not a pre-ticked box or continued browsing. Cookie banners that make 'reject all' harder than 'accept all' now attract ICO enforcement.
Email marketing
B2C email marketing needs consent unless the soft opt-in applies (existing customer, similar product, easy opt-out). B2B (individual @ company addresses) still needs consent for individuals; corporate addresses are lighter-touch but the ICO's line is tightening.
SMS and phone
SMS is treated like email. Live calls need consent unless the number isn't on TPS/CTPS. Automated calls always need consent.
The intersection with GDPR
PECR sits on top of GDPR — you need a valid lawful basis under GDPR and PECR consent where required. The two are often confused; treat them as two separate check-boxes on every marketing activity.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
UK GDPR, the Children's Code and age of consent
The Age Appropriate Design Code (Children's Code) has teeth. If under-18s can plausibly access your service, you're in scope.
Age of consent
For information society services in the UK, the age of consent for online services is 13. Under that, parental consent is required — with reasonable effort to verify.
The 15 standards
The Children's Code sets 15 standards: default high privacy, data minimisation, transparency in child-friendly language, no nudging into weaker settings, no profiling by default. Read the standards, don't skim the summary.
Age assurance
You don't always need hard age verification — the standard is 'a level of certainty appropriate to the risk'. That still means more than a birthday text box.
Consequences
The ICO has already opened investigations into major platforms under the Code. Non-compliance is expensive both financially and reputationally — parents notice, and so do MPs.
How ISO-STANDARD.app helps with UK GDPR
Inside the workspace, this topic maps to concrete artefacts: pre-loaded UK GDPR controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the UK GDPR shape.
Ready to evidence UK GDPR?
Load the pre-mapped controls, capture evidence continuously, and publish your UK GDPR posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.