New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
← Legislation library

United Kingdom

UK GDPR

The UK GDPR is the United Kingdom's version of the GDPR, retained in domestic law alongside the Data Protection Act 2018. It mirrors the EU regime closely while being enforced by the ICO under UK jurisdiction.

19 articles

Article 5

Principles relating to processing of personal data

Personal data shall be processed lawfully, fairly and in a transparent manner (UK GDPR mirrors EU GDPR Art. 5).

Article 6

Lawfulness of processing

Processing shall be lawful only if at least one legal basis applies (UK GDPR mirrors EU GDPR Art. 6).

Article 13

Information to be provided where personal data are collected from the data subject

When personal data are collected from the data subject, the controller shall provide the specified Art.13 information (UK mirrors EU GDPR Art.13).

Article 14

Information to be provided where personal data have not been obtained from the data subject

When personal data have not been obtained from the data subject, the controller shall provide the Art.14 information within one month (UK mirrors EU GDPR Art.14).

Article 15

Right of access by the data subject

Data subject has right to confirmation and access to personal data plus Art.15 information (UK mirrors EU GDPR Art.15).

Article 16

Right to rectification

Data subject has right to rectification without undue delay (UK mirrors EU GDPR Art.16).

Article 17

Right to erasure ('right to be forgotten')

Data subject can obtain erasure without undue delay on specified grounds (UK mirrors EU GDPR Art.17).

Article 20

Right to data portability

Right to receive data in structured, commonly used, machine-readable format and transmit to another controller (UK mirrors EU GDPR Art.20).

Article 22

Automated individual decision-making, including profiling

The data subject shall have the right not to be subject to a decision based solely on automated processing (UK GDPR mirrors EU GDPR Art. 22).

Article 25

Data protection by design and by default

The controller shall implement appropriate technical and organisational measures to implement data protection principles (UK GDPR mirrors EU GDPR Art. 25).

Article 28

Processor

Controllers must only use processors providing sufficient guarantees; processing governed by contract (UK mirrors EU GDPR Art.28).

Article 30

Records of processing activities

Controllers and processors must maintain written records of processing activities (UK mirrors EU GDPR Art.30).

Article 32

Security of processing

Controllers and processors must implement appropriate technical and organisational measures appropriate to the risk (UK mirrors EU GDPR Art.32).

Article 33

Notification of a personal data breach to the supervisory authority

Controller must notify ICO without undue delay and where feasible within 72 hours (UK mirrors EU GDPR Art.33).

Article 34

Communication of a personal data breach to the data subject

When breach is likely to result in high risk to rights and freedoms, controller shall communicate breach to data subject without undue delay (UK mirrors EU GDPR Art.34).

Article 35

Data protection impact assessment

Where processing is likely to result in a high risk, the controller shall carry out a DPIA (UK GDPR mirrors EU GDPR Art. 35).

Article 37

Designation of the data protection officer

Controllers/processors shall designate a DPO where required (public authority, large scale systematic monitoring, or large scale special categories); DPO contact details published and communicated to ICO (UK mirrors EU GDPR Art.37 with DPA 2018 overlay).

Article 44

General principle for transfers

Any transfer to a third country or international organisation shall take place only if conditions of Chapter V are complied with (UK mirrors EU GDPR Art.44, with UK adequacy decisions).

Article 83

General conditions for imposing administrative fines

Administrative fines up to GBP 17.5 million or 4% of global annual turnover (UK GDPR mirrors EU GDPR Art. 83).

Turn UK GDPR into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial