United Kingdom
UK GDPR
The UK GDPR is the United Kingdom's version of the GDPR, retained in domestic law alongside the Data Protection Act 2018. It mirrors the EU regime closely while being enforced by the ICO under UK jurisdiction.
19 articles
Principles relating to processing of personal data
Personal data shall be processed lawfully, fairly and in a transparent manner (UK GDPR mirrors EU GDPR Art. 5).
Lawfulness of processing
Processing shall be lawful only if at least one legal basis applies (UK GDPR mirrors EU GDPR Art. 6).
Information to be provided where personal data are collected from the data subject
When personal data are collected from the data subject, the controller shall provide the specified Art.13 information (UK mirrors EU GDPR Art.13).
Information to be provided where personal data have not been obtained from the data subject
When personal data have not been obtained from the data subject, the controller shall provide the Art.14 information within one month (UK mirrors EU GDPR Art.14).
Right of access by the data subject
Data subject has right to confirmation and access to personal data plus Art.15 information (UK mirrors EU GDPR Art.15).
Right to rectification
Data subject has right to rectification without undue delay (UK mirrors EU GDPR Art.16).
Right to erasure ('right to be forgotten')
Data subject can obtain erasure without undue delay on specified grounds (UK mirrors EU GDPR Art.17).
Right to data portability
Right to receive data in structured, commonly used, machine-readable format and transmit to another controller (UK mirrors EU GDPR Art.20).
Automated individual decision-making, including profiling
The data subject shall have the right not to be subject to a decision based solely on automated processing (UK GDPR mirrors EU GDPR Art. 22).
Data protection by design and by default
The controller shall implement appropriate technical and organisational measures to implement data protection principles (UK GDPR mirrors EU GDPR Art. 25).
Processor
Controllers must only use processors providing sufficient guarantees; processing governed by contract (UK mirrors EU GDPR Art.28).
Records of processing activities
Controllers and processors must maintain written records of processing activities (UK mirrors EU GDPR Art.30).
Security of processing
Controllers and processors must implement appropriate technical and organisational measures appropriate to the risk (UK mirrors EU GDPR Art.32).
Notification of a personal data breach to the supervisory authority
Controller must notify ICO without undue delay and where feasible within 72 hours (UK mirrors EU GDPR Art.33).
Communication of a personal data breach to the data subject
When breach is likely to result in high risk to rights and freedoms, controller shall communicate breach to data subject without undue delay (UK mirrors EU GDPR Art.34).
Data protection impact assessment
Where processing is likely to result in a high risk, the controller shall carry out a DPIA (UK GDPR mirrors EU GDPR Art. 35).
Designation of the data protection officer
Controllers/processors shall designate a DPO where required (public authority, large scale systematic monitoring, or large scale special categories); DPO contact details published and communicated to ICO (UK mirrors EU GDPR Art.37 with DPA 2018 overlay).
General principle for transfers
Any transfer to a third country or international organisation shall take place only if conditions of Chapter V are complied with (UK mirrors EU GDPR Art.44, with UK adequacy decisions).
General conditions for imposing administrative fines
Administrative fines up to GBP 17.5 million or 4% of global annual turnover (UK GDPR mirrors EU GDPR Art. 83).
Turn UK GDPR into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial