Compliance software · United Kingdom

UK GDPR and GRC compliance software for British SMEs

The UK GDPR still sets the rules for personal data, the Data (Use and Access) Act 2025 is changing some of them, and Cyber Essentials is a condition of more and more contracts. AI Pazz Govnex keeps your records, controls, policies and evidence in one place the ICO — or your customer — can be shown.

In short

Any UK organisation that processes personal data must follow the UK GDPR and the Data Protection Act 2018: have a lawful basis, keep records of processing, protect the data, and report a notifiable breach to the ICO within 72 hours. Govnex holds the GDPR as a ready-made control set, and keeps your records of processing, DPIAs, policies and breaches with owners and evidence.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in United Kingdom

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

UK GDPR

UK GDPR and the Data Protection Act 2018

Ready-made in the Govnex Library
Regulator
Information Commissioner's Office (ICO)
Who it applies to
Every organisation that processes personal data in the UK, or targets people in the UK — no size exemption, though some record-keeping duties are lighter for small firms.
If you fall short
Up to £17.5 million or 4% of annual worldwide turnover, whichever is higher.
What it asks of you
  • A lawful basis for each processing activity, and privacy information people can understand
  • Records of processing activities, and a data protection impact assessment for high-risk processing
  • Appropriate security, and a Data Protection Officer where the law requires one
  • Report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it
  • Answer data subject requests within one month, and safeguard international transfers (IDTA or UK Addendum)
  • Pay the ICO data protection fee unless exempt

The Library holds the EU GDPR, which the UK GDPR mirrors closely; add UK-specific duties as your own controls. The Data (Use and Access) Act 2025 amends the UK GDPR and PECR in stages — recognised legitimate interests, automated decision-making and complaint handling among them.

Source: ICO

Cyber Essentials

Cyber Essentials and Cyber Essentials Plus

Track it with your own controls
Regulator
National Cyber Security Centre (NCSC), certified through IASME
Who it applies to
Voluntary, but required for many UK government contracts and asked for by insurers and larger customers.
If you fall short
None in itself; without it you may not be able to bid.
What it asks of you
  • Firewalls and secure configuration
  • User access control and malware protection
  • Security update management — independently tested for Cyber Essentials Plus

Source: NCSC

NIS Regulations

Network and Information Systems Regulations 2018 and the Cyber Security and Resilience Bill

Track it with your own controls
Regulator
Sector competent authorities, with the ICO for digital service providers
Who it applies to
Operators of essential services and relevant digital service providers — a scope the Cyber Security and Resilience Bill proposes to widen to managed service providers and more.
If you fall short
Fines of up to £17 million under the current regulations.
What it asks of you
  • Appropriate and proportionate security measures
  • Incident reporting to the competent authority

Source: NCSC

Standards United Kingdom buyers ask for

How AI Pazz Govnex helps in United Kingdom

What you needHow Govnex does itModule
Records of processing and DPIAsKeep every processing activity with its lawful basis, data, owners and recipients, and a compliance checklist answered item by item.
UK GDPR controls and evidenceAdopt the GDPR control set, add UK specifics, assign owners and collect evidence cycle by cycle.
Breach response within 72 hoursLog each breach as an issue with an owner, a due date and the actions that close it — the record the ICO asks for.
Policies staff have actually readPublish data protection and security policies, version them and track acknowledgement.
Keeping up with the Data (Use and Access) ActRecord each change that applies to you, who owns it and the work it needs.

Your first 90 days

  1. 1Map your processing activities and record the lawful basis for each.
  2. 2Adopt the GDPR control set, add your UK-specific duties, and assign owners.
  3. 3Check whether you need a DPO and whether you have paid the ICO fee.
  4. 4Put your breach response plan in place, and publish the policies staff must acknowledge.
  5. 5Work towards Cyber Essentials or ISO 27001, and report your position to leadership.

Start with what applies to you

Adopt the control sets that fit, add your own for the rest, and give every control an owner. The first months are free.

Start free

Compliance in United Kingdom: questions and answers

Is the UK GDPR different from the EU GDPR?
They are very close. After Brexit the UK kept the GDPR as the UK GDPR alongside the Data Protection Act 2018, and the Data (Use and Access) Act 2025 now changes some details. Govnex's GDPR control set covers the shared ground; add UK-specific duties as your own controls.
How quickly must a personal data breach be reported to the ICO?
Within 72 hours of becoming aware of it, if it is likely to result in a risk to people's rights and freedoms — and to the affected people without undue delay if the risk is high.
Do we need a Data Protection Officer?
Only if you are a public authority, or your core activities involve large-scale regular monitoring of people or large-scale processing of special category data. Many SMEs appoint a named privacy lead instead.
Does Govnex help with Cyber Essentials?
Yes — track its five technical controls as your own control set, assign owners, attach evidence and see what is outstanding before you certify.
Can we keep a record of processing activities in Govnex?
Yes. The Data Compliance Tracker keeps each processing activity with its data, owners, lawful basis and recipients, with a compliance checklist per activity.
Is Govnex only for data protection?
No. The same workspace runs ISO 27001 and other standards, policies, risk registers, issues, internal audits, regulatory change and ESG & EHS.