UK GDPR
UK GDPR and the Data Protection Act 2018
- Regulator
- Information Commissioner's Office (ICO)
- Who it applies to
- Every organisation that processes personal data in the UK, or targets people in the UK — no size exemption, though some record-keeping duties are lighter for small firms.
- If you fall short
- Up to £17.5 million or 4% of annual worldwide turnover, whichever is higher.
- What it asks of you
- A lawful basis for each processing activity, and privacy information people can understand
- Records of processing activities, and a data protection impact assessment for high-risk processing
- Appropriate security, and a Data Protection Officer where the law requires one
- Report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it
- Answer data subject requests within one month, and safeguard international transfers (IDTA or UK Addendum)
- Pay the ICO data protection fee unless exempt
The Library holds the EU GDPR, which the UK GDPR mirrors closely; add UK-specific duties as your own controls. The Data (Use and Access) Act 2025 amends the UK GDPR and PECR in stages — recognised legitimate interests, automated decision-making and complaint handling among them.