UK GDPR and Data Protection Act 2018 Compliance for Businesses
UK GDPR in Brief
- Lawful basis for processing personal data
- Data Subject Rights including access, rectification and erasure
- Breach notification to ICO within 72 hours where reportable
The UK Data Protection Framework
UK data protection compliance rests on UK legislation working together with retained EU law. The principal sources are the UK GDPR (the retained version of the EU General Data Protection Regulation) and the Data Protection Act 2018, which sits alongside it dealing with national derogations, law enforcement processing and intelligence services processing. Reform legislation has amended the framework over time and continues to do so, but the core structure has stayed in place since 2018.
The framework applies to all UK organisations that process personal data, regardless of size. There is no general SME exemption. Most organisations need to register with the ICO and pay an annual data protection fee, follow the data protection principles, identify a lawful basis for each processing activity, respect data subject rights, keep records of processing, and respond to breaches within tight timescales. The Information Commissioner's Office publishes detailed and current guidance for organisations at ico.org.uk.
For cross-border data flows, the EU's adequacy decision for UK transfers continues to allow personal data to flow freely between the EU and UK without additional safeguards, subject to periodic renewal. Transfers from the UK to most other countries still need an Article 46 safeguard such as standard contractual clauses or the UK International Data Transfer Agreement.
The Data Protection Principles
Article 5 of the UK GDPR sets out seven principles that all processing of personal data must follow:
- Lawfulness, fairness and transparency - processing must have a valid legal basis, be fair to the individual, and be done openly
- Purpose limitation - personal data is collected for specified purposes and not used for incompatible purposes later
- Data minimisation - personal data is adequate, relevant and limited to what is needed for the purpose
- Accuracy - personal data is kept accurate and up to date, with reasonable steps to correct inaccuracies
- Storage limitation - personal data is kept only as long as needed for the purpose, with retention periods documented
- Integrity and confidentiality (security) - personal data is protected by appropriate technical and organisational measures
- Accountability - the organisation is responsible for compliance and must be able to demonstrate it
Accountability is the principle that drives most of the documentation requirements. Records of processing, lawful basis assessments, retention schedules, breach logs, privacy notices and policy documents are all part of demonstrating compliance, not just describing it.
Lawful Bases for Processing
Article 6 of the UK GDPR sets out six lawful bases for processing personal data. The organisation must identify and document the lawful basis for each processing activity before it begins:
- Consent - the individual has given clear, specific, freely given consent. Not the right basis for most employment processing because the employer/employee relationship makes truly free consent difficult
- Contract - processing is necessary to perform a contract with the individual, or to take steps before entering one. Used for employee payroll, customer order fulfilment
- Legal obligation - processing is necessary for compliance with a UK legal obligation (statutory tax records, right to work checks, accident reporting)
- Vital interests - processing is necessary to protect someone's life. Rarely used outside emergency situations
- Public task - processing is necessary for a task in the public interest or exercise of official authority. Mainly relevant to public bodies
- Legitimate interests - processing is necessary for the legitimate interests of the organisation or a third party, except where overridden by the individual's rights and freedoms. Requires a documented legitimate interests assessment (LIA)
For most SMEs, the practical lawful bases are contract (for employees and customers), legal obligation (for tax, employment and regulatory records), and legitimate interests (for marketing, fraud prevention, IT security, and similar business operations). Consent is reserved for situations where the individual genuinely has a free choice - typically marketing communications under PECR, optional staff benefits, or research participation.
Special Category Data and Criminal Records
Some types of personal data are subject to extra restrictions. Article 9 of the UK GDPR defines special category data:
- Race or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data used for identification
- Health data
- Data about sex life or sexual orientation
Processing special category data requires both a lawful basis under Article 6 and a separate condition under Article 9(2) - typically explicit consent, employment law compliance (for example, sickness absence and equality monitoring), substantial public interest with a Schedule 1 condition under the Data Protection Act 2018, or vital interests. Most employers process some special category data (sickness absence records, equality monitoring data, accident records) and need to identify the relevant Article 9(2) condition and any Schedule 1 condition that applies.
Criminal offence data is treated separately under Article 10. Processing it generally requires either official authority or a specific Schedule 1 condition under the DPA 2018. DBS checks, for example, fall under Schedule 1 conditions for safeguarding and prevention of unlawful acts.
For SMEs, the most common compliance gap is not understanding which lawful basis applies to which processing activity. The default reaction is to put consent forms in front of everyone for everything, which is usually wrong - consent is the weakest basis because it can be withdrawn at any time, and in employment contexts it is rarely freely given. The right approach is to map each processing activity to the appropriate basis: payroll on contract, tax records on legal obligation, marketing emails to existing customers on legitimate interests with an opt-out, and prospective marketing to individuals on consent under PECR. Once the mapping is documented, the rest of the privacy notice and the records of processing flow from it.
Data Subject Rights
The UK GDPR gives individuals a set of rights they can exercise over their personal data. Organisations must respond within statutory time limits, generally one month from receipt:
- Right of access (DSAR) - the right to obtain confirmation of processing and a copy of the personal data being held, plus information about the processing
- Right to rectification - the right to have inaccurate data corrected and incomplete data completed
- Right to erasure (the "right to be forgotten") - the right to have data deleted in certain circumstances, including where consent is withdrawn or the data is no longer needed
- Right to restrict processing - the right to limit how data is used while a question over it is resolved
- Right to data portability - the right to receive personal data provided to the organisation in a structured, commonly used, machine-readable format
- Right to object - the right to object to processing based on legitimate interests, public task, or direct marketing
- Rights related to automated decision-making and profiling - the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects
Organisations also need a clear internal complaints route so individuals can raise concerns directly before going to the ICO. A documented procedure for receiving, acknowledging, investigating and responding to data protection complaints is part of the accountability framework.
ICO Registration and the Data Protection Fee
Most organisations that process personal data need to register with the ICO and pay an annual data protection fee. The fee is set in tiers based on organisation size and turnover, with the smallest tier intended for sole traders and micro businesses. Some organisations are exempt - including those processing only for personal use, certain narrow non-profit purposes, and specific judicial or public functions. Failing to pay when required is a civil offence with its own penalty.
The current fee tiers and exemption criteria are published by the ICO and updated periodically. Organisations should use the ICO's self-assessment tool at ico.org.uk to confirm whether they need to pay and at what tier.
Personal Data Breaches
Article 33 of the UK GDPR requires organisations to notify the ICO of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it - unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where the risk to individuals is high, Article 34 also requires the affected individuals to be notified directly without undue delay.
The 72-hour clock starts when the organisation becomes aware that a breach has occurred, not when the breach itself happened. The notification needs to describe the breach, the categories and approximate numbers of individuals affected, the likely consequences, and the measures taken or proposed to address it. If the full information is not available within 72 hours, an initial notification can be made and supplemented later.
All breaches need to be recorded internally, regardless of whether they are reportable to the ICO. The accountability principle requires the organisation to be able to demonstrate that it considered whether a notification was needed in each case.
What I look for on data protection in audits is not just the policy but the operational evidence behind it. Is there a record of processing activities that matches the actual processing the organisation does? Have lawful bases been documented for each activity? Is there a privacy notice that staff have actually been told about, with retention periods specified? Are DSARs being received and tracked, with response dates met? Are breaches being logged - including the ones that did not need ICO notification - so the organisation can show it considered each one properly?
The accountability principle is what audit and ICO investigations look at hardest. An organisation can have all the right processing activities and the right lawful bases, but if it cannot demonstrate the analysis behind those decisions, it has not satisfied accountability. The records of processing, legitimate interests assessments, data protection impact assessments for higher-risk processing, breach logs and DSAR logs are the documents that prove compliance, not just describe it.
Records of Processing Activities
Article 30 of the UK GDPR requires organisations to maintain a Record of Processing Activities (ROPA). The ROPA documents each processing purpose, the categories of personal data and individuals involved, the lawful basis, the recipients of the data, the retention period and the technical and organisational security measures in place.
In practice, every UK organisation that processes personal data should maintain a ROPA. While there is a narrow exemption for some smaller organisations, it only applies where processing is occasional, does not include special category or criminal offence data, and is unlikely to result in a risk to individuals - conditions that very few organisations actually meet, since employee data alone usually defeats the exemption. Treating the ROPA as a standard requirement is the safer and clearer position.
The ROPA is also one of the first documents the ICO will ask to see in an investigation or audit. An up-to-date ROPA that matches the actual processing the organisation does is central to demonstrating accountability.
ICO Enforcement
The ICO has a graduated set of enforcement powers under the Data Protection Act 2018:
- Information notices - requiring the organisation to provide specific information
- Assessment notices - permitting the ICO to enter premises and inspect
- Enforcement notices - requiring specific corrective action
- Penalty notices - civil monetary penalties
- Reprimands and warnings - public statements of concern, often used for less serious breaches by smaller organisations
Civil penalties under the UK GDPR are tiered, with the higher tier reserved for serious breaches of the principles, lawful basis or data subject rights and the standard tier for administrative breaches such as failure to maintain a ROPA or notify a breach. The maximum penalties are substantial and based on percentages of global annual turnover. The ICO is required to consider proportionality and the impact of fines on small and medium organisations, and most SME enforcement uses reprimands rather than fines. Persistent or serious breaches do attract penalties, and unpaid data protection fees can also lead to monetary penalties.
The thing that catches small businesses out on data protection is not the headline rules - it is the bits that prove the rules were followed. The privacy notice on the website is fine, but is there a record showing when it was last reviewed? The DSAR procedure exists, but has anyone actually walked through it with a real request? The breach log is in place, but does it include the small near-miss where someone emailed the wrong attachment last March? The substance of compliance is not the policy document, it is the trail of decisions and actions behind it. An ICO inspection looks at the trail.
Practical Advice
For most SMEs, data protection compliance starts with ICO registration, a privacy notice, a Record of Processing Activities mapping each processing purpose to its lawful basis and retention period, a DSAR procedure, a breach log, and a complaints procedure for individuals to raise concerns. The toolkit and policies below provide the documented basis.
The legislation is updated periodically - reviewing the framework against current ICO guidance is part of normal compliance work. The ICO website at ico.org.uk publishes the current guidance, fee tiers and self-assessment tools.
| alphaZ document | How to use it |
|---|---|
| GDPR Toolkit | The full data protection and privacy toolkit. Includes the policies, procedures, registers and templates that form the documented data protection framework, aligned to the UK GDPR and the Data Protection Act 2018. |
| P-25 Data Protection Policy | The standalone data protection policy. Sets out the principles, lawful bases framework, data subject rights, breach notification process and the organisational responsibilities. |
| PP-1-16 Data Protection Procedure | The procedural document that sits below the policy. Operationalises the policy into specific steps for handling DSARs, breaches, complaints and other data protection activities. |
| F-IMS30 Record of Processing Activities | The Article 30 ROPA template. Lists each processing purpose, the categories of data, the lawful basis, retention period and recipients - the central document for demonstrating accountability. |
| F-Q106 Personal Data Compliance Checklist | A self-assessment checklist for reviewing personal data processing against the UK GDPR requirements. Useful for periodic compliance reviews. |
Note: subscribers to alphaZ documents can download all of the documents above as part of the subscription.
Frequently Asked Questions
Most do. Organisations that process personal data must register with the ICO and pay an annual data protection fee unless they qualify for a specific exemption. The fee tiers are scaled to organisation size and turnover, with the smallest tier intended for sole traders and micro businesses. Exemptions are narrow - they include processing for personal or domestic use, certain non-profit purposes, and specific judicial or public functions. The ICO publishes a self-assessment tool at ico.org.uk to confirm whether registration is required and at what tier.
Most do not. Article 37 of the UK GDPR requires a DPO only for public authorities, organisations whose core activities consist of large-scale regular and systematic monitoring of individuals, or organisations whose core activities consist of large-scale processing of special category data. For most SMEs none of these apply. Even where a formal DPO is not required, it is good practice to allocate data protection responsibility to a named person with the time and authority to act on it. Some organisations appoint a "data protection lead" or "privacy contact" without giving them the formal DPO title or independence requirements.
Under Article 12 of the UK GDPR, a response is required without undue delay and at the latest within one month of receipt. The deadline can be extended for complex requests, with the requester told of the extension and the reasons within the original month. The response clock can also be paused while the organisation seeks reasonable clarification from the requester. The DSAR is free in most cases - a fee can only be charged for manifestly unfounded or excessive requests, or for additional copies.
Under Article 33 of the UK GDPR, a personal data breach must be notified to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it - unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The 72-hour clock starts when the organisation becomes aware that a breach has occurred, not when the breach itself happened. Where the risk to individuals is high, Article 34 also requires direct notification to those individuals. All breaches should be logged internally regardless of whether external notification is required, so that the organisation can demonstrate it considered each one properly.
In practice, yes. Article 30 of the UK GDPR requires organisations to maintain a Record of Processing Activities (ROPA) documenting each processing purpose, the categories of data and individuals, the lawful basis, recipients, retention periods and security measures. While there is a narrow exemption for some smaller organisations, it only applies where processing is occasional, does not include special category or criminal offence data, and is unlikely to result in risk - conditions very few organisations actually meet, since employee data alone usually defeats the exemption. The ROPA is one of the first documents the ICO will ask to see in an investigation, so treating it as a standard requirement is the safer and clearer position.
UK Legislation
- Data Protection Act 2018
- UK GDPR (retained Regulation (EU) 2016/679)
- Privacy and Electronic Communications Regulations 2003 (PECR)
