UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025 and PECR compliance software
Assess and evidence UK data protection law as it stands after the Data (Use and Access) Act 2025, per group or per controller and processor: the UK GDPR, the Data Protection Act 2018 and PECR, from lawful basis and individuals' rights to international transfers and the 72-hour breach clock.
- Legal instrumentsUK GDPR; Data Protection Act 2018; Data (Use and Access) Act 2025; PECR 2003
- RegulatorInformation Commission, still branded ICO, which replaced the Information Commissioner on 30 September 2026
- Assessable items178 requirements in 10 domains, 68 of them critical
- Breach clockNotify within 72 h of becoming aware, where feasible (UK GDPR Article 33; PECR regulation 5A since 20 August 2025)
- Rights clocksSubject access requests within one month, extendable by two; complaints acknowledged within 30 days
- ScopeGroup or legal entity; profiles controller, processor, public authority, law enforcement, children's services
What UK GDPR requires
Who it applies to
- Companies and other organisations processing personal data in the UK, as controller, processor or both
- Public authorities, which must designate a DPO and cannot rely on legitimate interests for processing in performing their tasks
- Police forces, prosecutors and other competent authorities processing for law-enforcement purposes under DPA 2018 Part 3
- Online services likely to be accessed by children, which must meet the Children's code, and charities using the charity soft opt-in
UK data protection law rests on the UK GDPR, the retained version of the EU regulation as amended for the UK, and the Data Protection Act 2018, which adds the UK's conditions and exemptions, a separate regime for law-enforcement processing in Part 3, and the regulator's powers and penalties. The Privacy and Electronic Communications Regulations 2003 (PECR) govern electronic marketing, cookies and communications providers. Together they bind every controller and processor of personal data in the UK.
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its data-protection provisions are now in force. Most arrived on 5 February 2026: recognised legitimate interests, new purpose-compatibility rules, Articles 22A to 22D on automated decision-making, DSAR time limits with a 'stop the clock', cookie exemptions, the charity soft opt-in and PECR enforcement through the Data Protection Act. The duty to handle data-protection complaints, acknowledging each within 30 days, applied from 19 June 2026, and on 30 September 2026 the Information Commission, a body corporate with a board that is still branded ICO, replaced the Information Commissioner.
A personal data breach is notified to the Information Commission without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals; individuals are told without undue delay where the risk is high. Maximum fines are £17.5 million or 4% of worldwide turnover at the higher tier and £8.7 million or 2% at the standard tier, and since 5 February 2026 the serious PECR infringements carry the higher maximum too. The ICO received 17,431 personal data breach reports in 2025/26, 40% more than the year before.
How GRCLens supports UK GDPR
UK GDPR runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Group and entity assessment with roll-up
The group answers programme and policy items once, and each controller or processor is assessed on its own, with profiles for public authorities, DPA Part 3 law-enforcement processing and online services likely to be accessed by children. Entities roll up into a group view with a heat map across 15 risk areas.
Written for UK law, not copied from the EU
Recognised legitimate interests, the Article 8A compatibility rules, the DSAR clock and reasonable-and-proportionate searches, Articles 22A to 22D, the complaints duty, the DPA Schedule 1 conditions and appropriate policy document, the data protection fee, and UK transfers by adequacy regulations, the IDTA, the UK Addendum and the data protection test are each assessed as their own requirement.
Four stakeholder dashboards
The board sees conformity and critical gaps; the DPO the heat map, domain scores and gaps; operations the control validation and open remediation; third-party and procurement teams processors, data sharing and international transfers.
Continuous assurance from connectors
Incident records, backup and restore, vulnerability and patch, identity and MFA, the third-party register, resilience testing, training (LMS) and log monitoring are read against the questionnaire, alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. A failing check whose requirement was answered Implemented is flagged as a contradiction.
Assurance register, remediation and KRIs
Each requirement can carry several owners in the assurance register. Gaps become owned, dated actions in the remediation and risk treatment plan, and key risk indicators name the requirements they measure, so an indicator outside appetite beside an answer of Implemented is a finding.
Baseerah summary, Word and PDF reports
Baseerah, the platform's AI assistant running on a self-hosted language model, writes a one-paragraph executive summary for the board and the DPO. Entity and group reports export as Word and PDF.
UK GDPR frequently asked questions
What did the Data (Use and Access) Act 2025 change?
Most of its data-protection changes commenced on 5 February 2026: recognised legitimate interests, new purpose-compatibility rules, Articles 22A to 22D on automated decision-making, DSAR time limits with a 'stop the clock', cookie exemptions, the charity soft opt-in and PECR fines aligned with the UK GDPR. The duty to handle data-protection complaints followed on 19 June 2026, and the Information Commission replaced the Information Commissioner on 30 September 2026.
How quickly must a personal data breach be reported?
Without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals; a later notification must give reasons, and information may be provided in phases. Individuals are told without undue delay where the risk is high, and every breach is recorded whether or not it is reported. Since 20 August 2025 PECR breaches run on the same 72-hour clock, replacing 24 hours.
What are the maximum fines under UK data protection law?
£17.5 million or 4% of worldwide turnover at the higher tier and £8.7 million or 2% at the standard tier. Since 5 February 2026 PECR is enforced through the Data Protection Act, so the serious PECR infringements, including those on cookies and electronic marketing, carry the higher maximum. In October 2025 the ICO fined Capita £14 million for a 2023 breach affecting 6.6 million people.
How are international transfers made under UK GDPR?
A restricted transfer relies on UK adequacy regulations, on an appropriate safeguard such as the International Data Transfer Agreement (IDTA), the UK Addendum to the EU standard contractual clauses or binding corporate rules, or on an exception. Where it relies on a safeguard, the exporter must reasonably and proportionately conclude that protection after the transfer will not be materially lower than under UK law: the data protection test introduced by the 2025 Act.
Who regulates UK data protection now?
The Information Commission, a body corporate with a board, which took over the Information Commissioner's functions on 30 September 2026 under the Data (Use and Access) Act 2025. It is still branded ICO, and its guidance is still published on ico.org.uk.
One platform, many obligations
See all supported frameworks → Every framework that applies in United Kingdom →

Talk to us about UK GDPR
Security Solution Consultants provides UK GDPR and data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.