UK GDPR Compliance Checklist 2026

17 August 2026

Practical UK GDPR compliance checklist for 2026. Covers lawful basis, data subject rights, breach reporting, DPIAs, and more.

Assess Your Scope and Accountability

The UK GDPR applies to most organisations processing personal data in the UK, as well as non-UK businesses that target UK residents. The first step in your checklist is to confirm whether your organisation falls within scope. If you process personal data, you must record your processing activities, designate a data protection lead, and ensure you have a lawful basis for each purpose. The ICO expects you to adopt a 'privacy by design' approach. This means considering data protection from the outset, not as an afterthought. Document decisions, assign responsibilities, and make sure senior management is on board. A clear governance structure is the foundation of UK GDPR compliance.

Document Your Lawful Basis and Be Transparent

Every instance of processing needs a documented lawful basis – consent, contract, legal obligation, vital interests, public task, or legitimate interests. Your privacy notice must clearly explain which bases you rely on, what you collect, why, and how long you keep it. In the UK, consent must be unambiguous, freely given, and easy to withdraw. The ICO is especially strict about pre-ticked boxes and bundled consent. Review your forms, cookies, and marketing preferences. If you rely on legitimate interests, carry out a balancing test. Remember that the UK GDPR and Data Protection Act 2018 together set out additional conditions for special category data and criminal offence data.

Ensure Data Subject Rights Are Honoured

Individuals have the right to access, rectify, erase, restrict, port, and object to processing. Under the UK GDPR, subject access requests (SARs) must be handled within one month, and you can no longer charge a fee unless the request is manifestly unfounded or excessive. Your checklist should include a process for verifying identity, searching all systems, and providing data in a structured, machine-readable format when asked. Also remember the right to not be subject to automated decision-making with legal effects. Make sure your staff know how to spot and escalate SARs. The ICO can issue fines and enforcement notices for failing to respond properly, so have templates and a tracking system in place.

Strengthen Security and Breach Response

Security under the UK GDPR is about protecting personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. The ICO recommends encryption, pseudonymisation, access controls, and routine testing. Your checklist should include staff training, incident response plans, and a breach register. If a breach is likely to result in a risk to individuals, you must report it to the ICO within 72 hours. If the risk is high, you also need to inform affected individuals without undue delay. In the UK, you can call the ICO's breach hotline or report online. Make sure your plan covers how to assess severity and document decisions.

Complete DPIAs and Review International Transfers

Some processing requires a Data Protection Impact Assessment (DPIA) before you start – for example, using new technologies, profiling on a large scale, or processing biometric data. The ICO provides a template, but your checklist should make sure you complete one when needed and consult the ICO if the DPIA identifies high residual risks. You also need to check international transfers. The UK has its own adequacy decisions in place, so identify whether you send personal data to organisations in the EU, US, or elsewhere. Use the UK's International Data Transfer Agreement (IDTA) or a recognised safeguard. The ICO expects you to map data flows and review transfer mechanisms regularly.

FAQ

The UK GDPR is the UK version of the EU GDPR, retained and adapted by the Data Protection Act 2018. It applies to processing in the UK and to UK residents, while the EU GDPR applies to the EU. Both have similar principles and rights, but there are separate adequacy decisions and transfer rules.

Latest guides