Streaks of light forming data trails, representing UK GDPR compliance and regulatory obligations

UK GDPR Compliance

Download the Bratby Law DPIA template: a general-form Article 35 framework with a 5×5 risk register and the Article 36 prior consultation gateway.

DPIA advice for UK organisations processing personal data

A controller or processor operating in the United Kingdom must comply with the UK GDPR, the General Data Protection Regulation as retained in domestic law following the United Kingdom’s exit from the European Union, and the Data Protection Act 2018. The Data (Use and Access) Act 2025 (DUAA), which received Royal Assent on 19 June 2025 and came into force in stages from that date, amended both. The principal data protection amendments took effect on 5 February 2026 and the last of them on 19 June 2026, and they now apply to processing already under way. The UK regime diverges materially from the EU GDPR, and the divergence is continuing.

A controller must identify a lawful basis for each processing activity, tell data subjects what it does with their personal data, set and keep retention periods, put a mechanism in place for each international transfer, apply technical and organisational security measures, notify the ICO and affected data subjects of a notifiable breach, answer access and other rights requests, carry out a data protection impact assessment before high-risk processing begins, and keep the accountability records required by Article 5(2) and Article 30. The lawful bases now include the recognised legitimate interests introduced by the DUAA. A telecoms operator, a payments firm or a PE-backed fintech must also meet the sector-specific requirements dealt with below.

What this practice area covers

The Data Protection practice area covers UK GDPR and DPA 2018 obligations. The pages below deal with particular topics:

  • AI and Automated Decision-Making: the Articles 22A to 22D UK GDPR framework introduced by DUAA 2025, replacing the original Article 22, which gave a data subject a qualified right not to be subject to a decision based solely on automated processing where it produced legal effects or similarly significantly affected them.
  • Data Governance, Transfers and Accountability: Article 5 accountability, Article 30 records of processing, and international data transfer mechanisms including transfer risk assessments.
  • Sector-Specific Data Protection: how UK GDPR obligations interact with sectoral regulation in telecoms (PECR, CA 2003), payments (PSRs 2017, FCA rules), and financial services.
  • Data Breach Response: Article 33 and Article 34 notification obligations, the ICO breach portal, and breach management.
  • PECR and e-Privacy: the Privacy and Electronic Communications Regulations 2003 as amended, including the revised penalty regime.
  • DPIAs: the Article 35 assessment process, prior consultation with the ICO under Article 36, and when a DPIA is required in practice.
  • UK/EU Divergence: the growing gap between the UK and EU regimes and the implications for businesses operating across both.

What the DUAA 2025 changed

The DUAA amended the UK GDPR and DPA 2018 in several areas that are already in force. A controller relying on a recognised legitimate interest satisfies the Article 6(1)(ea) UK GDPR basis without carrying out a balancing test; DUAA Schedule 4 inserted the list of those interests into the UK GDPR as a new Annex 1 (pursuant to section 70(6) of the Act). A controller taking automated decisions must comply with Articles 22A to 22D, which replaced Article 22 and give data subjects specific transparency and human intervention rights; the UK position differs structurally from the EU one. The DUAA also amended the international transfer provisions and the research, archiving and statistics provisions, including the Article 14(5) disproportionate effort exemption on transparency for indirectly collected personal data.

The DUAA also introduced a mandatory controller complaints procedure. Section 164A, inserted into the DPA 2018 by the DUAA, requires a controller to facilitate the making of complaints, to acknowledge receipt of a complaint within 30 days, and then without undue delay to take appropriate steps to respond and to tell the complainant the outcome. Only the acknowledgement carries a fixed period. Those provisions came into force on 19 June 2026, under regulation 3 of the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), the same instrument that commenced the principal amendments on 5 February 2026. A controller in the telecoms or payments sector, like any other, must now have a documented complaint-handling procedure. The ICO has published guidance for organisations on handling data protection complaints, and says that in most cases it will ask a complainant to raise the complaint with the controller first. In my view a controller without a working procedure is therefore exposed at the point the ICO looks at the file.

How Bratby Law helps

For discrete compliance questions, a lawful basis review, an Article 35 DPIA, a response to an ICO information notice, or advice on a specific international transfer mechanism, we provide direct legal advice against a defined scope and timetable. The Lexology Index recognises Rob Bratby as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection.

For organisations whose technology, media and telecommunications advisors are generalists with no dedicated data protection specialist, we act as specialist co-counsel. We take the data protection workstream, work within the client’s existing outside counsel relationship, and produce analysis the lead firm can rely on without building its own UK privacy capability.

For businesses that require ongoing data protection leadership, a fractional DPO function, an in-house programme to meet the complaints obligations that took effect on 19 June 2026, or continuous advisory support as the post-DUAA ICO guidance develops, we operate as Fractional General Counsel. That structure gives a regulated business experienced general counsel judgement on data protection without a full-time appointment.

Primary sources

To discuss a specific data protection matter, contact us to arrange an introductory call.

Related data protection pages

See also our other data protection pages:

Lawful Basis and Legitimate Interests
Data Protection Impact Assessments
Data Governance, Transfers and Accountability
UK/EU Data Protection Divergence
AI and Automated Decision-Making
The EU AI Act: what UK businesses need to know
Sector-Specific Data Protection
Data Breach Response and ICO Notification
PECR and ePrivacy