A UK GDPR compliance checklist written before February 2026 is now out of date in at least six places. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and its main data protection changes commenced on 5 February 2026: a new lawful basis, a new timetable for subject rights, new rules for automated decisions, new cookie exceptions and a new test for international transfers. A statutory complaints duty followed for complaints received from 19 June 2026, and on 30 September 2026 the Information Commissioner’s Office became the Information Commission.
This UK GDPR compliance checklist covers what a regulator would expect to see today, area by area, with the evidence that proves each item. It is written for the person who has to answer for the programme, not for a lawyer. Where the 2025 Act changed something, the item says so.
How to use this UK GDPR compliance checklist
Treat every line as a question with three possible answers: not in place, in place but not evidenced, and in place with records. The middle answer is the dangerous one. Accountability under Article 5(2) means being able to demonstrate compliance, and a practice nobody wrote down is, in an investigation, the same as no practice at all.
If you want the same checklist scored automatically, the free UK GDPR gap assessment scores 54 requirements across these areas and gives you a readiness score by area. For the background to the law itself, start with our complete guide to UK GDPR after the Data (Use and Access) Act.
1. Scope, accountability and the regulator
- Applicability. A documented decision on whether the UK GDPR applies, through a UK establishment or by targeting or monitoring people in the UK.
- UK representative. If you have no UK establishment, a written Article 27 appointment, named in your privacy notices.
- Data protection fee. Paid at the right tier: £52 for turnover up to £632,000 or up to 10 staff, £78 for up to £36 million or 250 staff, and £3,763 for everyone else.
- Accountability framework. Named owners, a compliance calendar and a record of decisions.
- 2025 Act review. A dated record of what you changed in policies, notices and procedures because of the Data (Use and Access) Act.
2. Lawful basis and principles
- A lawful basis recorded for every purpose before processing starts, with the reasoning.
- Completed legitimate interests assessments wherever you rely on Article 6(1)(f).
- New: where you rely on a recognised legitimate interest under Article 6(1)(ea) and Annex 1, such as disclosures for crime prevention, safeguarding, emergencies or national security, a record that the condition is met. No balancing test is needed for these.
- New: a purpose compatibility check under Article 8A whenever personal data is reused for a new purpose.
- An Article 9 condition, and a Schedule 1 condition where the DPA 2018 requires one, for every use of special category data, with an appropriate policy document where required.
- Consent that is specific, recorded and as easy to withdraw as to give.
- A retention schedule with periods and their source, and evidence of deletion.
3. Transparency and notices
- Privacy notices for each audience: customers, staff, job applicants, website visitors, CCTV and business contacts.
- Notices for data obtained from third parties, given within one month at the latest.
- Notices written in plain language and layered, so the key points are seen first.
- References to the regulator updated for the Information Commission.
4. Data subject rights under the 2026 timetable
This is the area where a pre-2026 UK GDPR compliance checklist is most likely to be wrong. Article 12A now sets the time limit as one month from the “relevant time”, which is the latest of receiving the request, confirming the requester’s identity, or receiving any fee. You can extend by two further months for complex or numerous requests, telling the person within the first month. You can also pause the clock while you wait for clarification you reasonably need because you hold a large amount of information about them.
- A request log that records the relevant time, any pause for clarification and the response date.
- New: a record of the searches made for each subject access request. Article 15(1A) now requires reasonable and proportionate searches, treated as applying from 1 January 2024. Our guide to the UK subject access request time limit walks through the clock in detail.
- Procedures for rectification, erasure, restriction, portability and objection, reaching every system in your records of processing.
- A record of each Schedule 2 exemption relied on, and why.
5. Automated decisions and complaints
- New: an inventory of significant decisions made solely by automated means, meaning with no meaningful human involvement. Articles 22A to 22D replaced the general prohibition on 5 February 2026.
- New: for those decisions, the four safeguards: information about the decision, a way to make representations, human intervention and a way to contest it. Decisions using special category data, or based on recognised legitimate interests, remain restricted. See our guide to UK GDPR automated decision-making.
- New: a complaints procedure under section 164A of the DPA 2018: a way to complain, acknowledgement within 30 days and a response without undue delay, for complaints received from 19 June 2026.
- A complaints log you could hand to the regulator.
6. Records, DPIAs and processors
| Requirement | Evidence a regulator would ask for |
|---|---|
| Article 30 records of processing | A current register with purposes, data, recipients, transfers, retention and security |
| Article 35 DPIAs | Screening records for new processing and completed DPIAs for high-risk processing |
| Article 36 prior consultation | A recorded decision where a high risk could not be reduced |
| Article 25 by design and default | Design reviews for recent projects |
| Article 28 processor contracts | A contract register with the required terms confirmed |
| Controller-to-controller sharing | Data sharing agreements and a sharing log |
7. Security and personal data breaches
- Article 32 measures matched to risk: access control, encryption, backups, logging and regular testing.
- Staff rules for acceptable use, remote working and devices, with training records.
- A breach procedure that can notify the regulator within 72 hours of becoming aware, weekends included.
- A letter template for telling people when a breach is likely to result in a high risk to them.
- A register of every breach, including the ones you decided not to report.
8. International transfers
- A register of every restricted transfer, including remote access from overseas.
- Adequacy checks per destination. Transfers to the EEA remain straightforward, and the EU renewed its adequacy decisions for the UK in December 2025. US recipients are covered by the UK-US data bridge only if they are certified under the UK extension.
- New: for other transfers, the IDTA or the UK Addendum, plus a reasonable and proportionate assessment that protection in the destination is “not materially lower” than in the UK.
9. Marketing, cookies and PECR
PECR fines were raised to UK GDPR levels on 5 February 2026, so marketing and cookie failures can now cost up to £17.5 million or 4% of worldwide turnover.
- Consent or the soft opt-in before marketing emails and texts, with an opt-out in every message.
- Call lists screened against the TPS, the CTPS and your own suppression list.
- New: a cookie audit that classifies every technology. Analytics and site appearance or functionality cookies can now be set without consent if you give clear information and a simple, free way to object. Advertising cookies still need consent.
10. Governance and assurance
- A recorded decision on whether you need a data protection officer.
- Training at induction and at regular intervals.
- An assessment and staff notice for any employee monitoring.
- A data protection risk register reviewed by management.
- An annual internal audit with findings tracked to closure.
- A procedure for responding to the regulator’s information notices, which the 2025 Act strengthened.
UK GDPR compliance checklist: what changed in 2026 at a glance
| Change | In force from |
|---|---|
| Recognised legitimate interests (Article 6(1)(ea)) | 5 February 2026 |
| Time limits for rights requests (Article 12A) | 5 February 2026 |
| Automated decisions (Articles 22A to 22D) | 5 February 2026 |
| Cookie exceptions and higher PECR fines | 5 February 2026 |
| “Not materially lower” transfer test | 5 February 2026 |
| Complaints duty (DPA 2018 section 164A) | Complaints received from 19 June 2026 |
| ICO becomes the Information Commission | 30 September 2026 |
The full dated list is in our article on the Data (Use and Access) Act 2025, and the regulator’s own summary is on the ICO’s Data (Use and Access) Act page.
How often to revisit the checklist
Run the full UK GDPR compliance checklist at least once a year, and whenever something material changes: a new system, a new supplier that handles personal data, a new country you transfer data to, or a new use of data you already hold. The 2025 Act also has provisions outside data protection still to commence, so keep a change register and check it each quarter. A checklist that was complete in 2025 and never reopened is the most common reason an otherwise careful organisation ends up behind.
Score yourself against the checklist
Working through a UK GDPR compliance checklist on paper tells you what is missing but not how far you have to go. The free UK GDPR gap assessment scores each of the 54 requirements on a five-step scale, from not started to implemented and evidenced, and shows your readiness by area. The optional full report adds a prioritised gap list and a 30/60/90-day plan.
If the gaps are mostly documents, the UK GDPR Toolkit has 90 editable templates mapped to the same areas, including the 2025 Act change register, the complaints procedure and the transfer risk assessment.
Free privacy risk assessment
Which privacy risks would hurt the people whose data you hold?
List your personal data and processing, pick from 38 privacy risk scenarios, rate them for the people concerned and for you, and plan treatment with ISO 27701 controls. You get a heat map, a process score and the findings an auditor would raise, free.
Run the free privacy risk assessment → or View premium report sample
Frequently asked questions
Is the UK GDPR still the same as the EU GDPR?
No. They started identical in 2021, but the Data (Use and Access) Act 2025 changed rights timings, automated decisions, cookies, transfers and complaints in the UK only. If you are subject to both, run a separate UK GDPR compliance checklist rather than relying on your EU programme.
How long do we have to answer a subject access request?
One month from the relevant time, which is the latest of receiving the request, confirming identity or receiving any fee. You can extend by two months for complex or numerous requests, and pause the clock while you wait for clarification you reasonably need.
Do we still need consent for analytics cookies?
Not always. Since 5 February 2026, statistical cookies and cookies for site appearance or functionality are exempt from consent if you tell people clearly and give them a simple, free way to object. Advertising and tracking cookies still need consent.
Who should own the UK GDPR compliance checklist?
Whoever is accountable for data protection: the DPO if you have one, otherwise a named privacy or compliance lead. Each area needs its own owner too, because HR, marketing and IT hold most of the evidence.
Do we need a complaints procedure?
Yes, for complaints received from 19 June 2026. You must make it easy to complain, acknowledge each complaint within 30 days and respond without undue delay.