Most UK GDPR checklists were written before the Data (Use and Access) Act 2025. The UK regime they describe no longer exists. The main changes commenced on 5 February 2026: recognised legitimate interests, a new timetable for rights requests, safeguards for automated decisions, new cookie exceptions and a new test for international transfers. A statutory complaints duty followed on 19 June 2026.

This assessment scores the UK GDPR, the Data Protection Act 2018 and PECR as they stand now, requirement by requirement, and asks what you could evidence today rather than what your policy says. It is free, it saves as you go, and you can stop and come back to it.

Premium report

See what the premium UK GDPR gap assessment report looks like

A worked sample for a fictional organization: readiness by area, every open gap in a remediation plan, an AI-assisted analysis with priorities and a 30/60/90-day roadmap, plus the live Excel workbook.

What is a UK GDPR gap assessment?

A UK GDPR gap assessment compares your current practice with what UK data protection law requires and records the distance, so you can turn a general sense of exposure into a list of actions with owners. It is the step that comes before a remediation plan, and the evidence you would want if the regulator ever asked how you know you comply.

The UK and EU regimes started out identical in 2021. They are not any more. An organisation running one EU GDPR programme for both will now be missing UK-only duties, such as the complaints procedure, and applying EU rules the UK has relaxed, such as the stricter cookie consent position.

What this assessment covers

54 assessable requirements across eleven areas.

AreaItemsWhat it asks about
Scope and accountability5Territorial scope, UK representative, accountability, the data protection fee, the 2025 Act review
Lawful basis and principles10Principles, lawful basis per purpose, legitimate interests, recognised legitimate interests, purpose compatibility, special category data, the appropriate policy document, consent, children, retention
Transparency and notices4Article 13 and 14 notices, plain language, CCTV
Data subject rights6The Article 12A timetable, subject access and reasonable searches, rectification and erasure, portability and objection, Schedule 2 exemptions
Automated decisions and complaints3Articles 22A to 22C and the section 164A complaints duty
Records and DPIA4Records of processing, DPIAs, prior consultation, by design and default
Processors and data sharing4Article 28 contracts, due diligence, joint controllers, controller-to-controller sharing
Security and breaches5Article 32 measures, staff and devices, 72-hour notification, telling individuals, the breach register
International transfers3Transfer mapping, adequacy and the UK-US data bridge, the IDTA and Addendum with the new data protection test
Marketing, cookies and PECR4Email and text marketing, TPS screening, cookies and the new exceptions, PECR breach rules
Governance and assurance6DPO, training, employee monitoring, risk register, internal audit, dealing with the regulator

What changed with the Data (Use and Access) Act 2025

ChangeIn forceWhat to check
Recognised legitimate interests, Article 6(1)(ea) and Annex 15 February 2026Whether any disclosures for crime, safeguarding or emergencies can use the new basis
Time limits for rights requests, Article 12A5 February 2026That the clock starts at the “relevant time” and your log records any pause for clarification
Reasonable and proportionate searches, Article 15(1A)Royal Assent, treated as applying from 1 January 2024That you keep a record of the searches made for each access request
Automated decisions, Articles 22A to 22D5 February 2026Which decisions are solely automated, and that the four safeguards are in place
Cookie exceptions, PECR Schedule A15 February 2026Which cookies now fall under the analytics or functionality exceptions, and that people can object
PECR fines raised to UK GDPR levels5 February 2026Marketing and cookie compliance, now carrying fines of up to £17.5 million or 4% of turnover
International transfers, the “not materially lower” test5 February 2026That transfer risk assessments use the new test
Complaints to controllers, DPA 2018 section 164AComplaints received from 19 June 2026A complaints procedure, 30-day acknowledgement and a log
The ICO becomes the Information Commission30 September 2026References to the regulator in notices and procedures

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records the regulator could inspect
Not applicable—A justified exclusion, removed from the score

The requirements that fail most often

  • Article 30 records built for the 2018 deadline and never updated. Almost everything else depends on them.
  • Rights request logs that record the date received but not the relevant time, the clarification pause or the searches made.
  • Cookie banners that still load advertising tags before consent, now with PECR fines at UK GDPR levels.
  • The complaints procedure, which most organisations did not have before June 2026.
  • Article 33(5), the register of breaches you decided not to report. The regulator asks for that list first.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every requirement with your status and notes, the score broken down by area, a prioritised gap list, an AI-assisted analysis with a 30/60/90-day roadmap, and the UK GDPR Toolkit documents that close each gap, as a PDF and a working Excel file.

How long does it take?

About 40 minutes if you know your processing. Answers save as you go, so you can run it over several sittings and involve HR, marketing and IT.

Frequently asked questions

Is this assessment really free?

Yes. Every requirement, your area breakdown and your overall score cost nothing. The $39 full report is optional.

We already comply with the EU GDPR. Do we need this?

If UK law applies to you, yes. The core is still similar, but the 2025 Act changed rights timings, automated decisions, cookies, transfers and complaints in ways the EU has not. Use the EU GDPR gap assessment for the EU side.

Does it cover PECR?

Yes: email and text marketing, marketing calls, cookies and the service provider breach rules.

Does it cover the 2025 Act changes still to come?

It scores the law in force on 30 September 2026. Some provisions of the Act that are outside data protection, such as digital verification services and smart data, are not covered.

Is a high score the same as being compliant?

No. It is a structured self-assessment, not legal advice or a certification. It tells you where the documented gaps are.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.