Most UK GDPR checklists were written before the Data (Use and Access) Act 2025. The UK regime they describe no longer exists. The main changes commenced on 5 February 2026: recognised legitimate interests, a new timetable for rights requests, safeguards for automated decisions, new cookie exceptions and a new test for international transfers. A statutory complaints duty followed on 19 June 2026.
This assessment scores the UK GDPR, the Data Protection Act 2018 and PECR as they stand now, requirement by requirement, and asks what you could evidence today rather than what your policy says. It is free, it saves as you go, and you can stop and come back to it.
Premium report
See what the premium UK GDPR gap assessment report looks like
A worked sample for a fictional organization: readiness by area, every open gap in a remediation plan, an AI-assisted analysis with priorities and a 30/60/90-day roadmap, plus the live Excel workbook.
What is a UK GDPR gap assessment?
A UK GDPR gap assessment compares your current practice with what UK data protection law requires and records the distance, so you can turn a general sense of exposure into a list of actions with owners. It is the step that comes before a remediation plan, and the evidence you would want if the regulator ever asked how you know you comply.
The UK and EU regimes started out identical in 2021. They are not any more. An organisation running one EU GDPR programme for both will now be missing UK-only duties, such as the complaints procedure, and applying EU rules the UK has relaxed, such as the stricter cookie consent position.
What this assessment covers
54 assessable requirements across eleven areas.
| Area | Items | What it asks about |
|---|---|---|
| Scope and accountability | 5 | Territorial scope, UK representative, accountability, the data protection fee, the 2025 Act review |
| Lawful basis and principles | 10 | Principles, lawful basis per purpose, legitimate interests, recognised legitimate interests, purpose compatibility, special category data, the appropriate policy document, consent, children, retention |
| Transparency and notices | 4 | Article 13 and 14 notices, plain language, CCTV |
| Data subject rights | 6 | The Article 12A timetable, subject access and reasonable searches, rectification and erasure, portability and objection, Schedule 2 exemptions |
| Automated decisions and complaints | 3 | Articles 22A to 22C and the section 164A complaints duty |
| Records and DPIA | 4 | Records of processing, DPIAs, prior consultation, by design and default |
| Processors and data sharing | 4 | Article 28 contracts, due diligence, joint controllers, controller-to-controller sharing |
| Security and breaches | 5 | Article 32 measures, staff and devices, 72-hour notification, telling individuals, the breach register |
| International transfers | 3 | Transfer mapping, adequacy and the UK-US data bridge, the IDTA and Addendum with the new data protection test |
| Marketing, cookies and PECR | 4 | Email and text marketing, TPS screening, cookies and the new exceptions, PECR breach rules |
| Governance and assurance | 6 | DPO, training, employee monitoring, risk register, internal audit, dealing with the regulator |
What changed with the Data (Use and Access) Act 2025
| Change | In force | What to check |
|---|---|---|
| Recognised legitimate interests, Article 6(1)(ea) and Annex 1 | 5 February 2026 | Whether any disclosures for crime, safeguarding or emergencies can use the new basis |
| Time limits for rights requests, Article 12A | 5 February 2026 | That the clock starts at the “relevant time” and your log records any pause for clarification |
| Reasonable and proportionate searches, Article 15(1A) | Royal Assent, treated as applying from 1 January 2024 | That you keep a record of the searches made for each access request |
| Automated decisions, Articles 22A to 22D | 5 February 2026 | Which decisions are solely automated, and that the four safeguards are in place |
| Cookie exceptions, PECR Schedule A1 | 5 February 2026 | Which cookies now fall under the analytics or functionality exceptions, and that people can object |
| PECR fines raised to UK GDPR levels | 5 February 2026 | Marketing and cookie compliance, now carrying fines of up to £17.5 million or 4% of turnover |
| International transfers, the “not materially lower” test | 5 February 2026 | That transfer risk assessments use the new test |
| Complaints to controllers, DPA 2018 section 164A | Complaints received from 19 June 2026 | A complaints procedure, 30-day acknowledgement and a log |
| The ICO becomes the Information Commission | 30 September 2026 | References to the regulator in notices and procedures |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records the regulator could inspect |
| Not applicable | — | A justified exclusion, removed from the score |
The requirements that fail most often
- Article 30 records built for the 2018 deadline and never updated. Almost everything else depends on them.
- Rights request logs that record the date received but not the relevant time, the clarification pause or the searches made.
- Cookie banners that still load advertising tags before consent, now with PECR fines at UK GDPR levels.
- The complaints procedure, which most organisations did not have before June 2026.
- Article 33(5), the register of breaches you decided not to report. The regulator asks for that list first.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every requirement with your status and notes, the score broken down by area, a prioritised gap list, an AI-assisted analysis with a 30/60/90-day roadmap, and the UK GDPR Toolkit documents that close each gap, as a PDF and a working Excel file.
How long does it take?
About 40 minutes if you know your processing. Answers save as you go, so you can run it over several sittings and involve HR, marketing and IT.
Frequently asked questions
Is this assessment really free?
Yes. Every requirement, your area breakdown and your overall score cost nothing. The $39 full report is optional.
We already comply with the EU GDPR. Do we need this?
If UK law applies to you, yes. The core is still similar, but the 2025 Act changed rights timings, automated decisions, cookies, transfers and complaints in ways the EU has not. Use the EU GDPR gap assessment for the EU side.
Does it cover PECR?
Yes: email and text marketing, marketing calls, cookies and the service provider breach rules.
Does it cover the 2025 Act changes still to come?
It scores the law in force on 30 September 2026. Some provisions of the Act that are outside data protection, such as digital verification services and smart data, are not covered.
Is a high score the same as being compliant?
No. It is a structured self-assessment, not legal advice or a certification. It tells you where the documented gaps are.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.
