Description
The UK GDPR Toolkit is written for UK law as it stands in 2026
The United Kingdom’s data protection regime is no longer the EU GDPR with the flags changed. The Data (Use and Access) Act 2025 rewrote the lawful bases, the purpose limitation rules, the time limits for rights requests, automated decision-making, international transfers, the cookie rules and the way complaints are handled, and it did so in stages: 19 June 2025, 20 August 2025, 5 February 2026 and 19 June 2026. A pack that still names an EU regulator instead of the Commissioner, cites the complaint article the UK has omitted, relies on the EU standard contractual clauses without the UK Addendum, or sets the age of digital consent at sixteen is describing a different jurisdiction.
The UK GDPR Toolkit is 90 editable templates, 70 Word documents and 20 Excel workbooks, across 13 sections, written against the UK GDPR as amended, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations, every one of them read on legislation.gov.uk. Every document in the UK GDPR Toolkit names the Information Commissioner as the regulator, states the complaint routes that now apply, and cites the provision it answers.
What the UK GDPR Toolkit maps to
The UK GDPR Toolkit claims 97 provisions across 4 instruments, and the legal crosswalk workbook lists every one against the document that answers it:
- the UK GDPR: 57 articles and annexes, from the principles and lawful bases through the rights, accountability, security, breach, DPIA, DPO and transfer provisions, including the articles the 2025 Act inserted: 6(1)(ea) and Annex 1, 8A and Annex 2, 12A, 15(1A), 22A to 22C, 25(1A), 44A, 45A, 45B, 46(1A), 47A and 49A;
- the Data Protection Act 2018: 14 provisions, including section 10 and Schedule 1 for special category and criminal offence data, the appropriate policy document at paragraphs 39 to 41, the Schedule 2 exemptions, the new sections 164A and 164B on complaints, the Part 6 enforcement regime and the section 157 penalty maxima;
- the Data (Use and Access) Act 2025: 15 of its sections, each dated to its commencement;
- PECR: 11 provisions, including the new regulation 6 and Schedule A1 cookie exceptions, the marketing rules in regulations 19 to 23, and the service-provider breach rules.
Every Word document in the UK GDPR Toolkit carries a Requirements-addressed table naming the provisions it answers, and a Legal basis panel that says, in plain words, what the law requires and since when.
The 2025 Act changes, built in rather than bolted on
The UK GDPR Toolkit does not carry a supplement explaining what changed. The changes are where they belong:
- the DSAR procedure runs on the applicable time period in Article 12A, with the relevant time, the two-month extension and the clarification clock stop, and records the reasonable and proportionate search that Article 15(1A) has required since June 2025;
- the complaints procedure, log, form and letters operate the statutory duty in section 164A: facilitate complaints, acknowledge within 30 days, respond without undue delay;
- the lawful basis documents cover recognised legitimate interests under Article 6(1)(ea) and Annex 1, the Article 6(11) examples, and the Article 8A compatibility test;
- the automated decision-making procedure applies Articles 22A to 22C: meaningful human involvement, the special category restriction, and the four safeguards;
- the transfers section applies the “not materially lower” data protection test, the transferor’s reasonable and proportionate assessment under Article 46(1A), and carries completion guides for the IDTA and the UK Addendum;
- the cookie procedure classifies every technology under the Schedule A1 exceptions, including the statistical exception with its objection route;
- the PECR procedure briefs the Board on the section 157 penalty maxima and officer liability that have applied to marketing since February 2026.
The UK GDPR Toolkit’s change register workbook lists all 15 changes with their commencement dates, who they affect and what to do, so the annual review has something to check against.
Privacy notices, agreements and letters ready to tailor
The UK GDPR Toolkit carries 9 privacy notice documents: a master notice, customer, employee, candidate, website, CCTV, supplier contact and children’s notices, and a layered notice guide, each with the complaint route and the UK-specific content. The contracts section carries an Article 28 data processing agreement written for UK law with a clause-by-clause guide, a controller-to-controller data sharing agreement, a joint controller arrangement and a sharing checklist. The rights section carries the DSAR letters, the complaint form and letters, and a Schedule 2 exemptions guide. The UK GDPR Toolkit’s breach section carries the ICO notification form and the data subject letter.
Registers in the UK GDPR Toolkit that ship populated
10 of the 20 workbooks arrive filled in rather than empty. The legal crosswalk carries every provision and every document. The gap assessment tool lists all 97 provisions with the document that closes each. The internal audit checklist carries 97 checks, one per provision. The change register carries the 15 changes. The adequacy reference carries 16 adequacy entries (the EU and EEA states counted as one), each with its scope limits, alongside every transfer mechanism and derogation. The records retention schedule carries 21 record types with the instrument each period comes from. The severity matrix carries the scales and the notification grid. The risk register carries fifteen starter risks. The document index carries all 90 documents.
Security policies that make Article 32 concrete
8 security policies sit in the UK GDPR Toolkit because a data protection programme without them has no answer to the question the Commissioner asks after every breach: information security, access control, encryption, mobile and remote working, acceptable use, clear desk, backup and restoration, and logging and monitoring, each stated as an Article 32 measure.
Written against the primary texts, and dated
Every provision the UK GDPR Toolkit cites was read on legislation.gov.uk on 13 September 2026, including the commencement regulations that set the dates. The ICO fee tiers are the amounts in force since 17 February 2025. The IDTA and Addendum are the instruments in force since 21 March 2022. Where the Act gives a new power that has not yet been used, the pack says so rather than inventing an instrument.
Where the UK GDPR Toolkit sits beside the rest of the catalogue
The GDPR Toolkit remains the EU regulation pack, for organisations answering to an EU data protection authority. The UK GDPR Toolkit is the UK regime pack, for organisations answering to the Information Commissioner. An organisation subject to both needs both; the two are written on the same house structure so they can be run side by side. The ISO 27701 Toolkit carries the privacy information management system that can sit over either.
Honest about the boundaries
- The UK GDPR Toolkit is a set of templates, not legal advice. Agreements and notices need review for the organisation’s facts.
- The UK GDPR Toolkit does not include the ICO’s own forms; it tells you which to use and what to put in them.
- The IDTA and the Addendum are the Commissioner’s documents; the pack carries completion guides, not copies.
- Commencement dates in the UK GDPR Toolkit are stated as at the date of writing; the Act has provisions still to commence, and the change register is built to take them.
- Retention periods drawn from other legislation are stated with their source and must be confirmed against the current text before adoption.
What you get in the UK GDPR Toolkit
| Section | Documents | What it holds |
|---|---|---|
| 00 Programme Guide | 4 | Implementation guide, legal crosswalk, gap assessment tool, 2025 Act change register |
| 01 Governance and Accountability | 8 | Data protection policy, roles, DPO, accountability framework, ICO fee, by design and default, training, ICO engagement |
| 02 Lawful Basis and Principles | 9 | Lawful basis procedure and register, LIA, recognised legitimate interests, compatibility, special category and APD, consent, research, children |
| 03 Privacy Notices | 9 | Master, customer, employee, candidate, website, CCTV, supplier contact and children’s notices; layered notice guide |
| 04 Data Subject Rights | 12 | DSAR procedure, log, identity and clarification, letters, rectification and erasure, portability and objection, automated decisions, complaints, exemptions, register |
| 05 Records and DPIA | 7 | ROPA procedure and register, DPIA procedure, screening, template, register, prior consultation |
| 06 Processors and Sharing | 7 | Due diligence, Article 28 DPA, data sharing agreement, joint controller arrangement, sub-processor register, clause guide, sharing checklist |
| 07 International Transfers | 6 | Transfers procedure, TRA template, IDTA and Addendum guides, transfer register, adequacy and mechanisms reference |
| 08 Breach Management | 6 | Response procedure, assessment and ICO notification form, data subject letter, register, severity matrix, PECR note |
| 09 Security | 8 | Information security, access control, encryption, mobile and remote, acceptable use, clear desk, backup, logging |
| 10 Marketing and PECR | 5 | Direct marketing policy, PECR procedure, cookie policy and consent, preference register, TPS and CTPS screening |
| 11 Employment | 3 | Employee monitoring, HR retention schedule, references and disclosures |
| 12 Registers and Implementation | 6 | Retention schedule, risk register, document index, 90-day plan, internal audit checklist, annual review |
00 Programme Guide
- UK GDPR Toolkit Implementation Guide
- Legal Crosswalk Workbook (Excel)
- UK GDPR Gap Assessment Tool (Excel)
- DUAA 2025 Change Register (Excel)
01 Governance and Accountability
- UK Data Protection Policy
- Data Protection Roles and RACI Matrix
- DPO Appointment Letter and Role Description
- Accountability Framework and Compliance Calendar
- ICO Fee Registration Procedure
- Data Protection by Design and Default Procedure
- Data Protection Training and Awareness Plan
- ICO Engagement and Regulatory Notices Procedure
02 Lawful Basis and Principles
- Lawful Basis Assessment Procedure
- Lawful Basis Register (Excel)
- Legitimate Interests Assessment Template
- Recognised Legitimate Interests Procedure
- Purpose Compatibility Assessment Template
- Special Category and Criminal Offence Data Policy
- Appropriate Policy Document
- Consent Management Procedure and Consent Form
- Children’s Data Procedure
03 Privacy Notices
- Privacy Notice Procedure
- Website Privacy Notice
- Customer Privacy Notice
- Employee Privacy Notice
- Job Applicant Privacy Notice
- CCTV Policy and Privacy Notice
- Supplier and Business Contact Privacy Notice
- Privacy Notice Planning Form
- Layered and Just-in-Time Notice Guidance
04 Data Subject Rights
- Data Subject Access Request Procedure
- DSAR Log (Excel)
- Identity Verification and Clarification Procedure
- DSAR Response Letter Templates
- Rectification, Erasure and Restriction Procedure
- Data Portability and Objection Procedure
- Automated Decision-Making Procedure
- Data Protection Complaints Procedure
- Complaints Log (Excel)
- Complaint Form and Acknowledgement Templates
- Schedule 2 Exemptions Guide
- Rights Request Register (Excel)
05 Records and DPIA
- Records of Processing Procedure
- Records of Processing Register (Excel)
- DPIA Procedure
- DPIA Screening Questionnaire
- DPIA Template
- DPIA Register (Excel)
- Prior Consultation Procedure
06 Processors and Sharing
- Processor Due Diligence Checklist
- Data Processing Agreement (UK GDPR Article 28)
- Data Sharing Agreement Controller to Controller
- Joint Controller Arrangement
- Sub-Processor Register (Excel)
- Processor Clause Guide
- Data Sharing Checklist
07 International Transfers
- International Transfers Procedure
- Transfer Risk Assessment Template
- IDTA Completion Guide
- UK Addendum Completion Guide
- Transfer Register (Excel)
- Adequacy and Transfer Mechanisms Reference (Excel)
08 Breach Management
- Personal Data Breach Response Procedure
- Breach Assessment and ICO Notification Form
- Breach Notification Letter to Data Subjects
- Personal Data Breach Register (Excel)
- Breach Severity Assessment Matrix (Excel)
- PECR Breach Notification Note for Service Providers
09 Security
- Information Security Policy
- Access Control Policy
- Encryption and Cryptography Policy
- Mobile Device and Remote Working Policy
- Acceptable Use Policy
- Clear Desk and Clear Screen Policy
- Backup and Restoration Policy
- Logging and Monitoring Policy
10 Marketing and PECR
- Direct Marketing Policy
- PECR Compliance Procedure
- Cookie Policy and Consent Procedure
- Marketing Preference Register (Excel)
- TPS and CTPS Screening Procedure
11 Employment
- Employee Monitoring Policy
- HR Data Retention Schedule (Excel)
- References and Disclosure Procedure
12 Registers and Implementation
- Records Retention Schedule (Excel)
- Data Protection Risk Register (Excel)
- Document Index (Excel)
- 90-Day Implementation Plan
- Internal Audit Checklist (Excel)
- Annual Compliance Review Record
HACCP Toolkit - Comprehensive 30+ Templates 




































Reviews
There are no reviews yet