UK GDPR
UK GDPR & Data Protection Act 2018 Checklist
A UK-focused privacy checklist covering ICO expectations, UK GDPR, DPA 2018, and PECR cookies.
- Estimated time
- 2–4 Months
- Audience
- Organizations Offering Goods or Services in the UK
- Last updated
Operational reference for UK data-protection readiness. The ICO and UK courts determine compliance.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Applicability
Phase 2: Core Duties
Phase 3: Transfers & PECR
Phase 4: Incidents & Governance
FAQ
Is UK GDPR identical to EU GDPR?+–
They are closely aligned but not identical. Transfers, representatives, and ICO guidance differ.
Do EU SCCs work for UK transfers?+–
The UK has its own IDTA and an Addendum to the EU SCCs. Use the current UK mechanism.
Who is the regulator?+–
The Information Commissioner’s Office (ICO).
Does Adequacy help?+–
EU-UK adequacy eases some EU→UK flows; check the current adequacy status and any reviews.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer