What is UK GDPR?
The UK General Data Protection Regulation (UK GDPR) is the UK's version of the EU GDPR, retained in UK law after Brexit. It sets out the core data protection principles, lawful bases for processing, individual rights, and accountability obligations for organisations handling personal data of UK residents.
How is UK GDPR different from EU GDPR?
UK GDPR is substantively very similar to EU GDPR. The key differences are jurisdictional: UK GDPR is enforced by the ICO (not EU data protection authorities), the UK has its own adequacy decisions for international transfers, and the UK government can make independent amendments to the framework. The core principles, rights, and obligations remain aligned.
Who does UK GDPR apply to?
UK GDPR applies to organisations established in the UK that process personal data, and to organisations outside the UK that offer goods or services to individuals in the UK or monitor the behaviour of individuals in the UK. This extraterritorial scope means global companies may need to comply.
What are the lawful bases for processing under UK GDPR?
There are six lawful bases: consent, contract (processing necessary for a contract with the individual), legal obligation, vital interests (protecting someone's life), public task (processing necessary for official functions), and legitimate interests (processing necessary for the organisation's legitimate interests, balanced against the individual's rights).
What individual rights does UK GDPR provide?
UK GDPR provides eight rights: the right to be informed, right of access, right to rectification, right to erasure (right to be forgotten), right to restrict processing, right to data portability, right to object, and rights related to automated decision-making and profiling.
What is a Data Protection Impact Assessment (DPIA)?
A DPIA is a mandatory assessment required before processing that is likely to result in a high risk to individuals' rights and freedoms. This includes large-scale processing of sensitive data, systematic monitoring of public areas, and automated decision-making with significant effects. The DPIA must describe the processing, assess necessity and proportionality, and identify measures to mitigate risks.
Do I need a Data Protection Officer under UK GDPR?
A DPO is mandatory if you are a public authority, your core activities involve regular and systematic monitoring of individuals on a large scale, or your core activities involve large-scale processing of special category data or criminal offence data. Even where not mandatory, appointing a DPO is considered good practice.
What are the penalties for breaching UK GDPR?
The ICO can impose fines of up to 17.5 million pounds or 4% of annual global turnover, whichever is higher, for the most serious infringements. Lower-level infringements attract fines of up to 8.7 million pounds or 2% of global turnover. The ICO also has powers to issue enforcement notices, warnings, reprimands, and orders to cease processing.
What is the data breach notification requirement?
Organisations must report personal data breaches to the ICO without undue delay and within 72 hours of becoming aware of the breach, where the breach is likely to result in a risk to individuals' rights and freedoms. If the breach is likely to result in a high risk to individuals, those individuals must also be notified directly.
Does UK GDPR apply to employee data?
Yes. UK GDPR applies to the processing of employees' personal data. Employers must have a lawful basis for processing employee data, provide privacy notices to staff, implement appropriate security measures, and respect employees' data subject rights. Consent is rarely the appropriate lawful basis for employee data due to the power imbalance in the employment relationship.