Use this checklist each year to confirm your business meets its data protection obligations under UK GDPR and the Data Protection Act 2018. Work through each section and resolve any gaps before moving on.
Registration and fees
- ICO data protection fee renewed and paid before the expiry date
- ICO registration details up to date (business name, address, nature of processing)
- Correct fee tier confirmed based on current turnover and staff numbers
Privacy and transparency
- Privacy notices reviewed and updated for any changes to processing activities, data recipients, or retention periods
- Privacy notices include all mandatory information required by UK GDPR Articles 13 and 14
- Cookie consent mechanism compliant with PECR and any Data Use and Access Act 2025 changes (consent-or-pay models, analytical cookie reforms)
- Lawful basis documented for each processing purpose
- Legitimate interest assessments reviewed for any processing relying on that basis
Individual rights and requests
- Subject access request (SAR) response process documented and tested within the last 12 months
- Staff trained on recognising and handling all eight data subject rights requests
- Response within one calendar month confirmed as standard procedure (with documented escalation for complex requests)
- Identity verification process in place for rights requests
- Third-party recipients notified of any rectifications, erasures, or restrictions during the year
Security and breach management
- Data breach response plan in place and tested (desktop exercise or drill) within the last 12 months
- Staff trained on identifying and escalating potential breaches
- 72-hour ICO notification process documented and assigned to a named individual
- Internal breach register maintained and reviewed for patterns or repeat incidents
- Technical security measures reviewed (encryption, access controls, backups, patch management)
- Passwords and access credentials rotated or reviewed in line with your security policy
Governance and accountability
- Records of processing activities (ROPA) updated to reflect any new or changed processing
- Data Protection Officer or Senior Responsible Individual appointed and contact details published (if required)
- Data Protection Impact Assessments (DPIAs) reviewed for all high-risk processing activities
- New DPIAs completed for any processing introduced during the year that meets mandatory triggers
- Staff data protection training completed and recorded for all employees handling personal data
- Data protection policies reviewed and version-controlled
Data management
- Retention schedule applied and data deleted or anonymised on schedule
- International transfer mechanisms reviewed and still valid (adequacy decisions, standard contractual clauses, or binding corporate rules)
- Processor contracts include all required UK GDPR Article 28 clauses
- Processor compliance verified (security measures, sub-processor controls, breach notification obligations)
- Data minimisation reviewed: no unnecessary personal data still being collected or held
Related guidance
- Data protection for businesses for full UK GDPR compliance guidance
- Register with the ICO and pay data protection fee for registration details
- Respond to data subject access requests (DSARs) for handling rights requests
- Responding to data breaches: legal requirements for breach notification procedures
- International data transfers: UK GDPR requirements for transfer mechanisms
ICO accountability framework self-assessment (opens in a new tab)
Legal basis
Primary legislation and key regulations
Official guidance
ICO: Accountability and governance (opens in a new tab)
ICO self-assessment toolkit for data protection accountability.
ICO
ICO: Data protection fee (opens in a new tab)
Fee tiers, self-assessment tool, and payment.
ICO
ICO: Report a personal data breach (opens in a new tab)
Online breach reporting tool and guidance.
ICO
ICO: Guide to data protection impact assessments (opens in a new tab)
When and how to conduct a DPIA.
ICO
UK General Data Protection Regulation (legislation.gov.uk) (opens in a new tab)
Full text of UK GDPR.
legislation
Data Protection Act 2018 (legislation.gov.uk) (opens in a new tab)
UK domestic data protection legislation.
legislation
Data Use and Access Act 2025 (legislation.gov.uk) (opens in a new tab)
Reforms to UK data protection framework including cookie consent and automated decision-making.
legislation
Data protection audit framework (opens in a new tab)
ICO
Toolkits (opens in a new tab)
ICO
Risks and data protection impact assessments (DPIA) (opens in a new tab)
ICO
Records management and security (opens in a new tab)
ICO
Policies and procedures (opens in a new tab)
ICO
Information rights (opens in a new tab)
ICO