Data protection for businesses
How to comply with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful bases for …
Annual checklist for verifying your data protection compliance. Covers ICO fee renewal, privacy notices, records of processing, breach procedures, staff training, DPIAs, retention schedules, and international transfers.
Check your business meets UK data protection rules every year. Pay the ICO fee, update privacy notices, and train staff. Fines for missing the fee can be up to £4,350.
How to comply with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful bases for …
How healthcare providers must handle patient data under UK GDPR, including special category health data requirements, Caldicott Principles, …
How to register with the Information Commissioner's Office and pay the annual data protection fee. Covers who must …
How to recognise, process, and respond to subject access requests under UK GDPR. Covers the one-month response deadline, …
Emergency response guide for reporting cyber attacks and data breaches. Covers who to contact (Report Fraud, ICO, NCSC, …
Use this checklist each year to confirm your business meets its data protection obligations under UK GDPR and the Data Protection Act 2018. Work through each section and resolve any gaps before moving on.
If you identified gaps in any section, address them promptly. The ICO can issue enforcement notices, reprimands, and fines of up to GBP 17.5 million or 4% of annual worldwide turnover for serious infringements. If you are uncertain about a compliance gap, seek specialist data protection advice before your next ICO fee renewal date.
ICO self-assessment toolkit for data protection accountability.
ico.org.ukFee tiers, self-assessment tool, and payment.
ico.org.ukOnline breach reporting tool and guidance.
ico.org.ukWhen and how to conduct a DPIA.
ico.org.ukFull text of UK GDPR.
legislationUK domestic data protection legislation.
legislationReforms to UK data protection framework including cookie consent and automated decision-making.
legislation