Journey

Data protection compliance checklist

Quick compliance check for UK GDPR and Data Protection Act 2018. Verify your ICO registration, lawful basis documentation, privacy notice, data subject rights process, breach response plan, international transfers, and marketing compliance.

Running a Business Updated 15 September 2026
7 milestones references 5 guides

Quick compliance check

Use this checklist to verify your business meets UK GDPR and Data Protection Act 2018 requirements. Work through each item - if you cannot tick it off, follow the signpost to the relevant guide.

  1. ICO registration and fee payment

    Check: Are you registered with the ICO and is your annual fee paid?

    Register with the ICO

    How to register, determine your fee tier, and set up annual renewal

  2. Lawful basis for processing

    Check: Have you documented which lawful basis applies to each type of personal data you process?

    Data protection for businesses

    Full guidance on choosing and documenting lawful bases, including special category data

  3. Privacy notice in place

    Check: Do you have a privacy notice that tells people what data you collect, why, and what you do with it?

    Your privacy notice must be clear, accessible, and cover all your processing activities. Update it when anything changes.

    Privacy notice requirements

    What your privacy notice must contain under UK GDPR Articles 13 and 14

  4. Data subject rights process

    Check: Do you have a process for handling requests from individuals (access, erasure, correction)?

    You must respond within one month. Train staff to recognise requests - they do not need to use formal language.

    Handling data subject requests

    The eight individual rights under UK GDPR and how to respond within the one-month deadline

  5. Data breach response plan

    Check: Do you have a documented plan for handling data breaches, including who to notify and when?

    Data breach response

    What counts as a reportable breach, assessing risk, notification deadlines, and communicating with affected individuals

  6. International data transfers

    Check: If you transfer personal data outside the UK, do you have appropriate safeguards in place?

    This applies to cloud services, overseas suppliers, and international group companies - many businesses transfer data internationally without realising it.

    International data transfers

    Adequacy decisions, Standard Contractual Clauses, the UK IDTA, and Transfer Risk Assessments

  7. Electronic marketing compliance (PECR)

    Check: Do you have valid consent for marketing emails, texts, and calls?

    Marketing compliance is one of the most common reasons for ICO enforcement action. The rules work alongside UK GDPR.

    Electronic marketing rules (PECR)

    Consent requirements, the soft opt-in exception, telephone preference screening, and cookie compliance

    Annual review

    Data protection is not a one-off exercise. Review this checklist at least annually and whenever your business activities change significantly.