Journey
Data protection compliance checklist
Quick compliance check for UK GDPR and Data Protection Act 2018. Verify your ICO registration, lawful basis documentation, privacy notice, data subject rights process, breach response plan, international transfers, and marketing compliance.
Quick compliance check
Use this checklist to verify your business meets UK GDPR and Data Protection Act 2018 requirements. Work through each item - if you cannot tick it off, follow the signpost to the relevant guide.
-
ICO registration and fee payment
Check: Are you registered with the ICO and is your annual fee paid?
Register with the ICO
How to register, determine your fee tier, and set up annual renewal
-
Lawful basis for processing
Check: Have you documented which lawful basis applies to each type of personal data you process?
Data protection for businesses
Full guidance on choosing and documenting lawful bases, including special category data
-
Privacy notice in place
Check: Do you have a privacy notice that tells people what data you collect, why, and what you do with it?
Your privacy notice must be clear, accessible, and cover all your processing activities. Update it when anything changes.
Privacy notice requirements
What your privacy notice must contain under UK GDPR Articles 13 and 14
-
Data subject rights process
Check: Do you have a process for handling requests from individuals (access, erasure, correction)?
You must respond within one month. Train staff to recognise requests - they do not need to use formal language.
Handling data subject requests
The eight individual rights under UK GDPR and how to respond within the one-month deadline
-
Data breach response plan
Check: Do you have a documented plan for handling data breaches, including who to notify and when?
Data breach response
What counts as a reportable breach, assessing risk, notification deadlines, and communicating with affected individuals
-
International data transfers
Check: If you transfer personal data outside the UK, do you have appropriate safeguards in place?
This applies to cloud services, overseas suppliers, and international group companies - many businesses transfer data internationally without realising it.
International data transfers
Adequacy decisions, Standard Contractual Clauses, the UK IDTA, and Transfer Risk Assessments
-
Electronic marketing compliance (PECR)
Check: Do you have valid consent for marketing emails, texts, and calls?
Marketing compliance is one of the most common reasons for ICO enforcement action. The rules work alongside UK GDPR.
Electronic marketing rules (PECR)
Consent requirements, the soft opt-in exception, telephone preference screening, and cookie compliance
Annual review
Data protection is not a one-off exercise. Review this checklist at least annually and whenever your business activities change significantly.