Journey
Meet your data protection obligations
Ensure your business complies with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful basis for processing, data subject rights, international transfers, breach notification, and electronic marketing rules under PECR.
Data protection compliance for UK businesses
Every business that processes personal data must comply with UK GDPR and the Data Protection Act 2018. This includes collecting customer details, managing employee records, operating CCTV, or running marketing campaigns.
The Information Commissioner's Office (ICO) enforces data protection law. Serious breaches can result in fines of up to 17.5 million pounds or 4% of annual worldwide turnover (whichever is higher). Beyond fines, poor data protection damages customer trust and can disrupt your business operations.
-
Register with the Information Commissioner's Office
Most businesses that process personal data must pay an annual data protection fee to the ICO. This applies whether you have one employee or thousands. The fee depends on your size and turnover.
Register with the ICO and understand your obligations
Learn about UK GDPR requirements, the seven data protection principles, and how to register your business with the ICO.
-
Identify your lawful basis for processing
You need a valid legal reason (lawful basis) for every type of personal data you process. The six lawful bases under UK GDPR are: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Choosing the wrong basis - or having no basis at all - is a fundamental breach.
-
Respond to data subject rights requests
Individuals have rights over their personal data. When someone makes a request - such as asking for a copy of their data or asking you to delete it - you must respond within one month. Failing to do so is a breach that individuals can complain to the ICO about.
Data protection overview and compliance requirements
Detailed guidance on handling Subject Access Requests, erasure requests, and other data subject rights.
-
Ensure lawful international data transfers
Transferring personal data outside the UK requires additional safeguards. This applies whenever you use cloud services hosted abroad, share data with overseas partners, or send employee information to a foreign head office. Many businesses underestimate how many international transfers they make.
International data transfer requirements
Understand adequacy decisions, Standard Contractual Clauses, the UK IDTA, Transfer Risk Assessments, and when exemptions apply.
-
Report data breaches within 72 hours
When a data breach occurs, you have just 72 hours to report it to the ICO if it poses a risk to individuals. Some breaches also require you to notify the affected individuals directly. Having a breach response plan before an incident occurs is essential - you will not have time to work out your process during a crisis.
Data breach response requirements
What counts as a reportable breach, how to assess risk, the 72-hour notification deadline, and what to tell affected individuals.
-
Comply with electronic marketing rules (PECR)
The Privacy and Electronic Communications Regulations (PECR) set additional rules for marketing emails, texts, and telephone calls. These work alongside UK GDPR. Getting consent wrong for marketing is one of the most common reasons for ICO enforcement action.
Electronic marketing rules under PECR
Consent requirements, the soft opt-in exception for existing customers, TPS screening for calls, and avoiding ICO penalties.
-
Understand the consequences of non-compliance
The ICO has significant enforcement powers. Beyond fines, the ICO can issue enforcement notices requiring you to stop processing data, conduct compulsory audits, and publicise your failings. Serious breaches damage your reputation and can result in legal action from affected individuals.
-
Maintain ongoing compliance
Data protection is not a one-off exercise. Review your processing activities regularly, update your privacy notices when things change, train new staff, and keep records of your compliance efforts. The ICO expects organisations to embed data protection into their operations.