- Enforced by
- ICO
- Status
- Amended (in force with amendments)
- Penalty ceiling
- Prosecution 108 of 157 obligations carry a fine up to £17,500,000. 6 carry different penalties and 43 have no criminal penalty — flagged in the list below.
Does it bind you?
Business-side roles with duties under this instrument.
Plus 6 duties on the regulator, Crown ministers and public bodies — folded into the section list below.
Other Acts binding the same actors
If a role above is yours, these are the other instruments that most often bind it.
Data Controller — also bound by 35 other Acts
Data Processor — also bound by 20 other Acts
Employer — also bound by 682 other Acts
Any Person — also bound by 2340 other Acts
What it requires
Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.
- Adhere to the six data protection principles and prove complianceData Controller
- Comply with data protection principles and prove your complianceData Controller
- Comply with GDPR data protection principlesData Controller
- Ensure GDPR‑compliant processing of personal dataData Controller
- Follow GDPR data protection principles and demonstrate complianceData Controller
- Process personal data according to GDPR principles and show complianceData Controller
- Process personal data in line with GDPR principlesData Controller
- Process personal data in line with GDPR principles and demonstrate complianceData Controller
- Process personal data lawfully and demonstrate complianceData Controller
- Process personal data lawfully, fairly, transparently and securelyData Controller
Fine up to £17,500,000
- Ensure valid and withdrawable consent for data processingData Controller
- Obtain and manage consent in line with UK GDPRData Controller
- Obtain, document and allow withdrawal of valid consentData Controller
- Obtain, record and allow easy withdrawal of valid consentData Controller
- Obtain, document and manage valid consent for data processingData Controller
Fine up to £17,500,000
- Obtain and verify parental consent for children under 13Data Controller
- Obtain and verify parental consent for under‑13 users of online servicesData Controller
- Obtain parental consent for online services offered to children under 13Data Controller
- Verify parental consent for children under 13 using online servicesData Controller
Fine up to £17,500,000
- Only process criminal conviction data with proper authority or legal authorisationData Controller
Fine up to £17,500,000
- Provide clear, free information and enable data‑subject rightsData Controller
- Provide clear privacy information and handle data‑subject rights requests promptlyData Controller
- Respond to data subject rights requests transparently and promptlyData Controller
Fine up to £17,500,000
- Provide information to data subjects when you obtain their data from other sourcesData Controller
- Provide required data‑subject information when you collect data from other sourcesData Controller
- Provide required information when data not obtained directlyData Controller
- Provide required transparency information to data subjectsData Controller
- Provide privacy information when personal data is obtained from third partiesData Controller
- Provide required information to data subjects when you did not collect their data directlyData Controller
- Provide required privacy information to data subjects when data not obtained from themData Controller
- Give data subjects required information when you obtain their data from other sourcesData Controller
- Give required information to people when you collect their data from other sourcesData Controller
Fine up to £17,500,000
- Provide data subjects access to their personal data and related informationData Controller
- Provide data subjects with access to their personal dataData Controller
- Provide data subject access to personal data on requestData Controller
- Respond to personal data access requestsData Controller
Fine up to £17,500,000
- Correct personal data when requestedData Controller
- Rectify inaccurate or incomplete personal data on requestData Controller
Fine up to £17,500,000
- Notify all data recipients of corrections, deletions or restrictionsData Controller
- Notify all recipients when you correct, delete or restrict personal dataData Controller
- Notify data recipients of any correction, deletion or restriction of personal dataData Controller
- Notify data recipients of any rectification, erasure or restrictionData Controller
- Notify data recipients of corrections, deletions or processing limitsData Controller
- Notify recipients of data corrections, deletions or processing restrictionsData Controller
- Notify third parties when updating or deleting personal dataData Controller
- Notify third parties when you correct or delete personal dataData Controller
Fine up to £17,500,000
- Allow and respect data subjects’ right to objectData Controller
- Give individuals a right to object and stop processing on objectionData Controller
- Inform data subjects of right to object and stop processing on objectionData Controller
- Provide right‑to‑object notice and honour objectionsData Controller
- Respect data subjects’ right to object and inform themData Controller
- Respect data subjects' right to object and stop processing on requestData Controller
- Stop processing when a data subject objects and tell them they can objectData Controller
- Respect and notify individuals of their right to object to data processingData Controller
Fine up to £17,500,000
- Implement and demonstrate data protection compliance measuresData Controller
- Implement and demonstrate GDPR‑compliant data protection measuresData Controller
- Implement and maintain data protection measures and policiesData Controller
- Implement and maintain data‑protection policies and safeguardsData Controller
Fine up to £17,500,000
- Design your systems and processes to protect personal dataData Controller
- Implement data protection by design and by defaultData Controller
Fine up to £17,500,000
- Agree a joint‑controller arrangement and disclose it to data subjectsData Controller
- Agree and document joint controller responsibilitiesData Controller
- Agree joint‑controller responsibilities and inform data subjectsData Controller
- Agree on and share GDPR responsibilities with joint controllersData Controller
- Agree responsibilities with joint controllers and inform data subjectsData Controller
- Create a written agreement between joint data controllersData Controller
- Set up transparent joint‑controller agreementData Controller
Fine up to £17,500,000
- Comply with data processing contract and data protection dutiesData Processor
- Comply with data‑processor responsibilities under UK GDPRData Processor
- Comply with UK GDPR processor obligationsData Processor
- Contract with controller and control sub‑processorsData Processor
- Enter into a compliant data‑processing contract and meet processor dutiesData Processor
- Enter into a GDPR processor contract and follow its dutiesData Processor
- Enter into and comply with a data processing agreement with the controllerData Processor
- Enter into and comply with a written data‑processing contractData Processor
- Process personal data only under a compliant contract with the controllerData Processor
- Use and manage data processors under a written contractData Controller
- Enter into and comply with a data processing agreementData Processor
Unlimited fine
- Process personal data only on the controller’s instructionsData Processor
- Process personal data only on the instructions of the controllerData Controller
Unlimited fine
- Cooperate with the ICO when requestedEmployer
- Cooperate with the Information Commissioner’s Office (ICO)Data Controller
- Cooperate with the ICO when it requests assistanceData Controller
Fine up to £17,500,000
- Implement appropriate data security measuresData Controller
- Implement appropriate security measures for personal data processingEmployer
- Implement appropriate technical and organisational security measuresData Controller
- Secure all personal data using appropriate technical and organisational measuresData Controller
Unlimited fine
- Notify personal data breaches to the ICO within 72 hoursData Controller
- Notify the ICO of personal data breachesData Controller
- Notify the ICO of personal data breaches within 72 hoursData Controller
- Notify the ICO of personal data breaches and keep a breach registerData Controller
Fine up to £17,500,000
- Notify affected individuals of high‑risk data breachesData Controller
- Notify data subjects of high‑risk personal data breachesData Controller
- Tell people if their personal data has been breached and poses a high riskData Controller
Unlimited fine
- Carry out a Data Protection Impact Assessment (DPIA) before high‑risk processingData Controller
- Carry out data protection impact assessments (DPIAs)Data Controller
Fine up to £17,500,000
- Consult ICO before carrying out high‑risk data processingData Controller
- Consult ICO before high‑risk processing and supply required informationData Controller
Fine up to £17,500,000
- Appoint a Data Protection Officer and publish their contact detailsEmployer
- Appoint a Data Protection Officer (DPO) if specific criteria are metData Controller
- Appoint a Data Protection Officer (DPO) when requiredEmployer
- Appoint and publish a Data Protection Officer (DPO)Data Controller
- Designate a Data Protection Officer (DPO) if thresholds are metData Controller
Unlimited fine
- Ensure independent, adequately resourced DPO reporting to senior managementEmployer
- Ensure the Data Protection Officer is independent and properly supportedData Controller
- Give the Data Protection Officer independence, resources and senior reportingData Controller
- Give the DPO independence, resources and top‑level reportingData Controller
- Maintain an independent and well‑resourced Data Protection OfficerData Controller
- Maintain independence and support for your Data Protection OfficerEmployer
- Support and maintain independence of your data protection officerEmployer
- Support and protect your Data Protection Officer (DPO)Employer
Fine up to £17,500,000
- Appoint a Data Protection Officer and ensure they fulfill core dutiesData Controller
- Ensure data protection officer carries out required tasksData Controller
- Ensure DPO carries out advisory, monitoring and ICO liaison dutiesAny Person
- Ensure your Data Protection Officer carries out key data protection dutiesData Controller
- Ensure your Data Protection Officer performs prescribed GDPR tasksData Controller
Fine up to £17,500,000
- Adopt and follow an approved data‑protection code of conductData Controller
- Prepare and submit data‑protection codes of conduct for ICO approvalAny Person
- Adhere to an approved code of conduct by making binding commitmentsData Controller
- Adopt a UK GDPR code of conduct and commit to its safeguardsData Controller
- Adopt a GDPR‑approved code of conduct for data handlingData Controller
Other duties (1) — Crown / regulator
- ICO must encourage and approve industry codes of conductStatutory regulator
- Obtain and maintain data‑protection certification (if you choose to)Data Controller
- Provide information and access for data‑protection certificationData Controller
- Provide information to certification body for data‑protection certificationData Controller
- Apply for and keep a voluntary data‑protection certificationData Controller
- Provide information to certification bodies when seeking GDPR certificationData Controller
- Provide information to data protection certification bodiesData Controller
Fine up to £17,500,000
- Accredit and run a certified data‑protection compliance bodyAny Person
- Certification bodies must meet strict standards to issue GDPR certificatesData Controller
- Obtain and maintain accreditation for data‑protection certification bodiesAny Person
- Maintain accredited certification body status and processesAny Person
Fine up to £17,500,000
- Use appropriate safeguards for international data transfersData Controller
Other duties (1) — Crown / regulator
- ICO must cooperate internationally to enforce data protectionStatutory regulator
Other duties (1) — Crown / regulator
- ICO must act with complete independenceStatutory regulator
Other duties (1) — Crown / regulator
- ICO must monitor, enforce, and support UK GDPR complianceStatutory regulator
Other duties (1) — Crown / regulator
- ICO must ensure data protection fines are fair and effectiveStatutory regulator
- Infringe UK GDPR information obligations (Article 14)Data Controller
Unlimited fine
- Do not rely solely on automated decisions using special‑category dataData Controller
- Ensure lawful use of automated decisions with special personal dataData Controller
- Restrict automated decisions on special category dataData Controller
- Restricted use of sensitive data for automated decisionsData Controller
- Restrict fully automated decisions using sensitive personal dataData Controller
Fine up to £17,500,000
- Implement safeguards for automated decision‑makingData Controller
- Provide safeguards for automated decisions affecting individualsData Controller
- Provide safeguards for significant automated decisionsData Controller
- Put safeguards in place for fully automated decisions that affect individualsData Controller
- Put safeguards in place for significant automated decisionsData Controller
Fine up to £17,500,000
- Ensure international data transfers comply with UK GDPRData Controller
- Ensure lawful international transfers of personal dataData Controller
- Ensure lawful transfers of personal data overseasData Controller
- Ensure legal grounds before transferring personal data abroadData Controller
- Transfer personal data abroad only with appropriate safeguardsData Controller
Fine up to £17,500,000
Other duties (1) — Crown / regulator
- Secretary of State must monitor and update approved data transfer listsCrown / Minister / Government department
- Process personal data for RAS only if necessary and with safeguardsData Controller
- Process personal data for RAS only with justification and safeguardsData Controller
- Process personal data for research/statistics only with safeguardsData Controller
Fine up to £17,500,000
82 other provisions — procedural and definitional
Help complying
Guvnor’s practical routes through this instrument.
Marketing compliance: PECR and UK GDPR
Learn how to send compliant marketing emails, texts, and make telephone calls. Covers PECR consent rules, the soft opt-in exception, TPS screening, …
Comply with the Online Safety Act from scratch
A complete learning path for platform operators new to the Online Safety Act 2023. Covers understanding the Act, determining scope and platform …
Respond to a data breach
Step-by-step breach response when personal data has been compromised. Covers the 72-hour ICO notification deadline, assessing risk, notifying affected individuals, and documenting …
Data breach 72-hour checklist
Emergency checklist when you discover a personal data breach. Covers immediate containment, the 72-hour ICO notification rule, when to notify affected individuals, …
Start using AI responsibly in your business
End-to-end learning path for businesses adopting AI: understanding the regulatory landscape, assessing obligations, setting up governance, managing specific risks around data, bias, …
AI compliance quick check
Rapid AI compliance self-assessment: identify AI systems, map to regulators, flag critical obligations, confirm key safeguards in place.
AI compliance checklist
Quick verification checklist covering all major AI compliance obligations. Use this checklist to confirm your business meets its data protection, equality, transparency, …
AI transparency and explainability obligations
What transparency and explainability mean for AI systems and how to meet the obligations. Covers UK GDPR requirements for automated decision-making, ICO …
Assess your AI compliance obligations
Step-by-step guide to assessing what AI compliance obligations apply to your business. Covers inventorying AI systems, identifying personal data processing, mapping to …
Carry out a data protection impact assessment (DPIA)
How to carry out a data protection impact assessment under UK GDPR Article 35. Covers when a DPIA is legally required, the …
Create a data retention policy
How to write and implement a data retention policy that satisfies the UK GDPR storage limitation principle. Covers what to include, how …
Data Use and Access Act 2025: what changed for businesses
What the Data (Use and Access) Act 2025 means for UK businesses. Explains the eight key reforms now in force, including recognised …
Data protection annual compliance checklist
Annual checklist for verifying your data protection compliance. Covers ICO fee renewal, privacy notices, records of processing, breach procedures, staff training, DPIAs, …
Data protection for businesses
How to comply with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful bases for processing, data subject rights, …
33 more guides that reference this instrument
Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.