Retained EU Law 2016 United Kingdom

UK GDPR (retained EU law)

At a glance

Enforced by

ICO

What's here

156 compliance obligations, 39 practical guides across 5 topics · 34 journeys

Penalty landscape

108 of 156 obligations carry a fine up to £17,500,000. 6 carry different penalties and 42 have no criminal penalty — flagged in the list below.

Who this Act binds

Business-side actors with duties under this Act, ranked by how often they appear.

  • Data Controller 126
  • Data Processor 11
  • Employer 8
  • Any Person 5

Plus 6 non-business duties on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

Step-by-step journeys using this legislation

Walkthroughs that take you from a real business situation to compliance.

Relevant guidance

Practical guides for businesses affected by this Act, ordered by how closely they engage with it.

Other Acts binding the same actors

For each actor bound by this Act, the other UK Acts that bind them most often. Useful for understanding the full compliance landscape facing each role.

Data Controllers also bound by 38 other Acts (top 5 shown)
Data Processors also bound by 20 other Acts (top 5 shown)
Employers also bound by 694 other Acts (top 5 shown)
Any Person also bound by 2338 other Acts (top 5 shown)

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

s.005

Principles relating to processing of personal data

Fine up to £17,500,000
  • Adhere to the six data protection principles and prove compliance Data Controller
  • Comply with data protection principles and prove your compliance Data Controller
  • Comply with GDPR data protection principles Data Controller
  • Ensure GDPR‑compliant processing of personal data Data Controller
  • Follow GDPR data protection principles and demonstrate compliance Data Controller
  • Process personal data according to GDPR principles and show compliance Data Controller
  • Process personal data in line with GDPR principles Data Controller
  • Process personal data in line with GDPR principles and demonstrate compliance Data Controller
  • Process personal data lawfully and demonstrate compliance Data Controller
  • Process personal data lawfully, fairly, transparently and securely Data Controller
s.007

Conditions for consent

Fine up to £17,500,000
  • Ensure valid and withdrawable consent for data processing Data Controller
  • Obtain and manage consent in line with UK GDPR Data Controller
  • Obtain, document and allow withdrawal of valid consent Data Controller
  • Obtain, record and allow easy withdrawal of valid consent Data Controller
  • Obtain, document and manage valid consent for data processing Data Controller
s.008

Conditions applicable to child's consent in relation to information society services

Fine up to £17,500,000
  • Obtain and verify parental consent for children under 13 Data Controller
  • Obtain and verify parental consent for under‑13 users of online services Data Controller
  • Obtain parental consent for online services offered to children under 13 Data Controller
  • Verify parental consent for children under 13 using online services Data Controller
s.014

Information to be provided where personal data have not been obtained from the data subject

Fine up to £17,500,000
  • Provide information to data subjects when you obtain their data from other sources Data Controller
  • Provide required data‑subject information when you collect data from other sources Data Controller
  • Provide required information when data not obtained directly Data Controller
  • Provide required transparency information to data subjects Data Controller
  • Provide privacy information when personal data is obtained from third parties Data Controller
  • Provide required information to data subjects when you did not collect their data directly Data Controller
  • Provide required privacy information to data subjects when data not obtained from them Data Controller
  • Give data subjects required information when you obtain their data from other sources Data Controller
  • Give required information to people when you collect their data from other sources Data Controller
s.015

Right of access by the data subject

Fine up to £17,500,000
  • Provide data subjects access to their personal data and related information Data Controller
  • Provide data subjects with access to their personal data Data Controller
  • Provide data subject access to personal data on request Data Controller
  • Respond to personal data access requests Data Controller
s.016

Right to rectification

Fine up to £17,500,000
  • Correct personal data when requested Data Controller
  • Rectify inaccurate or incomplete personal data on request Data Controller
s.019

Notification obligation regarding rectification or erasure of personal data or restriction of processing

Fine up to £17,500,000
  • Notify all data recipients of corrections, deletions or restrictions Data Controller
  • Notify all recipients when you correct, delete or restrict personal data Data Controller
  • Notify data recipients of any correction, deletion or restriction of personal data Data Controller
  • Notify data recipients of any rectification, erasure or restriction Data Controller
  • Notify data recipients of corrections, deletions or processing limits Data Controller
  • Notify recipients of data corrections, deletions or processing restrictions Data Controller
  • Notify third parties when updating or deleting personal data Data Controller
  • Notify third parties when you correct or delete personal data Data Controller
s.021

Right to object

Fine up to £17,500,000
  • Allow and respect data subjects’ right to object Data Controller
  • Give individuals a right to object and stop processing on objection Data Controller
  • Inform data subjects of right to object and stop processing on objection Data Controller
  • Provide right‑to‑object notice and honour objections Data Controller
  • Respect data subjects’ right to object and inform them Data Controller
  • Respect data subjects' right to object and stop processing on request Data Controller
  • Stop processing when a data subject objects and tell them they can object Data Controller
  • Respect and notify individuals of their right to object to data processing Data Controller
s.024

Responsibility of the controller

Fine up to £17,500,000
  • Implement and demonstrate data protection compliance measures Data Controller
  • Implement and demonstrate GDPR‑compliant data protection measures Data Controller
  • Implement and maintain data protection measures and policies Data Controller
  • Implement and maintain data‑protection policies and safeguards Data Controller
s.025

Data protection by design and by default

Fine up to £17,500,000
  • Design your systems and processes to protect personal data Data Controller
  • Implement data protection by design and by default Data Controller
s.026

Joint controllers

Fine up to £17,500,000
  • Agree a joint‑controller arrangement and disclose it to data subjects Data Controller
  • Agree and document joint controller responsibilities Data Controller
  • Agree joint‑controller responsibilities and inform data subjects Data Controller
  • Agree on and share GDPR responsibilities with joint controllers Data Controller
  • Agree responsibilities with joint controllers and inform data subjects Data Controller
  • Create a written agreement between joint data controllers Data Controller
  • Set up transparent joint‑controller agreement Data Controller
s.028

Processor

Unlimited fine
  • Comply with data processing contract and data protection duties Data Processor
  • Comply with data‑processor responsibilities under UK GDPR Data Processor
  • Comply with UK GDPR processor obligations Data Processor
  • Contract with controller and control sub‑processors Data Processor
  • Enter into a compliant data‑processing contract and meet processor duties Data Processor
  • Enter into a GDPR processor contract and follow its duties Data Processor
  • Enter into and comply with a data processing agreement with the controller Data Processor
  • Enter into and comply with a written data‑processing contract Data Processor
  • Process personal data only under a compliant contract with the controller Data Processor
  • Use and manage data processors under a written contract Data Controller
  • Enter into and comply with a data processing agreement Data Processor
s.031

Cooperation with the Commissioner

Fine up to £17,500,000
  • Cooperate with the ICO when requested Employer
  • Cooperate with the Information Commissioner’s Office (ICO) Data Controller
  • Cooperate with the ICO when it requests assistance Data Controller
s.032

Security of processing

Unlimited fine
  • Implement appropriate data security measures Data Controller
  • Implement appropriate security measures for personal data processing Employer
  • Implement appropriate technical and organisational security measures Data Controller
  • Secure all personal data using appropriate technical and organisational measures Data Controller
s.033

Notification of a personal data breach to the Commissioner

Fine up to £17,500,000
  • Notify personal data breaches to the ICO within 72 hours Data Controller
  • Notify the ICO of personal data breaches Data Controller
  • Notify the ICO of personal data breaches within 72 hours Data Controller
  • Notify the ICO of personal data breaches and keep a breach register Data Controller
s.034

Communication of a personal data breach to the data subject

Unlimited fine
  • Notify affected individuals of high‑risk data breaches Data Controller
  • Notify data subjects of high‑risk personal data breaches Data Controller
  • Tell people if their personal data has been breached and poses a high risk Data Controller
s.035

Data protection impact assessment

Fine up to £17,500,000
  • Carry out a Data Protection Impact Assessment (DPIA) before high‑risk processing Data Controller
  • Carry out data protection impact assessments (DPIAs) Data Controller
s.036

Prior consultation

Fine up to £17,500,000
  • Consult ICO before carrying out high‑risk data processing Data Controller
  • Consult ICO before high‑risk processing and supply required information Data Controller
s.037

Designation of the data protection officer

Unlimited fine
  • Appoint a Data Protection Officer and publish their contact details Employer
  • Appoint a Data Protection Officer (DPO) if specific criteria are met Data Controller
  • Appoint a Data Protection Officer (DPO) when required Employer
  • Appoint and publish a Data Protection Officer (DPO) Data Controller
  • Designate a Data Protection Officer (DPO) if thresholds are met Data Controller
s.038

Position of the data protection officer

Fine up to £17,500,000
  • Ensure independent, adequately resourced DPO reporting to senior management Employer
  • Ensure the Data Protection Officer is independent and properly supported Data Controller
  • Give the Data Protection Officer independence, resources and senior reporting Data Controller
  • Give the DPO independence, resources and top‑level reporting Data Controller
  • Maintain an independent and well‑resourced Data Protection Officer Data Controller
  • Maintain independence and support for your Data Protection Officer Employer
  • Support and maintain independence of your data protection officer Employer
  • Support and protect your Data Protection Officer (DPO) Employer
s.039

Tasks of the data protection officer

Fine up to £17,500,000
  • Appoint a Data Protection Officer and ensure they fulfill core duties Data Controller
  • Ensure data protection officer carries out required tasks Data Controller
  • Ensure DPO carries out advisory, monitoring and ICO liaison duties Any Person
  • Ensure your Data Protection Officer carries out key data protection duties Data Controller
  • Ensure your Data Protection Officer performs prescribed GDPR tasks Data Controller
s.040

Codes of conduct

  • Adopt and follow an approved data‑protection code of conduct Data Controller
  • Prepare and submit data‑protection codes of conduct for ICO approval Any Person
  • Adhere to an approved code of conduct by making binding commitments Data Controller
  • Adopt a UK GDPR code of conduct and commit to its safeguards Data Controller
  • Adopt a GDPR‑approved code of conduct for data handling Data Controller
Other duties (1) — Crown / regulator
  • ICO must encourage and approve industry codes of conduct Statutory regulator
s.042

Certification

Fine up to £17,500,000
  • Obtain and maintain data‑protection certification (if you choose to) Data Controller
  • Provide information and access for data‑protection certification Data Controller
  • Provide information to certification body for data‑protection certification Data Controller
  • Apply for and keep a voluntary data‑protection certification Data Controller
  • Provide information to certification bodies when seeking GDPR certification Data Controller
  • Provide information to data protection certification bodies Data Controller
s.043

Certification bodies

Fine up to £17,500,000
  • Accredit and run a certified data‑protection compliance body Any Person
  • Certification bodies must meet strict standards to issue GDPR certificates Data Controller
  • Obtain and maintain accreditation for data‑protection certification bodies Any Person
  • Maintain accredited certification body status and processes Any Person
s.052

Independence

Other duties (1) — Crown / regulator
  • ICO must act with complete independence Statutory regulator
s.057

Tasks

Other duties (1) — Crown / regulator
  • ICO must monitor, enforce, and support UK GDPR compliance Statutory regulator
s.084

Penalties

Unlimited fine
  • Infringe UK GDPR information obligations (Article 14) Data Controller
s.art022

Restrictions on automated decision-making

Fine up to £17,500,000
  • Do not rely solely on automated decisions using special‑category data Data Controller
  • Ensure lawful use of automated decisions with special personal data Data Controller
  • Restrict automated decisions on special category data Data Controller
  • Restricted use of sensitive data for automated decisions Data Controller
  • Restrict fully automated decisions using sensitive personal data Data Controller
s.art022

Safeguards for automated decision-making

Fine up to £17,500,000
  • Implement safeguards for automated decision‑making Data Controller
  • Provide safeguards for automated decisions affecting individuals Data Controller
  • Provide safeguards for significant automated decisions Data Controller
  • Put safeguards in place for fully automated decisions that affect individuals Data Controller
  • Put safeguards in place for significant automated decisions Data Controller
s.art044

General principles for transfers

Fine up to £17,500,000
  • Ensure international data transfers comply with UK GDPR Data Controller
  • Ensure lawful international transfers of personal data Data Controller
  • Ensure lawful transfers of personal data overseas Data Controller
  • Ensure legal grounds before transferring personal data abroad Data Controller
  • Transfer personal data abroad only with appropriate safeguards Data Controller
s.art045

Transfers approved by regulations: monitoring

Other duties (1) — Crown / regulator
  • Secretary of State must monitor and update approved data transfer lists Crown / Minister / Government department
s.art084

Additional requirements when processing for RAS purposes

Fine up to £17,500,000
  • Process personal data for RAS only if necessary and with safeguards Data Controller
  • Process personal data for RAS only with justification and safeguards Data Controller
  • Process personal data for research/statistics only with safeguards Data Controller
Browse 83 other sections — procedural / definitional / commencement
s.appropriate safeguards

Appropriate safeguards

s.appropriate safeguards: further provision

Appropriate safeguards: further provision

s.art008

Child’s consent in relation to information society services: age verification

s.automated processing and significant decisions

Automated processing and significant decisions

s.further provision about automated decision-making

Further provision about automated decision-making

s.further provision about processing of special cate

Further provision about processing of special categories of personal data

s.meaning of “applicable time period”

Meaning of “applicable time period”

s.periods of time

Periods of time

s.processing and national security and defence

Processing and national security and defence

s.purpose limitation: further processing

Purpose limitation: further processing

s.regulations made by secretary of state

Regulations made by Secretary of State

s.research, archives and statistics

Research, archives and statistics

s.restriction in the public interest

Restriction in the public interest

s.the data protection test

The data protection test

s.transfers approved by regulations

Transfers approved by regulations

s.transfers subject to appropriate safeguards: furth

Transfers subject to appropriate safeguards: further provision

Official guidance

Authoritative sources published by regulators or government explaining this legislation.

Enforcement and responsible bodies

The regulators that administer or enforce this legislation.

ICO

Information Commissioner's Office

Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. …

Explore more

Browse legislation

Find other UK business legislation with related guidance.

Regulators

Learn more about the bodies that enforce this legislation.