Retained EU Law SI 2016 United Kingdom

UK GDPR (retained EU law)

Enforced by
ICO
Status
Amended (in force with amendments)
Penalty ceiling
Prosecution 108 of 157 obligations carry a fine up to £17,500,000. 6 carry different penalties and 43 have no criminal penalty — flagged in the list below.

Does it bind you?

Business-side roles with duties under this instrument.

Data Controller127 Data Processor11 Employer8 Any Person5

Plus 6 duties on the regulator, Crown ministers and public bodies — folded into the section list below.

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Data Controller — also bound by 35 other Acts
Data Processor — also bound by 20 other Acts
Employer — also bound by 682 other Acts
Any Person — also bound by 2340 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

s.005 Principles relating to processing of personal data (opens in a new tab) Prosecution
  • Adhere to the six data protection principles and prove complianceData Controller
  • Comply with data protection principles and prove your complianceData Controller
  • Comply with GDPR data protection principlesData Controller
  • Ensure GDPR‑compliant processing of personal dataData Controller
  • Follow GDPR data protection principles and demonstrate complianceData Controller
  • Process personal data according to GDPR principles and show complianceData Controller
  • Process personal data in line with GDPR principlesData Controller
  • Process personal data in line with GDPR principles and demonstrate complianceData Controller
  • Process personal data lawfully and demonstrate complianceData Controller
  • Process personal data lawfully, fairly, transparently and securelyData Controller

Fine up to £17,500,000

s.007 Conditions for consent (opens in a new tab) Prosecution
  • Ensure valid and withdrawable consent for data processingData Controller
  • Obtain and manage consent in line with UK GDPRData Controller
  • Obtain, document and allow withdrawal of valid consentData Controller
  • Obtain, record and allow easy withdrawal of valid consentData Controller
  • Obtain, document and manage valid consent for data processingData Controller

Fine up to £17,500,000

s.008 Conditions applicable to child's consent in relation to information society services (opens in a new tab) Prosecution
  • Obtain and verify parental consent for children under 13Data Controller
  • Obtain and verify parental consent for under‑13 users of online servicesData Controller
  • Obtain parental consent for online services offered to children under 13Data Controller
  • Verify parental consent for children under 13 using online servicesData Controller

Fine up to £17,500,000

s.010 Processing of personal data relating to criminal convictions and offences (opens in a new tab) Prosecution
  • Only process criminal conviction data with proper authority or legal authorisationData Controller

Fine up to £17,500,000

s.012 Transparent information, communication and modalities for the exercise of the rights of the data subject (opens in a new tab) Prosecution
  • Provide clear, free information and enable data‑subject rightsData Controller
  • Provide clear privacy information and handle data‑subject rights requests promptlyData Controller
  • Respond to data subject rights requests transparently and promptlyData Controller

Fine up to £17,500,000

s.014 Information to be provided where personal data have not been obtained from the data subject (opens in a new tab) Prosecution
  • Provide information to data subjects when you obtain their data from other sourcesData Controller
  • Provide required data‑subject information when you collect data from other sourcesData Controller
  • Provide required information when data not obtained directlyData Controller
  • Provide required transparency information to data subjectsData Controller
  • Provide privacy information when personal data is obtained from third partiesData Controller
  • Provide required information to data subjects when you did not collect their data directlyData Controller
  • Provide required privacy information to data subjects when data not obtained from themData Controller
  • Give data subjects required information when you obtain their data from other sourcesData Controller
  • Give required information to people when you collect their data from other sourcesData Controller

Fine up to £17,500,000

s.015 Right of access by the data subject (opens in a new tab) Prosecution
  • Provide data subjects access to their personal data and related informationData Controller
  • Provide data subjects with access to their personal dataData Controller
  • Provide data subject access to personal data on requestData Controller
  • Respond to personal data access requestsData Controller

Fine up to £17,500,000

s.016 Right to rectification (opens in a new tab) Prosecution
  • Correct personal data when requestedData Controller
  • Rectify inaccurate or incomplete personal data on requestData Controller

Fine up to £17,500,000

s.019 Notification obligation regarding rectification or erasure of personal data or restriction of processing (opens in a new tab) Prosecution
  • Notify all data recipients of corrections, deletions or restrictionsData Controller
  • Notify all recipients when you correct, delete or restrict personal dataData Controller
  • Notify data recipients of any correction, deletion or restriction of personal dataData Controller
  • Notify data recipients of any rectification, erasure or restrictionData Controller
  • Notify data recipients of corrections, deletions or processing limitsData Controller
  • Notify recipients of data corrections, deletions or processing restrictionsData Controller
  • Notify third parties when updating or deleting personal dataData Controller
  • Notify third parties when you correct or delete personal dataData Controller

Fine up to £17,500,000

s.021 Right to object (opens in a new tab) Prosecution
  • Allow and respect data subjects’ right to objectData Controller
  • Give individuals a right to object and stop processing on objectionData Controller
  • Inform data subjects of right to object and stop processing on objectionData Controller
  • Provide right‑to‑object notice and honour objectionsData Controller
  • Respect data subjects’ right to object and inform themData Controller
  • Respect data subjects' right to object and stop processing on requestData Controller
  • Stop processing when a data subject objects and tell them they can objectData Controller
  • Respect and notify individuals of their right to object to data processingData Controller

Fine up to £17,500,000

s.024 Responsibility of the controller (opens in a new tab) Prosecution
  • Implement and demonstrate data protection compliance measuresData Controller
  • Implement and demonstrate GDPR‑compliant data protection measuresData Controller
  • Implement and maintain data protection measures and policiesData Controller
  • Implement and maintain data‑protection policies and safeguardsData Controller

Fine up to £17,500,000

s.025 Data protection by design and by default (opens in a new tab) Prosecution
  • Design your systems and processes to protect personal dataData Controller
  • Implement data protection by design and by defaultData Controller

Fine up to £17,500,000

s.026 Joint controllers (opens in a new tab) Prosecution
  • Agree a joint‑controller arrangement and disclose it to data subjectsData Controller
  • Agree and document joint controller responsibilitiesData Controller
  • Agree joint‑controller responsibilities and inform data subjectsData Controller
  • Agree on and share GDPR responsibilities with joint controllersData Controller
  • Agree responsibilities with joint controllers and inform data subjectsData Controller
  • Create a written agreement between joint data controllersData Controller
  • Set up transparent joint‑controller agreementData Controller

Fine up to £17,500,000

s.028 Processor (opens in a new tab) Prosecution
  • Comply with data processing contract and data protection dutiesData Processor
  • Comply with data‑processor responsibilities under UK GDPRData Processor
  • Comply with UK GDPR processor obligationsData Processor
  • Contract with controller and control sub‑processorsData Processor
  • Enter into a compliant data‑processing contract and meet processor dutiesData Processor
  • Enter into a GDPR processor contract and follow its dutiesData Processor
  • Enter into and comply with a data processing agreement with the controllerData Processor
  • Enter into and comply with a written data‑processing contractData Processor
  • Process personal data only under a compliant contract with the controllerData Processor
  • Use and manage data processors under a written contractData Controller
  • Enter into and comply with a data processing agreementData Processor

Unlimited fine

s.029 Processing under the authority of the controller or processor (opens in a new tab) Prosecution
  • Process personal data only on the controller’s instructionsData Processor
  • Process personal data only on the instructions of the controllerData Controller

Unlimited fine

s.031 Cooperation with the Commissioner (opens in a new tab) Prosecution
  • Cooperate with the ICO when requestedEmployer
  • Cooperate with the Information Commissioner’s Office (ICO)Data Controller
  • Cooperate with the ICO when it requests assistanceData Controller

Fine up to £17,500,000

s.032 Security of processing (opens in a new tab) Prosecution
  • Implement appropriate data security measuresData Controller
  • Implement appropriate security measures for personal data processingEmployer
  • Implement appropriate technical and organisational security measuresData Controller
  • Secure all personal data using appropriate technical and organisational measuresData Controller

Unlimited fine

s.033 Notification of a personal data breach to the Commissioner (opens in a new tab) Prosecution
  • Notify personal data breaches to the ICO within 72 hoursData Controller
  • Notify the ICO of personal data breachesData Controller
  • Notify the ICO of personal data breaches within 72 hoursData Controller
  • Notify the ICO of personal data breaches and keep a breach registerData Controller

Fine up to £17,500,000

s.034 Communication of a personal data breach to the data subject (opens in a new tab) Prosecution
  • Notify affected individuals of high‑risk data breachesData Controller
  • Notify data subjects of high‑risk personal data breachesData Controller
  • Tell people if their personal data has been breached and poses a high riskData Controller

Unlimited fine

s.035 Data protection impact assessment (opens in a new tab) Prosecution
  • Carry out a Data Protection Impact Assessment (DPIA) before high‑risk processingData Controller
  • Carry out data protection impact assessments (DPIAs)Data Controller

Fine up to £17,500,000

s.036 Prior consultation (opens in a new tab) Prosecution
  • Consult ICO before carrying out high‑risk data processingData Controller
  • Consult ICO before high‑risk processing and supply required informationData Controller

Fine up to £17,500,000

s.037 Designation of the data protection officer (opens in a new tab) Prosecution
  • Appoint a Data Protection Officer and publish their contact detailsEmployer
  • Appoint a Data Protection Officer (DPO) if specific criteria are metData Controller
  • Appoint a Data Protection Officer (DPO) when requiredEmployer
  • Appoint and publish a Data Protection Officer (DPO)Data Controller
  • Designate a Data Protection Officer (DPO) if thresholds are metData Controller

Unlimited fine

s.038 Position of the data protection officer (opens in a new tab) Prosecution
  • Ensure independent, adequately resourced DPO reporting to senior managementEmployer
  • Ensure the Data Protection Officer is independent and properly supportedData Controller
  • Give the Data Protection Officer independence, resources and senior reportingData Controller
  • Give the DPO independence, resources and top‑level reportingData Controller
  • Maintain an independent and well‑resourced Data Protection OfficerData Controller
  • Maintain independence and support for your Data Protection OfficerEmployer
  • Support and maintain independence of your data protection officerEmployer
  • Support and protect your Data Protection Officer (DPO)Employer

Fine up to £17,500,000

s.039 Tasks of the data protection officer (opens in a new tab) Prosecution
  • Appoint a Data Protection Officer and ensure they fulfill core dutiesData Controller
  • Ensure data protection officer carries out required tasksData Controller
  • Ensure DPO carries out advisory, monitoring and ICO liaison dutiesAny Person
  • Ensure your Data Protection Officer carries out key data protection dutiesData Controller
  • Ensure your Data Protection Officer performs prescribed GDPR tasksData Controller

Fine up to £17,500,000

s.040 Codes of conduct (opens in a new tab) Regulated
  • Adopt and follow an approved data‑protection code of conductData Controller
  • Prepare and submit data‑protection codes of conduct for ICO approvalAny Person
  • Adhere to an approved code of conduct by making binding commitmentsData Controller
  • Adopt a UK GDPR code of conduct and commit to its safeguardsData Controller
  • Adopt a GDPR‑approved code of conduct for data handlingData Controller
Other duties (1) — Crown / regulator
  • ICO must encourage and approve industry codes of conductStatutory regulator
s.042 Certification (opens in a new tab) Prosecution
  • Obtain and maintain data‑protection certification (if you choose to)Data Controller
  • Provide information and access for data‑protection certificationData Controller
  • Provide information to certification body for data‑protection certificationData Controller
  • Apply for and keep a voluntary data‑protection certificationData Controller
  • Provide information to certification bodies when seeking GDPR certificationData Controller
  • Provide information to data protection certification bodiesData Controller

Fine up to £17,500,000

s.043 Certification bodies (opens in a new tab) Prosecution
  • Accredit and run a certified data‑protection compliance bodyAny Person
  • Certification bodies must meet strict standards to issue GDPR certificatesData Controller
  • Obtain and maintain accreditation for data‑protection certification bodiesAny Person
  • Maintain accredited certification body status and processesAny Person

Fine up to £17,500,000

s.046 Transfers subject to appropriate safeguards (opens in a new tab) Regulated
  • Use appropriate safeguards for international data transfersData Controller
s.050 International cooperation for the protection of personal data (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must cooperate internationally to enforce data protectionStatutory regulator
s.052 Independence (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must act with complete independenceStatutory regulator
s.057 Tasks (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must monitor, enforce, and support UK GDPR complianceStatutory regulator
s.083 General conditions for imposing administrative fines (opens in a new tab) Regulated
Other duties (1) — Crown / regulator
  • ICO must ensure data protection fines are fair and effectiveStatutory regulator
s.084 Penalties (opens in a new tab) Prosecution
  • Infringe UK GDPR information obligations (Article 14)Data Controller

Unlimited fine

s.art022 Restrictions on automated decision-making Prosecution
  • Do not rely solely on automated decisions using special‑category dataData Controller
  • Ensure lawful use of automated decisions with special personal dataData Controller
  • Restrict automated decisions on special category dataData Controller
  • Restricted use of sensitive data for automated decisionsData Controller
  • Restrict fully automated decisions using sensitive personal dataData Controller

Fine up to £17,500,000

s.art022 Safeguards for automated decision-making Prosecution
  • Implement safeguards for automated decision‑makingData Controller
  • Provide safeguards for automated decisions affecting individualsData Controller
  • Provide safeguards for significant automated decisionsData Controller
  • Put safeguards in place for fully automated decisions that affect individualsData Controller
  • Put safeguards in place for significant automated decisionsData Controller

Fine up to £17,500,000

s.art044 General principles for transfers Prosecution
  • Ensure international data transfers comply with UK GDPRData Controller
  • Ensure lawful international transfers of personal dataData Controller
  • Ensure lawful transfers of personal data overseasData Controller
  • Ensure legal grounds before transferring personal data abroadData Controller
  • Transfer personal data abroad only with appropriate safeguardsData Controller

Fine up to £17,500,000

s.art045 Transfers approved by regulations: monitoring Regulated
Other duties (1) — Crown / regulator
  • Secretary of State must monitor and update approved data transfer listsCrown / Minister / Government department
s.art084 Additional requirements when processing for RAS purposes Prosecution
  • Process personal data for RAS only if necessary and with safeguardsData Controller
  • Process personal data for RAS only with justification and safeguardsData Controller
  • Process personal data for research/statistics only with safeguardsData Controller

Fine up to £17,500,000

82 other provisions — procedural and definitional
s.appropriate safeguards Appropriate safeguards
s.appropriate safeguards: further provision Appropriate safeguards: further provision
s.art008 Child’s consent in relation to information society services: age verification
s.automated processing and significant decisions Automated processing and significant decisions
s.further provision about automated decision-making Further provision about automated decision-making
s.further provision about processing of special cate Further provision about processing of special categories of personal data
s.meaning of “applicable time period” Meaning of “applicable time period”
s.periods of time Periods of time
s.processing and national security and defence Processing and national security and defence
s.purpose limitation: further processing Purpose limitation: further processing
s.regulations made by secretary of state Regulations made by Secretary of State
s.research, archives and statistics Research, archives and statistics
s.restriction in the public interest Restriction in the public interest
s.the data protection test The data protection test
s.transfers approved by regulations Transfers approved by regulations
s.transfers subject to appropriate safeguards: furth Transfers subject to appropriate safeguards: further provision

Help complying

Guvnor’s practical routes through this instrument.

Marketing compliance: PECR and UK GDPR

Learn how to send compliant marketing emails, texts, and make telephone calls. Covers PECR consent rules, the soft opt-in exception, TPS screening, …

Comply with the Online Safety Act from scratch

A complete learning path for platform operators new to the Online Safety Act 2023. Covers understanding the Act, determining scope and platform …

Respond to a data breach

Step-by-step breach response when personal data has been compromised. Covers the 72-hour ICO notification deadline, assessing risk, notifying affected individuals, and documenting …

Data breach 72-hour checklist

Emergency checklist when you discover a personal data breach. Covers immediate containment, the 72-hour ICO notification rule, when to notify affected individuals, …

Start using AI responsibly in your business

End-to-end learning path for businesses adopting AI: understanding the regulatory landscape, assessing obligations, setting up governance, managing specific risks around data, bias, …

AI compliance quick check

Rapid AI compliance self-assessment: identify AI systems, map to regulators, flag critical obligations, confirm key safeguards in place.

AI compliance checklist

Quick verification checklist covering all major AI compliance obligations. Use this checklist to confirm your business meets its data protection, equality, transparency, …

AI transparency and explainability obligations

What transparency and explainability mean for AI systems and how to meet the obligations. Covers UK GDPR requirements for automated decision-making, ICO …

Assess your AI compliance obligations

Step-by-step guide to assessing what AI compliance obligations apply to your business. Covers inventorying AI systems, identifying personal data processing, mapping to …

Carry out a data protection impact assessment (DPIA)

How to carry out a data protection impact assessment under UK GDPR Article 35. Covers when a DPIA is legally required, the …

Create a data retention policy

How to write and implement a data retention policy that satisfies the UK GDPR storage limitation principle. Covers what to include, how …

Data Use and Access Act 2025: what changed for businesses

What the Data (Use and Access) Act 2025 means for UK businesses. Explains the eight key reforms now in force, including recognised …

Data protection annual compliance checklist

Annual checklist for verifying your data protection compliance. Covers ICO fee renewal, privacy notices, records of processing, breach procedures, staff training, DPIAs, …

Data protection for businesses

How to comply with UK GDPR and the Data Protection Act 2018. Covers ICO registration, lawful bases for processing, data subject rights, …

33 more guides that reference this instrument

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.