Compliance · GDPR
UK GDPR & data protection
UK GDPR and the Data Protection Act 2018 set obligations you have to meet and, just as importantly, be able to evidence. There is no GDPR certificate, so accountability is the proof.
What it is
A legal obligation, not a certification.
UK GDPR sits alongside the Data Protection Act 2018 to form the UK data protection regime, regulated by the Information Commissioner’s Office (ICO). The EU GDPR applies separately where you offer goods or services to people in the EU, or monitor their behaviour, so plenty of UK organisations answer to both.
There is no such thing as a GDPR certificate, and nobody can issue you one. What the law asks for is accountability: being able to demonstrate, through records, decisions and evidence, that your processing is lawful and your controls work. That is a different exercise from a certification audit, and we treat it as one.
What is changing
The Data (Use and Access) Act 2025 is still landing.
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends UK data protection law. Its provisions are being switched on in stages, through commencement regulations that have taken effect at points during 2026, so what applies to you depends partly on when you look.
This is a moving area and we do not ask clients to take a snapshot on trust. We track the commencement position as part of the programme, flag what it changes for your processing, and point you to the ICO’s published guidance for the authoritative current detail.
What good looks like
What you should be able to show on request.
- A record of processing activities (ROPA) that reflects what the organisation actually does
- A documented lawful basis for each activity, matched by the privacy information you publish
- Data protection impact assessments completed before high-risk processing starts, not after
- Retention schedules, and deletion that demonstrably happens
- Due diligence, contracts and transfer assessments covering processors and sub-processors
- A breach process that can assess and report a qualifying personal data breach to the ICO within 72 hours
- Evidence that information rights requests are recognised and answered in time
How we help
Readiness and accountability you can evidence.
We do not claim to make anyone GDPR compliant: that is a legal position, and it depends on how you operate every day. What we do is close the gaps, build the evidence and keep it current, so your accountability position holds up when a client, an auditor or the ICO asks.
- Gap assessment against UK GDPR and the Data Protection Act 2018, and against EU GDPR where you are in scope
- Documentation built to be used: ROPA, DPIAs, retention schedules, privacy information and policies
- Supplier and processor due diligence, contract clauses and international transfer assessments
- Breach readiness: roles, reporting thresholds and rehearsal against the 72-hour clock
- Continuous compliance monitoring, so the record stays current between reviews rather than ageing quietly
- Where a client wants independent assurance, ISO 27001 or ISO 27701 certification delivered through certified assessment partners
Would your data protection position survive scrutiny?
Tell us what you process and where. We’ll show you the gaps honestly, and what it takes to close them.
Book a call