ChecklistSecurityPDF · 460 KB

GDPR Compliance Checklist

Ensure your data handling meets UK GDPR requirements — lawful basis, consent, data subject rights, breach notification, and record keeping.

About This Resource

UK GDPR compliance is a legal obligation for every business that processes personal data. This checklist provides UK businesses with a practical, actionable framework for verifying compliance across lawful basis for processing, consent management, data subject rights fulfilment, breach notification procedures, and record-keeping obligations. It helps you identify gaps in your current data handling practices and take corrective action before they become regulatory issues.

What's Included

  • Lawful basis assessment for each data processing activity
  • Consent management verification and audit trail checks
  • Data subject rights fulfilment procedures and response timelines
  • Data breach notification process and ICO reporting requirements
  • Record of processing activities template and review schedule
  • Data protection impact assessment triggers and process

Who Is This For?

Data protection officers, compliance managers, and business owners at UK businesses who need to verify and maintain UK GDPR compliance across their data processing activities.

Frequently asked questions

The ICO can fine up to £17.5 million or 4% of global annual turnover, whichever is higher, for the most serious breaches, though most enforcement action against SMEs involves warnings and improvement notices rather than maximum fines. Reputational damage from a publicised breach often costs more than any penalty.

Yes — there is no small business exemption, and any organisation processing personal data of UK individuals must comply regardless of size. The obligations scale with risk, so a five-person business handling only staff and customer contact details faces lighter requirements than one processing sensitive data at volume.

UK GDPR requires one of six lawful bases for every processing activity — consent, contract, legal obligation, vital interests, public task, or legitimate interests. Most SME marketing activity relies on consent or legitimate interests, and getting the basis wrong is one of the most common compliance gaps found in audits.

Work through your lawful basis for each processing activity, verify consent records and data subject rights procedures are documented, and confirm a breach notification process exists that meets the 72-hour ICO reporting window. This checklist covers each of these areas with a practical review framework.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

3
  • IT Office Moves

The Hidden Costs of an Office Move: A UK Business Guide to Budgeting for IT Relocation in 2026

3 Sep, 2026

Almost every office move IT budget we see arrives at the same shape: a removals quote, a furniture allowance, a signage line, a contingency of ten per cent,...

Read more
2
  • IT Support

IT Support Response Times: A UK Business Guide to Setting SLAs That Actually Match Your Risk in 2026

2 Sep, 2026

An IT support SLA is the only part of a managed service contract that tells you what happens on the worst day of your year, and it is routinely the least...

Read more
1
  • Microsoft 365 Copilot

Microsoft 365 Copilot Data Security: A UK Business Guide to Controlling What Copilot Can See in 2026

1 Sep, 2026

Copilot data security is not a Copilot problem. It is a permissions problem that Copilot makes impossible to ignore. Microsoft 365 Copilot has no private...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.