What GDPR compliance means
GDPR compliance means an organisation can prove it meets every obligation under the UK General Data Protection Regulation or the EU General Data Protection Regulation. It is not a one-time certification — it is an ongoing demonstration that personal data is handled lawfully, fairly, transparently and securely.
The UK GDPR has applied since 1 January 2021 (the post-Brexit retained version of the EU GDPR), and was updated by the Data Protection and Digital Information Act 2026. The EU GDPR continues to apply directly in EU/EEA member states.
The 7 GDPR principles
Article 5 of the UK and EU GDPR sets out seven principles that govern every processing activity:
- Lawfulness, fairness & transparency. Process personal data lawfully, fairly and in a transparent manner.
- Purpose limitation. Collect data for specified, explicit and legitimate purposes — and only use it for those.
- Data minimisation. Hold only what is adequate, relevant and limited to what is necessary.
- Accuracy. Keep personal data accurate and, where necessary, kept up to date.
- Storage limitation. Keep data in identifiable form only as long as necessary.
- Integrity & confidentiality. Protect data with appropriate technical and organisational security measures.
- Accountability. Be responsible for, and able to demonstrate, compliance with the other six principles.
The seventh — accountability — is the meta-principle: you must be able to demonstrate compliance with the other six through documentation, training records, DPIAs and audit trails.
Lawful bases for processing
You cannot process personal data without a lawful basis. Article 6 provides six:
- Consent — freely given, specific, informed, unambiguous opt-in
- Contract — necessary to perform a contract with the data subject
- Legal obligation — required by UK or EU law
- Vital interests — necessary to protect someone's life
- Public task — necessary in the public interest or for an official function
- Legitimate interests — pursued by the controller, subject to a balancing test
Special category data (health, biometrics, race, religion, political views, sexual orientation, genetics, trade union membership) needs an additional Article 9 condition. Choose the basis before you start processing, and document it — switching basis later is rarely permissible.
Data subject rights
Articles 12–22 give individuals eight rights you must operationalise:
- The right to be informed (privacy notices)
- The right of access (Subject Access Requests)
- The right to rectification of inaccurate data
- The right to erasure ("right to be forgotten")
- The right to restriction of processing
- The right to data portability
- The right to object
- Rights related to automated decision-making and profiling
You generally have one calendar month to respond, extendable by two further months for complex requests. Failures here are upper-tier fining territory.
DPIA requirements
A Data Protection Impact Assessment is required under Article 35 whenever processing is likely to result in a high risk to data subjects. The ICO mandates DPIAs for:
- Systematic large-scale monitoring of public areas
- Large-scale processing of special category data
- Profiling that produces legal or similarly significant effects
- Innovative use of new technologies (including AI applied to personal data)
- Combining datasets in ways individuals would not expect
If a DPIA shows high residual risk you cannot mitigate, you must consult the ICO before processing.
Penalties and fines
The GDPR uses a two-tier fine structure:
- Lower tier: up to £8.7m / €10m or 2% of global turnover — for procedural failures (records, breach notification, DPIA, security)
- Upper tier: up to £17.5m / €20m or 4% of global turnover — for breaches of the data protection principles, lawful basis or data subject rights
The largest fine to date is Meta's €1.2 billion in 2023 for unlawful US data transfers. See how the maximum fine is calculated and what the largest 2025 fines teach us.
UK GDPR vs EU GDPR
The substantive rules are largely the same. The practical differences:
- Regulator: ICO in the UK; the relevant national DPA (often Ireland) in the EU
- Maximum fine cash cap: £17.5m (UK) vs €20m (EU)
- International transfers: UK uses the IDTA or the UK Addendum to the EU SCCs
- Adequacy: The EU has a UK adequacy decision (renewed in 2025) — data flows freely both ways
- The DPDI Act 2026: simplifies UK SAR thresholds, cookie consent and DPO requirements
The 12-step GDPR compliance checklist
This is the working checklist we recommend for organisations starting or refreshing their programme. For a small-business specific version, see our GDPR checklist for UK small businesses.
- Complete a data inventory mapping every processing activity
- Assign a lawful basis under Article 6 (and Article 9 for special category)
- Publish a clear, plain-English privacy notice
- Implement a cookie consent banner with a genuine reject option
- Document a process for Subject Access Requests within 1 month
- Sign Data Processing Agreements with every processor
- Use the UK IDTA or SCCs for international transfers
- Enforce MFA, encryption, least-privilege access and tested backups
- Maintain a breach response plan with 72-hour ICO notification
- Run DPIAs for high-risk processing (AI, monitoring, profiling)
- Appoint a DPO or data protection lead and train every staff member
- Review the programme at least annually
How DataDoc automates GDPR compliance
DataDoc analyses your existing policies, procedures and contracts against the UK GDPR, EU GDPR and ICO guidance, then tells you exactly which checklist items you have covered, which need wording fixes, and which are genuinely missing. It generates audit-ready reports, tracks changes over time, and helps you respond to RFPs and vendor due diligence faster.
Gap analysis
Map your documents to UK GDPR articles in minutes.
Policy generator
Generate context-aware privacy policies and DPAs.
Continuous monitoring
Real-time alerts when regulations or your stack changes.
Frequently asked questions
What is GDPR compliance?
GDPR compliance means an organisation meets all obligations under the UK GDPR or EU GDPR — including establishing a lawful basis for processing personal data, honouring data subject rights, implementing appropriate security measures, conducting DPIAs for high-risk processing, and being able to demonstrate accountability through documentation.
Who needs to be GDPR compliant?
Any organisation that processes the personal data of UK or EU residents, regardless of where the organisation is based. This includes controllers (who decide why and how data is processed) and processors (who handle data on a controller's behalf).
What is the maximum fine for GDPR non-compliance?
Up to £17.5 million or 4% of annual global turnover (whichever is higher) in the UK, and up to €20 million or 4% of global turnover in the EU. The maximum applies only to the most serious infringements such as breaching the data protection principles or processing without a lawful basis.
What is the difference between UK GDPR and EU GDPR?
The UK GDPR is the UK's domestic version of the EU GDPR, retained after Brexit. The substantive rules are nearly identical, but the regulator (ICO instead of EU DPAs), international transfer mechanisms (UK IDTA instead of EU SCCs), and the Data Protection and Digital Information Act 2026 amendments make practical compliance subtly different.
Do small businesses need to comply with GDPR?
Yes. There is no small-business exemption. The expectations are proportionate to the risk and scale of processing, but every business holding personal data — even just employee or customer records — must comply.
When is a DPIA required?
A Data Protection Impact Assessment is required whenever processing is likely to result in a high risk to data subjects — including large-scale processing of special category data, systematic monitoring of public areas, profiling that produces legal effects, and use of new technologies such as AI on personal data.
What are the seven GDPR principles?
Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability. Article 5 sets these out and the accountability principle requires controllers to be able to demonstrate compliance with the other six.
How long do I have to report a GDPR breach?
Controllers must notify the ICO within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals. If the risk is high, affected data subjects must also be informed without undue delay.
Do I need a Data Protection Officer (DPO)?
A DPO is mandatory for public authorities, organisations that carry out large-scale systematic monitoring of individuals, and those processing large-scale special category or criminal-conviction data. Other organisations may appoint one voluntarily — appointing a 'data protection lead' is good practice even when not required.
How long does it take to become GDPR compliant?
For a typical SME starting from scratch, a credible compliance baseline (data mapping, lawful bases, privacy notices, vendor DPAs, breach plan, training) takes 3–6 months. Compliance is then ongoing — annual reviews, incident handling, and updates as processing changes.
This is general guidance, not legal advice
DataDoc helps you operationalise GDPR compliance but does not replace tailored legal counsel for your specific processing activities.
Related GDPR resources
Complete Guide to GDPR Compliance
The deep-dive companion to this pillar.
GDPR Checklist for UK Small Business
Prioritised actions for SMEs.
Who is Responsible for GDPR Compliance?
Roles, accountability and the DPO.
Maximum Fine for GDPR Non-Compliance
How the two-tier fine system really works.
The Right to be Forgotten
When erasure applies and how to handle it.
Record GDPR Fines in 2025
What the biggest enforcement actions teach us.