GDPR Compliance: A Comprehensive Implementation Guide
GDPR compliance for UK businesses requires more than a privacy policy. This guide covers the practical steps: data mapping, appointing a DPO if required, documenting processing activities, implementing technical controls, and building a breach response capability.
AMVIA Team
Editorial
Most SMEs treat UK GDPR as a paperwork exercise and miss the part that actually triggers fines: weak security. The largest UK enforcement actions in recent years followed cyber attacks, not missing privacy notices. This guide walks through the seven steps that take an organisation from "we have a policy somewhere" to genuinely defensible. For the technical controls behind it, see our managed cybersecurity service.
UK GDPR after Brexit: what actually changed?
Very little of substance. Since leaving the EU, UK organisations follow the UK GDPR, retained in domestic law through the Data Protection Act 2018 and enforced by the Information Commissioner's Office (ICO). The data subject rights, lawful bases, controller and processor obligations, and breach rules mirror the EU regulation closely.
The practical divergence to watch is the UK government's ongoing data protection reform agenda, which may adjust some obligations over time. Organisations operating in both the UK and EU must still comply with both frameworks where each applies. If you handle EU residents' data, EU GDPR has not gone away.
Step 1: How do you map your data and build a RoPA?
Start by understanding what personal data you hold, where it came from, how it is used, who it is shared with, and where it is stored. That exercise is data mapping, and its output — a Record of Processing Activities (RoPA) — is a legal requirement for most organisations under Article 30 of UK GDPR.
A RoPA records, for each processing activity:
- The purpose of processing and the lawful basis
- Categories of personal data processed
- Categories of data subjects (employees, customers, suppliers)
- Recipients — internal and external — with access to the data
- Transfers outside the UK or EU, and the safeguards in place
- Data retention periods
- Technical and organisational security measures
Data mapping is harder than it looks. Personal data sits in CRM systems, email archives, shared drives, HR and finance platforms, paper records, and a growing sprawl of cloud services. Interview department heads and review system inventories — a half-mapped estate is a half-protected one.
Step 2: How do you choose a lawful basis for processing?
Every processing activity needs a documented lawful basis. UK GDPR provides six: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The right one depends on the nature of the processing and your relationship with the data subject — and you should fix it before processing, not justify it afterwards.
Many organisations reach for consent by default. That is usually the wrong call: consent must be freely given, specific, informed, unambiguous, and as easy to withdraw as to give. Where you process data to fulfil a contract or meet a legal obligation, those bases are more appropriate and more durable.
| Lawful basis | Best fit for | Watch out for |
|---|---|---|
| Consent | Marketing to new prospects, optional cookies | Must be withdrawable; weak for core operations |
| Contract | Fulfilling orders, employment, service delivery | Only covers what the contract needs |
| Legal obligation | Tax, HR, statutory reporting | Must point to the actual law |
| Legitimate interests | B2B marketing, fraud prevention, IT security | Requires a documented balancing test |
Legitimate interests — processing necessary for your interests, balanced against the individual's rights — is the workhorse for B2B marketing, fraud prevention, and securing your systems.
Step 3: What does a compliant privacy notice need?
UK GDPR requires you to tell data subjects what data is collected, why, how long it is kept, who it is shared with, and what rights they have. That information must be given at the point of collection, in clear and plain language. A notice buried in a footer fails the transparency test if real people cannot find or read it.
Write it for the individual, not the regulator. Layered notices — a short summary linking to full detail — work well for web forms and onboarding flows where attention is short.
Step 4: What technical and organisational security does Article 32 demand?
Article 32 of UK GDPR requires "appropriate" technical and organisational measures to protect personal data. The ICO judges appropriateness against the risk, the state of the art, and the cost of implementation. In plain terms: the more sensitive the data, the stronger the controls.
Article 32 explicitly names:
- Pseudonymisation and encryption where appropriate to the risk
- Ongoing confidentiality, integrity and availability of processing systems
- The ability to restore data in a timely manner after an incident
- Regular testing and evaluation of security measures
In practice the ICO expects to see least-privilege access controls, encryption of personal data at rest and in transit, MFA on systems holding personal data, prompt patching, and a tested backup and recovery capability. The ICO's personal data breach guidance maps cleanly onto these obligations.
Cyber Essentials gives you a documented baseline of five technical controls that demonstrates a systematic approach to Article 32. AMVIA holds Cyber Essentials Plus and builds the same control set — Microsoft Defender, MFA, conditional access, and tested backup — for clients. See Microsoft 365 security for how those controls are delivered across the Microsoft estate, and GDPR cybersecurity compliance for the full control mapping.
Step 5: When do you need a Data Protection Impact Assessment (DPIA)?
A DPIA is required when processing is likely to result in a high risk to individuals — for example large-scale processing of special category data, systematic monitoring of employees, or deploying new technologies that affect personal data. The DPIA identifies and scores risks to people's rights and documents how you will mitigate them.
Even where it is not strictly required, run a DPIA when introducing new systems, materially changing how existing data is processed, or adopting technologies like AI tooling that touch personal data. It is far cheaper to find the problem on paper than in production.
Step 6: How do you meet the 72-hour breach notification rule?
Personal data breaches likely to result in a risk to individuals must be reported to the ICO within 72 hours of discovery. Breaches posing a high risk must also be communicated directly to the people affected. Meeting that clock needs a documented incident response procedure, clear escalation paths, and pre-prepared notification templates.
The 72 hours start when you become aware of the breach — not when the investigation finishes. You can submit an initial notification with limited detail and follow up as you learn more. Missing the window without good reason is itself an infringement that can attract ICO sanctions. This is why a tested incident response capability is a GDPR control, not just an IT one.
Step 7: How do you handle data subject rights requests?
UK GDPR grants individuals rights including access (subject access requests), rectification, erasure, restriction, data portability, and the right to object. You must respond within one calendar month. Build a standard intake process and a request log now — scrambling to answer a SAR under deadline is how mistakes and complaints happen.
Keep a log of every request received and how it was handled. It supports your accountability obligations and gives you evidence if a complaint reaches the ICO.
Why security failures, not paperwork, drive the biggest fines
The pattern in recent UK enforcement is clear: serious financial penalties have followed cyber attacks and data losses, not missing privacy policies. The largest UK data protection fines of 2024–2025 followed security-related breaches after cyber attacks, not missing privacy notices. Capita faced a reported ICO fine of around £14 million for data loss following its 2023 cyber attack, and in March 2025 the ICO fined Advanced Computer Software Group Ltd £3.07 million for data loss following a 2022 ransomware attack.
The lesson for SMEs: GDPR compliance and cybersecurity are the same project. Strong phishing defences, endpoint protection, and monitoring are not "nice to have" alongside your RoPA — they are the controls Article 32 demands. Weak phishing protection is now a direct route to a reportable breach.
Do Your Technical Controls Meet UK GDPR Requirements?
UK GDPR requires appropriate technical measures to protect personal data. AMVIA can assess your current technical controls and implement the ones the ICO expects to see.
Frequently Asked Questions
Yes. UK GDPR applies to organisations of any size that process personal data in the UK, or process data about individuals in the UK. Narrow exemptions exist for purely household activity, but virtually every business — including sole traders and micro-businesses — holds customer, employee or supplier data and is therefore subject to UK GDPR.
A controller decides the purposes and means of processing; a processor acts on the controller's instructions. Most businesses are controllers for their own customer and employee data, but become processors when handling data on behalf of clients. Controllers carry the primary obligations; processors have specific duties under Article 28 of UK GDPR.
The ICO can fine up to £17.5 million or 4% of global annual turnover (whichever is higher) for the most serious infringements, and up to £8.7 million or 2% of turnover for lesser violations. In practice it is proportionate — SMEs making genuine compliance efforts are more likely to face enforcement notices and smaller fines than headline penalties.
A DPO is mandatory only for public authorities, organisations carrying out large-scale systematic monitoring, or those processing special category data at large scale. Most SMEs have no mandatory requirement, but appointing a data protection lead — internally or via a third party — is good practice and supports your accountability obligations.
A personal data breach is any security breach leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data. That includes emailing the wrong recipient, losing a USB drive, a ransomware attack that encrypts personal data, or an employee exporting customer records without authority.
Related Reading
GDPR Cybersecurity Compliance
The specific technical cybersecurity measures required to meet UK GDPR's Article 32 obligations.
ISO 27001 Cybersecurity: UK Implementation Guide
How ISO 27001 provides the information security management framework that supports GDPR compliance.
Cybersecurity Insurance
How strong data protection and cybersecurity controls support cyber insurance applications.
Protect your business → Get Cybersecurity Assessment