Frameworks · UK & Europe
UK GDPR & Data Protection Act compliance, run as a living system
The UK General Data Protection Regulation, read with the Data Protection Act 2018, governs the processing of personal data in the UK: lawful basis, accountability, data-subject rights, international transfers and breach notification to the supervisory authority within 72 hours.
Who it applies to
Controllers and processors established in the UK, and organisations outside the UK offering goods or services to, or monitoring, individuals in the UK.
What it demands
Accountability
Records of processing, data protection policies, DPIAs for high-risk processing and, where required, a data protection officer.
Rights
Access, rectification, erasure, portability and objection handled within statutory periods.
Transfers
Transfer mechanisms, the UK addendum and documented transfer risk assessments.
Breach
Notification to the supervisory authority within 72 hours where the threshold is met, and to individuals where required.
How Compli-Once runs it
- 1
The 72-hour clock is modelled inside the incident workflow beside every other jurisdictional deadline you carry.
- 2
ROPA, DPIAs and transfer assessments live as versioned artefacts with review dates and named owners.
- 3
Rights requests run as records with statutory deadlines, evidence of response and a defensible audit trail.
What you already satisfy
UK GDPR & Data Protection Act overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.
Implement once, satisfy many
In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.
Illustrative, computed live per tenant in the platform.
Frequently asked questions
What does UK GDPR require of a compliance programme?
Documented lawful basis and records of processing, DPIAs for high-risk processing, statutory handling of data-subject rights, controlled international transfers, and breach notification to the supervisory authority within 72 hours where the threshold is met.
How is the 72-hour breach clock handled?
It starts on the incident record at classification, with the owner, deadline and notification trail on the same record, so the submission is assembled from facts already captured.
Can UK and Indian privacy obligations share one programme?
Yes. Notice, retention, rights handling and security controls overlap substantially and are mapped by the crosswalk, so each is implemented once and reported per law.
Are DPIAs and transfer assessments tracked?
Yes, as living artefacts with owners, review dates and expiry, so a stale assessment raises a task rather than surfacing during an inspection.
