UK Information Commissioner's Office (ICO)

UK General Data Protection Regulation (UK GDPR)

In force since 1 January 2021

Agent Navigation: For section discovery, use /regulations/uk/gdpr/llms.txt

Quick Reference

The UK GDPR governs processing of personal data in the UK. Applies to any organisation processing personal data of UK residents, regardless of where the organisation is based.

Applies to: All organisations processing personal data of UK individuals

Key rules:

  • Must have a lawful basis before processing personal data [Art 6]
  • Must respect data subject rights (access, erasure, portability, etc.) [Arts 15-22]
  • Must implement appropriate security measures [Art 32]
  • Must notify ICO of breaches within 72 hours [Art 33]
  • Must restrict international transfers unless adequate safeguards [Arts 44-49]
QuestionAnswerCitation
Always need consent?No, 6 lawful basesArt 6(1)
Can process without asking?Yes, if lawful basis appliesArt 6
How long to respond to access request?1 monthArt 12(3)
When must I report a breach?72 hours to ICOArt 33(1)
Maximum fine?£17.5M or 4% global turnoverArt 83
Need a DPO?If public body or large-scale processingArt 37

Regulation Map (All Chunks)

Every section of the UK GDPR coverage is listed here for full-text lookup and agent navigation.

Definitions

Core Chunks

Requirements

Enforcement

Official Sources

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt