Over £19.6 million in ICO fines in 2025 alone, a 7× increase. Penalties up to £17.5M or 4% of global revenue.Get compliant now →

    UK GDPR, without the parallel paperwork.

    Most teams in scope are in scope twice. Whisperly runs one privacy programme with a UK overlay, so compliance never doubles.

    app.whisperly.ai / data-privacy
    Back
    Employee HR Data Management
    UK GDPRApproved
    SM
    Created by
    Sarah Mitchell
    1
    Overview
    Controller info
    2
    Processing
    Data activities
    3
    Data Subjects
    Categories
    4
    Recipients
    Transfers
    Basic information
    Provide the name and organizational unit for the processing activity.
    Name *
    Employee HR Data Management
    Responsible organizational unit *
    Lexelerate

    ICO enforcement is accelerating sharply.

    Fines collected in 2025 were seven times the 2024 figure, and the share attributable to UK GDPR breaches rose from one sixth to two thirds. Security failures are the pattern.

    £14M

    Capita, 2025

    Issued for failing to secure the personal data of 6.6 million people ahead of a ransomware attack, the ICO's largest security-failure penalty of 2025.

    £3.07M

    Advanced Computer Software, 2025

    The first ICO fine issued to a processor. Missing MFA and weak patch management were the cited failures, so processors can no longer point upstream.

    Year on year increase

    More than £19.6 million collected in 2025, roughly seven times the 2024 figure. Enforcement capacity, not just appetite, has changed.

    UK GDPR vs EU GDPR, what actually changed?

    The principles, the rights and the lawful bases carried over almost unchanged. Everything that costs teams time sits in the gaps below.

    EU GDPR
    UK GDPR
    International transfers
    The most common compliance failure for dual-regime teams
    EU Standard Contractual Clauses
    IDTA, or EU SCCs with the UK Addendum. EU SCCs alone are not valid.
    Regulator
    Who you notify, and within what window
    Lead supervisory authority, one-stop-shop
    The ICO directly. No one-stop-shop, so a dual breach means two notifications.
    Subject access requests
    Changed by the DUAA 2025
    One month, extendable by two
    Same window, but the clock can be stopped while you seek clarification.
    Legitimate interests
    Where the balancing test applies
    Balancing test required in every case
    Recognised legitimate interests need no balancing test, and cookies gained new exemptions.
    Maximum penalty
    Two tiers in both regimes
    €20M or 4% of global turnover
    £17.5M or 4% of global turnover, with PECR fines now aligned to the same levels.
    Adequacy is renewed until 2031, and that is not a reason to relax.
    The European Commission renewed the UK adequacy decisions in December 2025, so EU to UK transfers continue without extra safeguards. Mature teams still keep transfer mechanisms documented as a fallback, because adequacy has been withdrawn before.
    Compare with EU GDPR

    Dual compliance is the new normal.

    Almost nobody is subject to the UK GDPR alone. The instinct is to stand up a second programme, and that is the mistake: you double the maintenance and guarantee the two versions drift apart. Run one core programme with jurisdiction overlays instead.

    Practice 01

    Tag every record by regime

    Each processing activity, assessment and vendor carries a UK, EU or both marker. One record satisfies either regulator, and a filter produces the pack the ICO asks for.

    Practice 02

    Modularise your privacy notices

    Shared clauses live once; jurisdiction-specific blocks sit in their own modules. A DUAA cookie change updates the UK notice without touching the EU one, and version history shows which regime each edit affected.

    Practice 03

    Keep one control set, two mappings

    A security measure or a DPIA template is documented once and mapped to both regimes. Where they genuinely diverge, such as transfer mechanisms, the platform holds the IDTA alongside the EU SCCs rather than forcing a choice.

    Practice 04

    Plan for two notifications

    There is no one-stop-shop across the Channel. A breach touching both populations means notifying the ICO and the relevant EU authority, on the same 72 hour clock, from one incident record and one evidence pack.

    The test of a dual programme is what happens when one regime moves.
    The DUAA arrived in 2025 and the EU will reform in its turn. With overlays, a change is scoped to the affected regime in an afternoon. With two parallel programmes, it is a project.
    See the EU GDPR page

    Four stages. One continuous programme.

    This is the dual-compliance model in practice: every record tagged by regime, so one control satisfies the UK and the EU at once and each output doubles as evidence for the ICO.

    01

    Document

    Records for controller and processor roles, tagged UK, EU or both, with privacy notices modularised so a UK change does not force an EU rewrite.

    Records of processingArt. 30
    Notices, cookie and DPA templatesArt. 13, 14
    Transfer mechanisms, IDTA and AddendumCh. V
    Automate your RoPA →
    02

    Assess

    Impact assessments on templates aligned to ICO guidance and the DPA 2018, with security measures synced back to the activities they protect.

    Impact assessments, ICO alignedArt. 35
    Technical and organisational measuresArt. 32
    Vendor and sub-processor riskArt. 28
    Automate your DPIAs →
    03

    Respond

    The obligations that arrive with a clock. DSAR intake with identity verification and DUAA stop-the-clock handling, and a 72 hour ICO notification workflow.

    Data subject requestsArt. 15 to 22
    ICO breach notificationArt. 33, 34
    Retention calendar and deletion alertsArt. 17
    Automate your DSARs →
    04

    Prove

    Kanban boards give each obligation an owner and a date, and every action is logged so an ICO enquiry is answered from the record rather than from memory.

    Live tracker and gap analysisArt. 5(2)
    Task boards and role-based accessArt. 24
    Public Trust CenterTransparency
    Launch your Trust Center →

    Headquarters are irrelevant to scope.

    The UK GDPR and the DPA 2018 follow the individual. If you process the personal data of people in the United Kingdom, you are in scope.

    Data controllers

    You set the purposes and means, and carry accountability for lawfulness, rights and notifying the ICO within 72 hours.

    Data processors

    Security measures, your own records and breach reporting all apply, and since 2025 the ICO fines processors directly.

    Non-UK organisations

    Offering goods or services to UK residents, or monitoring their behaviour, brings you in scope and requires a UK representative under Article 27.

    Public authorities

    A DPO is mandatory, DPIAs are required for high-risk processing, and transparency duties toward citizens are stricter.

    Frequently asked questions

    If you process personal data of people in both the UK and the EU, then yes. The practical approach is not two programmes but one core programme with jurisdiction overlays: tag every processing activity by regime, modularise privacy notices so a UK change does not force an EU rewrite, and maintain separate transfer mechanisms. Whisperly is built around that model, so a control documented once counts for both.

    One programme. Both regimes.

    Run UK and EU data protection as one programme with jurisdiction overlays, and answer either regulator from a record that is already current.