Tips on Demonstrating UK GDPR Compliance

|
|
|
PUBLISHED on
22
July
2022
SUMMARY

The easy way (if it was available!) would be to certify to an approved UK GDPR certification scheme.  The Data Protection Act 2018 gave the UK’s privacy regulator, the Information Commissioner’s Office (ICO), the power to accredit providers of certification schemes for demonstrating compliance with the UK GDPR.  Unfortunately, a widely-applicable certification scheme, applicable to different types and sizes of UK organisations, still does not exist.  In August 2021, the ICO did approve 3 certification schemes, however, these were for quite specific purposes: IT asset disposal, age assurance and age-appropriate design.

Back in 2017/18, we saw many organisations creating a ‘task force’ or project team to address GDPR compliance in the run-up to the May 2018 deadline.  Most of these organisations typically disbanded their taskforce teams once they felt that compliance had been achieved, although some appointed a responsible data protection manager/DPO or compliance officer.  As with other compliance activities, we appreciate how difficult it is to maintain ‘good intentions’ as other business pressures/requirements take centre stage.  Equally, when the GDPR was launched, there was limited guidance available and, with the goalposts now having shifted slightly, some organisations may find that they are not as compliant as they originally thought.

What we do have now, is a British Standard, namely BS 10012, which provides a best practice framework for a personal information management system.   Whilst not an international standard, such as ISO 27001, or a complete model for the UK GDPR compliance, BS 10012 is aligned to the principles of the GDPR and a good starting point. However, this is not a quick (in the next few months type!) solution.

So, what can you do now to demonstrate UK GDPR compliance?  A very practical approach is to arrange an external audit by an experienced GDPR/DP practitioner.  If structured correctly, this will not only verify your compliance status, but will provide you with valuable advice and insight into good practices adopted by other organisations.

A valuable UK GDPR compliance audit is not all about the DP/UK GDPR rules, it’s also about ensuring you are complying with your own policies, processes, and procedures i.e., the measures you put in place to establish UK GDPR compliance in the first place.

Here are some questions which should help you in determining your level of compliance with the GDPR

  • Are you complying with your policies?
  • Have you reviewed consent mechanism?
  • Have you continued to evaluate third parties and their contractual conditions?
  • Have you maintained your register of processing activities?
  • Has your business changed at all and are your lawful grounds for processing still valid?
  • Have you reviewed your data flows in line with any chances?
  • Have you maintained your DPIA records and are you conducting DPIAs as and where required?
  • Do you nave an effective mechanism in place for dealing with subject access requests?

Do you need assistance in improving your GDPR compliance position?

URM can offer a host of consultancy services to improve your DP policies, privacy notices, DPIAs, ROPAs, data retention schedules and training programmes etc.
Thumbnail of the Blog Illustration
Data Protection
Published on
22/7/2022
Tips on Demonstrating UK GDPR Compliance

We provide some questions which should help you in determining your level of compliance with the GDPR

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
5/3/2026
Data Protection Interpretation Affirmed by the Court of Appeal in DSG Retail Case

URM’s blog unpacks the DSG vs. ICO case, how it reached the Court of Appeal, & the Court’s decision on the status of pseudonymised data in the hands of attacker

Read more
Thumbnail of the Blog Illustration
Data Protection
Published on
14/12/2023
Conducting Data Transfer Impact Assessments (DTIAs)

URM answers key questions around data transfer impact assessments (DTIAs), providing detailed guidance on the best practice approach to conducting them.

Read more
It’s one thing having the required technical knowledge, it’s another thing for a consultant to apply that knowledge to the context of our organisation. To use a sporting analogy, we view cyber and information security as a marathon not a sprint. I am not a believer in doing everything all at once. Our approach has been risk based and incremental, remediating our biggest risks first before moving on. I believe this approach is far more sustainable and effective. And URM’s consultants fully understand this and are very pragmatic and tailored in their guidance and advice. They know we are not implementing ISO 27001 purely for the certificate, but more as a framework for continual improvement, and at a pace where new systems and processes can be fully understood and absorbed by our team and be business as usual.
The Owners and Distributors of Quality Brands
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.