> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# UK GDPR

> Comply with the United Kingdom's data protection regime following Brexit.

> Comply with the United Kingdom's data protection regime following Brexit.

The UK GDPR is the United Kingdom's implementation of data protection law following its exit from the EU. It sits alongside the Data Protection Act 2018 and mirrors the EU GDPR closely, with the Information Commissioner's Office (ICO) as the supervisory authority.

<Note>
  Organizations offering goods or services to individuals in the UK, or monitoring their behavior, must comply with UK GDPR regardless of where the organization is based.
</Note>

## Who needs UK GDPR?

<CardGroup cols={2}>
  <Card title="UK-facing businesses" icon="flag">
    Any organization processing the personal data of individuals in the UK.
  </Card>

  <Card title="EU businesses with UK operations" icon="globe">
    Organizations subject to both EU GDPR and UK GDPR must comply with each separately.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Lawful basis" icon="scale-balanced">
    Establish and document a lawful basis for every processing activity.
  </Card>

  <Card title="Data subject rights" icon="user-shield">
    Honor access, erasure, rectification, portability, and objection rights.
  </Card>

  <Card title="ICO accountability" icon="landmark">
    Maintain records of processing and demonstrate compliance to the ICO.
  </Card>

  <Card title="Breach notification" icon="bell">
    Report qualifying breaches to the ICO within 72 hours.
  </Card>
</CardGroup>

## How DSALTA helps with UK GDPR

<Steps>
  <Step title="Activate UK GDPR">
    Select UK GDPR from the Frameworks page. DSALTA maps requirements to privacy controls.
  </Step>

  <Step title="Review privacy controls">
    Review controls for lawful basis, rights handling, and breach response.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to maintain records of processing and access evidence.
  </Step>

  <Step title="Approve privacy policies">
    Review and approve AI-generated UK-specific privacy notices.
  </Step>

  <Step title="Maintain accountability">
    Track your records of processing activities (ROPA) and DPIAs.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How is UK GDPR different from EU GDPR?" icon="code-compare">
    They are very similar in substance. The main differences are jurisdictional — the ICO is the regulator, and UK adequacy and international transfer rules differ slightly.
  </Accordion>

  <Accordion title="Do I need both EU and UK GDPR?" icon="globe">
    If you process personal data of individuals in both the EU and the UK, you must comply with both regimes.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
