UK GDPR
A UK customer or hire is weeks away. Here is what comes first.
The UK representative decision, transfer tools, ICO registration, UK notices and contract clauses, written for your company and kept current in the platform after we hand over.
4 UK decisions, each with written reasoning and the record behind it
- UK representative (Article 27)
- Required; appointed in week 3
- Done
- Transfer routes out of the UK
- 5 routes, IDTA or UK Addendum in place
- 5 / 5
- ICO data protection fee
- Tier 1, registered
- Done
- UK notices and DPA clauses
- Customers, website, staff; DPA template
- 4 / 4
Who this is for
Companies outside the UK with UK customers, UK staff or a UK office.
A fit
- A US SaaS company with UK customers that has been asked by one of them for a UK GDPR-compliant data processing agreement.
- An EU company with an existing GDPR programme that opened a UK office or hired UK staff after Brexit.
- A company outside the UK and EU that sells to both and needs the two programmes aligned rather than duplicated.
Also a fit
- A company hiring its first UK employee and unsure what must exist before their data moves.
- A vendor whose UK customer's procurement team asked about the IDTA or the UK Addendum.
- A company that received an ICO fee reminder and does not know which tier applies.
Not a fit
- Companies that need a UK representative appointed. We help you decide under Article 27 and appoint one; we do not take the role.
- UK-established companies building a programme from scratch. That is the full GDPR implementation, adapted to UK law; ask on the call.
- Teams looking for a formal legal opinion only. The practising privacy lawyer on your project gives it; the implementation is the service.
What you walk away with
The UK-specific decisions and documents, or your EU programme extended to cover the UK.
Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.
UK GDPR compliance
9 deliverables, 4 to 6 weeksUK applicability and representative decision
With written reasoning under Article 3 and Article 27
- DOCX
Records of processing covering UK data subjects
Extended from your EU register where one exists
- CSV
UK privacy notices
Customers, website visitors, staff
- DOCX
- HTML
UK transfer assessment and transfer tools
IDTA or UK Addendum per route
- DOCX
UK data processing agreement template
With UK-specific clauses
- DOCX
Data subject request and breach procedures with UK deadlines
With request tracking
- Procedure
ICO fee assessment and registration checklist
Tier and how to register
Evidence that each document is in use
Linked to the record it supports
- Platform
Recorded hand-over and readiness sign-off
With whoever owns the programme afterwards
- Video
How it works
Six weeks to hand-over. Shorter if the EU programme exists.
Most documents are extended rather than written when an EU GDPR programme is already in place.
- GRCTrail
- Hand-over
- Without us
Week 0
Scoping call
UK customers, staff, entities; what exists in the EU programme. Written fixed price within 3 business days.
Weeks 1 to 2
Assessment
UK applicability analysis, review of the existing programme, gap analysis against UK GDPR and the Data Protection Act 2018. Implementation price confirmed.
Weeks 3 to 5
Implementation
Representative decision, records, notices, transfer tools, DPA template, procedures, ICO fee checklist. One review sitting with your team.
Week 6
Hand-over
Notices published, representative appointed, recorded hand-over, readiness sign-off.
When a customer asks
DPA or questionnaire
Answered from the records with the UK clauses already in place. Your team, or the questionnaire service if you want us.
Every year
ICO fee and reviews
Fee renewed, notices reviewed, the Data (Use and Access) Act 2025 changes tracked. In GRCTrail or in your export.
How we price
What moves the price
Three things we ask about on the call.
Whether an EU GDPR programme exists.
Extending records and notices is far shorter than writing them.
Transfer routes out of the UK.
Each processor or group company outside the UK needs a tool and an assessment.
Your role and your data.
Controllers with staff data need more than processors; special-category data adds assessments.
Never in our price, named in the quote so you can budget
- Acting as your UK representative; we help you decide under Article 27 and appoint one
- The ICO data protection fee itself; we tell you the tier and how to register
- Formal legal opinions; the practising privacy lawyer on your project is named in the quote
- Penetration testing
Questions before the call
Does a US company need a UK representative?
Usually yes, if it has no UK establishment and processes UK personal data more than occasionally or processes special-category data. The assessment gives you a written answer with reasoning.
We already comply with EU GDPR. What is left for the UK?
The representative decision, UK transfer tools, UK-specific notices and contract clauses, the ICO fee and the amendments in the Data (Use and Access) Act 2025. That is why the engagement is shorter for companies with an EU programme.
Which transfer tool do we use for data leaving the UK?
The International Data Transfer Agreement, or the UK Addendum attached to EU standard contractual clauses if you already use those. Transfers to countries with UK adequacy regulations need neither.
Do we need to register with the ICO?
Most organisations that process personal data must pay the ICO data protection fee. There are exemptions. The assessment tells you whether one applies and which fee tier you fall in.
What has to exist before our first UK hire starts?
A UK staff privacy notice, a lawful basis for the HR processing, the transfer tool if HR data leaves the UK, and the representative decision. The assessment lists them in order; most are in place by week 4.
Related
Last reviewed: October 2026
Tell us where your UK customers and staff are.
You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.