Free ISO 27001 Assessment

UK GDPR

A UK customer or hire is weeks away. Here is what comes first.

The UK representative decision, transfer tools, ICO registration, UK notices and contract clauses, written for your company and kept current in the platform after we hand over.

UK applicability and transfer mapExample, US SaaS company

4 UK decisions, each with written reasoning and the record behind it

UK representative (Article 27)
Required; appointed in week 3
Done
Transfer routes out of the UK
5 routes, IDTA or UK Addendum in place
5 / 5
ICO data protection fee
Tier 1, registered
Done
UK notices and DPA clauses
Customers, website, staff; DPA template
4 / 4
Signed off by the programme owner, week 5Export · DOCX, PDF

Who this is for

Companies outside the UK with UK customers, UK staff or a UK office.

  • A fit

    • A US SaaS company with UK customers that has been asked by one of them for a UK GDPR-compliant data processing agreement.
    • An EU company with an existing GDPR programme that opened a UK office or hired UK staff after Brexit.
    • A company outside the UK and EU that sells to both and needs the two programmes aligned rather than duplicated.
  • Also a fit

    • A company hiring its first UK employee and unsure what must exist before their data moves.
    • A vendor whose UK customer's procurement team asked about the IDTA or the UK Addendum.
    • A company that received an ICO fee reminder and does not know which tier applies.
  • Not a fit

    • Companies that need a UK representative appointed. We help you decide under Article 27 and appoint one; we do not take the role.
    • UK-established companies building a programme from scratch. That is the full GDPR implementation, adapted to UK law; ask on the call.
    • Teams looking for a formal legal opinion only. The practising privacy lawyer on your project gives it; the implementation is the service.

What you walk away with

The UK-specific decisions and documents, or your EU programme extended to cover the UK.

Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.

UK GDPR compliance

9 deliverables, 4 to 6 weeks
  • UK applicability and representative decision

    With written reasoning under Article 3 and Article 27

    • DOCX
    • PDF
  • Records of processing covering UK data subjects

    Extended from your EU register where one exists

    • CSV
    • PDF
  • UK privacy notices

    Customers, website visitors, staff

    • DOCX
    • HTML
  • UK transfer assessment and transfer tools

    IDTA or UK Addendum per route

    • DOCX
    • PDF
  • UK data processing agreement template

    With UK-specific clauses

    • DOCX
  • Data subject request and breach procedures with UK deadlines

    With request tracking

    • Procedure
  • ICO fee assessment and registration checklist

    Tier and how to register

    • PDF
  • Evidence that each document is in use

    Linked to the record it supports

    • Platform
  • Recorded hand-over and readiness sign-off

    With whoever owns the programme afterwards

    • Video
    • PDF

How it works

Six weeks to hand-over. Shorter if the EU programme exists.

Most documents are extended rather than written when an EU GDPR programme is already in place.

  • GRCTrail
  • Hand-over
  • Without us
  1. Week 0

    Scoping call

    UK customers, staff, entities; what exists in the EU programme. Written fixed price within 3 business days.

  2. Weeks 1 to 2

    Assessment

    UK applicability analysis, review of the existing programme, gap analysis against UK GDPR and the Data Protection Act 2018. Implementation price confirmed.

  3. Weeks 3 to 5

    Implementation

    Representative decision, records, notices, transfer tools, DPA template, procedures, ICO fee checklist. One review sitting with your team.

  4. Week 6

    Hand-over

    Notices published, representative appointed, recorded hand-over, readiness sign-off.

  5. When a customer asks

    DPA or questionnaire

    Answered from the records with the UK clauses already in place. Your team, or the questionnaire service if you want us.

  6. Every year

    ICO fee and reviews

    Fee renewed, notices reviewed, the Data (Use and Access) Act 2025 changes tracked. In GRCTrail or in your export.

How we price

What moves the price

Three things we ask about on the call.

  • Whether an EU GDPR programme exists.

    Extending records and notices is far shorter than writing them.

  • Transfer routes out of the UK.

    Each processor or group company outside the UK needs a tool and an assessment.

  • Your role and your data.

    Controllers with staff data need more than processors; special-category data adds assessments.

Never in our price, named in the quote so you can budget

  • Acting as your UK representative; we help you decide under Article 27 and appoint one
  • The ICO data protection fee itself; we tell you the tier and how to register
  • Formal legal opinions; the practising privacy lawyer on your project is named in the quote
  • Penetration testing

Questions before the call

Does a US company need a UK representative?

Usually yes, if it has no UK establishment and processes UK personal data more than occasionally or processes special-category data. The assessment gives you a written answer with reasoning.

We already comply with EU GDPR. What is left for the UK?

The representative decision, UK transfer tools, UK-specific notices and contract clauses, the ICO fee and the amendments in the Data (Use and Access) Act 2025. That is why the engagement is shorter for companies with an EU programme.

Which transfer tool do we use for data leaving the UK?

The International Data Transfer Agreement, or the UK Addendum attached to EU standard contractual clauses if you already use those. Transfers to countries with UK adequacy regulations need neither.

Do we need to register with the ICO?

Most organisations that process personal data must pay the ICO data protection fee. There are exemptions. The assessment tells you whether one applies and which fee tier you fall in.

What has to exist before our first UK hire starts?

A UK staff privacy notice, a lawful basis for the HR processing, the transfer tool if HR data leaves the UK, and the representative decision. The assessment lists them in order; most are in place by week 4.

Tell us where your UK customers and staff are.

You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.