Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomePrivacy laws › EU / UK
Privacy law · Europe

🇪🇺 GDPR · UK GDPR in EU / UK

The EU General Data Protection Regulation (2016/679) and the UK GDPR are the benchmark comprehensive privacy laws, requiring a lawful basis, strong transparency, data-subject rights, breach notification and controlled international transfers, enforced by national authorities and the UK ICO.

Verified - cited to source law
GDPR · UK GDPR
Governing framework
EDPB and national DPAs / ICO
Supervisory authority
13
Controls this market requires
19
Required or strongly expected
Good to know: EU and UK grades are identical at this level; the paid tier splits UK-specific items (PECR, ICO).

What GDPR · UK GDPR expects of you

21 of our 22 tracked controls apply in EU / UK, graded by how firmly the law requires each one.

Required mandated by law Expected near-mandatory Prudent advisable Optional emerging
RecordsRequired

Records of processing (RoPA)

A living inventory of what personal data you hold, why, where it sits and where it flows.

Closes with: Records of Processing register
Lawful basisRequired

Lawful basis mapping

A valid legal reason for each use of personal data, mapped per activity.

Closes with: Lawful-basis mapping
ConsentRequired

Consent - specific, logged, withdrawable

Where you rely on consent it is freely given, specific, informed, unbundled and withdrawable, with a record.

Closes with: Consent notice + consent-record schema
TransparencyRequired

Privacy notice / transparency

A published, current privacy notice giving the prescribed information.

Closes with: Public privacy notice (per-market)
RightsRequired

Individual rights handling

Ability to find, correct and delete one person's data on request within the legal deadline.

Closes with: Rights-request procedure
Cross-borderRequired

Cross-border transfer mechanism

Every export of personal data is covered by a lawful transfer mechanism.

Closes with: Data-flow map + transfer pack (SCCs/TRA/adequacy)
SecurityRequired

Security controls (TOMs)

Encryption in transit and at rest, least-privilege access, and access logging.

Closes with: Security controls statement (TOMs)
BreachRequired

Breach detection & notification

A written breach plan and knowledge of each market's notification clock.

Closes with: Breach response plan + per-market templates
VendorsRequired

Vendor / processor agreements

DPAs with vendors handling your data, with controller/processor roles defined.

Closes with: Processor agreement template + role allocation
ePrivacyRequired

Cookies / e-privacy consent

Cookie/tracker consent and an accurate cookie policy where required (esp. EU/UK).

Closes with: Cookie policy + consent banner
RepresentativeRequired

Local representative appointment

A local/EU representative where you have no establishment in a market that requires one.

Closes with: Representative appointment letter
DPIARequired

Impact assessment / dossier

A DPIA/impact assessment for high-risk processing; some markets require a filed dossier.

Closes with: DPIA / transfer-impact assessment
ADM/AIRequired

Automated decisions / profiling

Safeguards and transparency for automated decision-making and profiling.

Closes with: ADM transparency + safeguards note
GovernanceExpected

Accountable privacy owner / DPO

A named person or role accountable for data protection, with published contact where required.

Closes with: DPO / privacy-owner appointment letter
RetentionExpected

Retention & deletion schedule

Defined, enforced retention periods and deletion, balancing storage-limitation and legal keep-periods.

Closes with: Retention schedule + deletion runbook
ChildrenExpected

Children's-data safeguards

Age assurance and verifiable parental consent; no behavioural tracking of children.

Closes with: Children's-data procedure + age-gating
SensitiveExpected

Sensitive / special-category data

Explicit consent, tighter access, and often a DPIA for special-category data.

Closes with: Sensitive-data policy + DPIA where required
MarketingExpected

Direct-marketing consent

Lawful basis/consent for e-marketing and an unsubscribe route.

Closes with: Marketing consent + suppression list
PaymentsExpected

PCI / payment-card handling

Card data offloaded to a compliant processor; PCI-DSS scope controlled.

Closes with: PCI-DSS scope note + card-handling policy
GrievancePrudent

Grievance / complaints channel

A published route to raise a privacy complaint; India requires a grievance officer.

Closes with: Grievance / complaint notice
LocalisationOptional

Data localisation / residency

Local storage/residency requirements for certain data or sectors.

Closes with: Data-residency design note

Get EU / UK-ready without the guesswork

Answer a few questions and PrivMatrix shows you exactly where you stand against GDPR · UK GDPR, then generates the policies, notices and registers that close each gap - written for EU / UK.

Other markets

See all 28 →
🇦🇪 UAE🇸🇦 Saudi Arabia🇶🇦 Qatar🇧🇭 Bahrain🇴🇲 Oman🇰🇼 Kuwait🇹🇷 Turkey🇨🇭 Switzerland