Skip to content
Cyber Horizon
All frameworks

// Privacy

UK GDPR & Data Protection Act 2018 Compliance Software

The UK's data protection regime: UK GDPR together with the Data Protection Act 2018.

Framework at a glance

Short name

UK GDPR

Version

2021

Category

Privacy

Controls

92

What UK GDPR covers

92 controls across 55 domains — every one tracked, owned and evidenced in Cyber Horizon.

Lawful Basis

1 controls
  • A.5.1 Lawfulness of processing

Data Management

2 controls
  • A.5.2 Purpose limitation
  • A.5.3 Data minimisation

Data Quality

1 controls
  • A.5.4 Accuracy

Retention

2 controls
  • A.5.5 Storage limitation
  • A.24.13 Retention schedule

Security

1 controls
  • A.5.6 Integrity and confidentiality

Governance

5 controls
  • A.5.7 Accountability
  • A.13.2 Data Protection Officer appointment
  • A.13.3 DPO tasks
  • A.21.1 UK representative appointment
  • A.24.10 Privacy in procurement

Consent

2 controls
  • A.6.1 Consent
  • A.22.1 Cookie and tracking consent

Contracts

3 controls
  • A.6.2 Contract performance
  • A.15.2 Data processing agreements
  • A.24.4 Data sharing agreements

Legal

1 controls
  • A.6.3 Legal obligation

Special Cases

2 controls
  • A.6.4 Vital interests
  • A.24.11 Research data governance

Public Sector

1 controls
  • A.6.5 Public task

Legitimate Interests

1 controls
  • A.6.6 Legitimate interests

Consent Management

2 controls
  • A.7.1 Conditions for consent
  • A.7.2 Withdrawing consent

Children's Data

1 controls
  • A.8.1 Child's consent for information society services

Sensitive Data

2 controls
  • A.9.1 Processing of special categories
  • A.9.2 Processing criminal convictions

Privacy by Design

1 controls
  • A.10.1 Privacy by design

Privacy Notice

5 controls
  • A.12.1 Transparent information
  • A.12.2 Information provided on collection
  • A.12.3 Information to be provided where obtained indirectly
  • A.23.1 Privacy notice completeness
  • A.23.2 Layered privacy notices

Access

1 controls
  • A.12.4 Right of access

Rectification

1 controls
  • A.12.5 Right to rectification

Erasure

1 controls
  • A.12.6 Right to erasure

Restriction

1 controls
  • A.12.7 Right to restriction

Portability

1 controls
  • A.12.8 Data portability

Objection

1 controls
  • A.12.9 Right to object

Automated Decisions

1 controls
  • A.12.10 Automated decision-making

Documentation

7 controls
  • A.13.1 Records of processing (ROPA)
  • A.16.4 Breach documentation
  • A.24.8 Sensitive data mapping
  • A.24.9 Data flow mapping
  • A.24.19 Privacy impact register

Risk Assessment

1 controls
  • A.13.4 Data Protection Impact Assessment

Regulatory

4 controls
  • A.13.5 Prior consultation
  • A.18.1 ICO cooperation
  • A.18.2 EU cooperation mechanism (post-Brexit)
  • A.19.1 One-stop-shop (post-Brexit)

Security Controls

2 controls
  • A.14.1 Security of processing
  • A.14.3 Ongoing confidentiality

Cryptography

2 controls
  • A.14.2 Pseudonymisation and encryption
  • A.24.15 Encryption key management

Business Continuity

1 controls
  • A.14.4 Data availability and resilience

Testing

1 controls
  • A.14.5 Regular testing and evaluation

Third-Party

3 controls
  • A.15.1 Processor contracts
  • A.15.3 Sub-processor authorisation
  • A.15.4 Processor audit rights

Incident Management

1 controls
  • A.16.1 Breach detection

Notification

3 controls
  • A.16.2 Controller breach notification to SA
  • A.16.3 Individual breach notification
  • A.24.24 Cross-border incident notification

Data Transfers

5 controls
  • A.17.1 Adequacy regulations
  • A.17.2 UK IDTA and Addendum
  • A.17.3 Binding corporate rules
  • A.17.4 Transfer risk assessments
  • A.17.5 Codes of conduct and certification

Data Subject Rights

1 controls
  • A.20.1 Right to lodge complaint

Marketing

1 controls
  • A.22.2 Email marketing consent

Automated Processing

1 controls
  • A.22.3 Profiling transparency

Awareness

1 controls
  • A.24.1 Staff privacy training

Incidents

1 controls
  • A.24.2 Privacy incident response plan

Vendors

1 controls
  • A.24.3 Vendor management programme

Management

1 controls
  • A.24.5 Privacy governance structure

Risk

1 controls
  • A.24.6 Privacy risk register

Audit

1 controls
  • A.24.7 Annual privacy review

Anonymisation

1 controls
  • A.24.12 Anonymisation standards

Disposal

1 controls
  • A.24.14 Secure disposal

Logging

1 controls
  • A.24.16 Access logs for PII

Vulnerability Management

1 controls
  • A.24.17 Vulnerability management for PII systems

DSR Management

1 controls
  • A.24.18 Data subject request tracking

Children

1 controls
  • A.24.20 Children age verification

Certification

1 controls
  • A.24.23 Privacy seal and certification

Reporting

1 controls
  • A.24.25 Accountability reporting

ICO Registration

1 controls
  • UK.1 ICO registration and data protection fee

Data Protection Act 2018

3 controls
  • UK.2 Data Protection Act 2018 (Part 2) and exemptions
  • UK.3 Data Protection Act 2018 (Part 3) — law enforcement processing
  • UK.4 Data Protection Act 2018 (Part 4) — intelligence services processing

PECR

1 controls
  • UK.5 PECR — electronic marketing, cookies and communications

How Cyber Horizon automates UK GDPR

Every UK GDPR control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is UK GDPR & Data Protection Act 2018?

The UK's data protection regime: UK GDPR together with the Data Protection Act 2018.

How many controls does UK GDPR & Data Protection Act 2018 have?

UK GDPR & Data Protection Act 2018 (2021) has 92 controls in Cyber Horizon's catalogue, organised across 55 domains.

How does Cyber Horizon help with UK GDPR & Data Protection Act 2018?

Cyber Horizon maps UK GDPR & Data Protection Act 2018 into a shared control library alongside every other framework you run, so evidence collected once counts towards UK GDPR and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See UK GDPR mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of UK GDPR in Cyber Horizon.