// Privacy
UK GDPR & Data Protection Act 2018 Compliance Software
The UK's data protection regime: UK GDPR together with the Data Protection Act 2018.
Framework at a glance
Short name
UK GDPR
Version
2021
Category
Privacy
Controls
92
What UK GDPR covers
92 controls across 55 domains — every one tracked, owned and evidenced in Cyber Horizon.
Lawful Basis
1 controls- A.5.1 Lawfulness of processing
Data Management
2 controls- A.5.2 Purpose limitation
- A.5.3 Data minimisation
Data Quality
1 controls- A.5.4 Accuracy
Retention
2 controls- A.5.5 Storage limitation
- A.24.13 Retention schedule
Security
1 controls- A.5.6 Integrity and confidentiality
Governance
5 controls- A.5.7 Accountability
- A.13.2 Data Protection Officer appointment
- A.13.3 DPO tasks
- A.21.1 UK representative appointment
- A.24.10 Privacy in procurement
Consent
2 controls- A.6.1 Consent
- A.22.1 Cookie and tracking consent
Contracts
3 controls- A.6.2 Contract performance
- A.15.2 Data processing agreements
- A.24.4 Data sharing agreements
Legal
1 controls- A.6.3 Legal obligation
Special Cases
2 controls- A.6.4 Vital interests
- A.24.11 Research data governance
Public Sector
1 controls- A.6.5 Public task
Legitimate Interests
1 controls- A.6.6 Legitimate interests
Consent Management
2 controls- A.7.1 Conditions for consent
- A.7.2 Withdrawing consent
Children's Data
1 controls- A.8.1 Child's consent for information society services
Sensitive Data
2 controls- A.9.1 Processing of special categories
- A.9.2 Processing criminal convictions
Privacy by Design
1 controls- A.10.1 Privacy by design
Privacy Notice
5 controls- A.12.1 Transparent information
- A.12.2 Information provided on collection
- A.12.3 Information to be provided where obtained indirectly
- A.23.1 Privacy notice completeness
- A.23.2 Layered privacy notices
Access
1 controls- A.12.4 Right of access
Rectification
1 controls- A.12.5 Right to rectification
Erasure
1 controls- A.12.6 Right to erasure
Restriction
1 controls- A.12.7 Right to restriction
Portability
1 controls- A.12.8 Data portability
Objection
1 controls- A.12.9 Right to object
Automated Decisions
1 controls- A.12.10 Automated decision-making
Documentation
7 controls- A.13.1 Records of processing (ROPA)
- A.16.4 Breach documentation
- A.24.8 Sensitive data mapping
- A.24.9 Data flow mapping
- A.24.19 Privacy impact register
Risk Assessment
1 controls- A.13.4 Data Protection Impact Assessment
Regulatory
4 controls- A.13.5 Prior consultation
- A.18.1 ICO cooperation
- A.18.2 EU cooperation mechanism (post-Brexit)
- A.19.1 One-stop-shop (post-Brexit)
Security Controls
2 controls- A.14.1 Security of processing
- A.14.3 Ongoing confidentiality
Cryptography
2 controls- A.14.2 Pseudonymisation and encryption
- A.24.15 Encryption key management
Business Continuity
1 controls- A.14.4 Data availability and resilience
Testing
1 controls- A.14.5 Regular testing and evaluation
Third-Party
3 controls- A.15.1 Processor contracts
- A.15.3 Sub-processor authorisation
- A.15.4 Processor audit rights
Incident Management
1 controls- A.16.1 Breach detection
Notification
3 controls- A.16.2 Controller breach notification to SA
- A.16.3 Individual breach notification
- A.24.24 Cross-border incident notification
Data Transfers
5 controls- A.17.1 Adequacy regulations
- A.17.2 UK IDTA and Addendum
- A.17.3 Binding corporate rules
- A.17.4 Transfer risk assessments
- A.17.5 Codes of conduct and certification
Data Subject Rights
1 controls- A.20.1 Right to lodge complaint
Marketing
1 controls- A.22.2 Email marketing consent
Automated Processing
1 controls- A.22.3 Profiling transparency
Awareness
1 controls- A.24.1 Staff privacy training
Incidents
1 controls- A.24.2 Privacy incident response plan
Vendors
1 controls- A.24.3 Vendor management programme
Management
1 controls- A.24.5 Privacy governance structure
Risk
1 controls- A.24.6 Privacy risk register
Audit
1 controls- A.24.7 Annual privacy review
Anonymisation
1 controls- A.24.12 Anonymisation standards
Disposal
1 controls- A.24.14 Secure disposal
Logging
1 controls- A.24.16 Access logs for PII
Vulnerability Management
1 controls- A.24.17 Vulnerability management for PII systems
DSR Management
1 controls- A.24.18 Data subject request tracking
Children
1 controls- A.24.20 Children age verification
Certification
1 controls- A.24.23 Privacy seal and certification
Reporting
1 controls- A.24.25 Accountability reporting
ICO Registration
1 controls- UK.1 ICO registration and data protection fee
Data Protection Act 2018
3 controls- UK.2 Data Protection Act 2018 (Part 2) and exemptions
- UK.3 Data Protection Act 2018 (Part 3) — law enforcement processing
- UK.4 Data Protection Act 2018 (Part 4) — intelligence services processing
PECR
1 controls- UK.5 PECR — electronic marketing, cookies and communications
How Cyber Horizon automates UK GDPR
Every UK GDPR control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is UK GDPR & Data Protection Act 2018?
The UK's data protection regime: UK GDPR together with the Data Protection Act 2018.
How many controls does UK GDPR & Data Protection Act 2018 have?
UK GDPR & Data Protection Act 2018 (2021) has 92 controls in Cyber Horizon's catalogue, organised across 55 domains.
How does Cyber Horizon help with UK GDPR & Data Protection Act 2018?
Cyber Horizon maps UK GDPR & Data Protection Act 2018 into a shared control library alongside every other framework you run, so evidence collected once counts towards UK GDPR and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Privacy frameworks
See UK GDPR mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of UK GDPR in Cyber Horizon.