Framework · Data protection
GDPR
The UK and EU data protection regimes governing the processing of personal data.
UK GDPR (under the Data Protection Act 2018) and EU GDPR are the principal data protection regimes UK organisations operate under. Enforcement by the ICO and EU supervisory authorities continues to expand.
WHERE THIS FRAMEWORK FITS
Where this framework fits at Goldline
Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. GDPR is not a service Goldline delivers as a standalone product.
GDPR compliance is substantially supported by an information security management system. Organisations approaching GDPR readiness typically find that an ISO 27001 implementation programme addresses the majority of the Article 32 technical and organisational measures GDPR expects.
For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.
Book the Free DiagnosticWhat is GDPR?
The General Data Protection Regulation governs the processing of personal data of UK and EU data subjects. UK GDPR (incorporated into UK law via the Data Protection Act 2018) and EU GDPR (Regulation 2016/679) impose principles-based obligations on controllers and processors covering lawful basis, transparency, data subject rights, security, breach notification, and accountability. Supervisory authorities (the ICO in the UK; national DPAs in EU member states) enforce with administrative fines up to 4% of global turnover.
What GDPR covers
Six core processing principles, six lawful bases, eight data subject rights, and detailed obligations on records, breach response, DPIAs, security, and international transfers.
Lawful basis and consent
Article 6 lawful bases for processing and Article 7 consent requirements covering all personal data activities.
Data subject rights
Articles 12-22 covering access, rectification, erasure, portability, restriction, and objection rights.
Breach notification
Article 33 supervisory authority notification within 72 hours; Article 34 data subject notification where high risk.
Records of processing
Article 30 records of processing activities (RoPA) for controllers and processors.
DPIAs and Article 35
Data Protection Impact Assessments for high-risk processing including profiling and large-scale special category data.
Article 32 security
Technical and organisational measures appropriate to the risk, including encryption, resilience, and regular testing.
Why UK organisations prioritise GDPR
Sustained ICO enforcement, customer scrutiny via DPIAs, and the operational reality of dual UK/EU exposure keep GDPR central to UK governance agendas.
UK GDPR enforcement by the ICO carries fines up to 4% of global annual turnover or £17.5m, whichever is higher.
EU GDPR exposure persists for any UK organisation processing personal data of EU data subjects.
Procurement and customer DPIAs increasingly require demonstrable GDPR governance from suppliers and processors.
Individual data subject complaints to the ICO are rising, with public investigation outcomes affecting brand and procurement.
Article 32 maps directly to ISO 27001 Annex A controls, enabling parallel security and privacy programme delivery.
Cross-border transfers under Schrems II require ongoing transfer impact assessments and SCC implementation.
UK GDPR vs EU GDPR vs ISO 27001
| UK GDPR | EU GDPR | ISO 27001 | |
|---|---|---|---|
| Source | UK Data Protection Act 2018 incorporating UK GDPR. | Regulation (EU) 2016/679 directly applicable across EU. | International ISMS standard. |
| Enforcement | ICO supervisory authority. Fines to 4% turnover or £17.5m. | National supervisory authorities. Fines to 4% turnover or €20m. | Annex A controls map to GDPR Article 32. |
| Cycle | Continuous compliance obligation. | Continuous compliance obligation. | Three-year certification cycle. |
| Status | Mandatory for any UK personal data processing. | Mandatory for any processing of EU data subject personal data. | Foundational complement to GDPR; not a substitute. |
METHODOLOGY
How Goldline delivers GDPR compliance
The Goldline Method applied to GDPR data protection. Five phases from data mapping through ongoing data protection governance, calibrated to your processing activities, data subject base, and regulatory exposure under UK GDPR and EU GDPR.
- 01
Phase 1
Data mapping and processing inventory
Senior practitioner-led data mapping across business processes. Article 30 records of processing activities established. Data flows identified including international transfers and third-party data sharing arrangements. Personal data categories and special category data classified.
- Article 30 ROPA
- Data flow map
- Processing inventory
- 02
Phase 2
Lawful basis and policy framework
Lawful basis confirmed per processing activity. Privacy policy, internal data protection policy, retention policy, and supporting policies drafted and implemented. Consent management workflows established where consent is the lawful basis. Data subject rights process configured.
- Policy suite
- Lawful basis register
- Consent workflows
- 03
Phase 3
Technical and organisational controls
Article 32 security of processing controls implemented. Encryption, access controls, pseudonymisation, and resilience controls calibrated to data sensitivity. Breach detection and notification process aligned to Article 33 and 34 timelines including the 72-hour authority notification requirement.
- Article 32 controls
- Breach process
- Notification workflow
- 04
Phase 4
Vendor and international transfer management
Article 28 processor agreements implemented with all third-party data processors. International data transfer mechanisms established (adequacy decisions, Standard Contractual Clauses, Transfer Impact Assessments). Sub-processor approval and monitoring workflows configured.
- Processor contracts
- Transfer mechanisms
- TIAs
- 05
Phase 5
DPIA, DPO, and ongoing governance
Article 35 Data Protection Impact Assessment process implemented for high-risk processing activities. Data Protection Officer appointment evaluated and implemented where required. Ongoing governance including data subject rights handling, breach response, and accountability documentation embedded.
- DPIA framework
- DPO appointment
- Accountability evidence
Frequently asked
Discuss where this framework fits your programme
Goldline delivers a fixed-scope GDPR Gap Assessment producing a prioritised remediation roadmap calibrated to your sector and processing footprint. Book the Free Diagnostic to scope your engagement, or read more about the GDPR Gap Assessment.
