Skip to main content

Framework · Data protection

GDPR

The UK and EU data protection regimes governing the processing of personal data.

UK GDPR (under the Data Protection Act 2018) and EU GDPR are the principal data protection regimes UK organisations operate under. Enforcement by the ICO and EU supervisory authorities continues to expand.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. GDPR is not a service Goldline delivers as a standalone product.

GDPR compliance is substantially supported by an information security management system. Organisations approaching GDPR readiness typically find that an ISO 27001 implementation programme addresses the majority of the Article 32 technical and organisational measures GDPR expects.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is GDPR?

The General Data Protection Regulation governs the processing of personal data of UK and EU data subjects. UK GDPR (incorporated into UK law via the Data Protection Act 2018) and EU GDPR (Regulation 2016/679) impose principles-based obligations on controllers and processors covering lawful basis, transparency, data subject rights, security, breach notification, and accountability. Supervisory authorities (the ICO in the UK; national DPAs in EU member states) enforce with administrative fines up to 4% of global turnover.

What GDPR covers

Six core processing principles, six lawful bases, eight data subject rights, and detailed obligations on records, breach response, DPIAs, security, and international transfers.

Lawful basis and consent

Article 6 lawful bases for processing and Article 7 consent requirements covering all personal data activities.

Data subject rights

Articles 12-22 covering access, rectification, erasure, portability, restriction, and objection rights.

Breach notification

Article 33 supervisory authority notification within 72 hours; Article 34 data subject notification where high risk.

Records of processing

Article 30 records of processing activities (RoPA) for controllers and processors.

DPIAs and Article 35

Data Protection Impact Assessments for high-risk processing including profiling and large-scale special category data.

Article 32 security

Technical and organisational measures appropriate to the risk, including encryption, resilience, and regular testing.

Why UK organisations prioritise GDPR

Sustained ICO enforcement, customer scrutiny via DPIAs, and the operational reality of dual UK/EU exposure keep GDPR central to UK governance agendas.

UK GDPR enforcement by the ICO carries fines up to 4% of global annual turnover or £17.5m, whichever is higher.

EU GDPR exposure persists for any UK organisation processing personal data of EU data subjects.

Procurement and customer DPIAs increasingly require demonstrable GDPR governance from suppliers and processors.

Individual data subject complaints to the ICO are rising, with public investigation outcomes affecting brand and procurement.

Article 32 maps directly to ISO 27001 Annex A controls, enabling parallel security and privacy programme delivery.

Cross-border transfers under Schrems II require ongoing transfer impact assessments and SCC implementation.

UK GDPR vs EU GDPR vs ISO 27001

 UK GDPREU GDPRISO 27001
SourceUK Data Protection Act 2018 incorporating UK GDPR.Regulation (EU) 2016/679 directly applicable across EU.International ISMS standard.
EnforcementICO supervisory authority. Fines to 4% turnover or £17.5m.National supervisory authorities. Fines to 4% turnover or €20m.Annex A controls map to GDPR Article 32.
CycleContinuous compliance obligation.Continuous compliance obligation.Three-year certification cycle.
StatusMandatory for any UK personal data processing.Mandatory for any processing of EU data subject personal data.Foundational complement to GDPR; not a substitute.

METHODOLOGY

How Goldline delivers GDPR compliance

The Goldline Method applied to GDPR data protection. Five phases from data mapping through ongoing data protection governance, calibrated to your processing activities, data subject base, and regulatory exposure under UK GDPR and EU GDPR.

  1. 01

    Phase 1

    Data mapping and processing inventory

    Senior practitioner-led data mapping across business processes. Article 30 records of processing activities established. Data flows identified including international transfers and third-party data sharing arrangements. Personal data categories and special category data classified.

    • Article 30 ROPA
    • Data flow map
    • Processing inventory
  2. 02

    Phase 2

    Lawful basis and policy framework

    Lawful basis confirmed per processing activity. Privacy policy, internal data protection policy, retention policy, and supporting policies drafted and implemented. Consent management workflows established where consent is the lawful basis. Data subject rights process configured.

    • Policy suite
    • Lawful basis register
    • Consent workflows
  3. 03

    Phase 3

    Technical and organisational controls

    Article 32 security of processing controls implemented. Encryption, access controls, pseudonymisation, and resilience controls calibrated to data sensitivity. Breach detection and notification process aligned to Article 33 and 34 timelines including the 72-hour authority notification requirement.

    • Article 32 controls
    • Breach process
    • Notification workflow
  4. 04

    Phase 4

    Vendor and international transfer management

    Article 28 processor agreements implemented with all third-party data processors. International data transfer mechanisms established (adequacy decisions, Standard Contractual Clauses, Transfer Impact Assessments). Sub-processor approval and monitoring workflows configured.

    • Processor contracts
    • Transfer mechanisms
    • TIAs
  5. 05

    Phase 5

    DPIA, DPO, and ongoing governance

    Article 35 Data Protection Impact Assessment process implemented for high-risk processing activities. Data Protection Officer appointment evaluated and implemented where required. Ongoing governance including data subject rights handling, breach response, and accountability documentation embedded.

    • DPIA framework
    • DPO appointment
    • Accountability evidence

Frequently asked

Discuss where this framework fits your programme

Goldline delivers a fixed-scope GDPR Gap Assessment producing a prioritised remediation roadmap calibrated to your sector and processing footprint. Book the Free Diagnostic to scope your engagement, or read more about the GDPR Gap Assessment.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.