
Privacy
UK GDPR and DPA 2018: what your enterprise customer will ask for
UK GDPR runs parallel to EU GDPR with British twists. A clean processor DPA closes the security questionnaire in a week.
The first enterprise customer that takes you seriously will send a data-protection questionnaire before signing anything. The DPA you attach to your master agreement decides whether that conversation lasts a week or three months. A clean template covering UK GDPR (the retained EU GDPR amended by the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 and the Data Protection Act 2018) closes it fast.
The contractual anchors are UK GDPR Article 28 (processor contracts), Article 32 (security of processing), Article 44 (general principle for transfers), and Sections 18 and 119A of the Data Protection Act 2018 (adequacy regulations and the UK transfer mechanism). All require a written agreement; all specify the minimum content; all require sub-processor disclosure.
What UK GDPR shares with EU GDPR
The substance is almost identical: written processor contracts under Art. 28, technical and organisational measures under Art. 32, breach notification to the supervisory authority within 72 hours under Art. 33 (the ICO in the UK rather than the customer's home regulator), data subject rights (access, rectification, erasure, portability), and DPIAs for high-risk processing under Art. 35. The lawful bases for processing under Art. 6 are unchanged, and so are the special category data rules under Art. 9.
Where UK GDPR differs from EU GDPR
- Maximum fine: up to 17.5 million pounds or 4 percent of global annual turnover (whichever is higher) under the Data Protection Act 2018 s.157, mirroring EU GDPR's 20 million euros / 4 percent. Same risk picture, different currency.
- International transfers out of the UK use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, both published by the ICO and in force since 21 March 2022. Replace 2010 SCCs with one of these by the deadlines the ICO has set.
- UK adequacy decisions are made by the Secretary of State under DPA 2018 s.17A, not by the European Commission. The UK currently recognises the EU/EEA, Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Jersey, New Zealand, Switzerland, Uruguay, plus the US under the UK-US data bridge in force since 12 October 2023 for organisations self-certified to the EU-US Data Privacy Framework's UK extension.
- The UK has no equivalent of the EU representative requirement (Art. 27 GDPR) for non-UK controllers; instead the UK requires a UK representative under UK GDPR Art. 27 if you target UK individuals from outside the UK.
- The ICO is the sole supervisory authority and the only fining body, simplifying the regulatory map compared with the EU one-stop-shop mechanism.
We host on AWS eu-west-2 (London) and use OpenAI's US endpoint. What goes in the transfer wording?
Two separate questions. AWS London is in the UK, so no international transfer is engaged for the storage. The OpenAI call is a UK-to-US transfer of personal data, which needs a UK GDPR Art. 44 mechanism. The cleanest answer post-12 October 2023 is the UK-US data bridge: confirm OpenAI is self-certified to the EU-US Data Privacy Framework's UK extension (check the official list at dataprivacyframework.gov), name it in the DPA, and you have a valid transfer mechanism with no IDTA needed. If OpenAI is not on the list, fall back to the IDTA or the UK Addendum to the EU SCCs, attached to the DPA as an annex, plus a documented Transfer Impact Assessment.
Sub-processors
List your sub-processors in an annex. Most UK enterprise customers want 30-day prior notice for new additions with a right to object. If they object, you owe a reasonable alternative or a termination right against the affected service. List your hosting provider (AWS, GCP, Azure, Hetzner), monitoring stack (Datadog, Sentry, New Relic), email infrastructure (Postmark, SendGrid), and any AI vendor (OpenAI, Anthropic, your fine-tuning service). Do not hide a vendor; an undisclosed sub-processor is the most common reason an enterprise renewal fails and the most common trigger for an ICO investigation under Section 142 DPA 2018.
Technical and organisational measures
Attach a one-page TOM annex covering: encryption at rest (AES-256, named) and in transit (TLS 1.3, named), access controls (SSO via SAML/OIDC, least privilege, MFA enforced), logging and audit retention (typically 12 months), backup frequency and retention (named numbers, not 'regular'), incident response (named on-call rotation and notification chain), and personnel training (annual, with attestation). UK GDPR Art. 32 plus the ICO's Security Outcomes guidance treat 'industry-standard' as too vague; use concrete language. Customers reject vague descriptions and accept terse, specific ones.
Controller vs processor: get the role right
Most SaaS providers are processors (Art. 4(8) UK GDPR) of customer data and controllers (Art. 4(7)) of their own user accounts, billing data, and product analytics. State both roles explicitly in the DPA and apply UK GDPR Art. 28 only to the processor relationship. Joint controllership (Art. 26) is rarer than enterprise customers think; their templates often try to push it onto you to share regulatory liability. Refuse it for product data unless you are jointly determining the purposes and means of processing, which a vendor delivering a standardised SaaS is not. The Wm Morrison Supermarkets v Various Claimants [2020] UKSC 12 line of cases makes vicarious data-protection liability narrow, but the joint-controllership question is decided on the contract, not the case law, so write it carefully.
Do I need to appoint a Data Protection Officer under UK GDPR?
Mandatory only if (a) you are a public authority, (b) your core activities require large-scale regular and systematic monitoring of data subjects, or (c) your core activities involve large-scale processing of special category data or criminal-conviction data. Most early-stage UK startups are not in scope. Voluntary appointment is recommended once you cross 25 to 50 employees: enterprise customers increasingly require a named contact in the DPA annex, and the role can be a fractional external DPO at 6,000 to 15,000 pounds per year, cheaper than one ICO audit response.
An ICO subject access request lands. What is the realistic timeline?
Under UK GDPR Art. 12(3) you have one month from receipt to respond, extendable by two months for complex requests. Free of charge for the first request; subsequent requests within a reasonable period can attract a reasonable fee. Identity verification is permitted under Art. 12(6) but cannot become an obstacle. Build a 30-day SAR workflow: who triages, who retrieves, who redacts third-party personal data, who approves the response. Most startups deal with their first SAR badly; the ICO's enforcement approach is graduated, and a first miss usually triggers a warning letter rather than a fine. The 17.5 million pound maximum is reserved for repeated or egregious failures.
When the customer sends their own DPA
Large UK enterprises (HSBC, BT, Sainsbury's, the major insurers) send their own template. Review it for three traps: (a) joint controllership clauses that try to make you a joint controller of the customer's data, refuse and propose a clean processor framing; (b) liability uncapped for any data event, refuse and propose a separate cap for data breaches at three times annual fees with the IP and confidentiality carve-outs; (c) audit rights with no notice period and no cost cap, propose 30 days' notice and one audit per 12 months at the customer's cost unless they find a material breach. These three are the negotiation; everything else usually flows.
Sources
- 01UK General Data Protection Regulation, Articles 28, 32, 33, 44 (processor contracts, security, breach notification, transfers)(UK GDPR Arts. 28, 32, 33, 44)
- 02Data Protection Act 2018, ss.17A-18, 119A, 142, 157 (adequacy, transfers, enforcement, fines)(DPA 2018 ss.17A-157)
- 03Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019(SI 2019/419)
- 04ICO — International Data Transfer Agreement (IDTA) and UK Addendum to the EU SCCs (in force 21 March 2022)(ICO IDTA guidance)
- 05ICO — Guide to the UK GDPR (controller, processor, lawful bases, SAR, DPIA, DPO)(ICO guide)
- 06UK-US Data Bridge (UK extension to the EU-US Data Privacy Framework, in force 12 October 2023)(GOV.UK / DPF List)