A privacy pack written before June 2025 is describing a regime the United Kingdom no longer has. This UK GDPR documentation set was rebuilt against the amended text rather than annotated after the fact.
On this page:
- Why most UK GDPR documentation is now out of date
- What is inside the UK GDPR documentation pack
- The record of processing is the UK GDPR documentation the ICO asks for first
- Who the UK GDPR documentation pack is written for
- What the UK GDPR documentation pack does not do
- Frequently asked questions
- Related toolkits
Why most UK GDPR documentation is now out of date
The Data (Use and Access) Act 2025 did not arrive in one piece. It landed in four stages – 19 June 2025, 20 August 2025, 5 February 2026 and 19 June 2026 – and each stage moved something a template set depends on: the lawful bases, purpose limitation, the clock on rights requests, automated decision-making, international transfers, the cookie rules and the handling of complaints.
The practical test is quick. Open your current data subject access request procedure. If it runs a flat one-month clock rather than the applicable time period in Article 12A, with the relevant time, the two-month extension and the clarification stop, it predates the Act. If your privacy notice names an EU supervisory authority rather than the Information Commissioner, or your transfer paperwork leans on the EU standard contractual clauses without the UK Addendum, the same conclusion follows.
Every document in this UK GDPR documentation set names the Commissioner, states the complaint route that now applies under sections 164A and 164B, and carries a panel saying in plain words what the law requires and since when. The date matters as much as the rule: a reviewer who can see when an obligation started can tell whether your evidence covers the right period.
What is inside the UK GDPR documentation pack
The UK GDPR documentation pack is 90 editable templates – 70 Word documents and 20 Excel workbooks – across 13 sections, written against the UK GDPR as amended, the Data Protection Act 2018, the Data (Use and Access) Act 2025 and PECR. The crosswalk workbook claims 97 provisions across those four instruments and names the document that answers each one.
- Programme and governance – scope, roles, the accountability framework and the documents a controller has to be able to produce on request.
- Lawful bases – including recognised legitimate interests under Article 6(1)(ea) and Annex 1, which did not exist before the 2025 Act.
- Records of processing – a UK ROPA workbook with the fields the ICO accountability framework looks for, kept separately for controller and processor activities.
- Rights procedures – the full set, with the DSAR procedure operating Article 12A properly and recording the reasonable and proportionate search Article 15(1A) requires.
- Complaints – procedure, log, form and letters built on the statutory duty in section 164A: facilitate, acknowledge within 30 days, respond without undue delay.
- Automated decision-making – Articles 22A to 22C as rewritten, rather than the old Article 22 with a note attached.
- International transfers – the UK transfer risk assessment, the Addendum, and the Articles 45A, 45B, 46(1A), 47A and 49A routes.
- Security – the policies that make Article 32 concrete, at a level an auditor can test.
- Breach – assessment, the 72-hour notification and the records that show the decision was made properly, including where you decided not to notify.
- DPIA and DPO – the threshold test, the assessment itself, and the appointment and independence records.
- Special category and criminal offence data – section 10, Schedule 1 and the appropriate policy document at paragraphs 39 to 41.
- PECR – the new regulation 6 and Schedule A1 cookie exceptions, plus the marketing rules in regulations 19 to 23.
- Legal crosswalk workbook – all 97 provisions against the document that answers each, so the coverage claim can be checked rather than believed.

The record of processing is the UK GDPR documentation the ICO asks for first
When the ICO opens a file, the record of processing activities is usually the first thing requested, because it is the one document that shows whether an organisation knows what it is doing with personal data. A ROPA that lists systems rather than processing activities, or that has no retention period against an activity, answers the question badly.
The workbook in this set is structured on Article 30 as it now reads, with separate controller and processor views, and columns for the lawful basis, the special category condition where one applies, the recipients, the transfer mechanism, the retention period and the security measures. It is filled in far enough to show the shape of a good entry and left open where the answer is yours.
Beside it sits a recognised legitimate interests assessment. Annex 1 is new, it is narrow, and treating it as a relabelled legitimate interests assessment is the most likely early mistake under the 2025 Act. The UK GDPR documentation keeps the two apart and records which one you relied on.
Who the UK GDPR documentation pack is written for
- UK controllers and processors updating a programme written under the pre-2025 regime.
- Data protection officers and privacy leads who need the changes built into the documents rather than listed in a supplement.
- Organisations that operate under both the EU GDPR and the UK GDPR and need the UK divergences stated rather than assumed away.
- Consultancies and in-house teams preparing accountability evidence for an ICO enquiry or a customer audit.
What the UK GDPR documentation pack does not do
It does not make you compliant, and no document set can. UK GDPR documentation gives you the written layer the law requires and the evidence structure a regulator asks for; operating it is your work.
It is not legal advice. Where a provision turns on facts only you have – whether a processing activity meets the Annex 1 test, whether an exemption applies – the template records the decision and the reasoning rather than making it for you.
It does not cover the EU GDPR. If you need the EU regime, the GDPR pack is the one to start from, and the two are built to sit together.
Frequently asked questions
Does this replace an EU GDPR template set?
No. It covers UK law. If you process personal data in the EU as well, you need both, and the two packs are written to be run side by side rather than merged.
We already have a UK privacy pack. Is this worth buying?
Check three things first: whether the DSAR procedure runs Article 12A, whether there is a complaints procedure built on section 164A, and whether the lawful basis documents cover recognised legitimate interests. If any is missing, your UK GDPR documentation predates the 2025 Act.
Are the documents editable?
Yes. Native .docx and .xlsx, no macros required, no portal. Every organisation-specific value is marked as a placeholder.
Does it cover PECR and cookies?
Yes, including the regulation 6 and Schedule A1 exceptions introduced by the 2025 Act, and the direct marketing rules in regulations 19 to 23.
Related toolkits
Pair it with the GDPR toolkit if you also process personal data in the EU, the ISO 27701 privacy information management toolkit if you want a certifiable privacy management system behind the paperwork, and the ISO 27001 toolkit for the security controls Article 32 expects. The legislation itself is free to read on legislation.gov.uk.
Implementing for clients? The Consultant Package licenses all 86 toolkits and assessment tools on this site for unlimited client engagements, under one firm-wide licence. One payment of $1,399, no subscription and no per-client fee.
Delivery, format and licence
The UK GDPR documentation pack downloads immediately after checkout as native Microsoft Word and Excel files. Nothing is locked, nothing is a PDF you cannot edit, and no add-on or portal login is needed to open it. Every organisation-specific value is marked as a placeholder so you can see what still has to be decided.
One payment, no subscription and no annual renewal. The source files behind the UK GDPR documentation pack are yours to adapt for your own organisation for as long as you need them, including future revisions of your own documents.




Reviews
There are no reviews yet.