SDUK {Studio}DemosBlogBook a call
Post FN-12Compliance

← All posts

What GDPR compliance actually requires

The law asks less for paperwork than for proof: six things your business must be able to do, and one question that tests them all.

Fig FN-12.1 · The test is retrieval: one record, produced on demand.

In February this year the biggest rewrite of UK data protection law since 2018 quietly began to take effect. The Data (Use and Access) Act rewrote the rules on automated decisions among a longer list of changes, and the ICO published plain-English guidance on what it means. Most businesses did not notice. That is not a criticism; it is a clue about how data protection is usually done: buy a policy pack, add a cookie banner, file the subject under finished.

The uncomfortable truth is that the law was never very interested in your paperwork. Strip away the legal language and the UK GDPR asks whether your business can actually do a short list of things:

  • tell people plainly what you hold about them, and why;
  • hand over a complete copy when a person asks, within one month;
  • correct or delete it when required, everywhere it lives;
  • keep it secure, in proportion to how sensitive it is;
  • tell the regulator within 72 hours of discovering a serious breach;
  • prove all of the above happened, not just that it was intended.

A policy describes those abilities. It does not create them. Whether you can answer a customer within the month depends on your systems, not your stationery.

Where businesses actually get caught

On the basics, and above all on the second item in that list. The right of access, a person asking for a copy of their data, is the single largest cause of complaints to the regulator: in the latest published quarter of the ICO's casework data (October to December 2025) it accounted for 43% of completed cases, far ahead of any other category.

Businesses do not fail these requests out of defiance. They fail because the answer is scattered: a CRM here, a spreadsheet there, an inbox everywhere, and nobody who can assemble a complete copy inside a month.

Security is the other half. The government's Cyber Security Breaches Survey found that 43% of UK businesses identified a breach or attack in the past year — around 612,000 firms. When it happens to you, the 72-hour clock starts the moment you become aware, and a business that cannot say where its data lives cannot say what was taken. The notification duty is really a knowledge duty in disguise.

How worried should you be?

Less than the people selling compliance would like, and more than “we're too small to matter” assumes.

The fear has a grain of truth: maximum fines run to £17.5 million or 4% of turnover. But the ICO's record with small organisations is mostly reprimands and orders to fix the basics rather than headline penalties, and its guidance is free and written for exactly this audience. You do not need a retainer and a forty-page manual.

Complacency is the more expensive mistake, because it misreads how trouble arrives. It rarely starts with a regulator's sweep. It starts with a person: an ex-employee in a dispute who requests everything you hold on them, or a customer whose complaint escalates. Your duties are triggered by the data you hold, not by the size of your company.

And one concession the compliance industry rarely makes: parts of the law are judgment, not machinery. What is your lawful basis for this mailing list? How long should you keep former clients' files? No software can make those calls for you, and anything sold as compliance-in-a-box is overselling. What a system can do is make your answers operational, so the decision you made once is enforced everywhere and provable afterwards.

How we build it in

When we build a client's system, data protection is declared at the design stage rather than documented after the fact. Every field that holds personal data is tagged: what kind of data it is, how sensitive, and what should happen to it when someone asks to be forgotten.

From that one pass, the system generates the working parts of compliance. A live register of what you hold and why, produced from the system itself, so it cannot drift out of date. A complete export of everything held on a person, so the one-month deadline becomes an afternoon. Deletion that follows the connections, removing or redacting through every linked record and logging that it did. And a conformance report the system writes about itself, which you can hand to an insurer or a large customer's procurement team — the same evidence we described when we introduced the studio.

Rather than describe that report, we can show you one. Bellwether is a CRM we built and run ourselves to demonstrate the platform (a demonstration, not a client), and its report is generated on every release like any other system's. It opens like this:

This is the evidence record for Bellwether Ltd’s software: the personal data it holds, the protections around that data, the checks it passed before release, and every piece of bespoke logic it contains. It is produced automatically from the same source as the running system and regenerated on every release — so it always describes exactly what is deployed, never an earlier version, and none of it is written by hand after the fact.

Read the full Bellwether report: every personal-data field classified for sensitivity, and what happens to each when someone asks to be forgotten.

The judgment calls stay yours. The machinery makes them stick.

What about the new EU AI rules?

A different law, about a different thing, and for most UK firms not the first one to act on. Since August, the EU's AI Act requires AI-generated content to be marked and labelled; that is the watermarking story you may have seen. It regulates AI systems as products, and it reaches a UK business only if you put AI systems or their output on the EU market.

Your data protection duties, by contrast, apply today whether or not you ever sell into Europe, and they already cover your use of AI. Run customer data through an AI tool and the UK GDPR governs it today, including February's rewritten rules on automated decisions about people. The new European rules changed the labels on the machines; your duties to the people in your database were there all along. We will take the AI Act apart properly in a separate post. Our own rules for AI inside business systems are already written down.

The one-question audit

If a customer emailed today asking for everything you hold on them, could you send a complete, provable answer within the month?

If yes, most of the rest follows, because the same knowledge that answers the request is what scopes a breach and keeps your records honest. If no, then no folder of policies changes the answer. Compliance is not a document you buy. It is a set of abilities your systems either have or lack, and abilities have to be built.

DocumentBlog post
NoteFN-12 · Compliance
Filed2 Sept 2026
StatusOn the record
Reading~ 6 min
SeriesBlog · FN
Book a discovery call