← All insights
Guides20 January 2026·9 min read

GDPR belts and braces guide

A practical, plain-English checklist for the controls and records that keep you defensible when the ICO comes knocking.

This is the checklist we run through with clients preparing for an ICO enquiry — no jargon, no ceremony, just the artefacts that matter and the state they need to be in. If you can produce these on request, you are in a defensible position regardless of what triggered the enquiry.

One: your Record of Processing Activities. The ROPA is the single most important document in any regulatory engagement. It should cover every processing activity, name the controller and any joint controllers, identify the lawful basis, describe the data categories and data subjects, list the recipients including processors, note any international transfers with their safeguards, and state the retention period. A ROPA that has not been updated in the last twelve months is worse than no ROPA at all, because it invites the regulator to compare it to reality.

Two: your privacy notice. It should be current, cover all Article 13 and 14 information requirements, be written in plain language, and be accessible at every point of data collection. A dated version-controlled copy of every previous version should be kept, because an enquiry may relate to processing that started under an earlier version.

Three: your lawful basis assessments. For every processing activity in the ROPA, there should be a documented rationale for the lawful basis. For legitimate interests, a legitimate interests assessment. For consent, evidence of how consent is captured and how it can be withdrawn. For contract, a link to the contract clause that necessitates the processing.

Four: your DPIAs. Any high-risk processing — new technology, large-scale profiling, systematic monitoring, special category data at scale — should have a DPIA that identifies the risks, the mitigations, and the residual risk after mitigation. DPIAs should be reviewed when the processing changes materially.

Five: your processor contracts. Every processor should have a written contract that meets Article 28 requirements, including sub-processor arrangements, transfer mechanisms, breach notification obligations, and audit rights. A register of processors and their contract review dates makes the annual refresh manageable.

Six: your international transfer safeguards. For every transfer outside the UK, the transfer tool and any supplementary measures should be documented. Where a TRA is required, it should be current and specific to the transfer.

Seven: your breach register. Every incident that involves personal data, whether or not it met the notification threshold, should be logged with the facts, the assessment, the decision, and the person who signed it off. A regulator asking about your breach handling wants to see the pattern of decisions, not just the notifiable ones.

Eight: your subject rights workflow. A documented process for handling access, rectification, erasure, portability, and objection requests, with evidence of recent responses and the median response time. If you have never received a request, walk through a hypothetical one to prove the workflow works.

Nine: your training records. Evidence that staff who handle personal data have received appropriate training within the last twelve months, tailored to their role. A single all-staff e-learning module is a baseline, not a ceiling.

Ten: your governance evidence. Minutes of the forum where privacy decisions are made, the risk register, and the reporting line to the board. A regulator asking who owns privacy in your organisation wants a name, a diary, and a paper trail.

Get these ten in order and most ICO enquiries become manageable. Get them out of order and even a minor enquiry can escalate.

Companies we've supported

59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai59AThe Compliance EngineersAikenCountry & Town HouseLightbulbGraffic JamSerenefounditAIMEaffiliate.ai