Module 25 of 26 · Practice & Strategy

Governance, regulation, and compliance

30 min read 3 outcomes Interactive + terminal 10 references

By the end of this module you will be able to:

  • Identify the correct GDPR lawful basis for a given data processing activity
  • Explain Schrems II, adequacy, the EU-US Data Privacy Framework, the UK Extension, and transfer risk assessment
  • Apply the accountability principle to design a compliance-by-design data architecture

Five privacy control families with named UK GDPR articles

Privacy governance maps to five UK GDPR control families: lawful basis, minimisation, security, rights, breach.

Five privacy control families with named UK GDPR articles Five cards left to right: Lawful basis (Art.6), Minimisation (Art.5), Security (Art.32, emphasised), Subject rights (Art.15-22), Breach notification (Art.33). Verb arrows + . A red-accent callout names the missing-evidence audit failure. PRIVACY CONTROLS · UK GDPR + ISO 27701:2025 1Art.6Lawful basisBasis documented first2Art.5(1)(c)MinimisationOnly what is necessary3Art.32SecurityAppropriate technical measures4Art.15-22Subject rightsAccess, rectify, erase, port5Art.33Breach notification72-hour to ICO ++++ Missing evidence is the audit failure Controls without recorded evidence (DPIA, training register, access log, incident report) fail audit. Evidence is the control, not the policy document. ransfordsnotes.com

Privacy governance maps to five concrete control families: lawful basis (UK GDPR Art.6), minimisation (Art.5), security (Art.32), rights (Art.15-22), breach notification (Art.33). Each family has named evidence; missing evidence is the most common audit failure. ISO/IEC 27701:2025 systematises the same controls.

DPIA evidence pack has four binding sections

A DPIA is a four-part evidence pack: nature, necessity, risk, controls plus DPO sign-off.

DPIA evidence pack has four binding sections Four cards left to right: Nature of processing, Necessity + proportionality, Risk assessment (emphasised), Controls + residual. Verb arrows then. A red-accent callout names the consultation-with-DPO step. DPIA EVIDENCE PACK · UK GDPR Art.35 · ICO TEMPLATE 1Art.35Nature of processingScope, context, purpose2Art.35Necessity + proportionalityWhy this data, this way3ICO 2022Risk assessmentLikelihood + severity to subject4ISO 27701Controls + residualMeasures + residual + DPO sign-off thenthenthen DPO consultation is the gate, not a courtesy Article 35(2) requires the controller to seek the DPO's advice; missing this gate is the most common ICO finding. ransfordsnotes.com

A DPIA (UK GDPR Article 35) is a four-part evidence pack: nature of processing, necessity and proportionality, risk assessment, controls and residual risk. Skipping any part fails the ICO template. ISO/IEC 27701:2025 systematises the same structure into the privacy information management system audit.

Retention chain: schedule, trigger, execute, record

Retention has four evidence steps: schedule, trigger, execute, record. The execute step is where evidence is created.

Retention chain: schedule, trigger, execute, record Four cards left to right: Schedule (when), Trigger (event fires), Execute (across copies, emphasised), Record (audit log). Verb arrows then. A red-accent callout names execute as the step where evidence is created. RETENTION CHAIN · FOUR EVIDENCE STEPS · UK GDPR Art.5(1)(e) 1Art.5(1)(e)ScheduleRetention period per dataset2ICOTriggerEvent fires deletion3ISO 27701ExecuteAcross copies + backups4Art.5(2)RecordAudit log with subject reference thenthenthen Execute is the step where evidence is created A retention policy without execution logs is paper. The audit log proves the policy ran, with timestamps and subject references where lawful. ransfordsnotes.com

Retention has four evidence steps: schedule (when to delete), trigger (event that fires deletion), execute (across copies and backups), record (audit log). UK GDPR Article 5(1)(e) requires data kept no longer than necessary; without the execute and record steps the schedule is paper.

Deterministic Data course visual for Governance, regulation, and compliance

Real-world enforcement · May 2023

Meta fined €1.2 billion for transferring EU user data to the US without adequate safeguards

In May 2023, the Irish Data Protection Commission (DPC) issued the largest GDPR fine in history: €1.2 billion against Meta Platforms Ireland, plus an order to suspend data transfers from the EU to the US within 5 months. The root issue was Schrems II.

In July 2020, the Court of Justice of the European Union (CJEU) invalidated the EU-US Privacy Shield framework in the Schrems II ruling. The court found that US surveillance law (particularly FISA Section 702 and Executive Order 12333) did not provide EU citizens with equivalent protections to those guaranteed under EU law. Standard Contractual Clauses (SCCs) remained valid in principle, but a controller had to assess whether the recipient country's law and practice undermined the safeguards in the clauses.

Meta continued transferring data using SCCs and supplementary measures that the DPC found did not address the risks identified by the CJEU. The current decision path is different from a blanket SCC answer: check for adequacy first, use the EU-US Data Privacy Framework or UK Extension only where the US recipient is actively certified and eligible, and use SCCs, the UK Addendum or an IDTA with a transfer risk assessment where no adequacy route applies. Meta's €1.2 billion fine remains a landmark demonstration that international transfer compliance has direct financial consequences.

Meta processed EU user data on US servers under Standard Contractual Clauses. The Irish DPC ruled these clauses were insufficient because US surveillance law (FISA 702) meant EU data was not adequately protected. What current decision path should an organisation apply before transferring personal data across jurisdictions?

Privacy compliance begins before data is collected: the controller must know the purpose, lawful basis, data categories, recipients, retention rule, and risk controls.

25.1 UK GDPR: seven lawful bases for processing

UK GDPR Article 6 requires every personal-data processing activity to have a lawful basis. The controller must identify and document the basis before processing begins; switching bases after the fact is not permitted. ICO guidance now lists seven UK lawful bases after the Data (Use and Access) Act 2025 introduced recognised legitimate interests:

  • Consent (Article 6(1)(a)): The data subject has given freely given, specific, informed, and unambiguous consent. Consent must be as easy to withdraw as to give. Consent is appropriate for marketing emails, optional analytics, and personalisation. It is the weakest basis because it can be withdrawn at any time.
  • Contract (Article 6(1)(b)): Processing is necessary for the performance of a contract with the data subject, or to take pre-contractual steps. Delivering an order to the address provided is processing under contract. Behavioural advertising is not: Meta's €390M fine (January 2023) arose from claiming advertising was necessary for the social media service contract.
  • Legal obligation (Article 6(1)(c)): Processing is required by law. Tax reporting, anti-money laundering checks, and employment records are examples. Legal obligation overrides erasure requests.
  • Vital interests (Article 6(1)(d)): Processing is necessary to protect someone's life. Sharing a patient's blood type with emergency services. Intended as a last resort when the subject cannot consent.
  • Public task (Article 6(1)(e)): Processing is necessary for a public authority to perform a statutory function. NHS patient records for treatment, HMRC tax assessments, police investigations.
  • Recognised legitimate interests (Article 6(1)(ea)): Processing is necessary for a narrow public-interest purpose pre-approved in UK law, such as responding to emergencies or safeguarding vulnerable people. The controller does not carry out the ordinary legitimate-interests balancing test, but must still show the processing fits the recognised purpose and remains necessary and proportionate.
  • Legitimate interests (Article 6(1)(f)): The controller has a legitimate interest that is not overridden by the rights and interests of the data subject, after a documented balancing test. Available to private sector organisations; not available to public authorities acting in an official capacity. Fraud prevention, network security monitoring, and direct marketing to existing customers are common legitimate interest use cases.

The seven bases are not a ladder. ICO guidance says there is no hierarchy and no basis is always safer than another. The correct basis follows the purpose, the controller's role, the data subject's reasonable expectations, and the legal context.

A lawful basis allows processing, but international transfer rules decide whether personal data may cross legal boundaries and under what safeguards.

The controller shall be responsible for, and be able to demonstrate compliance with, the principles relating to processing of personal data.

GDPR Regulation (EU) 2016/679 - Article 5(2) - the accountability principle

The accountability principle is the foundation of GDPR compliance. It is not enough to comply; the controller must be able to demonstrate compliance through records of processing activities, privacy impact assessments, data protection policies, staff training logs, and contractual evidence. In an enforcement investigation, the ICO or DPC will ask for documentation. Organisations without records cannot demonstrate compliance even if they are in fact compliant.

Loading interactive component...

25.2 International transfers: Schrems II and the Data Privacy Framework

Transferring personal data from the EU to a country outside the European Economic Area (EEA) requires an adequacy decision or an alternative transfer mechanism. The European Commission adopted UK adequacy decisions in 2021 and renewed the UK GDPR and law-enforcement adequacy decisions on 19 December 2025. For countries, sectors, or recipients not covered by adequacy, controllers must use appropriate safeguards such as SCCs, BCRs, or a limited derogation.

Standard Contractual Clauses (SCCs) are pre-approved contract terms that impose GDPR-equivalent obligations on the data importer. Following Schrems II (July 2020), using SCCs alone is insufficient: the controller must conduct a Transfer Impact Assessment (TIA) analysing whether the recipient country's surveillance law allows the importing organisation to honour the SCC commitments. If the law does not, supplementary technical measures (such as end-to-end encryption where the importer holds no keys) may be required.

The EU-US Data Privacy Framework (DPF), adopted by the European Commission on 10 July 2023, created an adequacy route for US organisations that self-certify and maintain active status under the DPF. The UK Extension, also called the UK-US data bridge, allows UK and Gibraltar organisations to transfer personal data to eligible US businesses that participate in the DPF and have opted into the UK Extension. The ICO warns that organisations must check active status, data type coverage, and extra requirements for HR, special category, and criminal offence data.

Binding Corporate Rules (BCRs) provide a third mechanism for multinational organisations to transfer data internally across countries. BCRs require approval from a lead supervisory authority and apply to all entities within the corporate group. They are usually a strategic investment for large organisations with repeated intra-group transfers, not a quick fix for a single vendor integration.

Worked example: a UK analytics team wants to send customer events to a US vendor. If the vendor has active DPF status and opted into the UK Extension for the relevant data type, the team may rely on the UK Extension while still meeting UK GDPR principles. If not, the team needs an IDTA or UK Addendum to SCCs, a transfer risk assessment, encryption and access controls matched to the risk, and records showing why the transfer remains lawful.

Transfer rules are only one part of the control environment; operating across UK and EU markets also brings domestic data protection reform and EU cybersecurity duties for in-scope entities.

Common misconception

Encrypting data before transferring it to a US cloud provider fully resolves Schrems II compliance concerns.

Encryption reduces risk but does not automatically resolve the transfer concern. The key question is: who holds the encryption keys? If the US cloud provider holds the keys, US surveillance authorities can compel access to the decrypted data, which means the transfer may still undermine the SCC commitments. The only technical measure that fully addresses Schrems II is end-to-end encryption where the EU-based controller retains all encryption keys and the US processor cannot access plaintext. This rules out most standard cloud services in their default configurations.

25.3 UK GDPR divergence and EU NIS2 duties for in-scope entities

Following Brexit, the UK retained GDPR in domestic law as UK GDPR (Data Protection Act 2018, amended by the European Union (Withdrawal) Act 2018). UK GDPR is substantively identical to EU GDPR in most respects, but UK organisations must consider two separate regulatory regimes: EU GDPR applies to processing related to EU residents, and UK GDPR applies to processing related to UK residents.

The Data (Use and Access) Act 2025 introduces targeted divergence from EU GDPR. ICO guidance highlights recognised legitimate interests, changes to automated decision-making, cookie rule changes for specified low-risk purposes, and new research and reuse provisions. For significant automated decisions using personal information, the Act opens the full range of lawful bases where safeguards continue to apply, but special category data remains more protected. UK organisations should monitor ICO guidance rather than assuming UK GDPR and EU GDPR remain aligned.

NIS2 is an EU directive, not a general UK statute. It matters to organisations established in EU Member States, entities that meet the directive's scope tests, and UK-headquartered groups with in-scope EU operations or services. Essential and important entities must implement proportionate security measures, manage supply-chain risk, and report significant incidents to the relevant national CSIRT or competent authority within 24 hours as an early warning and within 72 hours as a fuller incident notification. Management bodies have explicit governance duties and can face Member State enforcement where national transposition law applies.

25.4 Check your understanding

A retail company wants to send promotional emails about new products to customers who have previously purchased. The marketing team argues this is legitimate interests; the legal team argues consent is required. Under GDPR, which is correct?

Following the Schrems II ruling, a UK fintech transfers customer personal data to a US data analytics partner under updated SCCs. The DPO has not yet conducted a Transfer Impact Assessment. What risk does the organisation face?

A healthcare data platform operating in an EU Member State is in scope of NIS2 as an essential entity. It experiences a ransomware attack at 09:00 on Monday. By when must it make its early warning to the national competent authority or CSIRT, and what must that notification contain?

Loading interactive component...

Core checks before moving on

  • Every UK GDPR processing activity needs a lawful basis documented before processing begins: consent, contract, legal obligation, vital interests, public task, recognised legitimate interests, or legitimate interests.
  • International transfers need adequacy or safeguards. The UK adequacy decisions were renewed on 19 December 2025, and the EU-US DPF and UK Extension work only for participating US organisations with active certification.
  • Schrems II means SCCs still require transfer risk analysis and, where necessary, supplementary technical measures that actually prevent access to plaintext data.
  • The accountability principle requires evidence: RoPA, DPIAs, lawful-basis records, transfer assessments, processor contracts, training logs, and review dates.
  • NIS2 should be scoped carefully. It is an EU directive for in-scope essential and important entities, including UK groups where their EU operations or services fall within Member State implementing law.

Standards and sources cited in this module

  1. GDPR Regulation (EU) 2016/679

    Full text of the regulation including Article 6 (lawful bases), Article 5(2) (accountability), Article 30 (RoPA), Article 35 (DPIA), and Article 46 (international transfer mechanisms).

  2. CJEU, Data Protection Commissioner v Facebook Ireland (Schrems II), Case C-311/18 (July 2020)

    Landmark ruling invalidating Privacy Shield and establishing the TIA requirement for SCCs-based transfers.

  3. European Commission adequacy decisions

    Current official source for EU adequacy decisions, including UK adequacy renewal on 19 December 2025 and the EU-US Data Privacy Framework adequacy decision.

  4. ICO: UK Extension to the EU-US Data Privacy Framework

    Practical UK guidance on active DPF status, eligible US businesses, HR data, special category data, and periodic checks.

  5. GOV.UK: UK-US data bridge supporting documents

    Official UK source for the UK Extension effective from 12 October 2023 and the data bridge mechanism.

  6. Irish DPC Decision on Meta Platforms Ireland (May 2023)

    Source for the EUR1.2 billion fine, the suspension order, and the finding that Meta's transfer safeguards did not address Schrems II risks.

  7. ICO: Data (Use and Access) Act 2025 guidance

    Current ICO guidance on recognised legitimate interests, automated decision-making, cookies, and research reuse under DUAA 2025.

  8. NIS2 Directive (EU) 2022/2555

    Full text of NIS2 including the notification timeline (Article 23) and the expanded scope of essential and important entities.

  9. ENISA: NIS2 incident reporting

    Official EU cybersecurity agency summary of the 24-hour early warning and 72-hour incident notification structure.

  10. UK ICO: Lawful basis for processing

    Practical guidance on choosing and documenting the lawful basis under UK GDPR, including the Legitimate Interests Assessment checklist.

Module 25 of 26 · Practice & Strategy