UK General Data Protection Regulation (UK GDPR)
The UK GDPR is Regulation (EU) 2016/679 as it forms part of UK domestic law, published on legislation.gov.uk under the title "United Kingdom General Data Protection Regulation" and read alongside the Data Protection Act 2018. It is enforced by the Information Commissioner (referred to in the text as "the Commissioner").
Applicability to EdTech
EdTech products typically process personal data of UK teachers and pupils (accounts, device telemetry, uploaded content, audio/image data). Schools are typically the controller and the EdTech vendor a processor — Article 28 processor obligations and children's-data provisions are the most frequently cited in RFIs.
Contents
| Document | Covers |
|---|---|
| PRINCIPLES.md | Art. 5, 8A — processing principles, accountability, further-processing compatibility |
| LAWFUL-BASES.md | Art. 6, 7, 9, 10, 11, 11A — lawfulness, consent conditions, special categories, criminal-offence data |
| CHILDREN.md | Art. 8, 8ZA — children's consent (age 13 in the UK), age verification |
| DATA-SUBJECT-RIGHTS.md | Art. 12–23 (incl. 12A, 22A–22D) — transparency, access, erasure, portability, objection, automated decision-making |
| CONTROLLER-PROCESSOR.md | Art. 24–31, 37–39 — controller responsibility, data protection by design, Art. 28 processor contracts, records, DPOs |
| SECURITY-AND-BREACH.md | Art. 32–34 — security measures, breach notification |
| DPIA.md | Art. 35–36 — impact assessments, prior consultation |
| INTERNATIONAL-TRANSFERS.md | Art. 44–50 (incl. 44A, 45A–45C, 47A, 49A) — transfer principles, adequacy regulations, safeguards, derogations |
| ENFORCEMENT.md | Art. 58, 77–84 — Commissioner's powers, remedies, compensation, administrative fines |
Key obligations at a glance
Each line is a compressed pointer; the verbatim text in the linked documents is authoritative.
- Personal data must be processed according to the Art. 5 principles, and the controller must be able to demonstrate compliance (Art. 5(1)–(2) — PRINCIPLES.md).
- Processing needs an Art. 6(1) lawful basis; consent must meet the Art. 7 conditions (LAWFUL-BASES.md).
- For information society services offered directly to a child on the basis of consent, the child must be at least 13 years old; below 13, consent must come from the holder of parental responsibility (Art. 8(1) — CHILDREN.md).
- Services likely to be accessed by children must take the "children's higher protection matters" into account in design (Art. 25(1A)–(1B) — CONTROLLER-PROCESSOR.md).
- Processing by a processor must be governed by a contract containing the Art. 28(3) stipulations (documented instructions, confidentiality, security, sub-processor terms, assistance, deletion/return, audit) (CONTROLLER-PROCESSOR.md).
- Personal data breaches must be notified to the Commissioner without undue delay and where feasible within 72 hours, unless unlikely to result in risk (Art. 33(1) — SECURITY-AND-BREACH.md).
- High-risk processing requires a data protection impact assessment before it starts (Art. 35 — DPIA.md).
- Personal data may be transferred to a third country or international organisation only if the transfer is approved by regulations (Art. 45A), made subject to appropriate safeguards (Art. 46), or made in reliance on a derogation (Art. 49) (Art. 44A — INTERNATIONAL-TRANSFERS.md).
- Article 22 (automated individual decision-making) is repealed in the UK GDPR; the regime is now Art. 22A–22D (DATA-SUBJECT-RIGHTS.md).
Enforcement
Enforced by the Information Commissioner. Administrative fines reach £8,700,000 or 2% of total worldwide annual turnover (whichever is higher) for the Art. 83(4) tier, and £17,500,000 or 4% for the Art. 83(5) tier, which includes infringements of the basic principles, data subjects' rights, and transfer rules. Verbatim text in ENFORCEMENT.md.
Related
- Data Protection Act 2018 — companion statute; the UK GDPR must be read alongside it
- EU GDPR — the instrument the UK GDPR was retained from; diverging over time
Sources
- legislation.gov.uk — UK GDPR (Regulation (EU) 2016/679 as retained)
- legislation.gov.uk — Data Protection Act 2018
- ICO — UK GDPR guidance and resources
Meta
The fact documents in this folder reproduce the article text verbatim from the consolidated text on legislation.gov.uk (valid as at 2026-06-19 at last check), extracted mechanically from the official XML per METHODOLOGY.md. The consolidation includes substantial post-Brexit amendment: inserted articles (e.g. 8ZA, 8A, 11A, 22A–22D, 44A–49A) and repeals (e.g. Article 22), so the UK text now differs materially from the EU GDPR.
These documents are built and re-verified mechanically — see tools/legislation-gov-uk. build_gdpr.py regenerates the fact documents from the current consolidation and stamps last_checked; build_gdpr.py verify confirms every text node of the source XML appears verbatim in the output. Do not hand-edit article text.