Compliance Self-Assessment
UK GDPR Data (Use and Access) Act 2025 DPA 2018 PECR (as amended)

How compliant is your
organisation with UK GDPR
& the DUAA 2025?

A structured 20-question readiness assessment mapped to the current UK data protection framework — including the new obligations introduced by the Data (Use and Access) Act 2025 that took effect from June 2025. Generate a formal compliance gap report in under 10 minutes.

Assessment Overview
Current 2025/26
Total Questions20
Domains4
Est. Completion~8 min
UK GDPR & DPA 2018
Core data protection principles, lawful bases, data subject rights, controller obligations, DPO requirements, DPIA and breach notification.
Data (Use & Access) Act 2025
Recognised legitimate interests, automated decision-making reforms, children's higher protection, PECR alignment, complaints procedures & DSARs.
Governance & Accountability
Section 1 of 4
0 / 20
Section 01
UK GDPR Art. 5 / 24DPA 2018
Governance & Accountability

Accountability is a core UK GDPR principle (Art. 5(2)). Organisations must demonstrate compliance, not merely assert it. This section assesses your governance structures, designated roles, record-keeping and staff awareness obligations.

Section 02
UK GDPR Art. 6 / 7 / 12-22DUAA 2025
Lawful Basis & Data Subject Rights

Every processing activity requires a documented lawful basis under Art. 6. The DUAA 2025 introduced a new 'recognised legitimate interests' basis and new individual rights including a statutory right to raise complaints directly with controllers.

Section 03
UK GDPR Art. 25 / 32 / 33-34DUAA 2025
Data Management & Security

Privacy by Design (Art. 25), appropriate technical and organisational security measures (Art. 32), 72-hour breach notification (Art. 33), and the DUAA 2025 updated international transfer test — all require active technical implementation.

Section 04
DUAA 2025 — New Obligations
DUAA 2025 — New Specific Requirements

The Data (Use and Access) Act 2025, which came into force from June 2025 on a phased basis, introduces specific new obligations. This section assesses your readiness against the key reforms including automated decision-making, children's protections, cookie reforms and the new complaints regime.

UK GDPR & DUAA 2025 Compliance Report Confidential