UK Independent. Sourced. Primary. · Est. 2024
Document library

Data and privacy pack

Under UK GDPR a personal data breach likely to risk people's rights must be reported to the ICO within 72 hours, and a subject access request answered within one month. Both deadlines are missed most often by businesses with no written procedure to follow on the day.

Core pack · 11 documents · 68 pages

The short answer

Under UK GDPR a personal data breach likely to risk people's rights must be reported to the ICO within 72 hours, and a subject access request answered within one month. Both deadlines are missed most often by businesses with no written procedure to follow on the day.

Who this pack is for

  • Any UK business holding customer or staff records, which is all of them
  • Ecommerce and service businesses handling online enquiries
  • Employers storing HR files, payroll and health information
  • Businesses asked for a data processing agreement by a larger client
  • Anyone who has received a subject access request and does not know the deadline

Not for you if: You are a large organisation required to appoint a statutory data protection officer and need bespoke governance.

What it solves

1

A customer asks for everything you hold on them and the clock starts.

2

A laptop is lost and nobody knows whether the ICO must be told.

3

A corporate client refuses to sign until you produce a processor agreement.

What the law requires

Breaches: 72 hours

A personal data breach must be reported to the ICO without undue delay and within 72 hours of becoming aware, unless it is unlikely to risk people's rights. High risk breaches must also be told to the individuals. A breach log is required whether or not the breach is reportable.

Source: ICO, personal data breaches guidance

Subject access: one month, usually free

You must respond within one calendar month, extendable by two months for complex requests. There is no fee except where the request is manifestly unfounded or excessive. Identity checks pause the clock only if made promptly.

Source: ICO, right of access guidance

You must know what you hold

Most organisations must keep a record of processing activities covering purposes, categories of data, recipients, transfers and retention. It is the first document the ICO asks for, and it is what makes a retention schedule possible.

Source: ICO, documentation and ROPA guidance

What is in the pack

IDDocumentPages
DAT-01Privacy notice (customers)ICO privacy notice checklist6
DAT-02Privacy notice (employees)ICO employment practices guidance6
DAT-03Cookie policy and consent textPECR; ICO cookies guidance4
DAT-04Data retention scheduleICO storage limitation5
DAT-05Record of processing activitiesUK GDPR Article 307
DAT-08Subject access request procedure and lettersICO right of access8
DAT-09Breach log and response planICO breach reporting6

And four more: data protection policy, DPIA template, data processor agreement, staff training record.

How updates work

Every document carries a version number and a reviewed date. On the first Tuesday of each month the pack is checked against its primary sources. If anything has changed you receive the updated file and one line explaining what moved and why. If nothing has changed you receive an email saying so.

April and the Budget are the months when most figures move.

Questions

Do I need a data protection officer?

Most small businesses do not. A DPO is required for public authorities and for large scale monitoring or special category processing. The pack includes a named data contact instead.

Is a cookie banner enough?

No. Non-essential cookies need consent before they are set, and the policy has to describe them. The pack includes the policy text and the consent wording.

Does this cover EU customers?

The documents are written for UK GDPR. If you offer goods or services into the EU you may also need an EU representative, which is outside this pack.

What if I use cloud tools like Google or Microsoft?

Those are processors. The pack includes the processor agreement template and a supplier list for your ROPA.

How is it delivered?

By email, as Word and PDF files, personalised with your company details.

Sources

Built from published UK primary sources only: ICO, documentation and ROPA guidance, ICO, personal data breaches guidance, ICO, right of access guidance. No secondary or aggregator sources are used.

Order the data and privacy pack, or ask about an association licence covering your whole membership.

Email support@kaeltripton.com

Other packs in the library

See the full document library

Templates, not advice

These documents are drafted from published UK primary sources and are a starting point you adapt to your own circumstances. They are not legal, tax or immigration advice, and documents you edit become your responsibility.

Get Kael Tripton in your Google feed

⭐ Add as Preferred Source on Google