Framework library
Framework module · uk-gdpr

UK GDPR

The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock.

UK GDPR + DPA 2018 (as amended by DUAA 2025) · UK Information Commissioner's Office · published 2025-06-19

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

UK GDPR is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

Freely published; obligations not modelled as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Lawfulness · Data subject rights · Controller obligations · Security of processing · International transfers
Applies to
all sectors · UK
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
Pending change
DUAA data protection provisions commence in stages. The regulations published 2026-01-29 brought further changes into force from 2026-02-05; later tranches remain outstanding.Expected: Staged commencement through 2026

03Version ledger

2 editions
UK GDPR + DPA 2018Supersededdate not published
UK GDPR + DPA 2018 (as amended by DUAA 2025)Current edition · supersedes UK GDPR + DPA 20182025-06-19
UK GDPR — framework module | ControlFrame