Welcome to Simply-Docs

UK GDPR & Data Protection Documents

If your business collects or uses personal data about individuals, you will need to comply with the United Kingdom’s data protection regime. This is based primarily on the UK GDPR and the Data Protection Act 2018.

Legal and Compliant

All Simply-Docs templates are written and maintained by experienced legal professionals. These data protection templates are regularly reviewed and updated to ensure continued compliance with current UK law.

Starting 19th June, new legal requirements introduced by the Data (Use and Access) Act 2025 make it mandatory for all UK organisations to have a process in place for handling data protection complaints. Updated Data Protection Policies and a new Data Protection Complaints Policy & Procedure suite are now available.

When is Data Protection Documentation Important?

Data protection compliance obligations arise in many different contexts, from employment and HR to sales, customer service, business-to-business relationships, and much more.

This range of templates is designed to support a variety of common compliance tasks, including:

  • Reviewing your current position and assessing new projects;
  • Putting internal policies and controls in place;
  • Publishing appropriate website privacy and cookie information;
  • Responding consistently to data subject access requests and rights;
  • Recording and managing personal data breaches; and
  • Documenting controller, processor, and sharing arrangements with other organisations.

What is Included in This Range?

  • Data Protection Auditing and Privacy Impact Assessments - templates and guidance for reviewing current compliance and assessing risk in new or changed processing.
  • UK GDPR and Data Protection Policies - internal policies and supporting documents covering day-to-day data handling, security, and retention.
  • Website Privacy and Cookie Policies - website privacy policy options plus cookie policy wording and guidance to match your site’s use of cookies, analytics, and similar technologies.
  • Standard Privacy Notices - privacy notice templates for providing privacy information where data is collected offline or outside a website context.
  • Data Subject Access Requests - a toolkit for handling subject access requests (SARs), including guidance, policies, an optional form, and response letters.
  • Data Subject Rights - a policy-and-letters toolkit for managing other UK GDPR rights requests consistently, including common scenarios such as identity checks and time extensions.
  • Data Protection Complaints - a policy & procedure, supported by a form and letters toolkit for handling and responding to data protection complaints from individuals.
  • Personal Data Breaches - templates designed to work together for reporting, recording, and managing personal data breaches, including a register and guidance.
  • Data Processing Agreements - standalone templates for controller and processor arrangements, including options for international transfers where needed.
  • Data Sharing Agreement - a controller-to-controller data sharing agreement template for situations where organisations share personal data for their own purposes.
  • Data Protection and Data Processing Clauses - short clause templates for inserting into contracts and terms and conditions, with a clear distinction between general data protection and controller and processor wording.

Choosing the right selection of documents and adapting them to your business helps you to comply with data protection law and demonstrates that compliance, while protecting your interests and the rights of individuals whose personal data you handle.

Why Subscribe to Simply-Docs Business?

In addition to being able to select from this extensive range of data protection document templates, a subscription provides unlimited downloads of all contracts, letters, forms, policies, and more for one year, enabling you to document and protect your business transactions and to ensure compliance with regulations.

Click on the links below to discover the full range of UK GDPR & Data Protection templates:

UK GDPR & Data Protection Documents is part of Business . Just £38.50 + VAT provides unlimited downloads from Business for 1 year.

Frequently Asked Questions

What data protection law applies to my UK business? +
The core regime is the UK GDPR together with the Data Protection Act 2018, regulated by the Information Commissioner's Office. The Data (Use and Access) Act 2025 has since amended parts of that regime rather than replacing it. Separate rules under PECR govern cookies and electronic marketing. If you decide how and why personal data is used, these rules apply to you whatever your size.
Do small businesses have to comply with UK GDPR? +
Yes. There is no general small business exemption. If you process personal data as a controller or processor the core duties apply, whatever your size. Some record keeping is lighter for organisations with fewer than 250 staff, but only in limited circumstances, and the main obligations on lawful basis, security, transparency and individual rights still apply in full.
What is the difference between a data controller and a data processor? +
A controller decides why and how personal data is processed. A processor only acts on the controller's instructions, for example a payroll bureau or cloud provider. The distinction matters because controllers carry the primary duties, and whenever a controller uses a processor there must be a written contract with specific terms. Many businesses are controllers for some data and processors for other data.
Do I need to register or pay a fee to the ICO? +
Most organisations that process personal data must pay the ICO data protection fee each year unless they are exempt. There are three tiers based on size and turnover: £52 for micro organisations, £78 for small and medium organisations and £3,763 for large organisations, with a small discount for direct debit. Failing to pay when required can itself lead to a fine, separate from any breach of the UK GDPR.
What has the Data (Use and Access) Act 2025 changed? +
It keeps the UK GDPR and Data Protection Act 2018 framework but adjusts several points. From 19 June 2026 organisations must operate a data protection complaints process. Subject access searches now need only be reasonable and proportionate, with a formal stop the clock for clarification. Cookie rules gained narrow consent exemptions from 5 February 2026, PECR fines rose to UK GDPR levels and a set of recognised legitimate interests was introduced.
Where do I start with data protection compliance? +
Start by understanding what personal data you hold, why you hold it and how it flows, then build outwards. A data protection audit reviews your current position, internal policies set staff expectations, privacy notices tell people what you do, and procedures cover subject access, complaints and breaches. This group is arranged along those lines so you can put the pieces in place in a sensible order rather than all at once.

Simply-4-Business Ltd Registered in England and Wales No. 4868909, 20 Mortlake High Street, Mortlake, London SW14 8JN

Top