UK GDPR (the UK General Data Protection Regulation, alongside the Data Protection Act 2018) is the law that governs how organisations handle personal data in the UK. If a customer trusts you with any personal data, expect their security questionnaire to ask how you protect it.
Draft your UK GDPR answers free →What UK GDPR covers
Questionnaires tend to probe the same core obligations. Tickbox grounds your answers in each of them:
You process personal data only where a valid lawful basis applies, recorded before processing begins.
Appropriate technical and organisational measures protect personal data against loss or unauthorised access.
Breaches are detected, logged, and reported to the ICO within 72 hours where individuals are at risk.
You can recognise and fulfil access, erasure, and other rights requests, normally within a month.
You collect only the data you need and delete it securely once its purpose is met.
Transfers outside the UK use a recognised safeguard such as adequacy or an IDTA.
You keep records of processing, hold policies, train staff, and run DPIAs for high-risk work.
Third parties handling data for you are bound by a written contract and equivalent obligations.
Questions you might be asked
- What is your lawful basis for processing personal data?
- How do you respond to data subject access requests?
- Do you have a process to report personal data breaches within 72 hours?
- How is personal data protected in transit and at rest?
- Do you transfer personal data outside the UK, and how is it safeguarded?
- How long do you keep personal data, and how is it deleted?
Why you get asked about it
When you handle personal data on a customer’s behalf, they are accountable for choosing a supplier that keeps it safe. So they ask you to show your data protection is in order before they sign, and often every year after.
Explore other frameworks
Answer these in minutes, not days
Drop your questionnaire in and Tickbox drafts every answer for you to review.
Try it free