UK GDPR has been in force since January 2021. For most SMEs, the honest position is somewhere between "we did something in 2018" and "we know we should revisit this but haven't."

This checklist is designed for exactly that situation. Work through each section and note what's in place, what's partial, and what's missing. That gap analysis is the starting point for a manageable compliance roadmap.

Section 1: Foundations

Lawful basis

Record of Processing Activities (RoPA)

Privacy notice

Section 2: Individual Rights

UK GDPR gives individuals eight rights. You must be able to respond to requests exercising any of them.

Section 3: Data Processors and Third Parties

Section 4: Data Security

Section 5: Data Retention

Section 6: Data Breach Response

Section 7: Special Situations

Marketing

CCTV (if applicable)

Section 8: Governance

Interpreting your results

Mostly ticked: You have a solid foundation. Focus on the gaps, document your position, and build a review cadence.

Partial across most sections: This is the most common position for SMEs. Prioritise the areas with the highest risk: breach response (72-hour clock), SAR handling (30-day deadline), and processor agreements.

Several unticked in Sections 1–3: Your foundations need attention before more detailed work is useful. Start with the RoPA and lawful basis, as everything else builds on them.

Your next steps

If the checklist has identified gaps, tackle them in order of risk rather than trying to do everything at once.

Highest priority

  1. Document your lawful bases and build a basic RoPA
  2. Ensure your SAR response process is functional and timed
  3. Get DPAs in place with your processors
  4. Implement a breach log and response procedure

Medium priority

  1. Update your privacy notice
  2. Implement a data retention policy
  3. Review access controls on personal data systems

Ongoing

  1. Staff awareness and training
  2. Annual RoPA and policy review
  3. DPIA for new high-risk processing activities

How Quantra supports your compliance programme

Quantra's workbenches are built around the compliance obligations SMEs find hardest to operationalise: Q-SAR for Subject Access Request workflows, Q-ROT for retention obligation tracking, Q-RoPA for building and maintaining your Record of Processing Activities, and the Quantra Agent for local PII detection in documents before data leaves your environment.

See all Quantra products →
This checklist provides general guidance on UK GDPR compliance for SMEs. It does not constitute legal advice and is not a substitute for professional data protection advice tailored to your organisation. · Quantra Solutions Ltd · quantra-solutions.co.uk