Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

UK · GDPR / DPA 2018

Records, security & 72-hour breach notice.

Applies to: Controllers/processors of UK personal data. Built · in force

What the signed record shows

Processing records, security and breach detail supporting 72-hour ICO notification.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: UK GDPR Arts 5(2)/30/32/33/22; DPA 2018

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

UK GDPR (retained Regulation (EU) 2016/679 as it forms part of UK domestic law) together with the Data Protection Act 2018 (c. 12). Provisions addressed:

Art. 33
Notification of a personal data breach to the Commissioner (ICO) without undue delay and, where feasible, not later than 72 hours;
Art. 33(5) requires documenting personal data breaches.
Art. 30
Records of processing activities (ROPA).
Art. 5(2)
Accountability (demonstrate compliance).
Art. 32
Security of processing.
Art. 22
Automated individual decision-making, including profiling. Reforms under the Data (Use and Access) Act 2025 (and SI 2026/386) are phased; the in-force date of each amended provision should be confirmed.

Taken from the Regulayer entry for this instrument, which is built against the primary text.

This is the duty on the business. For what a lawyer in Europe must disclose about using AI in a filing, see Europe: the EU AI Act, the CCBE guides, and what Germany tells its lawyers.