UK GDPR + ICO guidance · 8 jurisdiction-specific documents · One-time purchase
AI governance documents built for UK obligations.
UK GDPR and ICO AI guidance create obligations a jurisdiction-neutral pack cannot cover, and the UK regime has diverged: the Data (Use and Access) Act 2025 replaced Article 22 with a new Section 4A. The UK Pro Pack adds 8 documents built on Articles 22A to 22D, UK GDPR record-keeping requirements, and the 72-hour breach notification clock to the Information Commissioner's Office.
UK GDPR Section 4A · Arts. 22A–22D
UK Automated Decision-Making Assessment
[Company Name] · Reviewed [Date] · Owner [Name]
Decision type assessed
Shortlisting, credit limit, pricing…
Significant decision? — Art. 22A(1)(b)
Legal or similarly significant effect
Meaningful human involvement? — Art. 22A(1)(a)
Reviewer role, departure rate
Art. 22C safeguards in place
Information / representations / intervention / contest
Who needs this
UK businesses have distinct GDPR obligations — the ICO supervises them, not EU regulators.
Post-Brexit, UK GDPR is a separate legal regime from EU GDPR. The ICO is the supervisory authority, with its own enforcement approach, guidance, and toolkit. UK businesses processing personal data using AI need documentation that references UK GDPR, the ICO, and Data Protection Act 2018 — not EU GDPR or EU data protection authorities.
UK-based businesses
Any SME in England, Scotland, Wales, or Northern Ireland using AI tools in a professional context.
Businesses with UK customers
Non-UK companies processing personal data of UK residents — UK GDPR applies regardless of where the company is registered.
HR and recruitment
AI-assisted CV screening, performance review, or scheduling tools — ICO has specific guidance on automated employment decisions.
Customer service and marketing
Chatbots, personalisation, and profiling tools where the ICO's transparency and fairness requirements apply.
What is included
8 documents, each aligned to UK GDPR obligations and ICO guidance.
Every file in this pack exists because UK GDPR or ICO guidance creates an obligation or expectation that the Starter Pack does not cover. Files that would be near-identical to the Starter Pack equivalent were not included — the Pro Pack earns its price on every document.
1 file
Assessment
UK Automated Decision-Making Assessment
XLSXWorks through the new UK GDPR Chapter III Section 4A — Articles 22A to 22D, substituted for the repealed Article 22 by the Data (Use and Access) Act 2025 and fully in force since 5 February 2026. Tests whether a decision is significant, whether it is solely automated, whether the Article 22B special-category restriction bites, and whether all four Article 22C safeguards are in place.
2 files
Policies
UK-Aligned AI Usage Policy
DOCX + PDFThe Starter Pack usage policy extended with the automated decision-making obligations in UK GDPR Articles 22A to 22D — the Section 4A regime that replaced Article 22 — plus the ICO as supervisory authority and British English throughout. Materially different from both the neutral version and the EU equivalent.
UK AI Transparency Notice
DOCX + PDFCustomer-facing and employee-facing AI transparency language aligned with UK GDPR Articles 13–14 privacy notice requirements and ICO guidance on explaining AI decisions. Includes the ICO's recommended elements for AI transparency.
2 files
Records
UK GDPR AI Data Processing Register
XLSXRecords each AI system, its lawful basis for processing personal data under UK GDPR, data categories, retention periods, and ICO contact details. Required for UK GDPR Article 30 compliance. Structured for the ICO's supervisory context.
UK DPIA Trigger Checklist
XLSXDetermines whether a Data Protection Impact Assessment is required for an AI use case, following UK GDPR Article 35 criteria and ICO DPIA guidance. Identifies when an ICO prior consultation is also required. No Starter Pack equivalent.
2 files
Checklists
UK GDPR Data Input Rules Checklist
XLSXThe Starter Pack data input checklist extended with a UK GDPR lawful basis column and special-category data flagging — health, biometric, and ethnic origin data have heightened obligations under the UK regime.
UK AI Vendor Due Diligence Checklist
XLSXThe Starter Pack vendor review checklist extended with UK GDPR Article 28 processor agreement requirements and ICO guidance on using AI vendors. Covers the contractual terms the ICO expects to see in data processing agreements.
1 file
Response
UK AI Incident Response Procedure
DOCX + PDFThe Starter Pack incident procedure extended with the 72-hour personal data breach notification clock to the ICO under UK GDPR Articles 33–34, and ICO enforcement context for AI-related incidents.
UK AI Governance Pro Pack
- All 8 UK-specific documents
- 3 editable DOCX + PDF files
- 5 fillable XLSX worksheets
- Aligned to ICO guidance
- Lifetime file access
- 7-day money-back guarantee
Already have the Starter Pack? The UK Pro Pack + Starter Pack bundle is available at checkout for $69 — save $9 versus buying separately.
Secure checkout and invoice through Lemon Squeezy. VAT applied where required.
Questions
Before you purchase.
- Does UK GDPR still apply after Brexit?
- Yes. The UK retained EU GDPR into UK law as 'UK GDPR' under the Data Protection Act 2018, and the supervisory authority is the Information Commissioner's Office (ICO) rather than EU data protection authorities. Many obligations still line up — Article 30 records and Article 35 DPIAs among them — but divergence is no longer theoretical. The Data (Use and Access) Act 2025 repealed Article 22 outright and substituted a new Chapter III Section 4A (Articles 22A to 22D), fully in force since 5 February 2026, which sets a narrower prohibition than the EU's Article 22 but adds four mandatory safeguards. That is why a UK-specific pack is not the EU pack with the spelling changed.
- Is there a UK AI Act equivalent?
- Not yet as of 2026. The UK government's AI regulatory approach (set out in the 2023 Pro-innovation Approach to AI Regulation White Paper) is principles-based and relies on existing sector regulators rather than a single binding AI law. The ICO has published detailed AI and data protection guidance — including the AI and Data Protection Risk Toolkit — which sets the practical standard for AI governance in the UK. This pack is ICO-guidance-framed, not a binding law equivalent.
- Do I need the Starter Pack too?
- The UK Pro Pack adds UK-specific documents on top of a foundation of good AI governance practice. It is designed to complement the Starter Pack, not replace it. The Starter Pack covers neutral operational rules, employee guidance, and training notes that are not UK-specific. If you already have internal AI governance documents, review them against the UK Pro Pack before purchasing both.
- Is this legal or compliance advice?
- No. The pack provides practical operational templates informed by UK GDPR, the Data Protection Act 2018, and ICO guidance. It does not guarantee regulatory compliance, does not constitute legal advice, and does not replace qualified legal or data protection counsel. Requirements vary by processing activity, sector, and business context. Consult a qualified lawyer or Data Protection Officer for your specific obligations.
- What is the refund policy?
- 7-day money-back guarantee. Contact us within seven days of purchase if the materials do not meet your needs.
Keep going
Start with the foundation, or read the background
AI Governance Starter Pack
The jurisdiction-neutral foundation: 12 policies, checklists, and procedures for any SME. Built on NIST AI RMF.
EU AI Governance Pro Pack
EU AI Act and GDPR documents for businesses operating in or trading with the EU. 8 files referenced to EU AI Act Regulation 2024/1689.
AI Vendor Review Tool
Generate a structured vendor review report covering data handling, contracts, and oversight — free, in your browser.
AI Risk Checklist
Score a specific AI use case across five dimensions and get the safeguards that fit it.
The Small Business AI Governance Checklist
The 20 steps worth completing before your team uses AI, and how to score yourself.
AI Risk Management for Small Businesses
The five risk dimensions that decide how tight your controls need to be.
Important disclaimer
The UK AI Governance Pro Pack provides operational guidance and templates informed by UK GDPR, the Data Protection Act 2018, and ICO guidance. It is not legal advice, does not guarantee regulatory compliance, and does not substitute for qualified legal or data protection counsel. Requirements vary by processing activity, sector, and business context. Consult a qualified lawyer or Data Protection Officer for obligations specific to your situation.