Skip to content

Evidence request lists

UK Data Protection Act 2018

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

General Processing (Part 2)

UK-DPA18-GEN-01
Lawful Bases and Conditions

UK-specific conditions for processing special categories of data beyond UK GDPR Article 9 including employment, health research, archiving, and substantial public interest conditions.

Artefacts an auditor will ask for
  • Documented procedure addressing lawful bases and conditions
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
UK-DPA18-GEN-02
ICO Powers and Enforcement

ICO may issue information notices, assessment notices, enforcement notices, and penalty notices. Maximum fines: GBP 17.5 million or 4% of annual worldwide turnover for highest tier violations.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent
UK-DPA18-GEN-03
Age of Consent for ISS

Consent age for information society services in the UK is 13 (UK derogation from GDPR default of 16). Controllers must make reasonable efforts to verify parental consent for under-13s.

Artefacts an auditor will ask for
  • Consent capture mechanism design records
  • Consent log with timestamp and purpose linkage
  • Withdrawal workflow evidence
  • Privacy notice version aligned to consent text
Where this commonly fails
  • Bundled consent across distinct purposes
  • Withdrawal not as easy as granting consent
  • Records lack granularity per processing purpose
  • Children consent thresholds not enforced
UK-DPA18-GEN-04
UK-Specific Exemptions

Exemptions for journalism, academic, artistic, and literary expression. National security certificate provisions. Immigration exemption for data subject rights.

Artefacts an auditor will ask for
  • Documented procedure addressing uk-specific exemptions
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

ICO

UKDPA-4
ICO Powers and Enforcement

Per UK DPA 2018: Information Commissioner powers + enforcement + administrative fines.

Artefacts an auditor will ask for
  • UK DPA 2018 evidence for UKDPA-4
Where this commonly fails
  • intelligence + LED + AADC partial

Law Enforcement Processing (Part 3)

UK-DPA18-LE-01
Law Enforcement Processing Principles

Law enforcement processing must be lawful, fair, for specified purposes. Data must be adequate, relevant, not excessive, accurate, and kept no longer than necessary.

Artefacts an auditor will ask for
  • Legal register tracking enforcement risk
  • Counsel opinion on liability exposure
  • Self disclosure decision records
  • Insurance coverage evidence
Where this commonly fails
  • Legal register not refreshed for new enforcement actions
  • Director and officer awareness thin
  • Self disclosure protocols undefined
  • Cooperation credit strategy absent
UK-DPA18-LE-02
Data Subject Rights (Law Enforcement)

Data subjects have rights to information, access, rectification, erasure, and restriction. Rights may be limited where necessary and proportionate for law enforcement purposes.

Artefacts an auditor will ask for
  • Data subject rights request intake workflow
  • Identity verification procedure for requesters
  • Response register with SLA timestamps
  • Template responses approved by privacy office
Where this commonly fails
  • SLA breaches not tracked or escalated
  • Identity verification inconsistent across channels
  • Processor downstream actions not orchestrated
  • Exemption decisions undocumented
UK-DPA18-LE-03
International Transfers (Law Enforcement)

Transfers of law enforcement personal data outside the UK require adequacy decision, appropriate safeguards, or specific conditions. Enhanced safeguards for sensitive data.

Artefacts an auditor will ask for
  • Transfer impact assessment per destination
  • Standard contractual clauses or equivalent
  • Supplementary measures evidence
  • Recipient list with onward transfer terms
Where this commonly fails
  • TIA missing for high risk destinations
  • Supplementary measures asserted but not implemented
  • Onward transfer obligations unmonitored
  • Reliance on outdated adequacy decision

Part 3 Law Enforcement

UKDPA-2
Law Enforcement Processing (Part 3)

Per UK DPA 2018 Part 3: law enforcement processing per LED. Different rules from general processing.

Artefacts an auditor will ask for
  • UK DPA 2018 evidence for UKDPA-2
Where this commonly fails
  • intelligence + LED + AADC partial

Part 4 Intelligence

UKDPA-3
Intelligence Services Processing (Part 4)

Per UK DPA 2018 Part 4: intelligence services processing. Modified protections per national security.

Artefacts an auditor will ask for
  • UK DPA 2018 evidence for UKDPA-3
Where this commonly fails
  • intelligence + LED + AADC partial

Scope

UKDPA-1
Scope, UK GDPR Implementation, Parts 1-2

Per UK Data Protection Act 2018 Parts 1-2: UK GDPR + general processing + scope.

Artefacts an auditor will ask for
  • UK DPA 2018 evidence for UKDPA-1
Where this commonly fails
  • intelligence + LED + AADC partial

Specific Topics

UKDPA-5
Children, Automated Decisions, Breach, International Transfers

Per UK DPA 2018: Children and AADC + Automated Decision Making Safeguards + Personal Data Breach Notification + International Transfers + Interface with NIS Regulations.

Artefacts an auditor will ask for
  • UK DPA 2018 evidence for UKDPA-5
Where this commonly fails
  • intelligence + LED + AADC partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Data Protection Act 2018 framework page.