TechVault Pulse Lab
Articles · UK GDPR 2026-03-11

UK GDPR and your technology systems: what to check

A practical starting point for organisations reviewing their data handling obligations
H
Harry Ratcliffe
Founder
2026-03-11
data acquisition system, machine, tripod stands, data acquisition, daq, mic stands, microphone stands, room, technology,

UK GDPR has been in force since January 2021, and most organisations have done something in response to it. The question worth asking now is whether what was done at the time still reflects how your systems actually handle data today. Systems change. Integrations are added. Staff change and access rights are not always reviewed. A compliance position that was accurate in 2021 may not be accurate in 2026.

Where the common gaps appear

The most frequent gap we find in technology risk reviews is a mismatch between the data processing register and the systems that are actually in use. A new integration was added eighteen months ago and nobody updated the register. A third-party tool was adopted by a team without going through the standard procurement process, and nobody assessed whether it processes personal data.

The second common gap is access control. The principle of least privilege. Giving staff access only to the data they need for their role. Is well understood in theory and inconsistently applied in practice. Staff who have changed roles often retain access from their previous position. Leavers are sometimes removed from the main HR system but not from the specialist applications they used.

What the ICO expects from mid-sized organisations

The Information Commissioner's Office publishes guidance for organisations of different sizes, and the expectations for a mid-sized organisation are more demanding than many assume. A documented data protection impact assessment process, a tested breach notification procedure, and a named data protection lead are all expected, not optional.

The ICO's enforcement activity in 2024 and 2025 has focused increasingly on organisations that had policies in place but could not demonstrate that those policies were being followed in practice. The gap between documented policy and operational reality is where most enforcement action originates.

How a technology risk review addresses data handling

The data handling section of a risk and resilience review covers where personal data is stored, who has access to it, how it is transmitted between systems, and whether the controls in place are proportionate to the sensitivity of the data. It is not a legal compliance audit. We are not solicitors. But it surfaces the technical and operational gaps that a legal review would need to address.

The output is a set of findings with a clear distinction between issues that require immediate attention and issues that require a planned remediation. Most organisations find that the findings are more specific and more actionable than a generic compliance checklist.

Data handling is one of the areas where the gap between what organisations think they are doing and what they are actually doing tends to be widest. A risk review is a practical way to find out where that gap is.

#UK GDPR#Data protection#Technology compliance#Risk review

Related reading

See all news

Clear thinking from a higher vantage point.

Home

Home

Learn more about what we do.

Read more
About

The story behind us

Meet the people behind the work.

Read more
Contact

Get in touch directly

Come visit, or drop us a line.

Read more
Privacy

Privacy

Learn more about what we do.

Read more
Terms

Terms

Learn more about what we do.

Read more