UK’s trusted IT infrastructure partner since 2003
sales@servnetuk.com
0800 987 4111
Servnet
ConfiguratorGet in Touch
Compliance · UK GDPR · Privacy

UK GDPR for IT teams: DPIA, DSAR, data residency

Servnet Editorial · Compliance Practice8 min read

UK GDPR (the post-Brexit version of EU GDPR) has been law since January 2021. The ICO's enforcement appetite increased significantly in 2024-25 — multiple seven-figure fines and increased focus on technical + organisational measures (TOMs). This is the practical IT-team guide to the three GDPR workflows that hit IT hardest: DPIAs, DSARs, and data residency.

UK GDPR — IT-relevant articles
UK GDPR (DPA 2018) — control mapA5Principles (lawful · minimal · accurate)COREA6Lawful basis for processingCOREA15Right of access (DSAR — 1 month)COREA17Right to erasureCOREA30Records of processing activitiesCOREA32Security of processing (technical)COREA33Breach notification (72 hours)COREA35DPIA when high riskPLUS

DPIA — Data Protection Impact Assessment

Required for any new processing likely to result in high risk to data subjects. Deployment of new CRM, new analytics platform, new monitoring tool, new identity system — DPIA before go-live.

IT teams don't own the DPIA (DPO does) but provide the technical detail — data flow diagrams, retention period, encryption at rest + in transit, access control model, third-party data sharing.

A well-prepared DPIA template + IT pre-fill saves 70%+ of the DPO's drafting time. Build the template once, reuse for every new processing initiative.

DSAR — Data Subject Access Request

30-day response window (extendable by 60 days for complex requests).

IT teams build the search + extraction capability. Microsoft Purview Communication Compliance + eDiscovery, Google Workspace Vault, Salesforce DSAR tools, custom database queries.

Risk: missed DSAR = ICO complaint = enforcement attention. Operational discipline matters.

Volume reality: most mid-market UK orgs receive 5-50 DSARs per year. Some receive 500+ (consumer brands, multi-site retailers).

Data residency + international transfers

Post-Brexit: UK is a "third country" from EU perspective. Adequacy decision (granted June 2021, renewed 2025) keeps EU→UK transfers possible.

UK→US transfers — UK-US Data Bridge (extension of EU-US Data Privacy Framework) applies since October 2023. Specific to vendors signed up to the framework.

Major cloud + SaaS vendors all support UK data residency options. Microsoft 365 UK datacentre, AWS UK regions, Azure UK regions, Salesforce UK + EU regions, etc.

IT teams should document data residency per system in the Record of Processing Activities (RoPA).

DSAR response — 30-day clock
W0W1W2W3W4W5Acknowledge1wIdentify systems1wExtract + redact2wDeliver + log1wTotal: 5 weeks end-to-end

Technical + organisational measures (TOMs)

Article 32 requires TOMs proportionate to risk. ICO enforcement increasingly tests specific TOMs.

Standard expected TOMs: encryption at rest, encryption in transit, MFA on access to personal data systems, audit logging, regular penetration testing, incident response plan, staff training, joiner/mover/leaver process — all visible in identity + access management.

Most ICO enforcement fines in 2024-25 cited missing or weak TOMs as primary aggravating factor. Pair UK GDPR work with Cyber Essentials Plus + ISO 27001 Annex A to evidence the technical baseline.

What Servnet does

Servnet supports UK GDPR technical controls — encryption deployment, identity governance, audit logging, DPIA template development, DSAR tooling integration. We don't replace your DPO but we provide the IT-side enablement — and tie evidence into our compliance + governance practice.

Key takeaways
  • DPIAs are required for high-risk new processing; IT provides technical detail to DPO.
  • DSARs have a 30-day window; build search + extraction capability in advance.
  • UK has EU adequacy + UK-US Data Bridge — international transfers manageable.
  • TOMs (Article 32) are the most-cited factor in ICO enforcement fines.
  • RoPA should document data residency per system.
Frequently asked

FAQs — UK GDPR for IT teams

DSARs

Can we charge for DSARs?

Generally no — DSARs must be provided free of charge. Only "manifestly unfounded or excessive" requests can attract a reasonable fee. ICO interprets this narrowly.

How do we search Microsoft 365 for DSAR data?

Microsoft Purview eDiscovery (E5) or Purview Premium (Compliance add-on) — search across mailboxes, Teams chats, SharePoint, OneDrive in one query. Servnet deploys + operates Purview for several UK customers.

Related

Got a question this article didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →