Procedures
Procedures are written as one archetype plus thin per-jurisdiction overrides. One GDPR-family SAR archetype covers the UK and every EU/EEA state, with a short override each, rather than thirty-one guides written from scratch. An override states only what differs.
Personal data breach notification (GDPR family)
The archetype
How to detect, assess, record and (where required) notify a personal data breach under the EU/EEA GDPR. Two distinct thresholds govern the two distinct notification duties: notify the supervisory authority where the breach is likely to result in a RISK to the rights and freedoms of natural persons (Art 33); notify affected individuals only where the breach is likely to result in a HIGH risk to them (Art 34). Conflating the two is the single most common breach-response error.
United Kingdom
UK deltas to the GDPR breach archetype. The two-threshold architecture (risk to the ICO under Art 33; high risk to individuals under Art 34) is inherited unchanged from the UK GDPR. What differs: the recipient is the ICO and its reporting channel; a specific criminal offence under s.173 DPA 2018; the separate PECR reg 5A 24-hour regime for public electronic communications service providers; and DUAA 2025 changes, with commencement status as at 2026-07-26.
Subject access requests — GDPR family
The archetype
How a subject access request works anywhere the rules descend from Article 15 GDPR. Everything here is the shared base: a jurisdiction override states only what differs, so a national guide is a short delta rather than a rewritten guide.
United Kingdom
The UK deltas from the GDPR-family SAR archetype, post-DUAA 2025. Three steps change, one procedural step is added that the archetype does not have, and one criminal backstop applies that a generic SAR guide never mentions.