BOARD GOVERNANCE
UK GDPR: What Every Board Member Needs to Know
Boards are accountable for data protection, and the law now expects directors to be able to answer for it. This page sets out what UK GDPR means in practice, the questions a board should be asking, and where boards get caught out.
Book a conversationWhy data protection sits with the board
Under UK GDPR the accountability principle makes the organisation, and its leadership, responsible not just for complying but for being able to demonstrate compliance. That is a governance duty, not a technical one, and it does not stop at the IT department. The Data (Use and Access) Act 2025 has since reshaped parts of the regime, including a more proportionate approach to subject access requests and, from 19 June 2026, a duty on organisations to have a complaints process for data protection concerns. A board that cannot evidence how it meets these obligations is carrying a risk it may not have priced.
What UK GDPR requires, in plain terms
Strip away the jargon and the regime asks a handful of concrete things of every organisation that handles personal data.
- Hold personal data only with a lawful basis, and only what you actually need
- Keep it secure, and be able to show the controls are real
- Report a notifiable personal data breach to the ICO within 72 hours of becoming aware of it
- Answer a subject access request, usually within one month, with a reasonable and proportionate search
- Keep records of what you hold, why, and who you share it with, including your processors
The questions a board should be asking
You do not need to be a lawyer to govern data protection well. You need to ask the right questions and expect answers you can trust.
- Who is accountable for data protection here, and do we need a Data Protection Officer?
- Could we respond to a subject access request inside the statutory deadline today?
- When did we last test our breach response, and could we meet the 72-hour reporting window?
- What personal data do we hold, where, and do we still have a reason to hold it?
- Are our third-party processors under proper contract, and do we know what they do with our data?
Where boards get caught out
The failures are rarely exotic. A subject access request lands and the deadline passes because no one owned it. A breach happens at a supplier and the board finds out too late to meet the reporting window. Personal data accumulates for years because deleting it is nobody’s job. Each of these is a governance gap, not a technical one, and each is avoidable with clear accountability. Where the concern is cyber risk specifically, our work on board cyber governance gives directors the reporting and challenge they are accountable for.
Getting board-level assurance without a permanent hire
Most mid-market organisations do not need a full-time data protection team; they need senior ownership and evidence. A fractional or outsourced DPO gives you board-level accountability on a retainer, and the free Data Rights Readiness check shows how ready you actually are to handle a request or a breach before one arrives.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Having carried the combined technology and security remit at group level, Daniel has built the data protection accountability, breach processes and board reporting that UK GDPR now expects directors to answer for.
Frequently asked questions
Is the board accountable for GDPR?
Yes. The accountability principle in UK GDPR makes the organisation and its leadership responsible for compliance and for being able to demonstrate it. Data protection is a governance duty that sits with the board, not something that can be fully delegated to the IT department.
What is a subject access request and how long do we have?
A subject access request is an individual asking for the personal data you hold about them. You normally have one month to respond. The Data (Use and Access) Act 2025 confirms the search must be reasonable and proportionate, and allows the clock to pause while you seek clarification.
Do we need a Data Protection Officer?
A DPO is mandatory for public authorities and for organisations whose core activities involve large-scale monitoring or processing of special-category data. Many other organisations appoint one voluntarily, or use a fractional or outsourced DPO, to hold clear accountability without a permanent hire.
What must we do if we have a data breach?
If a personal data breach is likely to risk people’s rights, you must report it to the ICO within 72 hours of becoming aware of it, and tell affected individuals if the risk is high. The practical challenge is detection and decision speed, which is why breach response should be tested, not just documented.
What is the Data (Use and Access) Act 2025?
It is UK legislation that reforms parts of the data protection regime, including a more proportionate approach to subject access requests and, from 19 June 2026, a duty on organisations to operate a complaints process for data protection concerns. It sits alongside UK GDPR rather than replacing it.
NEXT STEP
Could your organisation handle a data request on time?
The free Data Rights Readiness check shows how ready you are to handle a subject access request or a breach before one lands, and where the gaps sit. When you want to talk it through, a conversation is the next step.
Data Rights Readiness check Book a conversation