Skip to main content

UK law · United Kingdom

What UK GDPR asks of your vendors

Controllers and processors established in the UK, and those outside it that offer goods or services to, or monitor, people in the UK (Article 3). Applies in its retained UK form since 1 January 2021. UK GDPR, with the Data Protection Act 2018

Check my vendors

4 requirements that reach your vendors

Each provision, the evidence that usually supports it, and how many vendors in the index publish that evidence. Reviewed 21 Sep 2026.

Article 28(1)

Use processors that provide sufficient guarantees

A controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures.

  • Independent security assurance

    758 vendors in the index

    A current SOC 2 report or ISO/IEC 27001 certificate is the usual evidence that a supplier operates appropriate security measures.

  • Security testing and documentation

    441 vendors in the index

    A penetration test report, a completed standard questionnaire (SIG, CAIQ, HECVAT) or security documentation shows how the supplier tests and runs its controls.

Article 28(3)

Put processing under a written contract

Processing by a processor must be governed by a contract with the terms Article 28(3) lists, including documented instructions, confidentiality, security and assistance.

  • Data processing agreement

    191 vendors in the index

    The DPA is where processing instructions, confidentiality, security, sub-processing and audit rights are written down.

Article 28(2) and (4)

Know and control sub-processors

Sub-processors need the controller’s authorisation, changes must be notified, and obligations flow down by contract.

  • Published subprocessor list

    436 vendors in the index

    A current list of subprocessors, with purpose and location, is how a customer knows who else touches its data.

Articles 44 to 46

Transfer data outside the UK lawfully

Restricted transfers need UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework) or appropriate safeguards such as the International Data Transfer Agreement or the UK Addendum to the EU SCCs.

  • Transfer mechanism

    1,530 vendors in the index

    Transfers outside the EU or UK need a basis such as an adequacy decision (including the EU-US Data Privacy Framework) or standard contractual clauses.

  • Where data is hosted and processed

    245 vendors in the index

    The regions or countries where the service runs and data is stored, from the vendor or its subprocessor list.

Vendors publishing the most UK GDPR evidence

Among the most-searched vendors in the index, ranked by how many of the requirements above their public evidence reaches. Open one to see each item with its date and source.

Questions buyers ask

What does UK GDPR require from vendors?

Use processors that provide sufficient guarantees (Article 28(1)); Put processing under a written contract (Article 28(3)); Know and control sub-processors (Article 28(2) and (4)); Transfer data outside the UK lawfully (Articles 44 to 46). Each is listed below with the evidence that may support it.

Who does UK GDPR apply to?

Controllers and processors established in the UK, and those outside it that offer goods or services to, or monitor, people in the UK (Article 3). Applies in its retained UK form since 1 January 2021.

Is a SOC 2 report enough for UK GDPR?

A SOC 2 report or ISO 27001 certificate may support the security parts of UK GDPR, but put processing under a written contract, know and control sub-processors, transfer data outside the uk lawfully need other evidence. Confirm sufficiency with your counsel or auditor.

Other regulations

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.