The UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals.

Data Protection self assessment toolkit

We have created self assessment checklists for the GDPR. Use our checklists to assess your high level compliance with data protection legislation and find out what more you need to do to make sure you are keeping people’s personal data secure.

Lawful basis interactive tool

We have produced a lawful basis interactive tool to give tailored guidance on which lawful basis is likely to be most appropriate for your processing activities. It will give an rating for each lawful basis based on your answers to key questions with suggested actions and links to relevant guidance. 

Lawful basis resources 

In addition to our guidance, we have produced a variety of other resources to help you understand and identify your lawful basis for processing personal data.

Personal data breach reporting

We have created resources on breach management and reporting a personal data breach to the ICO.


We have produced an FAQs document answering the questions that have been asked most often in relation to the GDPR. These documents have been created for the following sectors:

Advice service for small organisations

We have a dedicated helpline and live chat service for sole traders, SMEs and other small organisations who have questions about data protection.