Skip to content
Guides

Does Cyber Essentials cover GDPR?

No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; GDPR is a data-protection regulation covering lawful basis, rights, transfers, and accountability. They overlap at the technical-security boundary but neither replaces the other.

a golden padlock sitting on top of a keyboard

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Does Cyber Essentials cover GDPR?

No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; the UK GDPR (and EU GDPR) is a data-protection regulation covering lawful basis for processing, data-subject rights, international transfers, and organisational accountability. They overlap at the technical-security boundary but neither replaces the other.

Section 02

Where they overlap

UK GDPR Article 32 requires "appropriate technical and organisational measures" to ensure security of processing. The five Cyber Essentials controls can help with baseline technical security. ICO guidance requires measures proportionate to the nature and risk of processing; other technical, physical and organisational measures may be needed.

The ICO lists Cyber Essentials as an example of basic technical controls to consider. A certificate may support an evidence discussion, but it does not establish Article 32 compliance for every processing activity.

Section 03

What GDPR requires that Cyber Essentials does not

  • Lawful basis for processing. Cyber Essentials does not assess whether you have a valid lawful basis.
  • Privacy notices, data-subject rights, and consent management. Out of scope.
  • Records of Processing Activities (RoPA). Out of scope.
  • Data Protection Impact Assessments. Out of scope.
  • International data transfer mechanisms (SCCs, IDTA). Out of scope.
  • Data Protection Officer designation. Out of scope.
  • Personal-data breach assessment and notification. Where a breach is likely to risk individuals' rights and freedoms, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. Other notification rules may apply; the certificate does not decide them.

Section 04

What Cyber Essentials requires that GDPR does not directly

  • The specific 14-day patching rule for high/critical vulnerabilities.
  • The specific firewall / boundary device configuration rules.
  • The scheme's applicable MFA requirements for in-scope accounts and cloud services.
  • The specific supported-OS rules.

UK GDPR calls for measures appropriate to the processing risk. Cyber Essentials provides one useful baseline; it is not a universal Article 32 threshold.

Section 05

The practical answer for UK SMEs

For most UK SMEs the sensible stack is:

1. Cyber Essentials - one technical baseline to consider in a risk-based Article 32 programme.

2. A published privacy notice, a documented lawful basis, a RoPA, a breach-response plan - organisational GDPR measures.

3. Optional higher tiers - IASME Cyber Assurance Level 2 or ISO 27001 where contractual or regulatory expectation requires a broader ISMS.

Cyber Essentials can support technical security, alongside controls chosen for the actual processing risk.

Section 06

Bottom line

Cyber Essentials does not cover GDPR. Assess your processing risks, use appropriate technical and organisational measures and keep the governance records your circumstances require. A CE certificate can contribute evidence without proving the whole programme.

Fig Group offers a conditional Basic six-working-hour guarantee after a complete, compliant submission under its terms, from £299.99 + VAT.

Start Cyber Essentials from £299.99 + VAT | Cyber Essentials vs ISO 27001 | Free readiness check

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group