Auditors rarely fail a certification because a firm lacks a firewall. They fail it because nobody can show which laws apply and how the business meets them. That is the gap ISO 27001 compliance with legal requirements is meant to close, and it catches out many UK organisations at their first audit.
Here is the short answer. ISO 27001 itself is not a legal requirement in the UK. But Annex A control 5.31 requires you to identify, document and keep up to date every legal, statutory, regulatory and contractual requirement that touches your information security. Think UK GDPR, the Data Protection Act 2018, the Computer Misuse Act and client contracts. You then show evidence that you meet them.
Below, we explain what control 5.31 expects, how to find your obligations, how to build and maintain a legal register, and what evidence auditors ask for. It draws on more than 30 years of IT services experience and our work helping clients through ISO 27001 implementation and certification.
Why legal compliance matters in ISO 27001
Legal duties sit underneath the whole standard, not in one corner of it. Your information security management system (ISMS) exists to protect information, and the law decides much of what "protect" means for your business. ISO 27001 legal compliance therefore shapes your scope, risk assessment and controls from the start.
Where the standard asks for it
Three parts of ISO 27001:2022 point straight at the law. Clause 4.2 makes you identify interested parties and the requirements they place on you. Control 5.31 turns that into a documented, maintained list of obligations. Clause 6.1 then feeds those obligations into risk treatment, because a legal duty often decides which risks you cannot simply accept.
| Part of the standard | What it asks for | Typical UK example |
|---|---|---|
| Clause 4.2 | Identify interested parties and their requirements | Regulators, customers, insurers |
| Control 5.31 | Identify, document and update legal, statutory, regulatory and contractual requirements | UK GDPR, Computer Misuse Act, client security schedules |
| Clause 6.1 | Reflect those requirements in risk assessment and treatment | Breach notification rules drive logging and alerting |
Take the 72-hour breach notification duty in UK GDPR. It means detection and escalation must work at weekends, not just on Monday morning. The ISO 27001 legal requirements you record are what justify that kind of control, so they sit inside the ISMS rather than beside it.
What non-compliance costs you
Fines grab the headlines. For the most serious infringements, the ICO can fine you up to £17.5 million or 4% of global annual turnover, whichever is higher. Contracts bite just as hard. A missed security clause can mean service credits, lost renewals or a liability claim, and an insurer may dispute a cyber claim if you ignored a condition in the policy.
Certification is at stake too. In our experience, a missing or out-of-date legal register is one of the easiest nonconformities for an auditor to raise, because it takes minutes to check. You cannot argue that your controls are proportionate if you never recorded what the law requires of you.
If you cannot show which laws apply to you, you cannot show that your ISMS protects against them.
What you gain beyond the audit
Done properly, this work pays back quickly. A clear view of your obligations also speeds up customer due diligence and removes guesswork when something goes wrong. Typical gains include:
- Faster answers to customer security questionnaires, because the evidence already exists.
- Clear ownership of each obligation, so nothing depends on one person’s memory.
- Better board decisions, since legal risk is visible next to technical risk.
- A calmer incident response, because notification duties are already mapped.
Is ISO 27001 a legal requirement in the UK?
No. No UK statute requires you to hold ISO 27001 certification. It is a voluntary international standard, and you can run a lawful business without it. The confusion comes from the heavy overlap between the standard and the law, and from buyers who treat a certificate as a condition of doing business.
What the law actually requires
UK GDPR Article 32 says you must put in place appropriate technical and organisational measures to protect personal data. It names no standard. ISO 27001 is a respected way to show you have done that, but the ICO judges whether your measures were appropriate, not whether you hold a certificate. The NIS Regulations 2018 work the same way for operators of essential services. They demand proper security risk management, not one named framework.
So ISO 27001 compliance with legal requirements runs in one direction. The standard helps you meet and evidence your legal duties. It does not replace them, and certification alone does not make you compliant with UK GDPR.
ISO 27001 helps you prove you meet the law, but the certificate is never the law itself.
When it becomes a requirement in practice
Contracts are where ISO 27001 turns mandatory. A customer, tender or insurer may demand certification as a condition of the deal. That makes it a contractual requirement, and control 5.31 says it belongs in your register. These ISO 27001 legal requirements are real, even though they come from a contract and not from an Act of Parliament.
| Situation | Is ISO 27001 required? |
|---|---|
| Running a UK business | No |
| Processing personal data under UK GDPR | No, but appropriate security is |
| A customer or tender specifies it | Yes, by contract |
| Central government contracts | Often Cyber Essentials, sometimes ISO 27001 as well |
Check every tender and master services agreement for named standards and certification clauses before you sign. Then record each one, with its renewal or audit date, so a lapsed certificate never becomes a breach of contract by surprise.
How to meet Control 5.31 step by step
Control 5.31 looks abstract on paper, but you can meet it in five repeatable steps. Run them in order and ISO 27001 compliance with legal requirements becomes routine work, not a scramble the month before your audit.

Find and judge your obligations
Begin with scope. Your ISMS scope decides which laws apply, so note where you operate, what data you hold and which sectors you serve. A UK accountancy firm with EU clients faces different duties from a UK-only logistics firm. Then work through three steps:
- Define scope: locations, data types, services and key suppliers.
- Gather sources: legislation.gov.uk, ICO guidance, sector regulator notices, customer contracts and insurance policies.
- Judge applicability: record why each requirement applies or does not, so the auditor can follow your reasoning.
Assign owners and link controls
Next, give every obligation an owner. A named person, such as your data protection officer or head of IT, answers for each requirement and decides how you meet it. Then tie the duty to the policy, procedure or technical control that delivers it. The UK GDPR breach notification rule, for example, maps to your incident response procedure and your logging and alerting.
A legal duty only counts once it has an owner, a control and evidence behind it.
This mapping is what auditors test. They pick a requirement at random and ask you to walk them from the law, to the owner, to the control, to the proof. If any link is missing, expect a question you cannot answer on the day.
Review on a schedule
Finally, set a review rhythm. Laws change, as the Data (Use and Access) Act 2025 showed by amending parts of UK GDPR, so a list written once goes stale fast. Review the sources at least annually, and also after any trigger event, such as a new service, a new country or a major contract. Log each review with a date and a reviewer’s name. That small habit is the evidence that the control is actually maintained.
How to build and maintain an ISO 27001 legal register
Your register is where ISO 27001 compliance with legal requirements becomes visible on a single page. Keep the format simple. A tidy spreadsheet beats an expensive tool nobody opens, and auditors only ask that it is complete, current and traceable.

What to put in the register
Every row should answer one question: what must we do, and how do we know we do it? Use one row per requirement and make sure each row links to evidence an auditor can open. These columns cover what most auditors ask for.
| Column | What to record | Example |
|---|---|---|
| Requirement | Law, regulation or contract clause | UK GDPR Article 33 |
| Why it applies | Link to your scope | We process customer personal data |
| Owner | A named role | Data protection officer |
| Control or policy | How you meet it | Incident response procedure |
| Evidence | Where the proof lives | Breach log, test report |
| Next review | A date | 31 March 2027 |
How to keep it current
Upkeep matters more than layout. Give one person the job of watching your sources, such as ICO updates, legislation.gov.uk and regulator bulletins, and let them add or retire rows as the law moves. Then connect the register to everyday processes. Your contract sign-off and change management steps should each ask, "Does this add an obligation?"
A register nobody updates is worse than none, because it records assurance you cannot back up.
Finally, treat the register as a controlled document. Keep a version history with dates and reviewer names, and archive superseded versions rather than overwriting them. When an auditor asks how you handled a change in the law last year, the change log is your answer. This approach also keeps ISO 27001 legal compliance manageable as the register grows.
UK laws and contractual obligations to include
A register is only as good as its contents. Start with the laws that nearly every UK organisation faces, then add the rules specific to your sector and customers. This list shows what ISO 27001 legal requirements usually look like in practice.

Core UK legislation
Most UK registers begin with the same handful of Acts. Each one should carry a short note on how it affects your ISMS, not just its title.
| Law | Why it matters to your ISMS |
|---|---|
| UK GDPR and Data Protection Act 2018 | Security of personal data, breach reporting, individual rights |
| Data (Use and Access) Act 2025 | Amends UK GDPR and PECR, so check which changes touch you |
| Computer Misuse Act 1990 | Unauthorised access offences, which inform access policies and staff terms |
| Privacy and Electronic Communications Regulations 2003 | Marketing emails and cookies |
| Copyright, Designs and Patents Act 1988 | Software licensing and asset records |
| Companies Act 2006 | Record keeping and retention periods |
Sector and regional rules
Beyond the core, your industry may add binding extra duties. Operators of essential services and some digital providers fall under the NIS Regulations 2018. Financial firms answer to FCA rules on systems and controls. Public bodies must handle the Freedom of Information Act 2000 alongside data protection.
Geography matters as well. If you serve EU customers or hold their data, EU GDPR may apply in addition to the UK version, so record it and note why.
Contractual obligations
Contracts belong in the register just as firmly as statutes. Work through your agreements and pull out every clause that touches security. Typical sources include:
- Customer security schedules and audit rights.
- Confidentiality agreements and data processing agreements.
- Insurance policy conditions, such as mandatory multi-factor authentication.
- Supplier contracts that pass security duties down the chain.
- Industry standards you have agreed to, such as PCI DSS.
These are easy to miss because they live with sales and procurement, not IT. Ask those teams for a contract list once a year, and have them flag new clauses as deals close.
A contract clause is as binding as an Act, so give it the same row, owner and evidence.
Related controls that support legal compliance
Control 5.31 does not work alone. Several neighbouring controls turn your list of duties into day-to-day practice, and auditors often test them together. Treat them as one set and ISO 27001 compliance with legal requirements becomes far easier to evidence.
The compliance group in Annex A
Controls 5.32 to 5.36 sit beside 5.31, and each covers a specific legal pressure point. Link each one to rows in your register.
| Control | Focus | Typical legal link |
|---|---|---|
| 5.32 Intellectual property rights | Software licences and use of protected material | Copyright, Designs and Patents Act 1988 |
| 5.33 Protection of records | Retention, integrity and secure disposal | Companies Act 2006 |
| 5.34 Privacy and protection of PII | Handling of personal data | UK GDPR, Data Protection Act 2018 |
| 5.35 Independent review of information security | Review by someone outside the process | Evidence your approach holds up |
| 5.36 Compliance with policies, rules and standards | Checks that staff follow the rules | Proof that duties are met in practice |
Of these, 5.34 and 5.36 draw the most attention. Control 5.34 is where UK GDPR duties become working procedures, such as handling subject access requests and recording processing activity. Control 5.36 then checks that people follow them. In short, 5.31 says what must be done, and 5.36 shows that it is done.
Control 5.31 says what the law requires, and control 5.36 proves you actually do it.
Controls that deliver specific duties
Some legal duties are met by controls outside that group. These four come up most often in UK audits:
- 5.5 Contact with authorities: know who you must call, such as the ICO or the NCSC, and when.
- 5.20 Information security in supplier agreements: pass your security and data protection duties down the chain in writing.
- 5.24 to 5.26 Incident management: plan, assess and respond so you can meet the 72-hour notification rule.
- 8.15 Logging: keep the records that let you investigate and judge whether a breach is reportable.
Finally, write these control numbers into the "Control or policy" column of your register. That gives an auditor a clear trail from each obligation to the control that meets it, and it keeps ISO 27001 legal compliance consistent across your whole ISMS rather than isolated in one control.
How to demonstrate compliance to an auditor
Auditors do not take your word for it. They sample your register, pick a few rows and ask for proof. To show ISO 27001 compliance with legal requirements, you need a traceable trail from each obligation to evidence you can open in seconds.
What auditors ask to see
Expect questions in three areas: is the list complete, is it current, and do the controls actually work. This table shows the evidence that answers each one.
| Auditor asks | Evidence to show |
|---|---|
| How did you identify these requirements? | Scope statement, source list, contract review notes |
| When did you last review them? | Dated review log, version history |
| Who owns this duty? | Named owner in the register |
| Does the control work? | Breach log, subject access request tracker, training records |
| How do you handle change? | Change log, management review minutes |
Walking an auditor through a sample
Most auditors choose one requirement, such as UK GDPR Article 33, and follow it end to end. You show the register row, then the incident response procedure, then a breach log or test exercise record. Practise this trace with five random rows before audit day.
Honesty also helps. If you spot a gap, log it as a nonconformity yourself, with a corrective action and a deadline. An auditor who sees you found and fixed a problem trusts your system more than one who has to find it for you.
Auditors trust a gap you logged far more than a gap they discovered.
Run a pre-audit check
A month before the audit, test your own ISO 27001 legal compliance evidence. Work through this checklist and fix anything that fails:
- The register was reviewed within the last 12 months, and the review is logged.
- Every row names an owner, a control and a piece of evidence.
- The contract list from sales and procurement is up to date.
- Your internal audit covered control 5.31 and its findings are closed.
- Management review minutes mention legal and regulatory changes.
Finally, brief the owners named in the register. Each one should be able to explain their duty in two minutes, without reading from the spreadsheet.
Keeping legal compliance on track
Legal compliance in ISO 27001 comes down to one habit. Know which laws and contracts apply to you, record them in a register, and prove you meet each one. ISO 27001 compliance with legal requirements is not a one-off project, because the law changes and so does your business. Keep an owner on every row, review the register at least once a year, and practise the audit trail before the auditor does.
If you would rather not carry that work alone, we can help. With more than 30 years of IT services experience and a proven record in ISO 27001 implementation and certification, our team can build the register with you, close the gaps and prepare you for audit. Talk to TrustedIA about ISO 27001 support and turn control 5.31 into routine work.



