Data protection regime

This Overview signposts core materials on the data protection regime, with links to appropriate materials including guidance, precedents and analysis. The regime is principally set by the UK GDPR and the Data Protection Act 2018, alongside the Privacy and Electronic Communications Regulations 2003 and, for public sector data sharing, the Digital Economy Act 2017.

For public bodies, data protection is a public law obligation engaging lawfulness, fairness, transparency and accuracy, and interacting with Article 8 ECHR. Practitioners must assess controller and processor roles, select a lawful basis (often public task), and address special category and criminal offence data conditions. Governance requirements include accountability, records of processing, data protection by design and default, data protection impact assessments, and appropriate technical and organisational measures.

Key procedural issues include responding to information rights requests, applying statutory exemptions, managing personal data breaches (including notification to the Information Commissioner’s Office and affected individuals), and ensuring compliant procurement and data sharing arrangements. International transfers require an adequacy decision or appropriate safeguards, typically the UK International Data Transfer Agreement or the UK Addendum to EU standard contractual clauses.

Regulatory oversight is exercised by the ICO, with enforcement...

To view the latest version of this document and thousands of others like it, sign-in with LexisNexis or register for a free trial.

Powered by Lexis+®
Latest Public Law News
View Public Law by content type :

Popular documents