SCHEDULES
Section 10
SCHEDULE 1U.K.Special categories of personal data and criminal convictions etc data
PART 1 U.K.Conditions relating to employment, health and research etc
Employment, social security and social protectionU.K.
1(1)This condition is met if—U.K.
(a)the processing is necessary for the purposes of performing or exercising obligations or rights which are imposed or conferred by law on the controller or the data subject in connection with employment, social security or social protection, and
(b)when the processing is carried out, the controller has an appropriate policy document in place (see paragraph 39 in Part 4 of this Schedule).
(2)See also the additional safeguards in Part 4 of this Schedule.
(3)In this paragraph—
“social security” includes any of the branches of social security listed in Article 3(1) of Regulation (EC) No. 883/2004 of the European Parliament and of the Council on the co-ordination of social security systems (as amended from time to time);
“social protection” includes an intervention described in Article 2(b) of Regulation (EC) 458/2007 of the European Parliament and of the Council of 25 April 2007 on the European system of integrated social protection statistics (ESSPROS) (as amended from time to time).
Commencement Information
I1Sch. 1 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Health or social care purposesU.K.
2(1)This condition is met if the processing is necessary for health or social care purposes.U.K.
(2)In this paragraph “health or social care purposes” means the purposes of—
(a)preventive or occupational medicine,
(b)the assessment of the working capacity of an employee,
(c)medical diagnosis,
(d)the provision of health care or treatment,
(e)the provision of social care, or
(f)the management of health care systems or services or social care systems or services.
(3)See also the conditions and safeguards in Article 9(3) of the GDPR (obligations of secrecy) and section 11(1).
Commencement Information
I2Sch. 1 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Public healthU.K.
3U.K.This condition is met if the processing—
(a)is necessary for reasons of public interest in the area of public health, and
(b)is carried out—
(i)by or under the responsibility of a health professional, or
(ii)by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law.
Commencement Information
I3Sch. 1 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Research etcU.K.
4U.K.This condition is met if the processing—
(a)is necessary for archiving purposes, scientific or historical research purposes or statistical purposes,
(b)is carried out in accordance with Article 89(1) of the GDPR (as supplemented by section 19), and
(c)is in the public interest.
Commencement Information
I4Sch. 1 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 2 U.K.Substantial public interest conditions
Requirement for an appropriate policy document when relying on conditions in this PartU.K.
5(1)Except as otherwise provided, a condition in this Part of this Schedule is met only if, when the processing is carried out, the controller has an appropriate policy document in place (see paragraph 39 in Part 4 of this Schedule).U.K.
(2)See also the additional safeguards in Part 4 of this Schedule.
Commencement Information
I5Sch. 1 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Statutory etc and government purposesU.K.
6(1)This condition is met if the processing—U.K.
(a)is necessary for a purpose listed in sub-paragraph (2), and
(b)is necessary for reasons of substantial public interest.
(2)Those purposes are—
(a)the exercise of a function conferred on a person by an enactment or rule of law;
(b)the exercise of a function of the Crown, a Minister of the Crown or a government department.
Modifications etc. (not altering text)
C1Sch. 1 para. 6 modified by S.I. 1999/677, art. 7(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 237 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
C2Sch. 1 para. 6 modified by S.I. 2007/1118, art. 5(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 324 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
C3Sch. 1 para. 6 modified by S.I. 1999/3145, art. 9(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 238 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
Commencement Information
I6Sch. 1 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Administration of justice and parliamentary purposesU.K.
7U.K.This condition is met if the processing is necessary—
(a)for the administration of justice, or
(b)for the exercise of a function of either House of Parliament.
Commencement Information
I7Sch. 1 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Equality of opportunity or treatmentU.K.
8(1)This condition is met if the processing—U.K.
(a)is of a specified category of personal data, and
(b)is necessary for the purposes of identifying or keeping under review the existence or absence of equality of opportunity or treatment between groups of people specified in relation to that category with a view to enabling such equality to be promoted or maintained,
subject to the exceptions in sub-paragraphs (3) to (5).
(2)In sub-paragraph (1), “specified” means specified in the following table—
Category of personal data | Groups of people (in relation to a category of personal data) |
---|---|
Personal data revealing racial or ethnic origin | People of different racial or ethnic origins |
Personal data revealing religious or philosophical beliefs | People holding different religious or philosophical beliefs |
Data concerning health | People with different states of physical or mental health |
Personal data concerning an individual's sexual orientation | People of different sexual orientation |
(3)Processing does not meet the condition in sub-paragraph (1) if it is carried out for the purposes of measures or decisions with respect to a particular data subject.
(4)Processing does not meet the condition in sub-paragraph (1) if it is likely to cause substantial damage or substantial distress to an individual.
(5)Processing does not meet the condition in sub-paragraph (1) if—
(a)an individual who is the data subject (or one of the data subjects) has given notice in writing to the controller requiring the controller not to process personal data in respect of which the individual is the data subject (and has not given notice in writing withdrawing that requirement),
(b)the notice gave the controller a reasonable period in which to stop processing such data, and
(c)that period has ended.
Commencement Information
I8Sch. 1 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Racial and ethnic diversity at senior levels of organisationsU.K.
9(1)This condition is met if the processing—U.K.
(a)is of personal data revealing racial or ethnic origin,
(b)is carried out as part of a process of identifying suitable individuals to hold senior positions in a particular organisation, a type of organisation or organisations generally,
(c)is necessary for the purposes of promoting or maintaining diversity in the racial and ethnic origins of individuals who hold senior positions in the organisation or organisations, and
(d)can reasonably be carried out without the consent of the data subject,
subject to the exception in sub-paragraph (3).
(2)For the purposes of sub-paragraph (1)(d), processing can reasonably be carried out without the consent of the data subject only where—
(a)the controller cannot reasonably be expected to obtain the consent of the data subject, and
(b)the controller is not aware of the data subject withholding consent.
(3)Processing does not meet the condition in sub-paragraph (1) if it is likely to cause substantial damage or substantial distress to an individual.
(4)For the purposes of this paragraph, an individual holds a senior position in an organisation if the individual—
(a)holds a position listed in sub-paragraph (5), or
(b)does not hold such a position but is a senior manager of the organisation.
(5)Those positions are—
(a)a director, secretary or other similar officer of a body corporate;
(b)a member of a limited liability partnership;
(c)a partner in a partnership within the Partnership Act 1890, a limited partnership registered under the Limited Partnerships Act 1907 or an entity of a similar character formed under the law of a country or territory outside the United Kingdom.
(6)In this paragraph, “senior manager”, in relation to an organisation, means a person who plays a significant role in—
(a)the making of decisions about how the whole or a substantial part of the organisation's activities are to be managed or organised, or
(b)the actual managing or organising of the whole or a substantial part of those activities.
(7)The reference in sub-paragraph (2)(b) to a data subject withholding consent does not include a data subject merely failing to respond to a request for consent.
Commencement Information
I9Sch. 1 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Preventing or detecting unlawful actsU.K.
10(1)This condition is met if the processing—U.K.
(a)is necessary for the purposes of the prevention or detection of an unlawful act,
(b)must be carried out without the consent of the data subject so as not to prejudice those purposes, and
(c)is necessary for reasons of substantial public interest.
(2)If the processing consists of the disclosure of personal data to a competent authority, or is carried out in preparation for such disclosure, the condition in sub-paragraph (1) is met even if, when the processing is carried out, the controller does not have an appropriate policy document in place (see paragraph 5 of this Schedule).
(3)In this paragraph—
“act” includes a failure to act;
“competent authority” has the same meaning as in Part 3 of this Act (see section 30).
Commencement Information
I10Sch. 1 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Protecting the public against dishonesty etcU.K.
11(1)This condition is met if the processing—U.K.
(a)is necessary for the exercise of a protective function,
(b)must be carried out without the consent of the data subject so as not to prejudice the exercise of that function, and
(c)is necessary for reasons of substantial public interest.
(2)In this paragraph, “protective function” means a function which is intended to protect members of the public against—
(a)dishonesty, malpractice or other seriously improper conduct,
(b)unfitness or incompetence,
(c)mismanagement in the administration of a body or association, or
(d)failures in services provided by a body or association.
Commencement Information
I11Sch. 1 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Regulatory requirements relating to unlawful acts and dishonesty etcU.K.
12(1)This condition is met if—U.K.
(a)the processing is necessary for the purposes of complying with, or assisting other persons to comply with, a regulatory requirement which involves a person taking steps to establish whether another person has—
(i)committed an unlawful act, or
(ii)been involved in dishonesty, malpractice or other seriously improper conduct,
(b)in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing, and
(c)the processing is necessary for reasons of substantial public interest.
(2)In this paragraph—
“act” includes a failure to act;
“regulatory requirement” means—
(a)a requirement imposed by legislation or by a person in exercise of a function conferred by legislation, or
(b)a requirement forming part of generally accepted principles of good practice relating to a type of body or an activity.
Commencement Information
I12Sch. 1 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Journalism etc in connection with unlawful acts and dishonesty etcU.K.
13(1)This condition is met if—U.K.
(a)the processing consists of the disclosure of personal data for the special purposes,
(b)it is carried out in connection with a matter described in sub-paragraph (2),
(c)it is necessary for reasons of substantial public interest,
(d)it is carried out with a view to the publication of the personal data by any person, and
(e)the controller reasonably believes that publication of the personal data would be in the public interest.
(2)The matters mentioned in sub-paragraph (1)(b) are any of the following (whether alleged or established)—
(a)the commission of an unlawful act by a person;
(b)dishonesty, malpractice or other seriously improper conduct of a person;
(c)unfitness or incompetence of a person;
(d)mismanagement in the administration of a body or association;
(e)a failure in services provided by a body or association.
(3)The condition in sub-paragraph (1) is met even if, when the processing is carried out, the controller does not have an appropriate policy document in place (see paragraph 5 of this Schedule).
(4)In this paragraph—
“act” includes a failure to act;
“the special purposes” means—
(a)the purposes of journalism;
(b)academic purposes;
(c)artistic purposes;
(d)literary purposes.
Commencement Information
I13Sch. 1 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Preventing fraudU.K.
14(1)This condition is met if the processing—U.K.
(a)is necessary for the purposes of preventing fraud or a particular kind of fraud, and
(b)consists of—
(i)the disclosure of personal data by a person as a member of an anti-fraud organisation,
(ii)the disclosure of personal data in accordance with arrangements made by an anti-fraud organisation, or
(iii)the processing of personal data disclosed as described in sub-paragraph (i) or (ii).
(2)In this paragraph, “anti-fraud organisation” has the same meaning as in section 68 of the Serious Crime Act 2007.
Commencement Information
I14Sch. 1 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Suspicion of terrorist financing or money launderingU.K.
15U.K.This condition is met if the processing is necessary for the purposes of making a disclosure in good faith under either of the following—
(a)section 21CA of the Terrorism Act 2000 (disclosures between certain entities within regulated sector in relation to suspicion of commission of terrorist financing offence or for purposes of identifying terrorist property);
(b)section 339ZB of the Proceeds of Crime Act 2002 (disclosures within regulated sector in relation to suspicion of money laundering).
Commencement Information
I15Sch. 1 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Support for individuals with a particular disability or medical conditionU.K.
16(1)This condition is met if the processing—U.K.
(a)is carried out by a not-for-profit body which provides support to individuals with a particular disability or medical condition,
(b)is of a type of personal data falling within sub-paragraph (2) which relates to an individual falling within sub-paragraph (3),
(c)is necessary for the purposes of—
(i)raising awareness of the disability or medical condition, or
(ii)providing support to individuals falling within sub-paragraph (3) or enabling such individuals to provide support to each other,
(d)can reasonably be carried out without the consent of the data subject, and
(e)is necessary for reasons of substantial public interest.
(2)The following types of personal data fall within this sub-paragraph—
(a)personal data revealing racial or ethnic origin;
(b)genetic data or biometric data;
(c)data concerning health;
(d)personal data concerning an individual's sex life or sexual orientation.
(3)An individual falls within this sub-paragraph if the individual is or has been a member of the body mentioned in sub-paragraph (1)(a) and—
(a)has the disability or condition mentioned there, has had that disability or condition or has a significant risk of developing that disability or condition, or
(b)is a relative or carer of an individual who satisfies paragraph (a) of this sub-paragraph.
(4)For the purposes of sub-paragraph (1)(d), processing can reasonably be carried out without the consent of the data subject only where—
(a)the controller cannot reasonably be expected to obtain the consent of the data subject, and
(b)the controller is not aware of the data subject withholding consent.
(5)In this paragraph—
“carer” means an individual who provides or intends to provide care for another individual other than—
(a)under or by virtue of a contract, or
(b)as voluntary work;
“disability” has the same meaning as in the Equality Act 2010 (see section 6 of, and Schedule 1 to, that Act).
(6)The reference in sub-paragraph (4)(b) to a data subject withholding consent does not include a data subject merely failing to respond to a request for consent.
Commencement Information
I16Sch. 1 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Counselling etcU.K.
17(1)This condition is met if the processing—U.K.
(a)is necessary for the provision of confidential counselling, advice or support or of another similar service provided confidentially,
(b)is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2), and
(c)is necessary for reasons of substantial public interest.
(2)The reasons mentioned in sub-paragraph (1)(b) are—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)the processing must be carried out without the consent of the data subject because obtaining the consent of the data subject would prejudice the provision of the service mentioned in sub-paragraph (1)(a).
Commencement Information
I17Sch. 1 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Safeguarding of children and of individuals at riskU.K.
18(1)This condition is met if—U.K.
(a)the processing is necessary for the purposes of—
(i)protecting an individual from neglect or physical, mental or emotional harm, or
(ii)protecting the physical, mental or emotional well-being of an individual,
(b)the individual is—
(i)aged under 18, or
(ii)aged 18 or over and at risk,
(c)the processing is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2), and
(d)the processing is necessary for reasons of substantial public interest.
(2)The reasons mentioned in sub-paragraph (1)(c) are—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)the processing must be carried out without the consent of the data subject because obtaining the consent of the data subject would prejudice the provision of the protection mentioned in sub-paragraph (1)(a).
(3)For the purposes of this paragraph, an individual aged 18 or over is “at risk” if the controller has reasonable cause to suspect that the individual—
(a)has needs for care and support,
(b)is experiencing, or at risk of, neglect or physical, mental or emotional harm, and
(c)as a result of those needs is unable to protect himself or herself against the neglect or harm or the risk of it.
(4)In sub-paragraph (1)(a), the reference to the protection of an individual or of the well-being of an individual includes both protection relating to a particular individual and protection relating to a type of individual.
Commencement Information
I18Sch. 1 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Safeguarding of economic well-being of certain individualsU.K.
19(1)This condition is met if the processing—U.K.
(a)is necessary for the purposes of protecting the economic well-being of an individual at economic risk who is aged 18 or over,
(b)is of data concerning health,
(c)is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2), and
(d)is necessary for reasons of substantial public interest.
(2)The reasons mentioned in sub-paragraph (1)(c) are—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)the processing must be carried out without the consent of the data subject because obtaining the consent of the data subject would prejudice the provision of the protection mentioned in sub-paragraph (1)(a).
(3)In this paragraph, “individual at economic risk” means an individual who is less able to protect his or her economic well-being by reason of physical or mental injury, illness or disability.
Commencement Information
I19Sch. 1 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
InsuranceU.K.
20(1)This condition is met if the processing—U.K.
(a)is necessary for an insurance purpose,
(b)is of personal data revealing racial or ethnic origin, religious or philosophical beliefs or trade union membership, genetic data or data concerning health, and
(c)is necessary for reasons of substantial public interest,
subject to sub-paragraphs (2) and (3).
(2)Sub-paragraph (3) applies where—
(a)the processing is not carried out for the purposes of measures or decisions with respect to the data subject, and
(b)the data subject does not have and is not expected to acquire—
(i)rights against, or obligations in relation to, a person who is an insured person under an insurance contract to which the insurance purpose mentioned in sub-paragraph (1)(a) relates, or
(ii)other rights or obligations in connection with such a contract.
(3)Where this sub-paragraph applies, the processing does not meet the condition in sub-paragraph (1) unless, in addition to meeting the requirements in that sub-paragraph, it can reasonably be carried out without the consent of the data subject.
(4)For the purposes of sub-paragraph (3), processing can reasonably be carried out without the consent of the data subject only where—
(a)the controller cannot reasonably be expected to obtain the consent of the data subject, and
(b)the controller is not aware of the data subject withholding consent.
(5)In this paragraph—
“insurance contract” means a contract of general insurance or long-term insurance;
“insurance purpose” means—
(a)advising on, arranging, underwriting or administering an insurance contract,
(b)administering a claim under an insurance contract, or
(c)exercising a right, or complying with an obligation, arising in connection with an insurance contract, including a right or obligation arising under an enactment or rule of law.
(6)The reference in sub-paragraph (4)(b) to a data subject withholding consent does not include a data subject merely failing to respond to a request for consent.
(7)Terms used in the definition of “insurance contract” in sub-paragraph (5) and also in an order made under section 22 of the Financial Services and Markets Act 2000 (regulated activities) have the same meaning in that definition as they have in that order.
Commencement Information
I20Sch. 1 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Occupational pensionsU.K.
21(1)This condition is met if the processing—U.K.
(a)is necessary for the purpose of making a determination in connection with eligibility for, or benefits payable under, an occupational pension scheme,
(b)is of data concerning health which relates to a data subject who is the parent, grandparent, great-grandparent or sibling of a member of the scheme,
(c)is not carried out for the purposes of measures or decisions with respect to the data subject, and
(d)can reasonably be carried out without the consent of the data subject.
(2)For the purposes of sub-paragraph (1)(d), processing can reasonably be carried out without the consent of the data subject only where—
(a)the controller cannot reasonably be expected to obtain the consent of the data subject, and
(b)the controller is not aware of the data subject withholding consent.
(3)In this paragraph—
“occupational pension scheme” has the meaning given in section 1 of the Pension Schemes Act 1993;
“member”, in relation to a scheme, includes an individual who is seeking to become a member of the scheme.
(4)The reference in sub-paragraph (2)(b) to a data subject withholding consent does not include a data subject merely failing to respond to a request for consent.
Commencement Information
I21Sch. 1 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Political partiesU.K.
22(1)This condition is met if the processing—U.K.
(a)is of personal data revealing political opinions,
(b)is carried out by a person or organisation included in the register maintained under section 23 of the Political Parties, Elections and Referendums Act 2000, and
(c)is necessary for the purposes of the person's or organisation's political activities,
subject to the exceptions in sub-paragraphs (2) and (3).
(2)Processing does not meet the condition in sub-paragraph (1) if it is likely to cause substantial damage or substantial distress to a person.
(3)Processing does not meet the condition in sub-paragraph (1) if—
(a)an individual who is the data subject (or one of the data subjects) has given notice in writing to the controller requiring the controller not to process personal data in respect of which the individual is the data subject (and has not given notice in writing withdrawing that requirement),
(b)the notice gave the controller a reasonable period in which to stop processing such data, and
(c)that period has ended.
(4)In this paragraph, “political activities” include campaigning, fund-raising, political surveys and case-work.
Commencement Information
I22Sch. 1 para. 22 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Elected representatives responding to requestsU.K.
23(1)This condition is met if—U.K.
(a)the processing is carried out—
(i)by an elected representative or a person acting with the authority of such a representative,
(ii)in connection with the discharge of the elected representative's functions, and
(iii)in response to a request by an individual that the elected representative take action on behalf of the individual, and
(b)the processing is necessary for the purposes of, or in connection with, the action reasonably taken by the elected representative in response to that request,
subject to sub-paragraph (2).
(2)Where the request is made by an individual other than the data subject, the condition in sub-paragraph (1) is met only if the processing must be carried out without the consent of the data subject for one of the following reasons—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the elected representative cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)obtaining the consent of the data subject would prejudice the action taken by the elected representative;
(d)the processing is necessary in the interests of another individual and the data subject has withheld consent unreasonably.
(3)In this paragraph, “elected representative” means—
(a)a member of the House of Commons;
(b)a member of the National Assembly for Wales;
(c)a member of the Scottish Parliament;
(d)a member of the Northern Ireland Assembly;
(e)a member of the European Parliament elected in the United Kingdom;
(f)an elected member of a local authority within the meaning of section 270(1) of the Local Government Act 1972, namely—
(i)in England, a county council, a district council, a London borough council or a parish council;
(ii)in Wales, a county council, a county borough council or a community council;
(g)an elected mayor of a local authority within the meaning of Part 1A or 2 of the Local Government Act 2000;
(h)a mayor for the area of a combined authority established under section 103 of the Local Democracy, Economic Development and Construction Act 2009;
(i)the Mayor of London or an elected member of the London Assembly;
(j)an elected member of—
(i)the Common Council of the City of London, or
(ii)the Council of the Isles of Scilly;
(k)an elected member of a council constituted under section 2 of the Local Government etc (Scotland) Act 1994;
(l)an elected member of a district council within the meaning of the Local Government Act (Northern Ireland) 1972 (c. 9 (N.I.));
(m)a police and crime commissioner.
(4)For the purposes of sub-paragraph (3), a person who is—
(a)a member of the House of Commons immediately before Parliament is dissolved,
(b)a member of the National Assembly for Wales immediately before that Assembly is dissolved,
(c)a member of the Scottish Parliament immediately before that Parliament is dissolved, or
(d)a member of the Northern Ireland Assembly immediately before that Assembly is dissolved,
is to be treated as if the person were such a member until the end of the fourth day after the day on which the subsequent general election in relation to that Parliament or Assembly is held.
(5)For the purposes of sub-paragraph (3), a person who is an elected member of the Common Council of the City of London and whose term of office comes to an end at the end of the day preceding the annual Wardmotes is to be treated as if he or she were such a member until the end of the fourth day after the day on which those Wardmotes are held.
Commencement Information
I23Sch. 1 para. 23 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Disclosure to elected representativesU.K.
24(1)This condition is met if—U.K.
(a)the processing consists of the disclosure of personal data—
(i)to an elected representative or a person acting with the authority of such a representative, and
(ii)in response to a communication to the controller from that representative or person which was made in response to a request from an individual,
(b)the personal data is relevant to the subject matter of that communication, and
(c)the disclosure is necessary for the purpose of responding to that communication,
subject to sub-paragraph (2).
(2)Where the request to the elected representative came from an individual other than the data subject, the condition in sub-paragraph (1) is met only if the disclosure must be made without the consent of the data subject for one of the following reasons—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the elected representative cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)obtaining the consent of the data subject would prejudice the action taken by the elected representative;
(d)the processing is necessary in the interests of another individual and the data subject has withheld consent unreasonably.
(3)In this paragraph, “elected representative” has the same meaning as in paragraph 23.
Commencement Information
I24Sch. 1 para. 24 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Informing elected representatives about prisonersU.K.
25(1)This condition is met if—U.K.
(a)the processing consists of the processing of personal data about a prisoner for the purpose of informing a member of the House of Commons, a member of the National Assembly for Wales or a member of the Scottish Parliament about the prisoner, and
(b)the member is under an obligation not to further disclose the personal data.
(2)The references in sub-paragraph (1) to personal data about, and to informing someone about, a prisoner include personal data about, and informing someone about, arrangements for the prisoner's release.
(3)In this paragraph—
“prison” includes a young offender institution, a remand centre, a secure training centre or a secure college;
“prisoner” means a person detained in a prison.
Commencement Information
I25Sch. 1 para. 25 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Publication of legal judgmentsU.K.
26U.K.This condition is met if the processing—
(a)consists of the publication of a judgment or other decision of a court or tribunal, or
(b)is necessary for the purposes of publishing such a judgment or decision.
Commencement Information
I26Sch. 1 para. 26 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Anti-doping in sportU.K.
27(1)This condition is met if the processing is necessary—U.K.
(a)for the purposes of measures designed to eliminate doping which are undertaken by or under the responsibility of a body or association that is responsible for eliminating doping in a sport, at a sporting event or in sport generally, or
(b)for the purposes of providing information about doping, or suspected doping, to such a body or association.
(2)The reference in sub-paragraph (1)(a) to measures designed to eliminate doping includes measures designed to identify or prevent doping.
(3)If the processing consists of the disclosure of personal data to a body or association described in sub-paragraph (1)(a), or is carried out in preparation for such disclosure, the condition in sub-paragraph (1) is met even if, when the processing is carried out, the controller does not have an appropriate policy document in place (see paragraph 5 of this Schedule).
Commencement Information
I27Sch. 1 para. 27 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Standards of behaviour in sportU.K.
28(1)This condition is met if the processing—U.K.
(a)is necessary for the purposes of measures designed to protect the integrity of a sport or a sporting event,
(b)must be carried out without the consent of the data subject so as not to prejudice those purposes, and
(c)is necessary for reasons of substantial public interest.
(2)In sub-paragraph (1)(a), the reference to measures designed to protect the integrity of a sport or a sporting event is a reference to measures designed to protect a sport or a sporting event against—
(a)dishonesty, malpractice or other seriously improper conduct, or
(b)failure by a person participating in the sport or event in any capacity to comply with standards of behaviour set by a body or association with responsibility for the sport or event.
Commencement Information
I28Sch. 1 para. 28 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 3 U.K.Additional conditions relating to criminal convictions etc
ConsentU.K.
29U.K.This condition is met if the data subject has given consent to the processing.
Commencement Information
I29Sch. 1 para. 29 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Protecting individual's vital interestsU.K.
30U.K.This condition is met if—
(a)the processing is necessary to protect the vital interests of an individual, and
(b)the data subject is physically or legally incapable of giving consent.
Commencement Information
I30Sch. 1 para. 30 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Processing by not-for-profit bodiesU.K.
31U.K.This condition is met if the processing is carried out—
(a)in the course of its legitimate activities with appropriate safeguards by a foundation, association or other not-for-profit body with a political, philosophical, religious or trade union aim, and
(b)on condition that—
(i)the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes, and
(ii)the personal data is not disclosed outside that body without the consent of the data subjects.
Commencement Information
I31Sch. 1 para. 31 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Personal data in the public domainU.K.
32U.K.This condition is met if the processing relates to personal data which is manifestly made public by the data subject.
Commencement Information
I32Sch. 1 para. 32 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Legal claimsU.K.
33U.K.This condition is met if the processing—
(a)is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings),
(b)is necessary for the purpose of obtaining legal advice, or
(c)is otherwise necessary for the purposes of establishing, exercising or defending legal rights.
Commencement Information
I33Sch. 1 para. 33 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Judicial actsU.K.
34U.K.This condition is met if the processing is necessary when a court or tribunal is acting in its judicial capacity.
Commencement Information
I34Sch. 1 para. 34 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Administration of accounts used in commission of indecency offences involving childrenU.K.
35(1)This condition is met if—U.K.
(a)the processing is of personal data about a conviction or caution for an offence listed in sub-paragraph (2),
(b)the processing is necessary for the purpose of administering an account relating to the payment card used in the commission of the offence or cancelling that payment card, and
(c)when the processing is carried out, the controller has an appropriate policy document in place (see paragraph 39 in Part 4 of this Schedule).
(2)Those offences are an offence under—
(a)section 1 of the Protection of Children Act 1978 (indecent photographs of children),
(b)Article 3 of the Protection of Children (Northern Ireland) Order 1978 (S.I. 1978/1047 (N.I. 17)) (indecent photographs of children),
(c)section 52 of the Civic Government (Scotland) Act 1982 (indecent photographs etc of children),
(d)section 160 of the Criminal Justice Act 1988 (possession of indecent photograph of child),
(e)Article 15 of the Criminal Justice (Evidence etc) (Northern Ireland) Order 1988 (S.I. 1988/1847 (N.I. 17)) (possession of indecent photograph of child), or
(f)section 62 of the Coroners and Justice Act 2009 (possession of prohibited images of children),
or incitement to commit an offence under any of those provisions.
(3)See also the additional safeguards in Part 4 of this Schedule.
(4)In this paragraph—
“caution” means a caution given to a person in England and Wales or Northern Ireland in respect of an offence which, at the time when the caution is given, is admitted;
“conviction” has the same meaning as in the Rehabilitation of Offenders Act 1974 or the Rehabilitation of Offenders (Northern Ireland) Order 1978 (S.I. 1978/1908 (N.I. 27));
“payment card” includes a credit card, a charge card and a debit card.
Commencement Information
I35Sch. 1 para. 35 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Extension of conditions in Part 2 of this Schedule referring to substantial public interestU.K.
36U.K.This condition is met if the processing would meet a condition in Part 2 of this Schedule but for an express requirement for the processing to be necessary for reasons of substantial public interest.
Commencement Information
I36Sch. 1 para. 36 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Extension of insurance conditionsU.K.
37U.K.This condition is met if the processing—
(a)would meet the condition in paragraph 20 in Part 2 of this Schedule (the “insurance condition”), or
(b)would meet the condition in paragraph 36 by virtue of the insurance condition,
but for the requirement for the processing to be processing of a category of personal data specified in paragraph 20(1)(b).
Commencement Information
I37Sch. 1 para. 37 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 4 U.K.Appropriate policy document and additional safeguards
Application of this Part of this ScheduleU.K.
38U.K.This Part of this Schedule makes provision about the processing of personal data carried out in reliance on a condition in Part 1, 2 or 3 of this Schedule which requires the controller to have an appropriate policy document in place when the processing is carried out.
Commencement Information
I38Sch. 1 para. 38 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Requirement to have an appropriate policy document in placeU.K.
39U.K.The controller has an appropriate policy document in place in relation to the processing of personal data in reliance on a condition described in paragraph 38 if the controller has produced a document which—
(a)explains the controller's procedures for securing compliance with the principles in Article 5 of the GDPR (principles relating to processing of personal data) in connection with the processing of personal data in reliance on the condition in question, and
(b)explains the controller's policies as regards the retention and erasure of personal data processed in reliance on the condition, giving an indication of how long such personal data is likely to be retained.
Commencement Information
I39Sch. 1 para. 39 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Additional safeguard: retention of appropriate policy documentU.K.
40(1)Where personal data is processed in reliance on a condition described in paragraph 38, the controller must during the relevant period—U.K.
(a)retain the appropriate policy document,
(b)review and (if appropriate) update it from time to time, and
(c)make it available to the Commissioner, on request, without charge.
(2)“Relevant period”, in relation to the processing of personal data in reliance on a condition described in paragraph 38, means a period which—
(a)begins when the controller starts to carry out processing of personal data in reliance on that condition, and
(b)ends at the end of the period of 6 months beginning when the controller ceases to carry out such processing.
Commencement Information
I40Sch. 1 para. 40 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Additional safeguard: record of processingU.K.
41U.K.A record maintained by the controller, or the controller's representative, under Article 30 of the GDPR in respect of the processing of personal data in reliance on a condition described in paragraph 38 must include the following information—
(a)which condition is relied on,
(b)how the processing satisfies Article 6 of the GDPR (lawfulness of processing), and
(c)whether the personal data is retained and erased in accordance with the policies described in paragraph 39(b) and, if it is not, the reasons for not following those policies.
Commencement Information
I41Sch. 1 para. 41 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 15
SCHEDULE 2U.K.Exemptions etc from the GDPR
PART 1 U.K.Adaptations and restrictions based on Articles 6(3) and 23(1)
GDPR provisions to be adapted or restricted: “the listed GDPR provisions”U.K.
1U.K.In this Part of this Schedule, “the listed GDPR provisions” means—
(a)the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(i)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(ii)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(iii)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(iv)Article 16 (right to rectification);
(v)Article 17(1) and (2) (right to erasure);
(vi)Article 18(1) (restriction of processing);
(vii)Article 19 (notification obligation regarding rectification or erasure of personal data or restriction of processing);
(viii)Article 20(1) and (2) (right to data portability);
(ix)Article 21(1) (objections to processing);
(x)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in sub-paragraphs (i) to (ix); and
(b)the following provisions of the GDPR (the application of which may be adapted by virtue of Article 6(3) of the GDPR)—
(i)Article 5(1)(a) (lawful, fair and transparent processing), other than the lawfulness requirements set out in Article 6;
(ii)Article 5(1)(b) (purpose limitation).
Commencement Information
I42Sch. 2 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Crime and taxation: generalU.K.
2(1)The listed GDPR provisions and Article 34(1) and (4) of the GDPR (communication of personal data breach to the data subject) do not apply to personal data processed for any of the following purposes—U.K.
(a)the prevention or detection of crime,
(b)the apprehension or prosecution of offenders, or
(c)the assessment or collection of a tax or duty or an imposition of a similar nature,
to the extent that the application of those provisions would be likely to prejudice any of the matters mentioned in paragraphs (a) to (c).
(2)Sub-paragraph (3) applies where—
(a)personal data is processed by a person (“Controller 1”) for any of the purposes mentioned in sub-paragraph (1)(a) to (c), and
(b)another person (“Controller 2”) obtains the data from Controller 1 for the purpose of discharging statutory functions and processes it for the purpose of discharging statutory functions.
(3)Controller 2 is exempt from the obligations in the following provisions of the GDPR—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided),
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided),
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers), and
(d)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in paragraphs (a) to (c),
to the same extent that Controller 1 is exempt from those obligations by virtue of sub-paragraph (1).
Commencement Information
I43Sch. 2 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Crime and taxation: risk assessment systemsU.K.
3(1)The GDPR provisions listed in sub-paragraph (3) do not apply to personal data which consists of a classification applied to the data subject as part of a risk assessment system falling within sub-paragraph (2) to the extent that the application of those provisions would prevent the system from operating effectively.U.K.
(2)A risk assessment system falls within this sub-paragraph if—
(a)it is operated by a government department, a local authority or another authority administering housing benefit, and
(b)it is operated for the purposes of—
(i)the assessment or collection of a tax or duty or an imposition of a similar nature, or
(ii)the prevention or detection of crime or apprehension or prosecution of offenders, where the offence concerned involves the unlawful use of public money or an unlawful claim for payment out of public money.
(3)The GDPR provisions referred to in sub-paragraph (1) are the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(d)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in paragraphs (a) to (c).
Commencement Information
I44Sch. 2 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
ImmigrationU.K.
4(1)The GDPR provisions listed in sub-paragraph (2) do not apply to personal data processed for any of the following purposes—U.K.
(a)the maintenance of effective immigration control, or
(b)the investigation or detection of activities that would undermine the maintenance of effective immigration control,
to the extent that the application of those provisions would be likely to prejudice any of the matters mentioned in paragraphs (a) and (b).
(2)The GDPR provisions referred to in sub-paragraph (1) are the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(d)Article 17(1) and (2) (right to erasure);
(e)Article 18(1) (restriction of processing);
(f)Article 21(1) (objections to processing);
(g)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in sub-paragraphs (a) to (f).
(That is, the listed GDPR provisions other than Article 16 (right to rectification), Article 19 (notification obligation regarding rectification or erasure of personal data or restriction of processing) and Article 20(1) and (2) (right to data portability) and, subject to sub-paragraph (2)(g) of this paragraph, the provisions of Article 5 listed in paragraph 1(b).)
(3)Sub-paragraph (4) applies where—
(a)personal data is processed by a person (“Controller 1”), and
(b)another person (“Controller 2”) obtains the data from Controller 1 for any of the purposes mentioned in sub-paragraph (1)(a) and (b) and processes it for any of those purposes.
(4)Controller 1 is exempt from the obligations in the following provisions of the GDPR—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided),
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided),
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers), and
(d)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in paragraphs (a) to (c),
to the same extent that Controller 2 is exempt from those obligations by virtue of sub-paragraph (1).
Commencement Information
I45Sch. 2 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Information required to be disclosed by law etc or in connection with legal proceedingsU.K.
5(1)The listed GDPR provisions do not apply to personal data consisting of information that the controller is obliged by an enactment to make available to the public, to the extent that the application of those provisions would prevent the controller from complying with that obligation.U.K.
(2)The listed GDPR provisions do not apply to personal data where disclosure of the data is required by an enactment, a rule of law or an order of a court or tribunal, to the extent that the application of those provisions would prevent the controller from making the disclosure.
(3)The listed GDPR provisions do not apply to personal data where disclosure of the data—
(a)is necessary for the purpose of, or in connection with, legal proceedings (including prospective legal proceedings),
(b)is necessary for the purpose of obtaining legal advice, or
(c)is otherwise necessary for the purposes of establishing, exercising or defending legal rights,
to the extent that the application of those provisions would prevent the controller from making the disclosure.
Commencement Information
I46Sch. 2 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 2 U.K.Restrictions based on Article 23(1): restrictions of rules in Articles 13 to 21 and 34
GDPR provisions to be restricted: “the listed GDPR provisions”U.K.
6U.K.In this Part of this Schedule, “the listed GDPR provisions” means the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(d)Article 16 (right to rectification);
(e)Article 17(1) and (2) (right to erasure);
(f)Article 18(1) (restriction of processing);
(g)Article 19 (notification obligation regarding rectification or erasure of personal data or restriction of processing);
(h)Article 20(1) and (2) (right to data portability);
(i)Article 21(1) (objections to processing);
(j)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in sub-paragraphs (a) to (i).
Commencement Information
I47Sch. 2 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Functions designed to protect the public etcU.K.
7U.K.The listed GDPR provisions do not apply to personal data processed for the purposes of discharging a function that—
(a)is designed as described in column 1 of the Table, and
(b)meets the condition relating to the function specified in column 2 of the Table,
to the extent that the application of those provisions would be likely to prejudice the proper discharge of the function.
TABLE
Description of function design | Condition |
---|---|
1. The function is designed to protect members of the public against— (a) financial loss due to dishonesty, malpractice or other seriously improper conduct by, or the unfitness or incompetence of, persons concerned in the provision of banking, insurance, investment or other financial services or in the management of bodies corporate, or (b) financial loss due to the conduct of discharged or undischarged bankrupts. | The function is— (a) conferred on a person by an enactment, (b) a function of the Crown, a Minister of the Crown or a government department, or (c) of a public nature, and is exercised in the public interest. |
2. The function is designed to protect members of the public against— (a) dishonesty, malpractice or other seriously improper conduct, or (b) unfitness or incompetence. | The function is— (a) conferred on a person by an enactment, (b) a function of the Crown, a Minister of the Crown or a government department, or (c) of a public nature, and is exercised in the public interest. |
3. The function is designed— (a) to protect charities or community interest companies against misconduct or mismanagement (whether by trustees, directors or other persons) in their administration, (b) to protect the property of charities or community interest companies from loss or misapplication, or (c) to recover the property of charities or community interest companies. | The function is— (a) conferred on a person by an enactment, (b) a function of the Crown, a Minister of the Crown or a government department, or (c) of a public nature, and is exercised in the public interest. |
4. The function is designed— (a) to secure the health, safety and welfare of persons at work, or (b) to protect persons other than those at work against risk to health or safety arising out of or in connection with the action of persons at work. | The function is— (a) conferred on a person by an enactment, (b) a function of the Crown, a Minister of the Crown or a government department, or (c) of a public nature, and is exercised in the public interest. |
5. The function is designed to protect members of the public against— (a) maladministration by public bodies, (b) failures in services provided by public bodies, or (c) a failure of a public body to provide a service which it is a function of the body to provide. | The function is conferred by any enactment on— (a) the Parliamentary Commissioner for Administration, (b) the Commissioner for Local Administration in England, (c) the Health Service Commissioner for England, (d) the Public Services Ombudsman for Wales, (e) the Northern Ireland Public Services Ombudsman, (f) the Prison Ombudsman for Northern Ireland, or (g) the Scottish Public Services Ombudsman. |
6. The function is designed— (a) to protect members of the public against conduct which may adversely affect their interests by persons carrying on a business, (b) to regulate agreements or conduct which have as their object or effect the prevention, restriction or distortion of competition in connection with any commercial activity, or (c) to regulate conduct on the part of one or more undertakings which amounts to the abuse of a dominant position in a market. | The function is conferred on the Competition and Markets Authority by an enactment. |
Modifications etc. (not altering text)
C4Sch. 2 para. 7 modified by S.I. 1999/3145, art. 9(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 238 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
C5Sch. 2 para. 7 modified by S.I. 1999/677, art. 7(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 237 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
C6Sch. 2 para. 7 modified by S.I. 2007/1118, art. 5(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 324 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
Commencement Information
I48Sch. 2 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Audit functionsU.K.
8(1)The listed GDPR provisions do not apply to personal data processed for the purposes of discharging a function listed in sub-paragraph (2) to the extent that the application of those provisions would be likely to prejudice the proper discharge of the function.U.K.
(2)The functions are any function that is conferred by an enactment on—
(a)the Comptroller and Auditor General;
(b)the Auditor General for Scotland;
(c)the Auditor General for Wales;
(d)the Comptroller and Auditor General for Northern Ireland.
Commencement Information
I49Sch. 2 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Functions of the Bank of EnglandU.K.
9(1)The listed GDPR provisions do not apply to personal data processed for the purposes of discharging a relevant function of the Bank of England to the extent that the application of those provisions would be likely to prejudice the proper discharge of the function.U.K.
(2)“Relevant function of the Bank of England” means—
(a)a function discharged by the Bank acting in its capacity as a monetary authority (as defined in section 244(2)(c) and (2A) of the Banking Act 2009);
(b)a public function of the Bank within the meaning of section 349 of the Financial Services and Markets Act 2000;
(c)a function conferred on the Prudential Regulation Authority by or under the Financial Services and Markets Act 2000 or by another enactment.
Commencement Information
I50Sch. 2 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Regulatory functions relating to legal services, the health service and children's servicesU.K.
10(1)The listed GDPR provisions do not apply to personal data processed for the purposes of discharging a function listed in sub-paragraph (2) to the extent that the application of those provisions would be likely to prejudice the proper discharge of the function.U.K.
(2)The functions are—
(a)a function of the Legal Services Board;
(b)the function of considering a complaint under the scheme established under Part 6 of the Legal Services Act 2007 (legal complaints);
(c)the function of considering a complaint under—
(i)section 14 of the NHS Redress Act 2006,
(ii)section 113(1) or (2) or section 114(1) or (3) of the Health and Social Care (Community Health and Standards) Act 2003,
(iii)section 24D or 26 of the Children Act 1989, or
(iv)Part 2A of the Public Services Ombudsman (Wales) Act 2005;
(d)the function of considering a complaint or representations under Chapter 1 of Part 10 of the Social Services and Well-being (Wales) Act 2014 (anaw 4).
Commencement Information
I51Sch. 2 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Regulatory functions of certain other personsU.K.
11U.K.The listed GDPR provisions do not apply to personal data processed for the purposes of discharging a function that—
(a)is a function of a person described in column 1 of the Table, and
(b)is conferred on that person as described in column 2 of the Table,
to the extent that the application of those provisions would be likely to prejudice the proper discharge of the function.
TABLE
Person on whom function is conferred | How function is conferred |
---|---|
1. The Commissioner. | By or under— (a) the data protection legislation; (b) the Freedom of Information Act 2000; (c) section 244 of the Investigatory Powers Act 2016; (d) the Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426); (e) the Environmental Information Regulations 2004 (S.I. 2004/3391); (f) the INSPIRE Regulations 2009 (S.I. 2009/3157); (g) Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC; (h) the Re-use of Public Sector Information Regulations 2015 (S.I. 2015/1415); (i) the Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696). |
2. The Scottish Information Commissioner. | By or under— (a) the Freedom of Information (Scotland) Act 2002 (asp 13); (b) the Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520); (c) the INSPIRE (Scotland) Regulations 2009 (S.S.I. 2009/440). |
3. The Pensions Ombudsman. | By or under Part 10 of the Pension Schemes Act 1993 or any corresponding legislation having equivalent effect in Northern Ireland. |
4. The Board of the Pension Protection Fund. | By or under sections 206 to 208 of the Pensions Act 2004 or any corresponding legislation having equivalent effect in Northern Ireland. |
5. The Ombudsman for the Board of the Pension Protection Fund. | By or under any of sections 209 to 218 or 286(1) of the Pensions Act 2004 or any corresponding legislation having equivalent effect in Northern Ireland. |
6. The Pensions Regulator. | By an enactment. |
7. The Financial Conduct Authority. | By or under the Financial Services and Markets Act 2000 or by another enactment. |
8. The Financial Ombudsman. | By or under Part 16 of the Financial Services and Markets Act 2000. |
9. The investigator of complaints against the financial regulators. | By or under Part 6 of the Financial Services Act 2012. |
10. A consumer protection enforcer, other than the Competition and Markets Authority. | By or under the CPC Regulation. |
11. The monitoring officer of a relevant authority. | By or under the Local Government and Housing Act 1989. |
12. The monitoring officer of a relevant Welsh authority. | By or under the Local Government Act 2000. |
13. The Public Services Ombudsman for Wales. | By or under the Local Government Act 2000. |
14. The Charity Commission. | By or under— (a) the Charities Act 1992; (b) the Charities Act 2006; (c) the Charities Act 2011. |
Commencement Information
I52Sch. 2 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
12U.K.In the Table in paragraph 11—
“consumer protection enforcer” has the same meaning as “CPC enforcer” in section 213(5A) of the Enterprise Act 2002;
the “CPC Regulation” has the meaning given in section 235A of the Enterprise Act 2002;
the “Financial Ombudsman” means the scheme operator within the meaning of Part 16 of the Financial Services and Markets Act 2000 (see section 225 of that Act);
the “investigator of complaints against the financial regulators” means the person appointed under section 84(1)(b) of the Financial Services Act 2012;
“relevant authority” has the same meaning as in section 5 of the Local Government and Housing Act 1989, and “monitoring officer”, in relation to such an authority, means a person designated as such under that section;
“relevant Welsh authority” has the same meaning as “relevant authority” in section 49(6) of the Local Government Act 2000, and “monitoring officer”, in relation to such an authority, has the same meaning as in Part 3 of that Act.
Commencement Information
I53Sch. 2 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Parliamentary privilegeU.K.
13U.K.The listed GDPR provisions and Article 34(1) and (4) of the GDPR (communication of personal data breach to the data subject) do not apply to personal data where this is required for the purpose of avoiding an infringement of the privileges of either House of Parliament.
Commencement Information
I54Sch. 2 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Judicial appointments, judicial independence and judicial proceedingsU.K.
14(1)The listed GDPR provisions do not apply to personal data processed for the purposes of assessing a person's suitability for judicial office or the office of Queen's Counsel.U.K.
(2)The listed GDPR provisions do not apply to personal data processed by—
(a)an individual acting in a judicial capacity, or
(b)a court or tribunal acting in its judicial capacity.
(3)As regards personal data not falling within sub-paragraph (1) or (2), the listed GDPR provisions do not apply to the extent that the application of those provisions would be likely to prejudice judicial independence or judicial proceedings.
Commencement Information
I55Sch. 2 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Crown honours, dignities and appointmentsU.K.
15(1)The listed GDPR provisions do not apply to personal data processed for the purposes of the conferring by the Crown of any honour or dignity.U.K.
(2)The listed GDPR provisions do not apply to personal data processed for the purposes of assessing a person's suitability for any of the following offices—
(a)archbishops and diocesan and suffragan bishops in the Church of England;
(b)deans of cathedrals of the Church of England;
(c)deans and canons of the two Royal Peculiars;
(d)the First and Second Church Estates Commissioners;
(e)lord-lieutenants;
(f)Masters of Trinity College and Churchill College, Cambridge;
(g)the Provost of Eton;
(h)the Poet Laureate;
(i)the Astronomer Royal.
(3)The Secretary of State may by regulations amend the list in sub-paragraph (2) to—
(a)remove an office, or
(b)add an office to which appointments are made by Her Majesty.
(4)Regulations under sub-paragraph (3) are subject to the affirmative resolution procedure.
Commencement Information
I56Sch. 2 para. 15 in force at Royal Assent for specified purposes, see s. 212(2)(f)
I57Sch. 2 para. 15 in force at 25.5.2018 in so far as not already in force by S.I. 2018/625, reg. 2(1)(b)
PART 3 U.K.Restriction based on Article 23(1): protection of rights of others
Protection of the rights of others: generalU.K.
16(1)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers), and Article 5 of the GDPR so far as its provisions correspond to the rights and obligations provided for in Article 15(1) to (3), do not oblige a controller to disclose information to the data subject to the extent that doing so would involve disclosing information relating to another individual who can be identified from the information.U.K.
(2)Sub-paragraph (1) does not remove the controller's obligation where—
(a)the other individual has consented to the disclosure of the information to the data subject, or
(b)it is reasonable to disclose the information to the data subject without the consent of the other individual.
(3)In determining whether it is reasonable to disclose the information without consent, the controller must have regard to all the relevant circumstances, including—
(a)the type of information that would be disclosed,
(b)any duty of confidentiality owed to the other individual,
(c)any steps taken by the controller with a view to seeking the consent of the other individual,
(d)whether the other individual is capable of giving consent, and
(e)any express refusal of consent by the other individual.
(4)For the purposes of this paragraph—
(a)“information relating to another individual” includes information identifying the other individual as the source of information;
(b)an individual can be identified from information to be provided to a data subject by a controller if the individual can be identified from—
(i)that information, or
(ii)that information and any other information that the controller reasonably believes the data subject is likely to possess or obtain.
Commencement Information
I58Sch. 2 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Assumption of reasonableness for health workers, social workers and education workersU.K.
17(1)For the purposes of paragraph 16(2)(b), it is to be considered reasonable for a controller to disclose information to a data subject without the consent of the other individual where—U.K.
(a)the health data test is met,
(b)the social work data test is met, or
(c)the education data test is met.
(2)The health data test is met if—
(a)the information in question is contained in a health record, and
(b)the other individual is a health professional who has compiled or contributed to the health record or who, in his or her capacity as a health professional, has been involved in the diagnosis, care or treatment of the data subject.
(3)The social work data test is met if—
(a)the other individual is—
(i)a children's court officer,
(ii)a person who is or has been employed by a person or body referred to in paragraph 8 of Schedule 3 in connection with functions exercised in relation to the information, or
(iii)a person who has provided for reward a service that is similar to a service provided in the exercise of any relevant social services functions, and
(b)the information relates to the other individual in an official capacity or the other individual supplied the information—
(i)in an official capacity, or
(ii)in a case within paragraph (a)(iii), in connection with providing the service mentioned in paragraph (a)(iii).
(4)The education data test is met if—
(a)the other individual is an education-related worker, or
(b)the other individual is employed by an education authority (within the meaning of the Education (Scotland) Act 1980) in pursuance of its functions relating to education and—
(i)the information relates to the other individual in his or her capacity as such an employee, or
(ii)the other individual supplied the information in his or her capacity as such an employee.
(5)In this paragraph—
“children's court officer” means a person referred to in paragraph 8(1)(q), (r), (s), (t) or (u) of Schedule 3;
“
” means a person referred to in paragraph 14(4)(a) or (b) or 16(4)(a), (b) or (c) of Schedule 3 (educational records);“relevant social services functions” means functions specified in paragraph 8(1)(a), (b), (c) or (d) of Schedule 3.
Commencement Information
I59Sch. 2 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 4 U.K.Restrictions based on Article 23(1): restrictions of rules in Articles 13 to 15
GDPR provisions to be restricted: “the listed GDPR provisions”U.K.
18U.K.In this Part of this Schedule, “the listed GDPR provisions” means the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(d)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in sub-paragraphs (a) to (c).
Commencement Information
I60Sch. 2 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Legal professional privilegeU.K.
19U.K.The listed GDPR provisions do not apply to personal data that consists of—
(a)information in respect of which a claim to legal professional privilege or, in Scotland, confidentiality of communications, could be maintained in legal proceedings, or
(b)information in respect of which a duty of confidentiality is owed by a professional legal adviser to a client of the adviser.
Commencement Information
I61Sch. 2 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Self incriminationU.K.
20(1)A person need not comply with the listed GDPR provisions to the extent that compliance would, by revealing evidence of the commission of an offence, expose the person to proceedings for that offence.U.K.
(2)The reference to an offence in sub-paragraph (1) does not include an offence under—
(a)this Act,
(b)section 5 of the Perjury Act 1911 (false statements made otherwise than on oath),
(c)section 44(2) of the Criminal Law (Consolidation) (Scotland) Act 1995 (false statements made otherwise than on oath), or
(d)Article 10 of the Perjury (Northern Ireland) Order 1979 (S.I. 1979/1714 (N.I. 19)) (false statutory declarations and other false unsworn statements).
(3)Information disclosed by any person in compliance with Article 15 of the GDPR is not admissible against the person in proceedings for an offence under this Act.
Commencement Information
I62Sch. 2 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Corporate financeU.K.
21(1)The listed GDPR provisions do not apply to personal data processed for the purposes of or in connection with a corporate finance service provided by a relevant person to the extent that either Condition A or Condition B is met.U.K.
(2)Condition A is that the application of the listed GDPR provisions would be likely to affect the price of an instrument.
(3)Condition B is that—
(a)the relevant person reasonably believes that the application of the listed GDPR provisions to the personal data in question could affect a decision of a person—
(i)whether to deal in, subscribe for or issue an instrument, or
(ii)whether to act in a way likely to have an effect on a business activity (such as an effect on the industrial strategy of a person, the capital structure of an undertaking or the legal or beneficial ownership of a business or asset), and
(b)the application of the listed GDPR provisions to that personal data would have a prejudicial effect on the orderly functioning of financial markets or the efficient allocation of capital within the economy.
(4)In this paragraph—
“corporate finance service” means a service consisting in—
(a)underwriting in respect of issues of, or the placing of issues of, any instrument,
(b)services relating to such underwriting, or
(c)advice to undertakings on capital structure, industrial strategy and related matters and advice and service relating to mergers and the purchase of undertakings;
“instrument” means an instrument listed in section C of Annex 1 to Directive 2004/39/EC of the European Parliament and of the Council of 21 April 2004 on markets in financial instruments, and references to an instrument include an instrument not yet in existence but which is to be or may be created;
“price” includes value;
“relevant person” means—
(a)a person who, by reason of a permission under Part 4A of the Financial Services and Markets Act 2000, is able to carry on a corporate finance service without contravening the general prohibition;
(b)an EEA firm of the kind mentioned in paragraph 5(a) or (b) of Schedule 3 to that Act which has qualified for authorisation under paragraph 12 of that Schedule, and may lawfully carry on a corporate finance service;
(c)a person who is exempt from the general prohibition in respect of any corporate finance service—
(i)as a result of an exemption order made under section 38(1) of that Act, or
(ii)by reason of section 39(1) of that Act (appointed representatives);
(d)a person, not falling within paragraph (a), (b) or (c), who may lawfully carry on a corporate finance service without contravening the general prohibition;
(e)a person who, in the course of employment, provides to their employer a service falling within paragraph (b) or (c) of the definition of “corporate finance service”;
(f)a partner who provides to other partners in the partnership a service falling within either of those paragraphs.
(5)In the definition of “relevant person” in sub-paragraph (4), references to “the general prohibition” are to the general prohibition within the meaning of section 19 of the Financial Services and Markets Act 2000.
Commencement Information
I63Sch. 2 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Management forecastsU.K.
22U.K.The listed GDPR provisions do not apply to personal data processed for the purposes of management forecasting or management planning in relation to a business or other activity to the extent that the application of those provisions would be likely to prejudice the conduct of the business or activity concerned.
Commencement Information
I64Sch. 2 para. 22 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
NegotiationsU.K.
23U.K.The listed GDPR provisions do not apply to personal data that consists of records of the intentions of the controller in relation to any negotiations with the data subject to the extent that the application of those provisions would be likely to prejudice those negotiations.
Commencement Information
I65Sch. 2 para. 23 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Confidential referencesU.K.
24U.K.The listed GDPR provisions do not apply to personal data consisting of a reference given (or to be given) in confidence for the purposes of—
(a)the education, training or employment (or prospective education, training or employment) of the data subject,
(b)the placement (or prospective placement) of the data subject as a volunteer,
(c)the appointment (or prospective appointment) of the data subject to any office, or
(d)the provision (or prospective provision) by the data subject of any service.
Commencement Information
I66Sch. 2 para. 24 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exam scripts and exam marksU.K.
25(1)The listed GDPR provisions do not apply to personal data consisting of information recorded by candidates during an exam.U.K.
(2)Where personal data consists of marks or other information processed by a controller—
(a)for the purposes of determining the results of an exam, or
(b)in consequence of the determination of the results of an exam,
the duty in Article 12(3) or (4) of the GDPR for the controller to provide information requested by the data subject within a certain time period, as it applies to Article 15 of the GDPR (confirmation of processing, access to data and safeguards for third country transfers), is modified as set out in sub-paragraph (3).
(3)Where a question arises as to whether the controller is obliged by Article 15 of the GDPR to disclose personal data, and the question arises before the day on which the exam results are announced, the controller must provide the information mentioned in Article 12(3) or (4)—
(a)before the end of the period of 5 months beginning when the question arises, or
(b)if earlier, before the end of the period of 40 days beginning with the announcement of the results.
(4)In this paragraph, “exam” means an academic, professional or other examination used for determining the knowledge, intelligence, skill or ability of a candidate and may include an exam consisting of an assessment of the candidate's performance while undertaking work or any other activity.
(5)For the purposes of this paragraph, the results of an exam are treated as announced when they are first published or, if not published, first communicated to the candidate.
Commencement Information
I67Sch. 2 para. 25 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 5 U.K.Exemptions etc based on Article 85(2) for reasons of freedom of expression and information
Journalistic, academic, artistic and literary purposesU.K.
26(1)In this paragraph, “the special purposes” means one or more of the following—U.K.
(a)the purposes of journalism;
(b)academic purposes;
(c)artistic purposes;
(d)literary purposes.
(2)Sub-paragraph (3) applies to the processing of personal data carried out for the special purposes if—
(a)the processing is being carried out with a view to the publication by a person of journalistic, academic, artistic or literary material, and
(b)the controller reasonably believes that the publication of the material would be in the public interest.
(3)The listed GDPR provisions do not apply to the extent that the controller reasonably believes that the application of those provisions would be incompatible with the special purposes.
(4)In determining whether publication would be in the public interest the controller must take into account the special importance of the public interest in the freedom of expression and information.
(5)In determining whether it is reasonable to believe that publication would be in the public interest, the controller must have regard to any of the codes of practice or guidelines listed in sub-paragraph (6) that is relevant to the publication in question.
(6)The codes of practice and guidelines are—
(a)BBC Editorial Guidelines;
(b)Ofcom Broadcasting Code;
(c)Editors' Code of Practice.
(7)The Secretary of State may by regulations amend the list in sub-paragraph (6).
(8)Regulations under sub-paragraph (7) are subject to the affirmative resolution procedure.
(9)For the purposes of this paragraph, the listed GDPR provisions are the following provisions of the GDPR (which may be exempted or derogated from by virtue of Article 85(2) of the GDPR)—
(a)in Chapter II of the GDPR (principles)—
(i)Article 5(1)(a) to (e) (principles relating to processing);
(ii)Article 6 (lawfulness);
(iii)Article 7 (conditions for consent);
(iv)Article 8(1) and (2) (child's consent);
(v)Article 9 (processing of special categories of data);
(vi)Article 10 (data relating to criminal convictions etc);
(vii)Article 11(2) (processing not requiring identification);
(b)in Chapter III of the GDPR (rights of the data subject)—
(i)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(ii)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(iii)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(iv)Article 16 (right to rectification);
(v)Article 17(1) and (2) (right to erasure);
(vi)Article 18(1)(a), (b) and (d) (restriction of processing);
(vii)Article 19 (notification obligation regarding rectification or erasure of personal data or restriction of processing);
(viii)Article 20(1) and (2) (right to data portability);
(ix)Article 21(1) (objections to processing);
(c)in Chapter IV of the GDPR (controller and processor)—
(i)Article 34(1) and (4) (communication of personal data breach to the data subject);
(ii)Article 36 (requirement for controller to consult Commissioner prior to high risk processing);
(d)in Chapter V of the GDPR (transfers of data to third countries etc), Article 44 (general principles for transfers);
(e)in Chapter VII of the GDPR (co-operation and consistency)—
(i)Articles 60 to 62 (co-operation);
(ii)Articles 63 to 67 (consistency).
Commencement Information
I68Sch. 2 para. 26 in force at Royal Assent for specified purposes, see s. 212(2)(f)
I69Sch. 2 para. 26 in force at 25.5.2018 in so far as not already in force by S.I. 2018/625, reg. 2(1)(b)
PART 6 U.K.Derogations etc based on Article 89 for research, statistics and archiving
Research and statisticsU.K.
27(1)The listed GDPR provisions do not apply to personal data processed for—U.K.
(a)scientific or historical research purposes, or
(b)statistical purposes,
to the extent that the application of those provisions would prevent or seriously impair the achievement of the purposes in question.
This is subject to sub-paragraph (3).
(2)For the purposes of this paragraph, the listed GDPR provisions are the following provisions of the GDPR (the rights in which may be derogated from by virtue of Article 89(2) of the GDPR)—
(a)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(b)Article 16 (right to rectification);
(c)Article 18(1) (restriction of processing);
(d)Article 21(1) (objections to processing).
(3)The exemption in sub-paragraph (1) is available only where—
(a)the personal data is processed in accordance with Article 89(1) of the GDPR (as supplemented by section 19), and
(b)as regards the disapplication of Article 15(1) to (3), the results of the research or any resulting statistics are not made available in a form which identifies a data subject.
Commencement Information
I70Sch. 2 para. 27 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Archiving in the public interestU.K.
28(1)The listed GDPR provisions do not apply to personal data processed for archiving purposes in the public interest to the extent that the application of those provisions would prevent or seriously impair the achievement of those purposes.U.K.
This is subject to sub-paragraph (3).
(2)For the purposes of this paragraph, the listed GDPR provisions are the following provisions of the GDPR (the rights in which may be derogated from by virtue of Article 89(3) of the GDPR)—
(a)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(b)Article 16 (right to rectification);
(c)Article 18(1) (restriction of processing);
(d)Article 19 (notification obligation regarding rectification or erasure of personal data or restriction of processing);
(e)Article 20(1) (right to data portability);
(f)Article 21(1) (objections to processing).
(3)The exemption in sub-paragraph (1) is available only where the personal data is processed in accordance with Article 89(1) of the GDPR (as supplemented by section 19).
Commencement Information
I71Sch. 2 para. 28 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 15
SCHEDULE 3U.K.Exemptions etc from the GDPR: health, social work, education and child abuse data
PART 1 U.K.GDPR provisions to be restricted
1U.K.In this Schedule “the listed GDPR provisions” means the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(a)Article 13(1) to (3) (personal data collected from data subject: information to be provided);
(b)Article 14(1) to (4) (personal data collected other than from data subject: information to be provided);
(c)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(d)Article 16 (right to rectification);
(e)Article 17(1) and (2) (right to erasure);
(f)Article 18(1) (restriction of processing);
(g)Article 20(1) and (2) (right to data portability);
(h)Article 21(1) (objections to processing);
(i)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in sub-paragraphs (a) to (h).
Commencement Information
I72Sch. 3 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 2 U.K.Health data
DefinitionsU.K.
2(1)In this Part of this Schedule—U.K.
“the appropriate health professional”, in relation to a question as to whether the serious harm test is met with respect to data concerning health, means—
(a)the health professional who is currently or was most recently responsible for the diagnosis, care or treatment of the data subject in connection with the matters to which the data relates,
(b)where there is more than one such health professional, the health professional who is the most suitable to provide an opinion on the question, or
(c)a health professional who has the necessary experience and qualifications to provide an opinion on the question, where—
(i)there is no health professional available falling within paragraph (a) or (b), or
(ii)the controller is the Secretary of State and data is processed in connection with the exercise of the functions conferred on the Secretary of State by or under the Child Support Act 1991 and the Child Support Act 1995, or the Secretary of State's functions in relation to social security or war pensions, or
(iii)the controller is the Department for Communities in Northern Ireland and data is processed in connection with the exercise of the functions conferred on the Department by or under the Child Support (Northern Ireland) Order 1991 (S.I. 1991/2628 (N.I. 23)) and the Child Support (Northern Ireland) Order 1995 (S.I. 1995/2702 (N.I. 13));
“war pension” has the same meaning as in section 25 of the Social Security Act 1989 (establishment and functions of war pensions committees).
(2)For the purposes of this Part of this Schedule, the “serious harm test” is met with respect to data concerning health if the application of Article 15 of the GDPR to the data would be likely to cause serious harm to the physical or mental health of the data subject or another individual.
Commencement Information
I73Sch. 3 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from the listed GDPR provisions: data processed by a courtU.K.
3(1)The listed GDPR provisions do not apply to data concerning health if—U.K.
(a)it is processed by a court,
(b)it consists of information supplied in a report or other evidence given to the court in the course of proceedings to which rules listed in subparagraph (2) apply, and
(c)in accordance with those rules, the data may be withheld by the court in whole or in part from the data subject.
(2)Those rules are—
(a)the Magistrates' Courts (Children and Young Persons) Rules (Northern Ireland) 1969 (S.R. (N.I.) 1969 No. 221);
(b)the Magistrates' Courts (Children and Young Persons) Rules 1992 (S.I. 1992/2071 (L. 17));
(c)the Family Proceedings Rules (Northern Ireland) 1996 (S.R. (N.I.) 1996 No. 322);
(d)the Magistrates' Courts (Children (Northern Ireland) Order 1995) Rules (Northern Ireland) 1996 (S.R. (N. I.) 1996 No. 323);
(e)the Act of Sederunt (Child Care and Maintenance Rules) 1997 (S.I. 1997/291 (S. 19));
(f)the Sheriff Court Adoption Rules 2009;
(g)the Family Procedure Rules 2010 (S.I. 2010/2955 (L. 17));
(h)the Children's Hearings (Scotland) Act 2011 (Rules of Procedure in Children's Hearings) Rules 2013 (S.S.I. 2013/194).
Commencement Information
I74Sch. 3 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from the listed GDPR provisions: data subject's expectations and wishesU.K.
4(1)This paragraph applies where a request for data concerning health is made in exercise of a power conferred by an enactment or rule of law and—U.K.
(a)in relation to England and Wales or Northern Ireland, the data subject is an individual aged under 18 and the person making the request has parental responsibility for the data subject,
(b)in relation to Scotland, the data subject is an individual aged under 16 and the person making the request has parental responsibilities for the data subject, or
(c)the data subject is incapable of managing his or her own affairs and the person making the request has been appointed by a court to manage those affairs.
(2)The listed GDPR provisions do not apply to data concerning health to the extent that complying with the request would disclose information—
(a)which was provided by the data subject in the expectation that it would not be disclosed to the person making the request,
(b)which was obtained as a result of any examination or investigation to which the data subject consented in the expectation that the information would not be so disclosed, or
(c)which the data subject has expressly indicated should not be so disclosed.
(3)The exemptions under sub-paragraph (2)(a) and (b) do not apply if the data subject has expressly indicated that he or she no longer has the expectation mentioned there.
Commencement Information
I75Sch. 3 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from Article 15 of the GDPR: serious harmU.K.
5(1)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not apply to data concerning health to the extent that the serious harm test is met with respect to the data.U.K.
(2)A controller who is not a health professional may not rely on sub-paragraph (1) to withhold data concerning health unless the controller has obtained an opinion from the person who appears to the controller to be the appropriate health professional to the effect that the serious harm test is met with respect to the data.
(3)An opinion does not count for the purposes of sub-paragraph (2) if—
(a)it was obtained before the beginning of the relevant period, or
(b)it was obtained during that period but it is reasonable in all the circumstances to re-consult the appropriate health professional.
(4)In this paragraph, “the relevant period” means the period of 6 months ending with the day on which the opinion would be relied on.
Commencement Information
I76Sch. 3 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Restriction of Article 15 of the GDPR: prior opinion of appropriate health professionalU.K.
6(1)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not permit the disclosure of data concerning health by a controller who is not a health professional unless the controller has obtained an opinion from the person who appears to the controller to be the appropriate health professional to the effect that the serious harm test is not met with respect to the data.U.K.
(2)Sub-paragraph (1) does not apply to the extent that the controller is satisfied that the data concerning health has already been seen by, or is within the knowledge of, the data subject.
(3)An opinion does not count for the purposes of sub-paragraph (1) if—
(a)it was obtained before the beginning of the relevant period, or
(b)it was obtained during that period but it is reasonable in all the circumstances to re-consult the appropriate health professional.
(4)In this paragraph, “the relevant period” means the period of 6 months ending with the day on which the opinion would be relied on.
Commencement Information
I77Sch. 3 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 3 U.K.Social work data
DefinitionsU.K.
7(1)In this Part of this Schedule—U.K.
“education data” has the meaning given by paragraph 17 of this Schedule;
“Health and Social Care trust” means a Health and Social Care trust established under the Health and Personal Social Services (Northern Ireland) Order 1991 (S.I. 1991/194 (N.I. 1));
“Principal Reporter” means the Principal Reporter appointed under the Children's Hearings (Scotland) Act 2011 (asp 1), or an officer of the Scottish Children's Reporter Administration to whom there is delegated under paragraph 10(1) of Schedule 3 to that Act any function of the Principal Reporter;
“social work data” means personal data which—
(a)is data to which paragraph 8 applies, but
(b)is not education data or data concerning health.
(2)For the purposes of this Part of this Schedule, the “serious harm test” is met with respect to social work data if the application of Article 15 of the GDPR to the data would be likely to prejudice carrying out social work, because it would be likely to cause serious harm to the physical or mental health of the data subject or another individual.
(3)In sub-paragraph (2), “carrying out social work” is to be taken to include doing any of the following—
(a)the exercise of any functions mentioned in paragraph 8(1)(a), (d), (f) to (j), (m), (p), (s), (t), (u), (v) or (w);
(b)the provision of any service mentioned in paragraph 8(1)(b), (c) or (k);
(c)the exercise of the functions of a body mentioned in paragraph 8(1)(e) or a person mentioned in paragraph 8(1)(q) or (r).
(4)In this Part of this Schedule, a reference to a local authority, in relation to data processed or formerly processed by it, includes a reference to the Council of the Isles of Scilly, in relation to data processed or formerly processed by the Council in connection with any functions mentioned in paragraph 8(1)(a)(ii) which are or have been conferred on the Council by an enactment.
Commencement Information
I78Sch. 3 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
8(1)This paragraph applies to personal data falling within any of the following descriptions—U.K.
(a)data processed by a local authority—
(i)in connection with its social services functions (within the meaning of the Local Authority Social Services Act 1970 or the Social Services and Well-being (Wales) Act 2014 (anaw 4)) or any functions exercised by local authorities under the Social Work (Scotland) Act 1968 or referred to in section 5(1B) of that Act, or
(ii)in the exercise of other functions but obtained or consisting of information obtained in connection with any of the functions mentioned in sub-paragraph (i);
(b)data processed by the Regional Health and Social Care Board—
(i)in connection with the provision of social care within the meaning of section 2(5) of the Health and Social Care (Reform) Act (Northern Ireland) 2009 (c. 1 (N.I.)), or
(ii)in the exercise of other functions but obtained or consisting of information obtained in connection with the provision of that care;
(c)data processed by a Health and Social Care trust—
(i)in connection with the provision of social care within the meaning of section 2(5) of the Health and Social Care (Reform) Act (Northern Ireland) 2009 (c. 1 (N.I.)) on behalf of the Regional Health and Social Care Board by virtue of an authorisation made under Article 3(1) of the Health and Personal Social Services (Northern Ireland) Order 1994 (S.I. 1994/429 (N.I. 2)), or
(ii)in the exercise of other functions but obtained or consisting of information obtained in connection with the provision of that care;
(d)data processed by a council in the exercise of its functions under Part 2 of Schedule 9 to the Health and Social Services and Social Security Adjudications Act 1983;
(e)data processed by—
(i)a probation trust established under section 5 of the Offender Management Act 2007, or
(ii)the Probation Board for Northern Ireland established by the Probation Board (Northern Ireland) Order 1982 (S.I. 1982/713 (N.I. 10));
(f)data processed by a local authority in the exercise of its functions under section 36 of the Children Act 1989 or Chapter 2 of Part 6 of the Education Act 1996, so far as those functions relate to ensuring that children of compulsory school age (within the meaning of section 8 of the Education Act 1996) receive suitable education whether by attendance at school or otherwise;
(g)data processed by the Education Authority in the exercise of its functions under Article 55 of the Children (Northern Ireland) Order 1995 (S.I. 1995/755 (N.I. 2)) or Article 45 of, and Schedule 13 to, the Education and Libraries (Northern Ireland) Order 1986 (S.I. 1986/594 (N.I. 3)), so far as those functions relate to ensuring that children of compulsory school age (within the meaning of Article 46 of the Education and Libraries (Northern Ireland) Order 1986) receive efficient full-time education suitable to their age, ability and aptitude and to any special educational needs they may have, either by regular attendance at school or otherwise;
(h)data processed by an education authority in the exercise of its functions under sections 35 to 42 of the Education (Scotland) Act 1980 so far as those functions relate to ensuring that children of school age (within the meaning of section 31 of the Education (Scotland) Act 1980) receive efficient education suitable to their age, ability and aptitude, whether by attendance at school or otherwise;
(i)data relating to persons detained in a hospital at which high security psychiatric services are provided under section 4 of the National Health Service Act 2006 and processed by a Special Health Authority established under section 28 of that Act in the exercise of any functions similar to any social services functions of a local authority;
(j)data relating to persons detained in special accommodation provided under Article 110 of the Mental Health (Northern Ireland) Order 1986 (S.I. 1986/595 (N.I. 4)) and processed by a Health and Social Care trust in the exercise of any functions similar to any social services functions of a local authority;
(k)data which—
(i)is processed by the National Society for the Prevention of Cruelty to Children, or by any other voluntary organisation or other body designated under this paragraph by the Secretary of State or the Department of Health in Northern Ireland, and
(ii)appears to the Secretary of State or the Department, as the case may be, to be processed for the purposes of the provision of any service similar to a service provided in the exercise of any functions specified in paragraph (a), (b), (c) or (d);
(l)data processed by a body mentioned in sub-paragraph (2)—
(i)which was obtained, or consists of information which was obtained, from an authority or body mentioned in any of paragraphs (a) to (k) or from a government department, and
(ii)in the case of data obtained, or consisting of information obtained, from an authority or body mentioned in any of paragraphs (a) to (k), fell within any of those paragraphs while processed by the authority or body;
(m)data processed by a National Health Service trust first established under section 25 of the National Health Service Act 2006, section 18 of the National Health Service (Wales) Act 2006 or section 5 of the National Health Service and Community Care Act 1990 in the exercise of any functions similar to any social services functions of a local authority;
(n)data processed by an NHS foundation trust in the exercise of any functions similar to any social services functions of a local authority;
(o)data processed by a government department—
(i)which was obtained, or consists of information which was obtained, from an authority or body mentioned in any of paragraphs (a) to (n), and
(ii)which fell within any of those paragraphs while processed by that authority or body;
(p)data processed for the purposes of the functions of the Secretary of State pursuant to section 82(5) of the Children Act 1989;
(q)data processed by—
(i)a children's guardian appointed under Part 16 of the Family Procedure Rules 2010 (S.I. 2010/2955 (L. 17)),
(ii)a guardian ad litem appointed under Article 60 of the Children (Northern Ireland) Order 1995 (S.I. 1995/755 (N.I. 2)) or Article 66 of the Adoption (Northern Ireland) Order 1987 (S.I. 1987/2203 (N.I. 22)), or
(iii)a safeguarder appointed under section 30(2) or 31(3) of the Children's Hearings (Scotland) Act 2011 (asp 1);
(r)data processed by the Principal Reporter;
(s)data processed by an officer of the Children and Family Court Advisory and Support Service for the purpose of the officer's functions under section 7 of the Children Act 1989 or Part 16 of the Family Procedure Rules 2010 (S.I. 2010/2955 (L. 17));
(t)data processed by the Welsh family proceedings officer for the purposes of the functions under section 7 of the Children Act 1989 or Part 16 of the Family Procedure Rules 2010;
(u)data processed by an officer of the service appointed as guardian ad litem under Part 16 of the Family Procedure Rules 2010;
(v)data processed by the Children and Family Court Advisory and Support Service for the purpose of its functions under section 12(1) and (2) and section 13(1), (2) and (4) of the Criminal Justice and Court Services Act 2000;
(w)data processed by the Welsh Ministers for the purposes of their functions under section 35(1) and (2) and section 36(1), (2), (4), (5) and (6) of the Children Act 2004;
(x)data processed for the purposes of the functions of the appropriate Minister pursuant to section 12 of the Adoption and Children Act 2002 (independent review of determinations).
(2)The bodies referred to in sub-paragraph (1)(l) are—
(a)a National Health Service trust first established under section 25 of the National Health Service Act 2006 or section 18 of the National Health Service (Wales) Act 2006;
(b)a National Health Service trust first established under section 5 of the National Health Service and Community Care Act 1990;
(c)an NHS foundation trust;
(d)a clinical commissioning group established under section 14D of the National Health Service Act 2006;
(e)the National Health Service Commissioning Board;
(f)a Local Health Board established under section 11 of the National Health Service (Wales) Act 2006;
(g)a Health Board established under section 2 of the National Health Service (Scotland) Act 1978.
Modifications etc. (not altering text)
C7Sch. 3 para. 8(1)(o) modified by S.I. 1999/3145, art. 9(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 238 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
C8Sch. 3 para. 8(1)(o) modified by S.I. 1999/677, art. 7(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 237 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
C9Sch. 3 para. 8(1)(o) modified by S.I. 2007/1118, art. 5(1)(2) (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 324 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g))
Commencement Information
I79Sch. 3 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from the listed GDPR provisions: data processed by a courtU.K.
9(1)The listed GDPR provisions do not apply to data that is not education data or data concerning health if—U.K.
(a)it is processed by a court,
(b)it consists of information supplied in a report or other evidence given to the court in the course of proceedings to which rules listed in subparagraph (2) apply, and
(c)in accordance with any of those rules, the data may be withheld by the court in whole or in part from the data subject.
(2)Those rules are—
(a)the Magistrates' Courts (Children and Young Persons) Rules (Northern Ireland) 1969 (S.R. (N.I.) 1969 No. 221);
(b)the Magistrates' Courts (Children and Young Persons) Rules 1992 (S.I. 1992/2071 (L. 17));
(c)the Family Proceedings Rules (Northern Ireland) 1996 (S.R. (N.I.) 1996 No. 322);
(d)the Magistrates' Courts (Children (Northern Ireland) Order 1995) Rules (Northern Ireland) 1996 (S.R. (N. I.) 1996 No. 323);
(e)the Act of Sederunt (Child Care and Maintenance Rules) 1997 (S.I. 1997/291 (S. 19));
(f)the Sheriff Court Adoption Rules 2009;
(g)the Family Procedure Rules 2010 (S.I. 2010/2955 (L. 17));
(h)the Children's Hearings (Scotland) Act 2011 (Rules of Procedure in Children's Hearings) Rules 2013 (S.S.I. 2013/194).
Commencement Information
I80Sch. 3 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from the listed GDPR provisions: data subject's expectations and wishesU.K.
10(1)This paragraph applies where a request for social work data is made in exercise of a power conferred by an enactment or rule of law and—U.K.
(a)in relation to England and Wales or Northern Ireland, the data subject is an individual aged under 18 and the person making the request has parental responsibility for the data subject,
(b)in relation to Scotland, the data subject is an individual aged under 16 and the person making the request has parental responsibilities for the data subject, or
(c)the data subject is incapable of managing his or her own affairs and the person making the request has been appointed by a court to manage those affairs.
(2)The listed GDPR provisions do not apply to social work data to the extent that complying with the request would disclose information—
(a)which was provided by the data subject in the expectation that it would not be disclosed to the person making the request,
(b)which was obtained as a result of any examination or investigation to which the data subject consented in the expectation that the information would not be so disclosed, or
(c)which the data subject has expressly indicated should not be so disclosed.
(3)The exemptions under sub-paragraph (2)(a) and (b) do not apply if the data subject has expressly indicated that he or she no longer has the expectation mentioned there.
Commencement Information
I81Sch. 3 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from Article 15 of the GDPR: serious harmU.K.
11U.K.Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not apply to social work data to the extent that the serious harm test is met with respect to the data.
Commencement Information
I82Sch. 3 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Restriction of Article 15 of the GDPR: prior opinion of Principal ReporterU.K.
12(1)This paragraph applies where—U.K.
(a)a question arises as to whether a controller who is a social work authority is obliged by Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) to disclose social work data, and
(b)the data—
(i)originated from or was supplied by the Principal Reporter acting in pursuance of the Principal Reporter's statutory duties, and
(ii)is not data which the data subject is entitled to receive from the Principal Reporter.
(2)The controller must inform the Principal Reporter of the fact that the question has arisen before the end of the period of 14 days beginning when the question arises.
(3)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not permit the controller to disclose the data to the data subject unless the Principal Reporter has informed the controller that, in the opinion of the Principal Reporter, the serious harm test is not met with respect to the data.
(4)In this paragraph “social work authority” means a local authority for the purposes of the Social Work (Scotland) Act 1968.
Commencement Information
I83Sch. 3 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 4 U.K.Education data
Educational recordsU.K.
13U.K.In this Part of this Schedule “educational record” means a record to which paragraph 14, 15 or 16 applies.
Commencement Information
I84Sch. 3 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
14(1)This paragraph applies to a record of information which—U.K.
(a)is processed by or on behalf of the proprietor of, or a teacher at, a school in England and Wales specified in sub-paragraph (3),
(b)relates to an individual who is or has been a pupil at the school, and
(c)originated from, or was supplied by or on behalf of, any of the persons specified in sub-paragraph (4).
(2)But this paragraph does not apply to information which is processed by a teacher solely for the teacher's own use.
(3)The schools referred to in sub-paragraph (1)(a) are—
(a)a school maintained by a local authority;
(b)an Academy school;
(c)an alternative provision Academy;
(d)an independent school that is not an Academy school or an alternative provision Academy;
(e)a non-maintained special school.
(4)The persons referred to in sub-paragraph (1)(c) are—
(a)an employee of the local authority which maintains the school;
(b)in the case of—
(i)a voluntary aided, foundation or foundation special school (within the meaning of the School Standards and Framework Act 1998),
(ii)an Academy school,
(iii)an alternative provision Academy,
(iv)an independent school that is not an Academy school or an alternative provision Academy, or
(v)a non-maintained special school,
a teacher or other employee at the school (including an educational psychologist engaged by the proprietor under a contract for services);
(c)the pupil to whom the record relates;
(d)a parent, as defined by section 576(1) of the Education Act 1996, of that pupil.
(5)In this paragraph—
“independent school” has the meaning given by section 463 of the Education Act 1996;
“local authority” has the same meaning as in that Act (see sections 579(1) and 581 of that Act);
“non-maintained special school” has the meaning given by section 337A of that Act;
“proprietor” has the meaning given by section 579(1) of that Act.
Commencement Information
I85Sch. 3 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
15(1)This paragraph applies to a record of information which is processed—U.K.
(a)by an education authority in Scotland, and
(b)for the purpose of the relevant function of the authority.
(2)But this paragraph does not apply to information which is processed by a teacher solely for the teacher's own use.
(3)For the purposes of this paragraph, information processed by an education authority is processed for the purpose of the relevant function of the authority if the processing relates to the discharge of that function in respect of a person—
(a)who is or has been a pupil in a school provided by the authority, or
(b)who receives, or has received, further education provided by the authority.
(4)In this paragraph “the relevant function” means, in relation to each education authority, its function under section 1 of the Education (Scotland) Act 1980 and section 7(1) of the Self-Governing Schools etc. (Scotland) Act 1989.
Commencement Information
I86Sch. 3 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
16(1)This paragraph applies to a record of information which—U.K.
(a)is processed by or on behalf of the Board of Governors, proprietor or trustees of, or a teacher at, a school in Northern Ireland specified in sub-paragraph (3),
(b)relates to an individual who is or has been a pupil at the school, and
(c)originated from, or was supplied by or on behalf of, any of the persons specified in sub-paragraph (4).
(2)But this paragraph does not apply to information which is processed by a teacher solely for the teacher's own use.
(3)The schools referred to in sub-paragraph (1)(a) are—
(a)a grant-aided school;
(b)an independent school.
(4)The persons referred to in sub-paragraph (1)(c) are—
(a)a teacher at the school;
(b)an employee of the Education Authority, other than a teacher at the school;
(c)an employee of the Council for Catholic Maintained Schools, other than a teacher at the school;
(d)the pupil to whom the record relates;
(e)a parent, as defined by Article 2(2) of the Education and Libraries (Northern Ireland) Order 1986 (S.I. 1986/594 (N.I. 3)).
(5)In this paragraph, “grant-aided school”, “independent school”, “proprietor” and “trustees” have the same meaning as in the Education and Libraries (Northern Ireland) Order 1986 (S.I. 1986/594 (N.I. 3)).
Commencement Information
I87Sch. 3 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Other definitionsU.K.
17(1)In this Part of this Schedule—U.K.
“education authority” and “further education” have the same meaning as in the Education (Scotland) Act 1980;
“education data” means personal data consisting of information which—
(a)constitutes an educational record, but
(b)is not data concerning health;
“Principal Reporter” means the Principal Reporter appointed under the Children's Hearings (Scotland) Act 2011 (asp 1), or an officer of the Scottish Children's Reporter Administration to whom there is delegated under paragraph 10(1) of Schedule 3 to that Act any function of the Principal Reporter;
“pupil” means—
(a)in relation to a school in England and Wales, a registered pupil within the meaning of the Education Act 1996,
(b)in relation to a school in Scotland, a pupil within the meaning of the Education (Scotland) Act 1980, and
(c)in relation to a school in Northern Ireland, a registered pupil within the meaning of the Education and Libraries (Northern Ireland) Order 1986 (S.I. 1986/594 (N.I. 3));
“school”—
(a)in relation to England and Wales, has the same meaning as in the Education Act 1996,
(b)in relation to Scotland, has the same meaning as in the Education (Scotland) Act 1980, and
(c)in relation to Northern Ireland, has the same meaning as in the Education and Libraries (Northern Ireland) Order 1986;
“teacher” includes—
(a)in Great Britain, head teacher, and
(b)in Northern Ireland, the principal of a school.
(2)For the purposes of this Part of this Schedule, the “serious harm test” is met with respect to education data if the application of Article 15 of the GDPR to the data would be likely to cause serious harm to the physical or mental health of the data subject or another individual.
Commencement Information
I88Sch. 3 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from the listed GDPR provisions: data processed by a courtU.K.
18(1)The listed GDPR provisions do not apply to education data if—U.K.
(a)it is processed by a court,
(b)it consists of information supplied in a report or other evidence given to the court in the course of proceedings to which rules listed in subparagraph (2) apply, and
(c)in accordance with those rules, the data may be withheld by the court in whole or in part from the data subject.
(2)Those rules are—
(a)the Magistrates' Courts (Children and Young Persons) Rules (Northern Ireland) 1969 (S.R. (N.I.) 1969 No. 221);
(b)the Magistrates' Courts (Children and Young Persons) Rules 1992 (S.I. 1992/2071 (L. 17));
(c)the Family Proceedings Rules (Northern Ireland) 1996 (S.R. (N.I.) 1996 No. 322);
(d)the Magistrates' Courts (Children (Northern Ireland) Order 1995) Rules (Northern Ireland) 1996 (S.R. (N. I.) 1996 No. 323);
(e)the Act of Sederunt (Child Care and Maintenance Rules) 1997 (S.I. 1997/291 (S. 19));
(f)the Sheriff Court Adoption Rules 2009;
(g)the Family Procedure Rules 2010 (S.I. 2010/2955 (L. 17));
(h)the Children's Hearings (Scotland) Act 2011 (Rules of Procedure in Children's Hearings) Rules 2013 (S.S.I. 2013/194).
Commencement Information
I89Sch. 3 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Exemption from Article 15 of the GDPR: serious harmU.K.
19U.K.Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not apply to education data to the extent that the serious harm test is met with respect to the data.
Commencement Information
I90Sch. 3 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Restriction of Article 15 of the GDPR: prior opinion of Principal ReporterU.K.
20(1)This paragraph applies where—U.K.
(a)a question arises as to whether a controller who is an education authority is obliged by Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) to disclose education data, and
(b)the controller believes that the data—
(i)originated from or was supplied by or on behalf of the Principal Reporter acting in pursuance of the Principal Reporter's statutory duties, and
(ii)is not data which the data subject is entitled to receive from the Principal Reporter.
(2)The controller must inform the Principal Reporter of the fact that the question has arisen before the end of the period of 14 days beginning when the question arises.
(3)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not permit the controller to disclose the data to the data subject unless the Principal Reporter has informed the controller that, in the opinion of the Principal Reporter, the serious harm test is not met with respect to the data.
Commencement Information
I91Sch. 3 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 5 U.K.Child abuse data
Exemption from Article 15 of the GDPR: child abuse dataU.K.
21(1)This paragraph applies where a request for child abuse data is made in exercise of a power conferred by an enactment or rule of law and—U.K.
(a)the data subject is an individual aged under 18 and the person making the request has parental responsibility for the data subject, or
(b)the data subject is incapable of managing his or her own affairs and the person making the request has been appointed by a court to manage those affairs.
(2)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) do not apply to child abuse data to the extent that the application of that provision would not be in the best interests of the data subject.
(3)“Child abuse data” is personal data consisting of information as to whether the data subject is or has been the subject of, or may be at risk of, child abuse.
(4)For this purpose, “child abuse” includes physical injury (other than accidental injury) to, and physical and emotional neglect, ill-treatment and sexual abuse of, an individual aged under 18.
(5)This paragraph does not apply in relation to Scotland.
Commencement Information
I92Sch. 3 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 15
SCHEDULE 4U.K.Exemptions etc from the GDPR: disclosure prohibited or restricted by an enactment
GDPR provisions to be restricted: “the listed GDPR provisions”U.K.
1U.K.In this Schedule “the listed GDPR provisions” means the following provisions of the GDPR (the rights and obligations in which may be restricted by virtue of Article 23(1) of the GDPR)—
(a)Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers);
(b)Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in Article 15(1) to (3).
Commencement Information
I93Sch. 4 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Human fertilisation and embryology informationU.K.
2U.K.The listed GDPR provisions do not apply to personal data consisting of information the disclosure of which is prohibited or restricted by any of sections 31, 31ZA to 31ZE and 33A to 33D of the Human Fertilisation and Embryology Act 1990.
Commencement Information
I94Sch. 4 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Adoption records and reportsU.K.
3(1)The listed GDPR provisions do not apply to personal data consisting of information the disclosure of which is prohibited or restricted by an enactment listed in sub-paragraph (2), (3) or (4).U.K.
(2)The enactments extending to England and Wales are—
(a)regulation 14 of the Adoption Agencies Regulations 1983 (S.I. 1983/1964);
(b)regulation 41 of the Adoption Agencies Regulations 2005 (S.I. 2005/389);
(c)regulation 42 of the Adoption Agencies (Wales) Regulations 2005 (S.I. 2005/1313 (W. 95));
(d)rules 5, 6, 9, 17, 18, 21, 22 and 53 of the Adoption Rules 1984 (S.I. 1984/265);
(e)rules 24, 29, 30, 65, 72, 73, 77, 78 and 83 of the Family Procedure (Adoption) Rules 2005 (S.I. 2005/2795 (L. 22));
(f)in the Family Procedure Rules 2010 (S.I. 2010/2955 (L. 17)), rules 14.6, 14.11, 14.12, 14.13, 14.14, 14.24, 16.20 (so far as it applies to a children's guardian appointed in proceedings to which Part 14 of those Rules applies), 16.32 and 16.33 (so far as it applies to a children and family reporter in proceedings to which Part 14 of those Rules applies).
(3)The enactments extending to Scotland are—
(a)regulation 23 of the Adoption Agencies (Scotland) Regulations 1996 (S.I. 1996/3266 (S. 254));
(b)rule 67.3 of the Act of Sederunt (Rules of the Court of Session 1994) 1994 (S.I. 1994/1443 (S. 69));
(c)rules 10.3, 17.2, 21, 25, 39, 43.3, 46.2 and 47 of the Act of Sederunt (Sheriff Court Rules Amendment) (Adoption and Children (Scotland) Act 2007) 2009 (S.S.I. 2009/284);
(d)sections 53 and 55 of the Adoption and Children (Scotland) Act 2007 (asp 4);
(e)regulation 28 of the Adoption Agencies (Scotland) Regulations 2009 (S.S.I. 2009/154);
(f)regulation 3 of the Adoption (Disclosure of Information and Medical Information about Natural Parents) (Scotland) Regulations 2009 (S.S.I. 2009/268).
(4)The enactments extending to Northern Ireland are—
(a)Articles 50 and 54 of the Adoption (Northern Ireland) Order 1987 (S.I. 1987/2203 (N.I. 22));
(b)rule 53 of Order 84 of the Rules of the Court of Judicature (Northern Ireland) 1980 (S.R. (N.I.) 1980 No. 346);
(c)rules 4A.4(5), 4A.5(1), 4A.6(6), 4A.22(5) and 4C.7 of Part IVA of the Family Proceedings Rules (Northern Ireland) 1996 (S.R. (N.I.) 1996 No. 322).
Commencement Information
I95Sch. 4 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Statements of special educational needsU.K.
4(1)The listed GDPR provisions do not apply to personal data consisting of information the disclosure of which is prohibited or restricted by an enactment listed in sub-paragraph (2).U.K.
(2)The enactments are—
(a)regulation 17 of the Special Educational Needs and Disability Regulations 2014 (S.I. 2014/1530);
(b)regulation 10 of the Additional Support for Learning (Co-ordinated Support Plan) (Scotland) Amendment Regulations 2005 (S.S.I. 2005/518);
(c)regulation 22 of the Education (Special Educational Needs) Regulations (Northern Ireland) 2005 (S.R. (N.I.) 2005 No. 384).
Commencement Information
I96Sch. 4 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Parental order records and reportsU.K.
5(1)The listed GDPR provisions do not apply to personal data consisting of information the disclosure of which is prohibited or restricted by an enactment listed in sub-paragraph (2), (3) or (4).U.K.
(2)The enactments extending to England and Wales are—
(a)sections 60, 77, 78 and 79 of the Adoption and Children Act 2002, as applied with modifications by regulation 2 of and Schedule 1 to the Human Fertilisation and Embryology (Parental Orders) Regulations 2010 (S.I. 2010/985) in relation to parental orders made under—
(i)section 30 of the Human Fertilisation and Embryology Act 1990, or
(ii)section 54 of the Human Fertilisation and Embryology Act 2008;
(b)rules made under section 144 of the Magistrates' Courts Act 1980 by virtue of section 141(1) of the Adoption and Children Act 2002, as applied with modifications by regulation 2 of and Schedule 1 to the Human Fertilisation and Embryology (Parental Orders) Regulations 2010, so far as the rules relate to—
(i)the appointment and duties of the parental order reporter, and
(ii)the keeping of registers and the custody, inspection and disclosure of documents and information relating to parental order proceedings or related proceedings;
(c)rules made under section 75 of the Courts Act 2003 by virtue of section 141(1) of the Adoption and Children Act 2002, as applied with modifications by regulation 2 of Schedule 1 to the Human Fertilisation and Embryology (Parental Orders) Regulations 2010 (S.I. 2010/985), so far as the rules relate to—
(i)the appointment and duties of the parental order reporter, and
(ii)the keeping of registers and the custody, inspection and disclosure of documents and information relating to parental order proceedings or related proceedings.
(3)The enactments extending to Scotland are—
(a)sections 53 and 55 of the Adoption and Children (Scotland) Act 2007 (asp 4), as applied with modifications by regulation 4 of and Schedule 3 to the Human Fertilisation and Embryology (Parental Orders) Regulations 2010 (S.I. 2010/985) in relation to parental orders made under—
(i)section 30 of the Human Fertilisation and Embryology Act 1990, or
(ii)section 54 of the Human Fertilisation and Embryology Act 2008;
(b)rules 2.47 and 2.59 of the Act of Sederunt (Child Care and Maintenance Rules) 1997 (S.I. 1997/291 (S. 19));
(c)rules 21 and 25 of the Sheriff Court Adoption Rules 2009.
(4)The enactments extending to Northern Ireland are—
(a)Articles 50 and 54 of the Adoption (Northern Ireland) Order 1987 (S.I. 1987/2203 (N.I. 22)), as applied with modifications by regulation 3 of and Schedule 2 to the Human Fertilisation and Embryology (Parental Orders) Regulations 2010 in respect of parental orders made under—
(i)section 30 of the Human Fertilisation and Embryology Act 1990, or
(ii)section 54 of the Human Fertilisation and Embryology Act 2008;
(b)rules 4, 5 and 16 of Order 84A of the Rules of the Court of Judicature (Northern Ireland) 1980 (S.R. (N.I.) 1980 No. 346);
(c)rules 3, 4 and 15 of Order 50A of the County Court Rules (Northern Ireland) 1981 (S.R. (N.I.) 1981 No. 225).
Commencement Information
I97Sch. 4 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Information provided by Principal Reporter for children's hearingU.K.
6U.K.The listed GDPR provisions do not apply to personal data consisting of information the disclosure of which is prohibited or restricted by any of the following enactments—
(a)section 178 of the Children's Hearings (Scotland) Act 2011 (asp 1);
(b)the Children's Hearings (Scotland) Act 2011 (Rules of Procedure in Children's Hearings) Rules 2013 (S.S.I. 2013/194).
Commencement Information
I98Sch. 4 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 17
SCHEDULE 5U.K.Accreditation of certification providers: reviews and appeals
IntroductionU.K.
1(1)This Schedule applies where—U.K.
(a)a person (“the applicant”) applies to an accreditation authority for accreditation as a certification provider, and
(b)is dissatisfied with the decision on that application.
(2)In this Schedule—
“accreditation authority” means—
(a)the Commissioner, or
(b)the national accreditation body;
“certification provider” and “national accreditation body” have the same meaning as in section 17.
Commencement Information
I99Sch. 5 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
ReviewU.K.
2(1)The applicant may ask the accreditation authority to review the decision.U.K.
(2)The request must be made in writing before the end of the period of 28 days beginning with the day on which the person receives written notice of the accreditation authority's decision.
(3)The request must specify—
(a)the decision to be reviewed, and
(b)the reasons for asking for the review.
(4)The request may be accompanied by additional documents which the applicant wants the accreditation authority to take into account for the purposes of the review.
(5)If the applicant makes a request in accordance with sub-paragraphs (1) to (4), the accreditation authority must—
(a)review the decision, and
(b)inform the applicant of the outcome of the review in writing before the end of the period of 28 days beginning with the day on which the request for a review is received.
Commencement Information
I100Sch. 5 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Right to appealU.K.
3(1)If the applicant is dissatisfied with the decision on the review under paragraph 2, the applicant may ask the accreditation authority to refer the decision to an appeal panel constituted in accordance with paragraph 4.U.K.
(2)The request must be made in writing before the end of the period of 3 months beginning with the day on which the person receives written notice of the decision on the review.
(3)A request must specify—
(a)the decision to be referred to the appeal panel, and
(b)the reasons for asking for it to be referred.
(4)The request may be accompanied by additional documents which the applicant wants the appeal panel to take into account.
(5)The applicant may discontinue an appeal at any time by giving notice in writing to the accreditation authority.
Commencement Information
I101Sch. 5 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Appeal panelU.K.
4(1)If the applicant makes a request in accordance with paragraph 3, an appeal panel must be established in accordance with this paragraph.U.K.
(2)An appeal panel must consist of a chair and at least two other members.
(3)Where the request relates to a decision of the Commissioner—
(a)the Secretary of State may appoint one person to be a member of the appeal panel other than the chair, and
(b)subject to paragraph (a), the Commissioner must appoint the members of the appeal panel.
(4)Where the request relates to a decision of the national accreditation body—
(a)the Secretary of State—
(i)may appoint one person to be a member of the appeal panel other than the chair, or
(ii)may direct the Commissioner to appoint one person to be a member of the appeal panel other than the chair, and
(b)subject to paragraph (a), the chair of the national accreditation body must appoint the members of the appeal panel.
(5)A person may not be a member of an appeal panel if the person—
(a)has a commercial interest in the decision referred to the panel,
(b)has had any prior involvement in any matters relating to the decision, or
(c)is an employee or officer of the accreditation authority.
(6)The Commissioner may not be a member of an appeal panel to which a decision of the Commissioner is referred.
(7)The applicant may object to all or any of the members of the appeal panel appointed under sub-paragraph (3) or (4).
(8)If the applicant objects to a member of the appeal panel under sub-paragraph (7), the person who appointed that member must appoint a replacement.
(9)The applicant may not object to a member of the appeal panel appointed under sub-paragraph (8).
Commencement Information
I102Sch. 5 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
HearingU.K.
5(1)If the appeal panel considers it necessary, a hearing must be held at which both the applicant and the accreditation authority may be represented.U.K.
(2)Any additional documents which the applicant or the accreditation authority want the appeal panel to take into account must be submitted to the chair of the appeal panel at least 5 working days before the hearing.
(3)The appeal panel may allow experts and witnesses to give evidence at a hearing.
Commencement Information
I103Sch. 5 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Decision following referral to appeal panelU.K.
6(1)The appeal panel must, before the end of the period of 28 days beginning with the day on which the appeal panel is established in accordance with paragraph 4—U.K.
(a)make a reasoned recommendation in writing to the accreditation authority, and
(b)give a copy of the recommendation to the applicant.
(2)For the purposes of sub-paragraph (1), where there is an objection under paragraph 4(7), an appeal panel is not to be taken to be established in accordance with paragraph 4 until the replacement member is appointed (or, if there is more than one objection, until the last replacement member is appointed).
(3)The accreditation authority must, before the end of the period of 3 working days beginning with the day on which the authority receives the recommendation—
(a)make a reasoned final decision in writing, and
(b)give a copy of the decision to the applicant.
(4)Where the accreditation authority is the national accreditation body, the recommendation must be given to, and the final decision must be made by, the chief executive of that body.
Commencement Information
I104Sch. 5 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Meaning of “working day”U.K.
7U.K.In this Schedule, “working day” means any day other than—
(a)Saturday or Sunday,
(b)Christmas Day or Good Friday, or
(c)a day which is a bank holiday under the Banking and Financial Dealings Act 1971 in any part of the United Kingdom.
Commencement Information
I105Sch. 5 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 22
SCHEDULE 6U.K.The applied GDPR and the applied Chapter 2
PART 1 U.K.Modifications to the GDPR
IntroductoryU.K.
1U.K.In its application by virtue of section 22(1), the GDPR has effect as if it were modified as follows.
Commencement Information
I106Sch. 6 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
References to the GDPR and its provisionsU.K.
2(1)References to “this Regulation” and to provisions of the GDPR have effect as references to the applied GDPR and to the provisions of the applied GDPR.U.K.
(2)But sub-paragraph (1) does not have effect—
(a)in the case of the references which are modified or inserted by paragraphs 9(f)(ii), 15(b), 16(a)(ii), 35, 36(a) and (e)(ii) and 38(a)(i);
(b)in relation to the references in points (a) and (b) of paragraph 2 of Article 61, as inserted by paragraph 49.
Commencement Information
I107Sch. 6 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
References to Union law and Member State lawU.K.
3(1)References to “Union law”, “Member State law”, “the law of a Member State” and “Union or Member State law” have effect as references to domestic law.U.K.
(2)Sub-paragraph (1) is subject to the specific modifications made in this Part of this Schedule.
(3)In this paragraph, “domestic law” means the law of the United Kingdom, or of a part of the United Kingdom, and includes law in the form of an enactment, an instrument made under Her Majesty's prerogative or a rule of law.
Commencement Information
I108Sch. 6 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
References to the Union and to Member StatesU.K.
4(1)References to “the Union”, “a Member State” and “Member States” have effect as references to the United Kingdom.U.K.
(2)Sub-paragraph (1) is subject to the specific modifications made in this Part of this Schedule (including paragraph 3(1)).
Commencement Information
I109Sch. 6 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
References to supervisory authoritiesU.K.
5(1)References to a “supervisory authority”, a “competent supervisory authority” or “supervisory authorities”, however expressed, have effect as references to the Commissioner.U.K.
(2)Sub-paragraph (1) does not apply to the references in—
(a)Article 4(21) as modified by paragraph 9(f);
(b)Article 57(1)(h);
(c)Article 61(1) inserted by paragraph 49.
(3)Sub-paragraph (1) is also subject to the specific modifications made in this Part of this Schedule.
Commencement Information
I110Sch. 6 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
References to the national parliamentU.K.
6U.K.References to “the national parliament” have effect as references to both Houses of Parliament.
Commencement Information
I111Sch. 6 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter I of the GDPR (general provisions)U.K.
7U.K.For Article 2 (material scope) substitute—
“2This Regulation applies to the processing of personal data to which Chapter 3 of Part 2 of the 2018 Act applies (see section 21 of that Act).”
Commencement Information
I112Sch. 6 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
8U.K.For Article 3 substitute—
“Article 3U.K.Territorial application
Subsections (1), (2) and (7) of section 207 of the 2018 Act have effect for the purposes of this Regulation as they have effect for the purposes of that Act but as if the following were omitted—
(a)in subsection (1), the reference to subsection (3), and
(b)in subsection (7), the words following paragraph (d).”
Commencement Information
I113Sch. 6 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
9U.K.In Article 4 (definitions)—
(a)in paragraph (7) (meaning of “controller”), for “; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law” substitute “ , subject to section 6 of the 2018 Act (meaning of “controller”) ”;
(b)after paragraph (7) insert—
“(7A)“the 2018 Act” means the Data Protection Act 2018 as applied by section 22 of that Act and further modified by section 3 of that Act.”;
(c)omit paragraph (16) (meaning of “main establishment”);
(d)omit paragraph (17) (meaning of “representative”);
(e)in paragraph (20) (meaning of “binding corporate rules”), for “on the territory of a Member State” substitute “ in the United Kingdom ”;
(f)in paragraph (21) (meaning of “supervisory authority”)—
(i)after “a Member State” insert “ (other than the United Kingdom) ”;
(ii)for “Article 51” substitute “ Article 51 of the GDPR ”;
(g)after paragraph (21) insert—
“(21A)“the Commissioner” means the Information Commissioner (see section 114 of the 2018 Act);”;
(h)omit paragraph (22) (meaning of “supervisory authority concerned”);
(i)omit paragraph (23) (meaning of “cross-border processing”);
(j)omit paragraph (24) (meaning of “relevant and reasoned objection”);
(k)after paragraph (26) insert—
“(27)“the GDPR” has the meaning given in section 3(10) of the 2018 Act.
(28)“domestic law” has the meaning given in paragraph 3(3) of Schedule 6 to the 2018 Act.”
Commencement Information
I114Sch. 6 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter II of the GDPR (principles)U.K.
10U.K.In Article 6 (lawfulness of processing)—
(a)omit paragraph 2;
(b)in paragraph 3, for the first subparagraph substitute—
“In addition to the provision made in section 15 of and Part 1 of Schedule 2 to the 2018 Act, a legal basis for the processing referred to in point (c) and (e) of paragraph 1 may be laid down by the Secretary of State in regulations (see section 16 of the 2018 Act).”;
(c)in paragraph 3, in the second subparagraph, for “The Union or the Member State law shall” substitute “ The regulations must ”.
Commencement Information
I115Sch. 6 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
11U.K.In Article 8 (conditions applicable to child's consent in relation to information society services)—
(a)in paragraph 1, for the second subparagraph substitute—
“This paragraph is subject to section 9 of the 2018 Act.”;
(b)in paragraph 3, for “the general contract law of Member States” substitute “ the general law of contract as it operates in domestic law ”.
Commencement Information
I116Sch. 6 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
12U.K.In Article 9 (processing of special categories of personal data)—
(a)in paragraph 2(a), omit “, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject”;
(b)in paragraph 2(b), for “Union or Member State law” substitute “ domestic law (see section 10 of the 2018 Act) ”;
(c)in paragraph 2, for point (g) substitute—
“(g)processing is necessary for reasons of substantial public interest and is authorised by domestic law (see section 10 of the 2018 Act);”;
(d)in paragraph 2(h), for “Union or Member State law” substitute “ domestic law (see section 10 of the 2018 Act) ”;
(e)in paragraph 2(i), for “Union or Member State law” insert “ domestic law (see section 10 of the 2018 Act); ”;
(f)in paragraph 2, for point (j) substitute—
“(j)processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) (as supplemented by section 19 of the 2018 Act) and is authorised by domestic law (see section 10 of that Act).”;
(g)in paragraph 3, for “national competent bodies”, in both places, substitute “ a national competent body of the United Kingdom ”;
(h)omit paragraph 4.
Commencement Information
I117Sch. 6 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
13U.K.In Article 10 (processing of personal data relating to criminal convictions and offences), in the first sentence, for “Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects” substitute “ domestic law (see section 10 of the 2018 Act) ”.
Commencement Information
I118Sch. 6 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 1 of Chapter III of the GDPR (rights of the data subject: transparency and modalities)U.K.
14U.K.In Article 12 (transparent information etc for the exercise of the rights of the data subject), omit paragraph 8.
Commencement Information
I119Sch. 6 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 2 of Chapter III of the GDPR (rights of the data subject: information and access to personal data)U.K.
15U.K.In Article 13 (personal data collected from data subject: information to be provided), in paragraph 1—
(a)in point (a), omit “and, where applicable, of the controller's representative”;
(b)in point (f), after “the Commission” insert “ pursuant to Article 45(3) of the GDPR ”.
Commencement Information
I120Sch. 6 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
16U.K.In Article 14 (personal data collected other than from data subject: information to be provided)—
(a)in paragraph 1—
(i)in point (a), omit “and, where applicable, of the controller's representative”;
(ii)in point (f), after “the Commission” insert “ pursuant to Article 45(3) of the GDPR ”;
(b)in paragraph 5(c), for “Union or Member State law to which the controller is subject” substitute “ a rule of domestic law ”.
Commencement Information
I121Sch. 6 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 3 of Chapter III of the GDPR (rights of the data subject: rectification and erasure)U.K.
17U.K.In Article 17 (right to erasure (‘right to be forgotten’))—
(a)in paragraph 1(e), for “in Union or Member State law to which the controller is subject” substitute “ under domestic law ”;
(b)in paragraph 3(b), for “by Union or Member State law to which the controller is subject” substitute “ under domestic law ”.
Commencement Information
I122Sch. 6 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
18U.K.In Article 18 (right to restriction of processing), in paragraph 2, for “of the Union or of a Member State” substitute “ of the United Kingdom ”.
Commencement Information
I123Sch. 6 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 4 of Chapter III of the GDPR (rights of the data subject: right to object and automated individual decision-making)U.K.
19U.K.In Article 21 (right to object), in paragraph 5, omit “, and notwithstanding Directive 2002/58/EC,”.
Commencement Information
I124Sch. 6 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
20U.K.In Article 22 (automated individual decision-making, including profiling), for paragraph 2(b) substitute—
“(b)is a qualifying significant decision for the purposes of section 14 of the 2018 Act; or”.
Commencement Information
I125Sch. 6 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 5 of Chapter III of the GDPR (rights of the data subject: restrictions)U.K.
21U.K.In Article 23 (restrictions), in paragraph 1—
(a)for “Union or Member State law to which the data controller or processor is subject” substitute “ In addition to the provision made by section 15 of and Schedules 2, 3 and 4 to the 2018 Act, the Secretary of State ”;
(b)in point (e), for “of the Union or of a Member State”, in both places, substitute “ of the United Kingdom ”;
(c)after point (j) insert—
“See section 16 of the 2018 Act.”
Commencement Information
I126Sch. 6 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 1 of Chapter IV of the GDPR (controller and processor: general obligations)U.K.
22U.K.In Article 26 (joint controllers), in paragraph 1, for “Union or Member State law to which the controllers are subject” substitute “ domestic law ”.
Commencement Information
I127Sch. 6 para. 22 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
23U.K.Omit Article 27 (representatives of controllers or processors not established in the Union).
Commencement Information
I128Sch. 6 para. 23 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
24U.K.In Article 28 (processor)—
(a)in paragraph 3, in point (a), for “Union or Member State law to which the processor is subject” substitute “ domestic law ”;
(b)in paragraph 3, in the second subparagraph, for “other Union or Member State data protection provisions” substitute “ any other rule of domestic law relating to data protection ”;
(c)in paragraph 6, for “paragraphs 7 and 8” substitute “ paragraph 8 ”;
(d)omit paragraph 7;
(e)in paragraph 8, omit “and in accordance with the consistency mechanism referred to in Article 63”.
Commencement Information
I129Sch. 6 para. 24 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
25U.K.In Article 30 (records of processing activities)—
(a)in paragraph 1, in the first sentence, omit “and, where applicable, the controller's representative,”;
(b)in paragraph 1, in point (a), omit “, the controller's representative”;
(c)in paragraph 1, in point (g), after “32(1)” insert “ or section 28(3) of the 2018 Act ”;
(d)in paragraph 2, in the first sentence, omit “and, where applicable, the processor's representative”;
(e)in paragraph 2, in point (a), omit “the controller's or the processor's representative, and”;
(f)in paragraph 2, in point (d), after “32(1)” insert “ or section 28(3) of the 2018 Act ”;
(g)in paragraph 4, omit “and, where applicable, the controller's or the processor's representative,”.
Commencement Information
I130Sch. 6 para. 25 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
26U.K.In Article 31 (co-operation with the supervisory authority), omit “and, where applicable, their representatives,”.
Commencement Information
I131Sch. 6 para. 26 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 3 of Chapter IV of the GDPR (controller and processor: data protection impact assessment and prior consultation)U.K.
27U.K.In Article 35 (data protection impact assessment), omit paragraphs 4, 5, 6 and 10.
Commencement Information
I132Sch. 6 para. 27 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
28U.K.In Article 36 (prior consultation)—
(a)for paragraph 4 substitute—
“4The Secretary of State must consult the Commissioner during the preparation of any proposal for a legislative measure which relates to processing.”;
(b)omit paragraph 5.
Commencement Information
I133Sch. 6 para. 28 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 4 of Chapter IV of the GDPR (controller and processor: data protection officer)U.K.
29U.K.In Article 37 (designation of data protection officers), omit paragraph 4.
Commencement Information
I134Sch. 6 para. 29 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
30U.K.In Article 39 (tasks of the data protection officer), in paragraph 1(a) and (b), for “other Union or Member State data protection provisions” substitute “ other rules of domestic law relating to data protection ”.
Commencement Information
I135Sch. 6 para. 30 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 5 of Chapter IV of the GDPR (controller and processor: codes of conduct and certification)U.K.
31U.K.In Article 40 (codes of conduct)—
(a)in paragraph 1, for “The Member States, the supervisory authorities, the Board and the Commission shall” substitute “ The Commissioner must ”;
(b)omit paragraph 3;
(c)in paragraph 6, omit “, and where the code of conduct concerned does not relate to processing activities in several Member States”;
(d)omit paragraphs 7 to 11.
Commencement Information
I136Sch. 6 para. 31 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
32U.K.In Article 41 (monitoring of approved codes of conduct), omit paragraph 3.
Commencement Information
I137Sch. 6 para. 32 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
33U.K.In Article 42 (certification)—
(a)in paragraph 1—
(i)for “The Member States, the supervisory authorities, the Board and the Commission” substitute “ The Commissioner ”;
(ii)omit “, in particular at Union level,”;
(b)omit paragraph 2;
(c)in paragraph 5, omit “or by the Board pursuant to Article 63. Where the criteria are approved by the Board, this may result in a common certification, the European Data Protection Seal”;
(d)omit paragraph 8.
Commencement Information
I138Sch. 6 para. 33 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
34U.K.In Article 43 (certification bodies)—
(a)in paragraph 1, in the second sentence, for “Member States shall ensure that those certification bodies are” substitute “ Those certification bodies must be ”;
(b)in paragraph 2, in point (b), omit “or by the Board pursuant to Article 63”;
(c)in paragraph 3, omit “or by the Board pursuant to Article 63”;
(d)in paragraph 6, omit the second and third sentences;
(e)omit paragraphs 8 and 9.
Commencement Information
I139Sch. 6 para. 34 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter V of the GDPR (transfers of data to third countries or international organisations)U.K.
35U.K.In Article 45 (transfers on the basis of an adequacy decision)—
(a)in paragraph 1, after “decided” insert “ in accordance with Article 45 of the GDPR ”;
(b)after paragraph 1 insert—
“1ABut a transfer of personal data to a third country or international organisation must not take place under paragraph 1, if the Commission's decision in relation to the third country (including a territory or sector within it) or the international organisation—
(a)is suspended,
(b)has been amended, or
(c)has been repealed,
by the Commission under Article 45(5) of the GDPR.”;
(c)omit paragraphs 2 to 8;
(d)in paragraph 9, for “of this Article” substitute “ of Article 45 of the GDPR ”.
Commencement Information
I140Sch. 6 para. 35 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
36U.K.In Article 46 (transfers subject to appropriate safeguards)—
(a)in paragraph 1, for “Article 45(3)” substitute “ Article 45(3) of the GDPR ”;
(b)in paragraph 2, omit point (c);
(c)in paragraph 2, in point (d), omit “and approved by the Commission pursuant to the examination procedure referred to in Article 93(2)”;
(d)omit paragraph 4;
(e)in paragraph 5—
(i)in the first sentence, for “a Member State or supervisory authority” substitute “ the Commissioner ”;
(ii)in the second sentence, for “this Article” substitute “ Article 46 of the GDPR ”.
Commencement Information
I141Sch. 6 para. 36 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
37U.K.In Article 47 (binding corporate rules)—
(a)in paragraph 1, in the first sentence, omit “in accordance with the consistency mechanism set out in Article 63”;
(b)in paragraph 2, in point (e), for “the competent courts of the Member States” substitute “ a court ”;
(c)in paragraph 2, in point (f), for “on the territory of a Member State” substitute “ in the United Kingdom ”;
(d)omit paragraph 3.
Commencement Information
I142Sch. 6 para. 37 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
38U.K.In Article 49 (derogations for specific situations)—
(a)in paragraph 1, in the first sentence—
(i)for “Article 45(3)” substitute “ Article 45(3) of the GDPR ”;
(ii)for “Article 46” substitute “ Article 46 of this Regulation ”;
(b)in paragraph 4, for “Union law or in the law of the Member State to which the controller is subject” substitute “ domestic law (see section 18 of the 2018 Act which makes certain provision about the public interest) ”;
(c)for paragraph 5 substitute—
“5Paragraph 1 is subject to any regulations made under section 18(2) of the 2018 Act.”
Commencement Information
I143Sch. 6 para. 38 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
39U.K.In Article 50 (international co-operation for the protection of personal data), omit “the Commission and”.
Commencement Information
I144Sch. 6 para. 39 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 1 of Chapter VI of the GDPR (independent supervisory authorities: independent status)U.K.
40U.K.In Article 51 (supervisory authority)—
(a)in paragraph 1—
(i)for “Each Member State shall provide for one or more independent public authorities to be” substitute “ The Commissioner is ”;
(ii)omit “and to facilitate the free flow of personal data within the Union (‘supervisory authority’)”;
(b)omit paragraphs 2 to 4.
Commencement Information
I145Sch. 6 para. 40 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
41U.K.In Article 52 (independence)—
(a)in paragraph 2—
(i)for “The member or members of each supervisory authority” substitute “ The Commissioner ”;
(ii)for “their”, in both places, substitute “the Commissioner's”;
(b)in paragraph 3—
(i)for “Member or members of each supervisory authority” substitute “ The Commissioner ”;
(ii)for “their”, in both places, substitute “the Commissioner's”;
(c)omit paragraphs 4 to 6.
Commencement Information
I146Sch. 6 para. 41 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
42U.K.Omit Article 53 (general conditions for the members of the supervisory authority).
Commencement Information
I147Sch. 6 para. 42 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
43U.K.Omit Article 54 (rules on the establishment of the supervisory authority).
Commencement Information
I148Sch. 6 para. 43 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 2 of Chapter VI of the GDPR (independent supervisory authorities: competence, tasks and powers)U.K.
44U.K.In Article 55 (competence)—
(a)in paragraph 1, omit “on the territory of its own Member State”;
(b)omit paragraph 2.
Commencement Information
I149Sch. 6 para. 44 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
45U.K.Omit Article 56 (competence of the lead supervisory authority).
Commencement Information
I150Sch. 6 para. 45 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
46U.K.In Article 57 (tasks)—
(a)in paragraph 1, in the first sentence, for “each supervisory authority shall on its territory” substitute “ the Commissioner is to ”;
(b)in paragraph 1, in point (e), omit “and, if appropriate, cooperate with the supervisory authorities in other Member States to that end”;
(c)in paragraph 1, in point (f), omit “or coordination with another supervisory authority”;
(d)in paragraph 1, omit points (g), (k) and (t);
(e)after paragraph 1 insert—
“1AIn this Article and Article 58, references to “this Regulation” have effect as references to this Regulation and section 28(3) of the 2018 Act.”
Commencement Information
I151Sch. 6 para. 46 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
47U.K.In Article 58 (powers)—
(a)in paragraph 1, in point (a), omit “, and, where applicable, the controller's or the processor's representative”;
(b)in paragraph 1, in point (f), for “Union or Member State procedural law” substitute “ domestic law ”;
(c)in paragraph 3, in point (b), for “the Member State government” substitute “ the Secretary of State ”;
(d)in paragraph 3, omit point (c);
(e)omit paragraphs 4 to 6.
Commencement Information
I152Sch. 6 para. 47 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
48U.K.In Article 59 (activity reports)—
(a)for “, the government and other authorities as designated by Member State law” substitute “ and the Secretary of State ”;
(b)omit “, to the Commission and to the Board”.
Commencement Information
I153Sch. 6 para. 48 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter VII of the GDPR (co-operation and consistency)U.K.
49U.K.For Articles 60 to 76 substitute—
“Article 61U.K.Co-operation with other supervisory authorities etc
1The Commissioner may, in connection with carrying out the Commissioner's functions under this Regulation—
(a)co-operate with, provide assistance to and seek assistance from other supervisory authorities;
(b)conduct joint operations with other supervisory authorities, including joint investigations and joint enforcement measures.
2The Commissioner must, in carrying out the Commissioner's functions under this Regulation, have regard to—
(a)decisions, advice, guidelines, recommendations and best practices issued by the European Data Protection Board established under Article 68 of the GDPR;
(b)any implementing acts adopted by the Commission under Article 67 of the GDPR (exchange of information).”
Commencement Information
I154Sch. 6 para. 49 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter VIII of the GDPR (remedies, liability and penalties)U.K.
50U.K.In Article 77 (right to lodge a complaint with a supervisory authority)—
(a)in paragraph 1, omit “in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement”;
(b)in paragraph 2, for “The supervisory authority with which the complaint has been lodged” substitute “ The Commissioner ”.
Commencement Information
I155Sch. 6 para. 50 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
51U.K.In Article 78 (right to an effective judicial remedy against a supervisory authority)—
(a)omit paragraph 2;
(b)for paragraph 3 substitute—
“3Proceedings against the Commissioner are to be brought before a court in the United Kingdom.”;
(c)omit paragraph 4.
Commencement Information
I156Sch. 6 para. 51 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
52U.K.In Article 79 (right to an effective judicial remedy against a controller or processor), for paragraph 2 substitute—
“2Proceedings against a controller or a processor are to be brought before a court (see section 180 of the 2018 Act).”
Commencement Information
I157Sch. 6 para. 52 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
53U.K.In Article 80 (representation of data subjects)—
(a)in paragraph 1, omit “where provided for by Member State law”;
(b)in paragraph 2, for “Member States” substitute “ The Secretary of State ”;
(c)after that paragraph insert—
“3The power under paragraph 2 may only be exercised by making regulations under section 190 of the 2018 Act.”
Commencement Information
I158Sch. 6 para. 53 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
54U.K.Omit Article 81 (suspension of proceedings).
Commencement Information
I159Sch. 6 para. 54 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
55U.K.In Article 82 (right to compensation and liability), for paragraph 6 substitute—
“6Proceedings for exercising the right to receive compensation are to be brought before a court (see section 180 of the 2018 Act).”
Commencement Information
I160Sch. 6 para. 55 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
56U.K.In Article 83 (general conditions for imposing administrative fines)—
(a)in paragraph 5, in point (d), for “pursuant to Member State law adopted under Chapter IX” substitute “ under Part 5 or 6 of Schedule 2 to the 2018 Act or under regulations made under section 16 of that Act ”;
(b)in paragraph 7—
(i)for “each Member State” substitute “ the Secretary of State ”;
(ii)for “that Member State” substitute “ the United Kingdom ”;
(c)for paragraph 8 substitute—
“8Section 115(9) of the 2018 Act makes provision about the exercise of the Commissioner's powers under this Article.”;
(d)omit paragraph 9.
Commencement Information
I161Sch. 6 para. 56 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
57U.K.In Article 84 (penalties)—
(a)for paragraph 1 substitute—
“1The rules on other penalties applicable to infringements of this Regulation are set out in the 2018 Act (see in particular Part 6 (enforcement)).”;
(b)omit paragraph 2.
Commencement Information
I162Sch. 6 para. 57 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter IX of the GDPR (provisions relating to specific processing situations)U.K.
58U.K.In Article 85 (processing and freedom of expression and information)—
(a)omit paragraph 1;
(b)in paragraph 2, for “Member States shall” substitute “ the Secretary of State, in addition to the relevant provisions, may by way of regulations (see section 16 of the 2018 Act), ”;
(c)in paragraph 2, at the end insert—
“In this paragraph, “the relevant provisions” means section 15 of and Part 5 of Schedule 2 to the 2018 Act.”;
(d)omit paragraph 3.
Commencement Information
I163Sch. 6 para. 58 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
59U.K.In Article 86 (processing and public access to official documents), for “Union or Member State law to which the public authority or body is subject” substitute “ domestic law ”.
Commencement Information
I164Sch. 6 para. 59 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
60U.K.Omit Article 87 (processing of national identification number).
Commencement Information
I165Sch. 6 para. 60 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
61U.K.Omit Article 88 (processing in the context of employment).
Commencement Information
I166Sch. 6 para. 61 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Prospective
F162U.K.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Textual Amendments
F1Sch. 6 omitted (31.12.2020) by virtue of The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (S.I. 2019/419), reg. 1(2), Sch. 2 para. 96 (with reg. 5); 2020 c. 1, Sch. 5 para. 1(1)
63U.K.Omit Article 90 (obligations of secrecy).
Commencement Information
I167Sch. 6 para. 63 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
64U.K.Omit Article 91 (existing data protection rules of churches and religious associations).
Commencement Information
I168Sch. 6 para. 64 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter X of the GDPR (delegated acts and implementing acts)U.K.
65U.K.Omit Article 92 (exercise of the delegation).
Commencement Information
I169Sch. 6 para. 65 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
66U.K.Omit Article 93 (committee procedure).
Commencement Information
I170Sch. 6 para. 66 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Chapter XI of the GDPR (final provisions)U.K.
67U.K.Omit Article 94 (repeal of Directive 95/46/EC).
Commencement Information
I171Sch. 6 para. 67 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
68U.K.Omit Article 95 (relationship with Directive 2002/58/EC).
Commencement Information
I172Sch. 6 para. 68 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
69U.K.In Article 96 (relationship with previously concluded Agreements), for “by Member States” substitute “ by the United Kingdom or the Commissioner ”.
Commencement Information
I173Sch. 6 para. 69 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
70U.K.Omit Article 97 (Commission reports).
Commencement Information
I174Sch. 6 para. 70 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
71U.K.Omit Article 98 (Commission reviews).
Commencement Information
I175Sch. 6 para. 71 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
72U.K.Omit Article 99 (entry into force and application).
Commencement Information
I176Sch. 6 para. 72 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
PART 2 U.K.Modifications to Chapter 2 of Part 2
IntroductoryU.K.
73U.K.In its application by virtue of section 22(2), Chapter 2 of Part 2 has effect as if it were modified as follows.
Commencement Information
I177Sch. 6 para. 73 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
General modificationsU.K.
74(1)References to Chapter 2 of Part 2 and the provisions of that Chapter have effect as references to the applied Chapter 2 and the provisions of the applied Chapter 2 .U.K.
(2)References to the GDPR and to the provisions of the GDPR have effect as references to the applied GDPR and to the provisions of the applied GDPR, except in section 18(2)(a).
(3)References to the processing of personal data to which Chapter 2 applies have effect as references to the processing of personal data to which Chapter 3 applies.
Commencement Information
I178Sch. 6 para. 74 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
ExemptionsU.K.
75U.K.In section 16 (power to make further exemptions etc by regulations), in subsection (1)(a), for “Member State law” substitute “ the Secretary of State ”.
Commencement Information
I179Sch. 6 para. 75 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(b)
Section 30
SCHEDULE 7U.K.Competent authorities
1U.K.Any United Kingdom government department other than a non-ministerial government department.
Commencement Information
I180Sch. 7 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
2U.K.The Scottish Ministers.
Commencement Information
I181Sch. 7 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
3U.K.Any Northern Ireland department.
Commencement Information
I182Sch. 7 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
4U.K.The Welsh Ministers.
Commencement Information
I183Sch. 7 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Chief officers of police and other policing bodiesU.K.
5U.K.The chief constable of a police force maintained under section 2 of the Police Act 1996.
Commencement Information
I184Sch. 7 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
6U.K.The Commissioner of Police of the Metropolis.
Commencement Information
I185Sch. 7 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
7U.K.The Commissioner of Police for the City of London.
Commencement Information
I186Sch. 7 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
8U.K.The Chief Constable of the Police Service of Northern Ireland.
Commencement Information
I187Sch. 7 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
9U.K.The chief constable of the Police Service of Scotland.
Commencement Information
I188Sch. 7 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
10U.K.The chief constable of the British Transport Police.
Commencement Information
I189Sch. 7 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
11U.K.The chief constable of the Civil Nuclear Constabulary.
Commencement Information
I190Sch. 7 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
12U.K.The chief constable of the Ministry of Defence Police.
Commencement Information
I191Sch. 7 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
13U.K.The Provost Marshal of the Royal Navy Police.
Commencement Information
I192Sch. 7 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
14U.K.The Provost Marshal of the Royal Military Police.
Commencement Information
I193Sch. 7 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
15U.K.The Provost Marshal of the Royal Air Force Police.
Commencement Information
I194Sch. 7 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
16U.K.The chief officer of—
(a)a body of constables appointed under provision incorporating section 79 of the Harbours, Docks, and Piers Clauses Act 1847;
(b)a body of constables appointed under an order made under section 14 of the Harbours Act 1964;
(c)the body of constables appointed under section 154 of the Port of London Act 1968 (c.xxxii).
Commencement Information
I195Sch. 7 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
17U.K.A body established in accordance with a collaboration agreement under section 22A of the Police Act 1996.
Commencement Information
I196Sch. 7 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
18U.K.The Director General of the Independent Office for Police Conduct.
Commencement Information
I197Sch. 7 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
19U.K.The Police Investigations and Review Commissioner.
Commencement Information
I198Sch. 7 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
20U.K.The Police Ombudsman for Northern Ireland.
Commencement Information
I199Sch. 7 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Other authorities with investigatory functionsU.K.
21U.K.The Commissioners for Her Majesty's Revenue and Customs.
Commencement Information
I200Sch. 7 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
22U.K.The Welsh Revenue Authority.
Commencement Information
I201Sch. 7 para. 22 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
23U.K.Revenue Scotland.
Commencement Information
I202Sch. 7 para. 23 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
24U.K.The Director General of the National Crime Agency.
Commencement Information
I203Sch. 7 para. 24 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
25U.K.The Director of the Serious Fraud Office.
Commencement Information
I204Sch. 7 para. 25 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
26U.K.The Director of Border Revenue.
Commencement Information
I205Sch. 7 para. 26 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
27U.K.The Financial Conduct Authority.
Commencement Information
I206Sch. 7 para. 27 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
28U.K.The Health and Safety Executive.
Commencement Information
I207Sch. 7 para. 28 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
29U.K.The Competition and Markets Authority.
Commencement Information
I208Sch. 7 para. 29 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
30U.K.The Gas and Electricity Markets Authority.
Commencement Information
I209Sch. 7 para. 30 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
31U.K.The Food Standards Agency.
Commencement Information
I210Sch. 7 para. 31 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
32U.K.Food Standards Scotland.
Commencement Information
I211Sch. 7 para. 32 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
33U.K.Her Majesty's Land Registry.
Commencement Information
I212Sch. 7 para. 33 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
34U.K.The Criminal Cases Review Commission.
Commencement Information
I213Sch. 7 para. 34 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
35U.K.The Scottish Criminal Cases Review Commission.
Commencement Information
I214Sch. 7 para. 35 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Authorities with functions relating to offender managementU.K.
36U.K.A provider of probation services (other than the Secretary of State), acting in pursuance of arrangements made under section 3(2) of the Offender Management Act 2007.
Commencement Information
I215Sch. 7 para. 36 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
37U.K.The Youth Justice Board for England and Wales.
Commencement Information
I216Sch. 7 para. 37 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
38U.K.The Parole Board for England and Wales.
Commencement Information
I217Sch. 7 para. 38 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
39U.K.The Parole Board for Scotland.
Commencement Information
I218Sch. 7 para. 39 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
40U.K.The Parole Commissioners for Northern Ireland.
Commencement Information
I219Sch. 7 para. 40 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
41U.K.The Probation Board for Northern Ireland.
Commencement Information
I220Sch. 7 para. 41 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
42U.K.The Prisoner Ombudsman for Northern Ireland.
Commencement Information
I221Sch. 7 para. 42 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
43U.K.A person who has entered into a contract for the running of, or part of—
(a)a prison or young offender institution under section 84 of the Criminal Justice Act 1991, or
(b)a secure training centre under section 7 of the Criminal Justice and Public Order Act 1994.
Commencement Information
I222Sch. 7 para. 43 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
44U.K.A person who has entered into a contract with the Secretary of State—
(a)under section 80 of the Criminal Justice Act 1991 for the purposes of prisoner escort arrangements, or
(b)under paragraph 1 of Schedule 1 to the Criminal Justice and Public Order Act 1994 for the purposes of escort arrangements.
Commencement Information
I223Sch. 7 para. 44 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
45U.K.A person who is, under or by virtue of any enactment, responsible for securing the electronic monitoring of an individual.
Commencement Information
I224Sch. 7 para. 45 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
46U.K.A youth offending team established under section 39 of the Crime and Disorder Act 1998.
Commencement Information
I225Sch. 7 para. 46 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Other authoritiesU.K.
47U.K.The Director of Public Prosecutions.
Commencement Information
I226Sch. 7 para. 47 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
48U.K.The Director of Public Prosecutions for Northern Ireland.
Commencement Information
I227Sch. 7 para. 48 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
49U.K.The Lord Advocate.
Commencement Information
I228Sch. 7 para. 49 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
50U.K.A Procurator Fiscal.
Commencement Information
I229Sch. 7 para. 50 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
51U.K.The Director of Service Prosecutions.
Commencement Information
I230Sch. 7 para. 51 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
52U.K.The Information Commissioner.
Commencement Information
I231Sch. 7 para. 52 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
53U.K.The Scottish Information Commissioner.
Commencement Information
I232Sch. 7 para. 53 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
54U.K.The Scottish Courts and Tribunal Service.
Commencement Information
I233Sch. 7 para. 54 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
55U.K.The Crown agent.
Commencement Information
I234Sch. 7 para. 55 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
56U.K.A court or tribunal.
Commencement Information
I235Sch. 7 para. 56 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Section 35(5)
SCHEDULE 8U.K.Conditions for sensitive processing under Part 3
Statutory etc purposesU.K.
1U.K.This condition is met if the processing—
(a)is necessary for the exercise of a function conferred on a person by an enactment or rule of law, and
(b)is necessary for reasons of substantial public interest.
Commencement Information
I236Sch. 8 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Administration of justiceU.K.
2U.K.This condition is met if the processing is necessary for the administration of justice.
Commencement Information
I237Sch. 8 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Protecting individual's vital interestsU.K.
3U.K.This condition is met if the processing is necessary to protect the vital interests of the data subject or of another individual.
Commencement Information
I238Sch. 8 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Safeguarding of children and of individuals at riskU.K.
4(1)This condition is met if—U.K.
(a)the processing is necessary for the purposes of—
(i)protecting an individual from neglect or physical, mental or emotional harm, or
(ii)protecting the physical, mental or emotional well-being of an individual,
(b)the individual is—
(i)aged under 18, or
(ii)aged 18 or over and at risk,
(c)the processing is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2), and
(d)the processing is necessary for reasons of substantial public interest.
(2)The reasons mentioned in sub-paragraph (1)(c) are—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)the processing must be carried out without the consent of the data subject because obtaining the consent of the data subject would prejudice the provision of the protection mentioned in sub-paragraph (1)(a).
(3)For the purposes of this paragraph, an individual aged 18 or over is “at risk” if the controller has reasonable cause to suspect that the individual—
(a)has needs for care and support,
(b)is experiencing, or at risk of, neglect or physical, mental or emotional harm, and
(c)as a result of those needs is unable to protect himself or herself against the neglect or harm or the risk of it.
(4)In sub-paragraph (1)(a), the reference to the protection of an individual or of the well-being of an individual includes both protection relating to a particular individual and protection relating to a type of individual.
Commencement Information
I239Sch. 8 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Personal data already in the public domainU.K.
5U.K.This condition is met if the processing relates to personal data which is manifestly made public by the data subject.
Commencement Information
I240Sch. 8 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Legal claimsU.K.
6U.K.This condition is met if the processing—
(a)is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings),
(b)is necessary for the purpose of obtaining legal advice, or
(c)is otherwise necessary for the purposes of establishing, exercising or defending legal rights.
Commencement Information
I241Sch. 8 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Judicial actsU.K.
7U.K.This condition is met if the processing is necessary when a court or other judicial authority is acting in its judicial capacity.
Commencement Information
I242Sch. 8 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Preventing fraudU.K.
8(1)This condition is met if the processing—U.K.
(a)is necessary for the purposes of preventing fraud or a particular kind of fraud, and
(b)consists of—
(i)the disclosure of personal data by a competent authority as a member of an anti-fraud organisation,
(ii)the disclosure of personal data by a competent authority in accordance with arrangements made by an anti-fraud organisation, or
(iii)the processing of personal data disclosed as described in sub-paragraph (i) or (ii).
(2)In this paragraph, “anti-fraud organisation” has the same meaning as in section 68 of the Serious Crime Act 2007.
Commencement Information
I243Sch. 8 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Archiving etcU.K.
9U.K.This condition is met if the processing is necessary—
(a)for archiving purposes in the public interest,
(b)for scientific or historical research purposes, or
(c)for statistical purposes.
Commencement Information
I244Sch. 8 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(c)
Section 86
SCHEDULE 9U.K.Conditions for processing under Part 4
1U.K.The data subject has given consent to the processing.
Commencement Information
I245Sch. 9 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
2U.K.The processing is necessary—
(a)for the performance of a contract to which the data subject is a party, or
(b)in order to take steps at the request of the data subject prior to entering into a contract.
Commencement Information
I246Sch. 9 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
3U.K.The processing is necessary for compliance with a legal obligation to which the controller is subject, other than an obligation imposed by contract.
Commencement Information
I247Sch. 9 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
4U.K.The processing is necessary in order to protect the vital interests of the data subject or of another individual.
Commencement Information
I248Sch. 9 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
5U.K.The processing is necessary—
(a)for the administration of justice,
(b)for the exercise of any functions of either House of Parliament,
(c)for the exercise of any functions conferred on a person by an enactment or rule of law,
(d)for the exercise of any functions of the Crown, a Minister of the Crown or a government department, or
(e)for the exercise of any other functions of a public nature exercised in the public interest by a person.
Commencement Information
I249Sch. 9 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
6(1)The processing is necessary for the purposes of legitimate interests pursued by—U.K.
(a)the controller, or
(b)the third party or parties to whom the data is disclosed.
(2)Sub-paragraph (1) does not apply where the processing is unwarranted in any particular case because of prejudice to the rights and freedoms or legitimate interests of the data subject.
(3)In this paragraph, “third party”, in relation to personal data, means a person other than the data subject, the controller or a processor or other person authorised to process personal data for the controller or processor.
Commencement Information
I250Sch. 9 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Section 86
SCHEDULE 10U.K.Conditions for sensitive processing under Part 4
Consent to particular processingU.K.
1U.K.The data subject has given consent to the processing.
Commencement Information
I251Sch. 10 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Right or obligation relating to employmentU.K.
2U.K.The processing is necessary for the purposes of exercising or performing any right or obligation which is conferred or imposed by an enactment or rule of law on the controller in connection with employment.
Commencement Information
I252Sch. 10 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Vital interests of a personU.K.
3U.K.The processing is necessary—
(a)in order to protect the vital interests of the data subject or of another person, in a case where—
(i)consent cannot be given by or on behalf of the data subject, or
(ii)the controller cannot reasonably be expected to obtain the consent of the data subject, or
(b)in order to protect the vital interests of another person, in a case where consent by or on behalf of the data subject has been unreasonably withheld.
Commencement Information
I253Sch. 10 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Safeguarding of children and of individuals at riskU.K.
4(1)This condition is met if—U.K.
(a)the processing is necessary for the purposes of—
(i)protecting an individual from neglect or physical, mental or emotional harm, or
(ii)protecting the physical, mental or emotional well-being of an individual,
(b)the individual is—
(i)aged under 18, or
(ii)aged 18 or over and at risk,
(c)the processing is carried out without the consent of the data subject for one of the reasons listed in sub-paragraph (2), and
(d)the processing is necessary for reasons of substantial public interest.
(2)The reasons mentioned in sub-paragraph (1)(c) are—
(a)in the circumstances, consent to the processing cannot be given by the data subject;
(b)in the circumstances, the controller cannot reasonably be expected to obtain the consent of the data subject to the processing;
(c)the processing must be carried out without the consent of the data subject because obtaining the consent of the data subject would prejudice the provision of the protection mentioned in sub-paragraph (1)(a).
(3)For the purposes of this paragraph, an individual aged 18 or over is “at risk” if the controller has reasonable cause to suspect that the individual—
(a)has needs for care and support,
(b)is experiencing, or at risk of, neglect or physical, mental or emotional harm, and
(c)as a result of those needs is unable to protect himself or herself against the neglect or harm or the risk of it.
(4)In sub-paragraph (1)(a), the reference to the protection of an individual or of the well-being of an individual includes both protection relating to a particular individual and protection relating to a type of individual.
Commencement Information
I254Sch. 10 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Data already published by data subjectU.K.
5U.K.The information contained in the personal data has been made public as a result of steps deliberately taken by the data subject.
Commencement Information
I255Sch. 10 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Legal proceedings etcU.K.
6U.K.The processing—
(a)is necessary for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings),
(b)is necessary for the purpose of obtaining legal advice, or
(c)is otherwise necessary for the purposes of establishing, exercising or defending legal rights.
Commencement Information
I256Sch. 10 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Administration of justice, parliamentary, statutory etc and government purposesU.K.
7U.K.The processing is necessary—
(a)for the administration of justice,
(b)for the exercise of any functions of either House of Parliament,
(c)for the exercise of any functions conferred on any person by an enactment or rule of law, or
(d)for the exercise of any functions of the Crown, a Minister of the Crown or a government department.
Commencement Information
I257Sch. 10 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Medical purposesU.K.
8(1)The processing is necessary for medical purposes and is undertaken by—U.K.
(a)a health professional, or
(b)a person who in the circumstances owes a duty of confidentiality which is equivalent to that which would arise if that person were a health professional.
(2)In this paragraph, “medical purposes” includes the purposes of preventative medicine, medical diagnosis, medical research, the provision of care and treatment and the management of healthcare services.
Commencement Information
I258Sch. 10 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
EqualityU.K.
9(1)The processing—U.K.
(a)is of sensitive personal data consisting of information as to racial or ethnic origin,
(b)is necessary for the purpose of identifying or keeping under review the existence or absence of equality of opportunity or treatment between persons of different racial or ethnic origins, with a view to enabling such equality to be promoted or maintained, and
(c)is carried out with appropriate safeguards for the rights and freedoms of data subjects.
(2)In this paragraph, “sensitive personal data” means personal data the processing of which constitutes sensitive processing (see section 86(7)).
Commencement Information
I259Sch. 10 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Section 112
SCHEDULE 11U.K.Other exemptions under Part 4
PreliminaryU.K.
1U.K.In this Schedule, “the listed provisions” means—
(a)Chapter 2 of Part 4 (the data protection principles), except section 86(1)(a) and (2) and Schedules 9 and 10;
(b)Chapter 3 of Part 4 (rights of data subjects);
(c)in Chapter 4 of Part 4 , section 108 (communication of personal data breach to the Commissioner).
Commencement Information
I260Sch. 11 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
CrimeU.K.
2U.K.The listed provisions do not apply to personal data processed for any of the following purposes—
(a)the prevention and detection of crime, or
(b)the apprehension and prosecution of offenders,
to the extent that the application of the listed provisions would be likely to prejudice any of the matters mentioned in paragraph (a) or (b).
Commencement Information
I261Sch. 11 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Information required to be disclosed by law etc or in connection with legal proceedingsU.K.
3(1)The listed provisions do not apply to personal data consisting of information that the controller is obliged by an enactment to make available to the public, to the extent that the application of the listed provisions would prevent the controller from complying with that obligation.U.K.
(2)The listed provisions do not apply to personal data where disclosure of the data is required by an enactment, a rule of law or the order of a court, to the extent that the application of the listed provisions would prevent the controller from making the disclosure.
(3)The listed provisions do not apply to personal data where disclosure of the data—
(a)is necessary for the purpose of, or in connection with, legal proceedings (including prospective legal proceedings),
(b)is necessary for the purpose of obtaining legal advice, or
(c)is otherwise necessary for the purposes of establishing, exercising or defending legal rights,
to the extent that the application of the listed provisions would prevent the controller from making the disclosure.
Commencement Information
I262Sch. 11 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Parliamentary privilegeU.K.
4U.K.The listed provisions do not apply to personal data where this is required for the purpose of avoiding an infringement of the privileges of either House of Parliament.
Commencement Information
I263Sch. 11 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Judicial proceedingsU.K.
5U.K.The listed provisions do not apply to personal data to the extent that the application of the listed provisions would be likely to prejudice judicial proceedings.
Commencement Information
I264Sch. 11 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Crown honours and dignitiesU.K.
6U.K.The listed provisions do not apply to personal data processed for the purposes of the conferring by the Crown of any honour or dignity.
Commencement Information
I265Sch. 11 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Armed forcesU.K.
7U.K.The listed provisions do not apply to personal data to the extent that the application of the listed provisions would be likely to prejudice the combat effectiveness of any of the armed forces of the Crown.
Commencement Information
I266Sch. 11 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Economic well-beingU.K.
8U.K.The listed provisions do not apply to personal data to the extent that the application of the listed provisions would be likely to prejudice the economic well-being of the United Kingdom.
Commencement Information
I267Sch. 11 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Legal professional privilegeU.K.
9U.K.The listed provisions do not apply to personal data that consists of—
(a)information in respect of which a claim to legal professional privilege or, in Scotland, confidentiality of communications, could be maintained in legal proceedings, or
(b)information in respect of which a duty of confidentiality is owed by a professional legal adviser to a client of the adviser.
Commencement Information
I268Sch. 11 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
NegotiationsU.K.
10U.K.The listed provisions do not apply to personal data that consists of records of the intentions of the controller in relation to any negotiations with the data subject to the extent that the application of the listed provisions would be likely to prejudice the negotiations.
Commencement Information
I269Sch. 11 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Confidential references given by the controllerU.K.
11U.K.The listed provisions do not apply to personal data consisting of a reference given (or to be given) in confidence by the controller for the purposes of—
(a)the education, training or employment (or prospective education, training or employment) of the data subject,
(b)the appointment (or prospective appointment) of the data subject to any office, or
(c)the provision (or prospective provision) by the data subject of any service.
Commencement Information
I270Sch. 11 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Exam scripts and marksU.K.
12(1)The listed provisions do not apply to personal data consisting of information recorded by candidates during an exam.U.K.
(2)Where personal data consists of marks or other information processed by a controller—
(a)for the purposes of determining the results of an exam, or
(b)in consequence of the determination of the results of an exam,
section 94 has effect subject to sub-paragraph (3).
(3)Where the relevant time falls before the results of the exam are announced, the period mentioned in section 94(10)(b) is extended until the earlier of—
(a)the end of the period of 5 months beginning with the relevant time, and
(b)the end of the period of 40 days beginning with the announcement of the results.
(4)In this paragraph—
“exam” means an academic, professional or other examination used for determining the knowledge, intelligence, skill or ability of a candidate and may include an exam consisting of an assessment of the candidate's performance while undertaking work or any other activity;
“the relevant time” has the same meaning as in section 94.
(5)For the purposes of this paragraph, the results of an exam are treated as announced when they are first published or, if not published, first communicated to the candidate.
Commencement Information
I271Sch. 11 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Research and statisticsU.K.
13(1)The listed provisions do not apply to personal data processed for—U.K.
(a)scientific or historical research purposes, or
(b)statistical purposes,
to the extent that the application of those provisions would prevent or seriously impair the achievement of the purposes in question.
(2)The exemption in sub-paragraph (1) is available only where—
(a)the personal data is processed subject to appropriate safeguards for the rights and freedoms of data subjects, and
(b)the results of the research or any resulting statistics are not made available in a form which identifies a data subject.
Commencement Information
I272Sch. 11 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Archiving in the public interestU.K.
14(1)The listed provisions do not apply to personal data processed for archiving purposes in the public interest to the extent that the application of those provisions would prevent or seriously impair the achievement of those purposes.U.K.
(2)The exemption in sub-paragraph (1) is available only where the personal data is processed subject to appropriate safeguards for the rights and freedoms of data subjects.
Commencement Information
I273Sch. 11 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(d)
Section 114
SCHEDULE 12U.K.The Information Commissioner
Status and capacityU.K.
1(1)The Commissioner is to continue to be a corporation sole.U.K.
(2)The Commissioner and the Commissioner's officers and staff are not to be regarded as servants or agents of the Crown.
Commencement Information
I274Sch. 12 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
AppointmentU.K.
2(1)The Commissioner is to be appointed by Her Majesty by Letters Patent.U.K.
(2)No recommendation may be made to Her Majesty for the appointment of a person as the Commissioner unless the person concerned has been selected on merit on the basis of fair and open competition.
(3)The Commissioner is to hold office for such term not exceeding 7 years as may be determined at the time of the Commissioner's appointment, subject to paragraph 3.
(4)A person cannot be appointed as the Commissioner more than once.
Commencement Information
I275Sch. 12 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Resignation and removalU.K.
3(1)The Commissioner may be relieved of office by Her Majesty at the Commissioner's own request.U.K.
(2)The Commissioner may be removed from office by Her Majesty on an Address from both Houses of Parliament.
(3)No motion is to be made in either House of Parliament for such an Address unless a Minister of the Crown has presented a report to that House stating that the Minister is satisfied that one or both of the following grounds is made out—
(a)the Commissioner is guilty of serious misconduct;
(b)the Commissioner no longer fulfils the conditions required for the performance of the Commissioner's functions.
Commencement Information
I276Sch. 12 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Salary etcU.K.
4(1)The Commissioner is to be paid such salary as may be specified by a resolution of the House of Commons.U.K.
(2)There is to be paid in respect of the Commissioner such pension as may be specified by a resolution of the House of Commons.
(3)A resolution for the purposes of this paragraph may—
(a)specify the salary or pension,
(b)specify the salary or pension and provide for it to be increased by reference to such variables as may be specified in the resolution, or
(c)provide that the salary or pension is to be the same as, or calculated on the same basis as, that payable to, or in respect of, a person employed in a specified office under, or in a specified capacity in the service of, the Crown.
(4)A resolution for the purposes of this paragraph may take effect from—
(a)the date on which it is passed, or
(b)from an earlier date or later date specified in the resolution.
(5)A resolution for the purposes of this paragraph may make different provision in relation to the pension payable to, or in respect of, different holders of the office of Commissioner.
(6)A salary or pension payable under this paragraph is to be charged on and issued out of the Consolidated Fund.
(7)In this paragraph, “pension” includes an allowance or gratuity and a reference to the payment of a pension includes a reference to the making of payments towards the provision of a pension.
Commencement Information
I277Sch. 12 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Officers and staffU.K.
5(1)The Commissioner—U.K.
(a)must appoint one or more deputy commissioners, and
(b)may appoint other officers and staff.
(2)The Commissioner is to determine the remuneration and other conditions of service of people appointed under this paragraph.
(3)The Commissioner may pay pensions, allowances or gratuities to, or in respect of, people appointed under this paragraph, including pensions, allowances or gratuities paid by way of compensation in respect of loss of office or employment.
(4)The references in sub-paragraph (3) to paying pensions, allowances or gratuities includes making payments towards the provision of pensions, allowances or gratuities.
(5)In making appointments under this paragraph, the Commissioner must have regard to the principle of selection on merit on the basis of fair and open competition.
(6)The Employers' Liability (Compulsory Insurance) Act 1969 does not require insurance to be effected by the Commissioner.
Commencement Information
I278Sch. 12 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Carrying out of the Commissioner's functions by officers and staffU.K.
6(1)The functions of the Commissioner are to be carried out by the deputy commissioner or deputy commissioners if—U.K.
(a)there is a vacancy in the office of the Commissioner, or
(b)the Commissioner is for any reason unable to act.
(2)When the Commissioner appoints a second or subsequent deputy commissioner, the Commissioner must specify which deputy commissioner is to carry out which of the Commissioner's functions in the circumstances referred to in sub-paragraph (1).
(3)A function of the Commissioner may, to the extent authorised by the Commissioner, be carried out by any of the Commissioner's officers or staff.
Commencement Information
I279Sch. 12 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Authentication of the seal of the CommissionerE+W+N.I.
7E+W+N.I.The application of the seal of the Commissioner is to be authenticated by—
(a)the Commissioner's signature, or
(b)the signature of another person authorised for the purpose.
Commencement Information
I280Sch. 12 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Presumption of authenticity of documents issued by the CommissionerE+W+N.I.
8E+W+N.I.A document purporting to be an instrument issued by the Commissioner and to be—
(a)duly executed under the Commissioner's seal, or
(b)signed by or on behalf of the Commissioner,
is to be received in evidence and is to be deemed to be such an instrument unless the contrary is shown.
Commencement Information
I281Sch. 12 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
MoneyU.K.
9U.K.The Secretary of State may make payments to the Commissioner out of money provided by Parliament.
Commencement Information
I282Sch. 12 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Fees etc and other sumsU.K.
10(1)All fees, charges, penalties and other sums received by the Commissioner in carrying out the Commissioner's functions are to be paid by the Commissioner to the Secretary of State.U.K.
(2)Sub-paragraph (1) does not apply where the Secretary of State, with the consent of the Treasury, otherwise directs.
(3)Any sums received by the Secretary of State under sub-paragraph (1) are to be paid into the Consolidated Fund.
Commencement Information
I283Sch. 12 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
AccountsU.K.
11(1)The Commissioner must—U.K.
(a)keep proper accounts and other records in relation to the accounts, and
(b)prepare in respect of each financial year a statement of account in such form as the Secretary of State may direct.
(2)The Commissioner must send a copy of the statement to the Comptroller and Auditor General—
(a)on or before 31 August next following the end of the year to which the statement relates, or
(b)on or before such earlier date after the end of that year as the Treasury may direct.
(3)The Comptroller and Auditor General must examine, certify and report on the statement.
(4)The Commissioner must arrange for copies of the statement and the Comptroller and Auditor General's report to be laid before Parliament.
(5)In this paragraph, “financial year” means a period of 12 months beginning with 1 April.
Commencement Information
I284Sch. 12 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
ScotlandU.K.
12U.K.Paragraphs 1(1), 7 and 8 do not extend to Scotland.
Commencement Information
I285Sch. 12 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Section 116
SCHEDULE 13U.K.Other general functions of the Commissioner
General tasksU.K.
1(1)The Commissioner must—U.K.
(a)monitor and enforce Parts 3 and 4 of this Act;
(b)promote public awareness and understanding of the risks, rules, safeguards and rights in relation to processing of personal data to which those Parts apply;
(c)advise Parliament, the government and other institutions and bodies on legislative and administrative measures relating to the protection of individuals' rights and freedoms with regard to processing of personal data to which those Parts apply;
(d)promote the awareness of controllers and processors of their obligations under Parts 3 and 4 of this Act;
(e)on request, provide information to a data subject concerning the exercise of the data subject's rights under Parts 3 and 4 of this Act and, if appropriate, co-operate with LED supervisory authorities and foreign designated authorities to provide such information;
(f)co-operate with LED supervisory authorities and foreign designated authorities with a view to ensuring the consistency of application and enforcement of the Law Enforcement Directive and the Data Protection Convention, including by sharing information and providing mutual assistance;
(g)conduct investigations on the application of Parts 3 and 4 of this Act, including on the basis of information received from an LED supervisory authority, a foreign designated authority or another public authority;
(h)monitor relevant developments to the extent that they have an impact on the protection of personal data, including the development of information and communication technologies;
(i)contribute to the activities of the European Data Protection Board established by the GDPR in connection with the processing of personal data to which the Law Enforcement Directive applies.
(2)Section 3(14)(c) does not apply to the reference to personal data in sub-paragraph (1)(h).
Commencement Information
I286Sch. 13 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
General powersU.K.
2U.K.The Commissioner has the following investigative, corrective, authorisation and advisory powers in relation to processing of personal data to which Part 3 or 4 of this Act applies—
(a)to notify the controller or the processor of an alleged infringement of Part 3 or 4 of this Act;
(b)to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of Part 3 or 4 of this Act;
(c)to issue reprimands to a controller or processor where processing operations have infringed provisions of Part 3 or 4 of this Act;
(d)to issue, on the Commissioner's own initiative or on request, opinions to Parliament, the government or other institutions and bodies as well as to the public on any issue related to the protection of personal data.
Commencement Information
I287Sch. 13 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
DefinitionsU.K.
3U.K.In this Schedule—
“foreign designated authority” means an authority designated for the purposes of Article 13 of the Data Protection Convention by a party, other than the United Kingdom, which is bound by that Convention;
“LED supervisory authority” means a supervisory authority for the purposes of Article 41 of the Law Enforcement Directive in a member State other than the United Kingdom.
Commencement Information
I288Sch. 13 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Section 118
SCHEDULE 14U.K.Co-operation and mutual assistance
PART 1 U.K.Law Enforcement Directive
Co-operationU.K.
1(1)The Commissioner may provide information or assistance to an LED supervisory authority to the extent that, in the opinion of the Commissioner, providing that information or assistance is necessary for the performance of the recipient's data protection functions.U.K.
(2)The Commissioner may ask an LED supervisory authority to provide information or assistance which the Commissioner requires for the performance of the Commissioner's data protection functions.
(3)In this paragraph, “data protection functions” means functions relating to the protection of individuals with respect to the processing of personal data.
Commencement Information
I289Sch. 14 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Requests for information and assistance from LED supervisory authoritiesU.K.
2(1)This paragraph applies where the Commissioner receives a request from an LED supervisory authority for information or assistance referred to in Article 41 of the Law Enforcement Directive and the request—U.K.
(a)explains the purpose of and reasons for the request, and
(b)contains all other information necessary to enable the Commissioner to respond.
(2)The Commissioner must—
(a)take all appropriate measures required to reply to the request without undue delay and, in any event, before the end of the period of 1 month beginning with receipt of the request, and
(b)inform the LED supervisory authority of the results or, as the case may be, of the progress of the measures taken in order to respond to the request.
(3)The Commissioner must not refuse to comply with the request unless—
(a)the Commissioner does not have power to do what is requested, or
(b)complying with the request would infringe the Law Enforcement Directive, EU legislation or the law of the United Kingdom or a part of the United Kingdom.
(4)If the Commissioner refuses to comply with a request from an LED supervisory authority, the Commissioner must inform the authority of the reasons for the refusal.
(5)As a general rule, the Commissioner must provide information requested by LED supervisory authorities by electronic means using a standardised format.
Commencement Information
I290Sch. 14 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
FeesU.K.
3(1)Subject to sub-paragraph (2), any information or assistance that is required to be provided by this Part of this Schedule must be provided free of charge.U.K.
(2)The Commissioner may enter into agreements with other LED supervisory authorities for the Commissioner and other authorities to indemnify each other for expenditure arising from the provision of assistance in exceptional circumstances.
Commencement Information
I291Sch. 14 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Restrictions on use of informationU.K.
4U.K.Where the Commissioner receives information from an LED supervisory authority as a result of a request under paragraph 1(2), the Commissioner may use the information only for the purposes specified in the request.
Commencement Information
I292Sch. 14 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
LED supervisory authorityU.K.
5U.K.In this Part of this Schedule, “LED supervisory authority” means a supervisory authority for the purposes of Article 41 of the Law Enforcement Directive in a member State other than the United Kingdom.
Commencement Information
I293Sch. 14 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
PART 2 U.K.Data Protection Convention
Co-operation between the Commissioner and foreign designated authoritiesU.K.
6(1)The Commissioner must, at the request of a foreign designated authority—U.K.
(a)provide that authority with such information referred to in Article 13(3)(a) of the Data Protection Convention (information on law and administrative practice in the field of data protection) as is the subject of the request, and
(b)take appropriate measures in accordance with Article 13(3)(b) of the Data Protection Convention for providing that authority with information relating to the processing of personal data in the United Kingdom.
(2)The Commissioner may ask a foreign designated authority—
(a)to provide the Commissioner with information referred to in Article 13(3) of the Data Protection Convention, or
(b)to take appropriate measures to provide such information.
Commencement Information
I294Sch. 14 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Assisting persons resident outside the UK with requests under Article 14 of the ConventionU.K.
7(1)This paragraph applies where a request for assistance in exercising any of the rights referred to in Article 8 of the Data Protection Convention in the United Kingdom is made by a person resident outside the United Kingdom, including where the request is forwarded to the Commissioner through the Secretary of State or a foreign designated authority.U.K.
(2)The Commissioner must take appropriate measures to assist the person to exercise those rights.
Commencement Information
I295Sch. 14 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Assisting UK residents with requests under Article 8 of the ConventionU.K.
8(1)This paragraph applies where a request for assistance in exercising any of the rights referred to in Article 8 of the Data Protection Convention in a country or territory (other than the United Kingdom) specified in the request is—U.K.
(a)made by a person resident in the United Kingdom, and
(b)submitted through the Commissioner under Article 14(2) of the Convention.
(2)If the Commissioner is satisfied that the request contains all necessary particulars referred to in Article 14(3) of the Data Protection Convention, the Commissioner must send the request to the foreign designated authority in the specified country or territory.
(3)Otherwise, the Commissioner must, where practicable, notify the person making the request of the reasons why the Commissioner is not required to assist.
Commencement Information
I296Sch. 14 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Restrictions on use of informationU.K.
9U.K.Where the Commissioner receives information from a foreign designated authority as a result of—
(a)a request made by the Commissioner under paragraph 6(2), or
(b)a request received by the Commissioner under paragraph 6(1) or 7,
the Commissioner may use the information only for the purposes specified in the request.
Commencement Information
I297Sch. 14 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Foreign designated authorityU.K.
10U.K.In this Part of this Schedule, “foreign designated authority” means an authority designated for the purposes of Article 13 of the Data Protection Convention by a party, other than the United Kingdom, which is bound by that Data Protection Convention.
Commencement Information
I298Sch. 14 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(e)
Section 154
SCHEDULE 15U.K.Powers of entry and inspection
Modifications etc. (not altering text)
C10Sch. 15 applied (with modifications) by S.I. 2016/696, Sch. 2 (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 406 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g) (with reg. 4))
Issue of warrants in connection with non-compliance and offencesU.K.
1(1)This paragraph applies if a judge of the High Court, a circuit judge or a District Judge (Magistrates' Courts) is satisfied by information on oath supplied by the Commissioner that—U.K.
(a)there are reasonable grounds for suspecting that—
(i)a controller or processor has failed or is failing as described in section 149(2), or
(ii)an offence under this Act has been or is being committed, and
(b)there are reasonable grounds for suspecting that evidence of the failure or of the commission of the offence is to be found on premises specified in the information or is capable of being viewed using equipment on such premises.
(2)The judge may grant a warrant to the Commissioner.
Commencement Information
I299Sch. 15 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Issue of warrants in connection with assessment noticesU.K.
2(1)This paragraph applies if a judge of the High Court, a circuit judge or a District Judge (Magistrates' Courts) is satisfied by information on oath supplied by the Commissioner that a controller or processor has failed to comply with a requirement imposed by an assessment notice.U.K.
(2)The judge may, for the purpose of enabling the Commissioner to determine whether the controller or processor has complied or is complying with the data protection legislation, grant a warrant to the Commissioner in relation to premises that were specified in the assessment notice.
Commencement Information
I300Sch. 15 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Restrictions on issuing warrants: processing for the special purposesU.K.
3U.K.A judge must not issue a warrant under this Schedule in respect of personal data processed for the special purposes unless a determination under section 174 with respect to the data or the processing has taken effect.
Commencement Information
I301Sch. 15 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Restrictions on issuing warrants: procedural requirementsU.K.
4(1)A judge must not issue a warrant under this Schedule unless satisfied that—U.K.
(a)the conditions in sub-paragraphs (2) to (4) are met,
(b)compliance with those conditions would defeat the object of entry to the premises in question, or
(c)the Commissioner requires access to the premises in question urgently.
(2)The first condition is that the Commissioner has given 7 days' notice in writing to the occupier of the premises in question demanding access to the premises.
(3)The second condition is that—
(a)access to the premises was demanded at a reasonable hour and was unreasonably refused, or
(b)entry to the premises was granted but the occupier unreasonably refused to comply with a request by the Commissioner or the Commissioner's officers or staff to be allowed to do any of the things referred to in paragraph 5.
(4)The third condition is that, since the refusal, the occupier of the premises—
(a)has been notified by the Commissioner of the application for the warrant, and
(b)has had an opportunity to be heard by the judge on the question of whether or not the warrant should be issued.
(5)In determining whether the first condition is met, an assessment notice given to the occupier is to be disregarded.
Commencement Information
I302Sch. 15 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Content of warrantsU.K.
5(1)A warrant issued under this Schedule must authorise the Commissioner or any of the Commissioner's officers or staff—U.K.
(a)to enter the premises,
(b)to search the premises, and
(c)to inspect, examine, operate and test any equipment found on the premises which is used or intended to be used for the processing of personal data.
(2)A warrant issued under paragraph 1 must authorise the Commissioner or any of the Commissioner's officers or staff—
(a)to inspect and seize any documents or other material found on the premises which may be evidence of the failure or offence mentioned in that paragraph,
(b)to require any person on the premises to provide, in an appropriate form, a copy of information capable of being viewed using equipment on the premises which may be evidence of that failure or offence,
(c)to require any person on the premises to provide an explanation of any document or other material found on the premises and of any information capable of being viewed using equipment on the premises, and
(d)to require any person on the premises to provide such other information as may reasonably be required for the purpose of determining whether the controller or processor has failed or is failing as described in section 149(2).
(3)A warrant issued under paragraph 2 must authorise the Commissioner or any of the Commissioner's officers or staff—
(a)to inspect and seize any documents or other material found on the premises which may enable the Commissioner to determine whether the controller or processor has complied or is complying with the data protection legislation,
(b)to require any person on the premises to provide, in an appropriate form, a copy of information capable of being viewed using equipment on the premises which may enable the Commissioner to make such a determination,
(c)to require any person on the premises to provide an explanation of any document or other material found on the premises and of any information capable of being viewed using equipment on the premises, and
(d)to require any person on the premises to provide such other information as may reasonably be required for the purpose of determining whether the controller or processor has complied or is complying with the data protection legislation.
(4)A warrant issued under this Schedule must authorise the Commissioner or any of the Commissioner's officers or staff to do the things described in sub-paragraphs (1) to (3) at any time in the period of 7 days beginning with the day on which the warrant is issued.
(5)For the purposes of this paragraph, a copy of information is in an “appropriate form” if —
(a)it can be taken away, and
(b)it is visible and legible or it can readily be made visible and legible.
Commencement Information
I303Sch. 15 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Copies of warrantsU.K.
6U.K.A judge who issues a warrant under this Schedule must—
(a)issue two copies of it, and
(b)certify them clearly as copies.
Commencement Information
I304Sch. 15 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Execution of warrants: reasonable forceU.K.
7U.K.A person executing a warrant issued under this Schedule may use such reasonable force as may be necessary.
Commencement Information
I305Sch. 15 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Execution of warrants: time when executedU.K.
8U.K.A warrant issued under this Schedule may be executed only at a reasonable hour, unless it appears to the person executing it that there are grounds for suspecting that exercising it at a reasonable hour would defeat the object of the warrant.
Commencement Information
I306Sch. 15 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Execution of warrants: occupier of premisesU.K.
9(1)If an occupier of the premises in respect of which a warrant is issued under this Schedule is present when the warrant is executed, the person executing the warrant must—U.K.
(a)show the occupier the warrant, and
(b)give the occupier a copy of it.
(2)Otherwise, a copy of the warrant must be left in a prominent place on the premises.
Commencement Information
I307Sch. 15 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Execution of warrants: seizure of documents etcU.K.
10(1)This paragraph applies where a person executing a warrant under this Schedule seizes something.U.K.
(2)The person must, on request—
(a)give a receipt for it, and
(b)give an occupier of the premises a copy of it.
(3)Sub-paragraph (2)(b) does not apply if the person executing the warrant considers that providing a copy would result in undue delay.
(4)Anything seized may be retained for so long as is necessary in all the circumstances.
Commencement Information
I308Sch. 15 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Matters exempt from inspection and seizure: privileged communicationsU.K.
11(1)The powers of inspection and seizure conferred by a warrant issued under this Schedule are not exercisable in respect of a communication which is made—U.K.
(a)between a professional legal adviser and the adviser's client, and
(b)in connection with the giving of legal advice to the client with respect to obligations, liabilities or rights under the data protection legislation.
(2)The powers of inspection and seizure conferred by a warrant issued under this Schedule are not exercisable in respect of a communication which is made—
(a)between a professional legal adviser and the adviser's client or between such an adviser or client and another person,
(b)in connection with or in contemplation of proceedings under or arising out of the data protection legislation, and
(c)for the purposes of such proceedings.
(3)Sub-paragraphs (1) and (2) do not prevent the exercise of powers conferred by a warrant issued under this Schedule in respect of—
(a)anything in the possession of a person other than the professional legal adviser or the adviser's client, or
(b)anything held with the intention of furthering a criminal purpose.
(4)The references to a communication in sub-paragraphs (1) and (2) include—
(a)a copy or other record of the communication, and
(b)anything enclosed with or referred to in the communication if made as described in sub-paragraph (1)(b) or in sub-paragraph (2)(b) and (c).
(5)In sub-paragraphs (1) to (3), the references to the client of a professional legal adviser include a person acting on behalf of such a client.
Commencement Information
I309Sch. 15 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Matters exempt from inspection and seizure: Parliamentary privilegeU.K.
12U.K.The powers of inspection and seizure conferred by a warrant issued under this Schedule are not exercisable where their exercise would involve an infringement of the privileges of either House of Parliament.
Commencement Information
I310Sch. 15 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Partially exempt materialU.K.
13(1)This paragraph applies if a person in occupation of premises in respect of which a warrant is issued under this Schedule objects to the inspection or seizure of any material under the warrant on the grounds that it consists partly of matters in respect of which those powers are not exercisable.U.K.
(2)The person must, if the person executing the warrant so requests, provide that person with a copy of so much of the material as is not exempt from those powers.
Commencement Information
I311Sch. 15 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Return of warrantsU.K.
14(1)Where a warrant issued under this Schedule is executed—U.K.
(a)it must be returned to the court from which it was issued after being executed, and
(b)the person by whom it is executed must write on the warrant a statement of the powers that have been exercised under the warrant.
(2)Where a warrant issued under this Schedule is not executed, it must be returned to the court from which it was issued within the time authorised for its execution.
Commencement Information
I312Sch. 15 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
OffencesU.K.
15(1)It is an offence for a person—U.K.
(a)intentionally to obstruct a person in the execution of a warrant issued under this Schedule, or
(b)to fail without reasonable excuse to give a person executing such a warrant such assistance as the person may reasonably require for the execution of the warrant.
(2)It is an offence for a person—
(a)to make a statement in response to a requirement under paragraph 5(2)(c) or (d) or (3)(c) or (d) which the person knows to be false in a material respect, or
(b)recklessly to make a statement in response to such a requirement which is false in a material respect.
Commencement Information
I313Sch. 15 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Self-incriminationU.K.
16(1)An explanation given, or information provided, by a person in response to a requirement under paragraph 5(2)(c) or (d) or (3)(c) or (d) may only be used in evidence against that person—U.K.
(a)on a prosecution for an offence under a provision listed in sub-paragraph (2), or
(b)on a prosecution for any other offence where—
(i)in giving evidence that person makes a statement inconsistent with that explanation or information, and
(ii)evidence relating to that explanation or information is adduced, or a question relating to it is asked, by that person or on that person's behalf.
(2)Those provisions are—
(a)paragraph 15,
(b)section 5 of the Perjury Act 1911 (false statements made otherwise than on oath),
(c)section 44(2) of the Criminal Law (Consolidation) (Scotland) Act 1995 (false statements made otherwise than on oath), or
(d)Article 10 of the Perjury (Northern Ireland) Order 1979 (S.I. 1979/1714 (N.I. 19)) (false statutory declarations and other false unsworn statements).
Commencement Information
I314Sch. 15 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Vessels, vehicles etcU.K.
17U.K.In this Schedule—
(a)“premises” includes a vehicle, vessel or other means of transport, and
(b)references to the occupier of premises include the person in charge of a vehicle, vessel or other means of transport.
Commencement Information
I315Sch. 15 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
ScotlandU.K.
18U.K.In the application of this Schedule to Scotland—
(a)references to a judge of the High Court have effect as if they were references to a judge of the Court of Session,
(b)references to a circuit judge have effect as if they were references to the sheriff or the summary sheriff,
(c)references to information on oath have effect as if they were references to evidence on oath, and
(d)references to the court from which the warrant was issued have effect as if they were references to the sheriff clerk.
Commencement Information
I316Sch. 15 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Northern IrelandU.K.
19U.K.In the application of this Schedule to Northern Ireland—
(a)references to a circuit judge have effect as if they were references to a county court judge, and
(b)references to information on oath have effect as if they were references to a complaint on oath.
Commencement Information
I317Sch. 15 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Section 155
SCHEDULE 16U.K.Penalties
Modifications etc. (not altering text)
C11Sch. 16 applied (with modifications) by S.I. 2016/696, Sch. 2 (as substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 406 (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g) (with reg. 4))
Meaning of “penalty”U.K.
1U.K.In this Schedule, “penalty” means a penalty imposed by a penalty notice.
Commencement Information
I318Sch. 16 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Notice of intent to impose penaltyU.K.
2(1)Before giving a person a penalty notice, the Commissioner must, by written notice (a “notice of intent”) inform the person that the Commissioner intends to give a penalty notice.U.K.
(2)The Commissioner may not give a penalty notice to a person in reliance on a notice of intent after the end of the period of 6 months beginning when the notice of intent is given, subject to sub-paragraph (3).
(3)The period for giving a penalty notice to a person may be extended by agreement between the Commissioner and the person.
Commencement Information
I319Sch. 16 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Contents of notice of intentU.K.
3(1)A notice of intent must contain the following information—U.K.
(a)the name and address of the person to whom the Commissioner proposes to give a penalty notice;
(b)the reasons why the Commissioner proposes to give a penalty notice (see sub-paragraph (2));
(c)an indication of the amount of the penalty the Commissioner proposes to impose, including any aggravating or mitigating factors that the Commissioner proposes to take into account.
(2)The information required under sub-paragraph (1)(b) includes—
(a)a description of the circumstances of the failure, and
(b)where the notice is given in respect of a failure described in section 149(2), the nature of the personal data involved in the failure.
(3)A notice of intent must also—
(a)state that the person may make written representations about the Commissioner's intention to give a penalty notice, and
(b)specify the period within which such representations may be made.
(4)The period specified for making written representations must be a period of not less than 21 days beginning when the notice of intent is given.
(5)If the Commissioner considers that it is appropriate for the person to have an opportunity to make oral representations about the Commissioner's intention to give a penalty notice, the notice of intent must also—
(a)state that the person may make such representations, and
(b)specify the arrangements for making such representations and the time at which, or the period within which, they may be made.
Commencement Information
I320Sch. 16 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Giving a penalty noticeU.K.
4(1)The Commissioner may not give a penalty notice before a time, or before the end of a period, specified in the notice of intent for making oral or written representations.U.K.
(2)When deciding whether to give a penalty notice to a person and determining the amount of the penalty, the Commissioner must consider any oral or written representations made by the person in accordance with the notice of intent.
Commencement Information
I321Sch. 16 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Contents of penalty noticeU.K.
5(1)A penalty notice must contain the following information—U.K.
(a)the name and address of the person to whom it is addressed;
(b)details of the notice of intent given to the person;
(c)whether the Commissioner received oral or written representations in accordance with the notice of intent;
(d)the reasons why the Commissioner proposes to impose the penalty (see sub-paragraph (2));
(e)the reasons for the amount of the penalty, including any aggravating or mitigating factors that the Commissioner has taken into account;
(f)details of how the penalty is to be paid;
(g)details of the rights of appeal under section 162;
(h)details of the Commissioner's enforcement powers under this Schedule.
(2)The information required under sub-paragraph (1)(d) includes—
(a)a description of the circumstances of the failure, and
(b)where the notice is given in respect of a failure described in section 149(2), the nature of the personal data involved in the failure.
Commencement Information
I322Sch. 16 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Period for payment of penaltyU.K.
6(1)A penalty must be paid to the Commissioner within the period specified in the penalty notice.U.K.
(2)The period specified must be a period of not less than 28 days beginning when the penalty notice is given.
Commencement Information
I323Sch. 16 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Variation of penaltyU.K.
7(1)The Commissioner may vary a penalty notice by giving written notice (a “penalty variation notice”) to the person to whom it was given.U.K.
(2)A penalty variation notice must specify—
(a)the penalty notice concerned, and
(b)how it is varied.
(3)A penalty variation notice may not—
(a)reduce the period for payment of the penalty;
(b)increase the amount of the penalty;
(c)otherwise vary the penalty notice to the detriment of the person to whom it was given.
(4)If—
(a)a penalty variation notice reduces the amount of the penalty, and
(b)when that notice is given, an amount has already been paid that exceeds the amount of the reduced penalty,
the Commissioner must repay the excess.
Commencement Information
I324Sch. 16 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Cancellation of penaltyU.K.
8(1)The Commissioner may cancel a penalty notice by giving written notice to the person to whom it was given.U.K.
(2)If a penalty notice is cancelled, the Commissioner—
(a)may not take any further action under section 155 or this Schedule in relation to the failure to which that notice relates, and
(b)must repay any amount that has been paid in accordance with that notice.
Commencement Information
I325Sch. 16 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Enforcement of paymentU.K.
9(1)The Commissioner must not take action to recover a penalty unless—U.K.
(a)the period specified in accordance with paragraph 6 has ended,
(b)any appeals against the penalty notice have been decided or otherwise ended,
(c)if the penalty notice has been varied, any appeals against the penalty variation notice have been decided or otherwise ended, and
(d)the period for the person to whom the penalty notice was given to appeal against the penalty, and any variation of it, has ended.
(2)In England and Wales, a penalty is recoverable—
(a)if the county court so orders, as if it were payable under an order of that court;
(b)if the High Court so orders, as if it were payable under an order of that court.
(3)In Scotland, a penalty may be enforced in the same manner as an extract registered decree arbitral bearing a warrant for execution issued by the sheriff court of any sheriffdom in Scotland.
(4)In Northern Ireland, a penalty is recoverable—
(a)if a county court so orders, as if it were payable under an order of that court;
(b)if the High Court so orders, as if it were payable under an order of that court.
Commencement Information
I326Sch. 16 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(f)
Yn ddilys o 23/07/2018
Section 178
SCHEDULE 17U.K.Review of processing of personal data for the purposes of journalism
InterpretationU.K.
1U.K.In this Schedule—
“relevant period” means—
(a)the period of 18 months beginning when the Commissioner starts the first review under section 178, and
(b)the period of 12 months beginning when the Commissioner starts a subsequent review under that section;
“the relevant review”, in relation to a relevant period, means the review under section 178 which the Commissioner must produce a report about by the end of that period.
Information noticesU.K.
2(1)This paragraph applies where the Commissioner gives an information notice during a relevant period.U.K.
(2)If the information notice—
(a)states that, in the Commissioner's opinion, the information is required for the purposes of the relevant review, and
(b)gives the Commissioner's reasons for reaching that opinion,
subsections (5) and (6) of section 142 do not apply but the notice must not require the information to be provided before the end of the period of 24 hours beginning when the notice is given.
Assessment noticesU.K.
3(1)Sub-paragraph (2) applies where the Commissioner gives an assessment notice to a person during a relevant period.U.K.
(2)If the assessment notice—
(a)states that, in the Commissioner's opinion, it is necessary for the controller or processor to comply with a requirement in the notice for the purposes of the relevant review, and
(b)gives the Commissioner's reasons for reaching that opinion,
subsections (6) and (7) of section 146 do not apply but the notice must not require the controller or processor to comply with the requirement before the end of the period of 7 days beginning when the notice is given.
(3)During a relevant period, section 147 has effect as if for subsection (5) there were substituted—
“(5)The Commissioner may not give a controller or processor an assessment notice with respect to the processing of personal data for the special purposes unless a determination under section 174 with respect to the data or the processing has taken effect.”
Applications in respect of urgent noticesU.K.
4U.K.Section 164 applies where an information notice or assessment notice contains a statement under paragraph 2(2)(a) or 3(2)(a) as it applies where such a notice contains a statement under section 142(7)(a) or 146(8)(a).
Section 184
SCHEDULE 18U.K.Relevant records
Relevant recordsU.K.
1(1)In section 184, “relevant record” means—U.K.
(a)a relevant health record (see paragraph 2),
(b)a relevant record relating to a conviction or caution (see paragraph 3), or
(c)a relevant record relating to statutory functions (see paragraph 4).
(2)A record is not a “relevant record” to the extent that it relates, or is to relate, only to personal data which falls within section 21(2) (manual unstructured personal data held by FOI public authorities).
Commencement Information
I327Sch. 18 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Relevant health recordsU.K.
2U.K.“Relevant health record” means a health record which has been or is to be obtained by a data subject in the exercise of a data subject access right.
Commencement Information
I328Sch. 18 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Relevant records relating to a conviction or cautionU.K.
3(1)“Relevant record relating to a conviction or caution” means a record which—U.K.
(a)has been or is to be obtained by a data subject in the exercise of a data subject access right from a person listed in sub-paragraph (2), and
(b)contains information relating to a conviction or caution.
(2)Those persons are—
(a)the chief constable of a police force maintained under section 2 of the Police Act 1996;
(b)the Commissioner of Police of the Metropolis;
(c)the Commissioner of Police for the City of London;
(d)the Chief Constable of the Police Service of Northern Ireland;
(e)the chief constable of the Police Service of Scotland;
(f)the Director General of the National Crime Agency;
(g)the Secretary of State.
(3)In this paragraph—
“caution” means a caution given to a person in England and Wales or Northern Ireland in respect of an offence which, at the time when the caution is given, is admitted;
“conviction” has the same meaning as in the Rehabilitation of Offenders Act 1974 or the Rehabilitation of Offenders (Northern Ireland) Order 1978 (S.I. 1978/1908 (N.I. 27)).
Commencement Information
I329Sch. 18 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Relevant records relating to statutory functionsU.K.
4(1)“Relevant record relating to statutory functions” means a record which—U.K.
(a)has been or is to be obtained by a data subject in the exercise of a data subject access right from a person listed in sub-paragraph (2), and
(b)contains information relating to a relevant function in relation to that person.
(2)Those persons are—
(a)the Secretary of State;
(b)the Department for Communities in Northern Ireland;
(c)the Department of Justice in Northern Ireland;
(d)the Scottish Ministers;
(e)the Disclosure and Barring Service.
(3)In relation to the Secretary of State, the “relevant functions” are—
(a)the Secretary of State's functions in relation to a person sentenced to detention under—
(i)section 92 of the Powers of Criminal Courts (Sentencing) Act 2000,
(ii)section 205(2) or 208 of the Criminal Procedure (Scotland) Act 1995, or
(iii)Article 45 of the Criminal Justice (Children) (Northern Ireland) Order 1998 (S.I. 1998/1504 (N.I. 9));
(b)the Secretary of State's functions in relation to a person imprisoned or detained under—
(i)the Prison Act 1952,
(ii)the Prisons (Scotland) Act 1989, or
(iii)the Prison Act (Northern Ireland) 1953 (c. 18 (N.I.));
(c)the Secretary of State's functions under—
(i)the Social Security Contributions and Benefits Act 1992,
(ii)the Social Security Administration Act 1992,
(iii)the Jobseekers Act 1995,
(iv)Part 5 of the Police Act 1997,
(v)Part 1 of the Welfare Reform Act 2007, or
(vi)Part 1 of the Welfare Reform Act 2012.
(4)In relation to the Department for Communities in Northern Ireland, the “relevant functions” are its functions under—
(a)the Social Security Contributions and Benefits (Northern Ireland) Act 1992,
(b)the Social Security Administration (Northern Ireland) Act 1992,
(c)the Jobseekers (Northern Ireland) Order 1995 (S.I. 1995/2705 (N.I. 15)), or
(d)Part 1 of the Welfare Reform Act (Northern Ireland) 2007 (c. 2 (N.I.)).
(5)In relation to the Department of Justice in Northern Ireland, the “relevant functions” are its functions under Part 5 of the Police Act 1997.
(6)In relation to the Scottish Ministers, the “relevant functions” are their functions under
(a)Part 5 of the Police Act 1997, or
(b)Parts 1 and 2 of the Protection of Vulnerable Groups (Scotland) Act 2007 (asp 14).
(7)In relation to the Disclosure and Barring Service, the “relevant functions” are its functions under—
(a)Part 5 of the Police Act 1997,
(b)the Safeguarding Vulnerable Groups Act 2006, or
(c)the Safeguarding Vulnerable Groups (Northern Ireland) Order 2007 (S.I. 2007/1351 (N.I. 11)).
Commencement Information
I330Sch. 18 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data subject access rightU.K.
5U.K.In this Schedule, “data subject access right” means a right under—
(a)Article 15 of the GDPR (right of access by the data subject);
(b)Article 20 of the GDPR (right to data portability);
(c)section 45 of this Act (law enforcement processing: right of access by the data subject);
(d)section 94 of this Act (intelligence services processing: right of access by the data subject).
Commencement Information
I331Sch. 18 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Records stating that personal data is not processedU.K.
6U.K.For the purposes of this Schedule, a record which states that a controller is not processing personal data relating to a particular matter is to be taken to be a record containing information relating to that matter.
Commencement Information
I332Sch. 18 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Power to amendU.K.
7(1)The Secretary of State may by regulations amend this Schedule.U.K.
(2)Regulations under this paragraph are subject to the affirmative resolution procedure.
Commencement Information
I333Sch. 18 para. 7 in force at Royal Assent for specified purposes, see s. 212(2)(f)
I334Sch. 18 para. 7 in force at 25.5.2018 in so far as not already in force by S.I. 2018/625, reg. 2(1)(g)
Section 211
SCHEDULE 19U.K.Minor and consequential amendments
PART 1 U.K.Amendments of primary legislation
Registration Service Act 1953 (c. 37)U.K.
1(1)Section 19AC of the Registration Service Act 1953 (codes of practice) is amended as follows.U.K.
(2)In subsection (2), for “issued under section 52B (data-sharing code) of the Data Protection Act 1998” substitute “ prepared under section 121 of the Data Protection Act 2018 (data-sharing code) and issued under section 125(4) of that Act ”.
(3)In subsection (11), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 ”.
Commencement Information
I335Sch. 19 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Veterinary Surgeons Act 1966 (c. 36)U.K.
2(1)Section 1A of the Veterinary Surgeons Act 1966 (functions of the Royal College of Veterinary Surgeons as competent authority) is amended as follows.U.K.
(2)In subsection (8)—
(a)omit “personal data protection legislation in the United Kingdom that implements”,
(b)for paragraph (a) substitute—
“(a)the GDPR; and”, and
(c)in paragraph (b), at the beginning insert “ legislation in the United Kingdom that implements ”.
(3)In subsection (9), after “section” insert “—
“the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I336Sch. 19 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Parliamentary Commissioner Act 1967 (c. 13)U.K.
3U.K.In section 11AA(1) of the Parliamentary Commissioner Act 1967 (disclosure of information by Parliamentary Commissioner to Information Commissioner)—
(a)in paragraph (a), for sub-paragraph (i) substitute—
“(i)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement),”, and
(b)for paragraph (b) substitute—
“(b)the commission of an offence under—
(i)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc), or
(ii)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I337Sch. 19 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Local Government Act 1974 (c. 7)U.K.
4U.K.The Local Government Act 1974 is amended as follows.
Commencement Information
I338Sch. 19 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
5U.K.In section 33A(1) (disclosure of information by Local Commissioner to Information Commissioner)—
(a)in paragraph (a), for sub-paragraph (i) substitute—
“(i)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement),”, and
(b)for paragraph (b) substitute—
“(b)the commission of an offence under—
(i)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc), or
(ii)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I339Sch. 19 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
6U.K.In section 34O(1) (disclosure of information by Local Commissioner to Information Commissioner)—
(a)in paragraph (a), for sub-paragraph (i) substitute—
“(i)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement),”, and
(b)for paragraph (b) substitute—
“(b)the commission of an offence under—
(i)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc), or
(ii)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I340Sch. 19 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Consumer Credit Act 1974 (c. 39)U.K.
7U.K.The Consumer Credit Act 1974 is amended as follows.
Commencement Information
I341Sch. 19 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
8U.K.In section 157(2A) (duty to disclose name etc of agency)—
(a)in paragraph (a), for “the Data Protection Act 1998” substitute “ the GDPR ”, and
(b)in paragraph (b), after “any” insert “ other ”.
Commencement Information
I342Sch. 19 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
9U.K.In section 159(1)(a) (correction of wrong information) for “section 7 of the Data Protection Act 1998” substitute “ Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers) ”.
Commencement Information
I343Sch. 19 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
10U.K.In section 189(1) (definitions), at the appropriate place insert—
““the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act);”.
Commencement Information
I344Sch. 19 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Pharmacy (Northern Ireland) Order 1976 (S.I. 1976/1213 (N.I. 22))U.K.
11U.K.The Pharmacy (Northern Ireland) Order 1976 is amended as follows.
Commencement Information
I345Sch. 19 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
12U.K.In article 2(2) (interpretation), omit the definition of “Directive 95/46/EC”.
Commencement Information
I346Sch. 19 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
13U.K.In article 8D (European professional card), after paragraph (3) insert—
“(4)In Schedule 2C, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018.”
Commencement Information
I347Sch. 19 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
14U.K.In article 22A(6) (Directive 2005/36/EC: functions of competent authority etc.), before sub-paragraph (a) insert—
“(za)“the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I348Sch. 19 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
15(1)Schedule 2C (Directive 2005/36/EC: European professional card) is amended as follows.U.K.
(2)In paragraph 8(1) (access to data), for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In paragraph 9 (processing data), omit sub-paragraph (2) (deeming the Society to be the controller for the purposes of Directive 95/46/EC).
Commencement Information
I349Sch. 19 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
16(1)The table in Schedule 2D (functions of the Society under Directive 2005/36/EC) is amended as follows.U.K.
(2)In the entry for Article 56(2), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In the entry for Article 56a(4), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I350Sch. 19 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
17(1)Paragraph 2 of Schedule 3 (fitness to practice: disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (2)(a), after “provision” insert “ or the GDPR ”.
(3)For sub-paragraph (3) substitute—
“(3)In determining for the purposes of sub-paragraph (2)(a) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this paragraph.”
(4)After sub-paragraph (4) insert—
“(5)In this paragraph, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I351Sch. 19 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Representation of the People Act 1983 (c. 2)U.K.
18(1)Schedule 2 to the Representation of the People Act 1983 (provisions which may be contained in regulations as to registration etc) is amended as follows.U.K.
(2)In paragraph 1A(5), for “the Data Protection Act 1998” substitute “ Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act) ”.
(3)In paragraph 8C(2), for “the Data Protection Act 1998” substitute “ Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act) ”.
(4)In paragraph 11A—
(a)in sub-paragraph (1) for “who are data users to supply data, or documents containing information extracted from data and” substitute “ to supply information ”, and
(b)omit sub-paragraph (2).
Commencement Information
I352Sch. 19 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Medical Act 1983 (c. 54)U.K.
19U.K.The Medical Act 1983 is amended as follows.
Commencement Information
I353Sch. 19 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
20(1)Section 29E (evidence) is amended as follows.U.K.
(2)In subsection (5), after “enactment” insert “ or the GDPR ”.
(3)For subsection (7) substitute—
“(7)In determining for the purposes of subsection (5) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this section.”
(4)In subsection (9), at the end insert—
““the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I354Sch. 19 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
21(1)Section 35A (General Medical Council's power to require disclosure of information) is amended as follows.U.K.
(2)In subsection (4), after “enactment” insert “ or the GDPR ”.
(3)For subsection (5A) substitute—
“(5A)In determining for the purposes of subsection (4) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this section.”
(4)In subsection (7), at the end insert—
““the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I355Sch. 19 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
22U.K.In section 49B(7) (Directive 2005/36: designation of competent authority etc.), after “Schedule 4A” insert “—
“the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I356Sch. 19 para. 22 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
23U.K.In section 55(1) (interpretation), omit the definition of “Directive 95/46/EC”.
Commencement Information
I357Sch. 19 para. 23 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
24(1)Paragraph 9B of Schedule 1 (incidental powers of the General Medical Council) is amended as follows.U.K.
(2)In sub-paragraph (2)(a), after “enactment” insert “ or the GPDR ”.
(3)After sub-paragraph (3) insert—
“(4)In this paragraph, “the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I358Sch. 19 para. 24 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
25(1)Paragraph 5A of Schedule 4 (professional performance assessments and health assessments) is amended as follows.U.K.
(2)In sub-paragraph (8), after “enactment” insert “ or the GDPR ”.
(3)For sub-paragraph (8A) substitute—
“(8A)In determining for the purposes of sub-paragraph (8) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this paragraph.”
(4)After sub-paragraph (13) insert—
“(14)In this paragraph, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I359Sch. 19 para. 25 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
26(1)The table in Schedule 4A (functions of the General Medical Council as competent authority under Directive 2005/36) is amended as follows.U.K.
(2)In the entry for Article 56(2), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In the entry for Article 56a(4), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I360Sch. 19 para. 26 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Dentists Act 1984 (c. 24)U.K.
27U.K.The Dentists Act 1984 is amended as follows.
Commencement Information
I361Sch. 19 para. 27 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
28(1)Section 33B (the General Dental Council's power to require disclosure of information: the dental profession) is amended as follows.U.K.
(2)In subsection (3), after “enactment” insert “ or relevant provision of the GDPR ”.
(3)For subsection (4) substitute—
“(4)For the purposes of subsection (3)—
“relevant enactment” means any enactment other than—
(a)this Act, or
(b)the listed provisions in paragraph 1 of Schedule 11 to the Data Protection Act 2018 (exemptions to Part 4 : disclosures required by law);
“relevant provision of the GDPR” means any provision of the GDPR apart from the listed GDPR provisions in paragraph 1 of Schedule 2 to the Data Protection Act 2018 (GDPR provisions to be adapted or restricted: disclosures required by law).”
(4)After subsection (10) insert—
“(11)In this section, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I362Sch. 19 para. 28 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
29U.K.In section 36ZA(6) (Directive 2005/36: designation of competent authority etc), after “Schedule 4ZA—” insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I363Sch. 19 para. 29 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
30(1)Section 36Y (the General Dental Council's power to require disclosure of information: professions complementary to dentistry) is amended as follows.U.K.
(2)In subsection (3), after “enactment” insert “ or relevant provision of the GDPR ”.
(3)For subsection (4) substitute—
“(4)For the purposes of subsection (3)—
“relevant enactment” means any enactment other than—
(a)this Act, or
(b)the listed provisions in paragraph 1 of Schedule 11 to the Data Protection Act 2018 (exemptions to Part 4 : disclosures required by law);
“relevant provision of the GDPR” means any provision of the GDPR apart from the listed GDPR provisions in paragraph 1 of Schedule 2 to the Data Protection Act 2018 (GDPR provisions to be adapted or restricted: disclosures required by law).”
(4)After subsection (10) insert—
“(11)In this section, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I364Sch. 19 para. 30 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
31U.K.In section 53(1) (interpretation), omit the definition of “Directive 95/46/EC”.
Commencement Information
I365Sch. 19 para. 31 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
32(1)The table in Schedule 4ZA (Directive 2005/36: functions of the General Dental Council under section 36ZA(3)) is amended as follows.U.K.
(2)In the entry for Article 56(2), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In the entry for Article 56a(4), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I366Sch. 19 para. 32 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Companies Act 1985 (c. 6)U.K.
33U.K.In section 449(11) of the Companies Act 1985 (provision for security of information obtained), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I367Sch. 19 para. 33 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Access to Medical Reports Act 1988 (c. 28)U.K.
34U.K.In section 2(1) of the Access to Medical Reports Act 1988 (interpretation), for the definition of “health professional” substitute—
““health professional” has the same meaning as in the Data Protection Act 2018 (see section 204 of that Act);”.
Commencement Information
I368Sch. 19 para. 34 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Opticians Act 1989 (c. 44)U.K.
35(1)Section 13B of the Opticians Act 1989 (the Council's power to require disclosure of information) is amended as follows.U.K.
(2)In subsection (3), after “enactment” insert “ or the GDPR ”.
(3)For subsection (4) substitute—
“(4)In determining for the purposes of subsection (3) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this section.”
(4)After subsection (9) insert—
“(10)In this section, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I369Sch. 19 para. 35 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Access to Health Records Act 1990 (c. 23)U.K.
36U.K.The Access to Health Records Act 1990 is amended as follows.
Commencement Information
I370Sch. 19 para. 36 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
37U.K.For section 2 substitute—
“2Health professionals
In this Act, “health professional” has the same meaning as in the Data Protection Act 2018 (see section 204 of that Act).”
Commencement Information
I371Sch. 19 para. 37 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
38(1)Section 3 (right of access to health records) is amended as follows.U.K.
(2)In subsection (2), omit “Subject to subsection (4) below,”.
(3)In subsection (4), omit from “other than the following” to the end.
Commencement Information
I372Sch. 19 para. 38 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Human Fertilisation and Embryology Act 1990 (c. 37)U.K.
39(1)Section 33D of the Human Fertilisation and Embryology Act 1990 (disclosure for the purposes of medical or other research) is amended as follows.U.K.
(2)In subsection (6), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (9), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I373Sch. 19 para. 39 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Trade Union and Labour Relations (Consolidation) Act 1992 (c. 52)U.K.
40(1)Section 251B of the Trade Union and Labour Relations (Consolidation) Act 1992 (prohibition on disclosure of information) is amended as follows.U.K.
(2)In subsection (3), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (6) insert—
“(7)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I374Sch. 19 para. 40 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Tribunals and Inquiries Act 1992 (c. 53)U.K.
41U.K.In the table in Part 1 of Schedule 1 to the Tribunals and Inquiries Act 1992 (tribunals to which the Act applies), in the second column, in paragraph 14(a), for “section 6 of the Data Protection Act 1998” substitute “ section 114 of the Data Protection Act 2018 ”.
Commencement Information
I375Sch. 19 para. 41 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Industrial Relations (Northern Ireland) Order 1992 (S.I. 1992/807 (N.I. 5))U.K.
42(1)Article 90B of the Industrial Relations (Northern Ireland) Order 1992 (prohibition on disclosure of information held by the Labour Relations Agency) is amended as follows.U.K.
(2)In paragraph (3), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After paragraph (6) insert—
“(7)In this Article, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I376Sch. 19 para. 42 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Health Service Commissioners Act 1993 (c. 46)U.K.
43U.K.In section 18A(1) of the Health Service Commissioners Act 1993 (power to disclose information)—
(a)in paragraph (a), for sub-paragraph (i) substitute—
“(i)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement),”, and
(b)for paragraph (b) substitute—
“(b)the commission of an offence under—
(i)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc), or
(ii)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I377Sch. 19 para. 43 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection Act 1998 (c. 29)U.K.
44U.K.The Data Protection Act 1998 is repealed, with the exception of section 62 and paragraphs 13, 15, 16, 18 and 19 of Schedule 15 (which amend other enactments).
Commencement Information
I378Sch. 19 para. 44 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Crime and Disorder Act 1998 (c. 37)U.K.
45U.K.In section 17A(4) of the Crime and Disorder Act 1998 (sharing of information), for “(within the meaning of the Data Protection Act 1998)” substitute “ (within the meaning of Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act)) ”.
Commencement Information
I379Sch. 19 para. 45 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Food Standards Act 1999 (c. 28)U.K.
46(1)Section 19 of the Food Standards Act 1999 (publication etc by the Food Standards Agency of advice and information) is amended as follows.U.K.
(2)In subsection (2), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (8), after “section” insert “—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I380Sch. 19 para. 46 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Immigration and Asylum Act 1999 (c. 33)U.K.
47(1)Section 13 of the Immigration and Asylum Act 1999 (proof of identity of persons to be removed or deported) is amended as follows.U.K.
(2)For subsection (4) substitute—
“(4)For the purposes of Article 49(1)(d) of the GDPR, the provision under this section of identification data is a transfer of personal data which is necessary for important reasons of public interest.”
(3)After subsection (4) insert—
“(4A)“The GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I381Sch. 19 para. 47 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Financial Services and Markets Act 2000 (c. 8)U.K.
48U.K.The Financial Services and Markets Act 2000 is amended as follows.
Commencement Information
I382Sch. 19 para. 48 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
49U.K.In section 86(9) (exempt offers to the public), for “the Data Protection Act 1998 or any directly applicable EU legislation relating to data protection” substitute “—
(a)the data protection legislation, or
(b)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection”.
Commencement Information
I383Sch. 19 para. 49 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
50U.K.In section 391A(6)(b) (publication: special provisions relating to the capital requirements directive), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I384Sch. 19 para. 50 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
51U.K.In section 391C(7)(a) (publication: special provisions relating to the UCITS directive), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I385Sch. 19 para. 51 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
52U.K.In section 391D(9)(a) (publication: special provisions relating to the markets in financial instruments directive), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I386Sch. 19 para. 52 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
53U.K.In section 417 (definitions), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I387Sch. 19 para. 53 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Terrorism Act 2000 (c. 11)U.K.
54U.K.In section 21F(2)(d) of the Terrorism Act 2000 (other permitted disclosures between institutions etc) for “(within the meaning of section 1 of the Data Protection Act 1998)” substitute “ (within the meaning of Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act)) ”.
Commencement Information
I388Sch. 19 para. 54 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Freedom of Information Act 2000 (c. 36)U.K.
55U.K.The Freedom of Information Act 2000 is amended as follows.
Commencement Information
I389Sch. 19 para. 55 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
56U.K.In section 2(3) (absolute exemptions), for paragraph (f) substitute—
“(f)section 40(1),
(fa)section 40(2) so far as relating to cases where the first condition referred to in that subsection is satisfied,”.
Commencement Information
I390Sch. 19 para. 56 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
57U.K.In section 18 (the Information Commissioner), omit subsection (1).
Commencement Information
I391Sch. 19 para. 57 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
58(1)Section 40 (personal information) is amended as follows.U.K.
(2)In subsection (2)—
(a)in paragraph (a), for “do” substitute “ does ”, and
(b)in paragraph (b), for “either the first or the second” substitute “ the first, second or third ”.
(3)For subsection (3) substitute—
“(3A)The first condition is that the disclosure of the information to a member of the public otherwise than under this Act—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(3B)The second condition is that the disclosure of the information to a member of the public otherwise than under this Act would contravene Article 21 of the GDPR (general processing: right to object to processing).”
(4)For subsection (4) substitute—
“(4A)The third condition is that—
(a)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018, or
(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section.”
(5)For subsection (5) substitute—
“(5A)The duty to confirm or deny does not arise in relation to information which is (or if it were held by the public authority would be) exempt information by virtue of subsection (1).
(5B)The duty to confirm or deny does not arise in relation to other information if or to the extent that any of the following applies—
(a)giving a member of the public the confirmation or denial that would have to be given to comply with section 1(1)(a)—
(i)would (apart from this Act) contravene any of the data protection principles, or
(ii)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded;
(b)giving a member of the public the confirmation or denial that would have to be given to comply with section 1(1)(a) would (apart from this Act) contravene Article 21 of the GDPR (general processing: right to object to processing);
(c)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for confirmation of whether personal data is being processed, the information would be withheld in reliance on a provision listed in subsection (4A)(a);
(d)on a request under section 45(1)(a) of the Data Protection Act 2018 (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section.”
(6)Omit subsection (6).
(7)For subsection (7) substitute—
“(7)In this section—
“the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR, and
(b)section 34(1) of the Data Protection Act 2018;
“data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“the GDPR”, “personal data”, “processing” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4), (10), (11) and (14) of that Act).
(8)In determining for the purposes of this section whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
Commencement Information
I392Sch. 19 para. 58 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
59U.K.Omit section 49 (reports to be laid before Parliament).
Commencement Information
I393Sch. 19 para. 59 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
60U.K.For section 61 (appeal proceedings) substitute—
“61Appeal proceedings
(1)Tribunal Procedure Rules may make provision for regulating the exercise of rights of appeal conferred by sections 57(1) and (2) and 60(1) and (4).
(2)In relation to appeals under those provisions, Tribunal Procedure Rules may make provision about—
(a)securing the production of material used for the processing of personal data, and
(b)the inspection, examination, operation and testing of equipment or material used in connection with the processing of personal data.
(3)Subsection (4) applies where—
(a)a person does something, or fails to do something, in relation to proceedings before the First-tier Tribunal on an appeal under those provisions, and
(b)if those proceedings were proceedings before a court having power to commit for contempt, the act or omission would constitute contempt of court.
(4)The First-tier Tribunal may certify the offence to the Upper Tribunal.
(5)Where an offence is certified under subsection (4), the Upper Tribunal may—
(a)inquire into the matter, and
(b)deal with the person charged with the offence in any manner in which it could deal with the person if the offence had been committed in relation to the Upper Tribunal.
(6)Before exercising the power under subsection (5)(b), the Upper Tribunal must—
(a)hear any witness who may be produced against or on behalf of the person charged with the offence, and
(b)hear any statement that may be offered in defence.
(7)In this section, “personal data” and “processing” have the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2), (4) and (14) of that Act).”
Commencement Information
I394Sch. 19 para. 60 in force at Royal Assent for specified purposes, see s. 212(2)(f)
I395Sch. 19 para. 60 in force at 25.5.2018 in so far as not already in force by S.I. 2018/625, reg. 2(1)(g)
61U.K.In section 76(1) (disclosure of information between Commissioner and ombudsmen), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I396Sch. 19 para. 61 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
62U.K.After section 76A insert—
“76BDisclosure of information to Tribunal
(1)No enactment or rule of law prohibiting or restricting the disclosure of information precludes a person from providing the First-tier Tribunal or the Upper Tribunal with information necessary for the discharge of their functions in connection with appeals under section 60 of this Act.
(2)But this section does not authorise the making of a disclosure which is prohibited by any of Parts 1 to 7 or Chapter 1 of Part 9 of the Investigatory Powers Act 2016.
(3)Until the repeal of Part 1 of the Regulation of Investigatory Powers Act 2000 by paragraphs 45 and 54 of Schedule 10 to the Investigatory Powers Act 2016 is fully in force, subsection (2) has effect as if it included a reference to that Part.”
Commencement Information
I397Sch. 19 para. 62 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
63U.K.In section 77(1)(b) (offence of altering etc records with intent to prevent disclosure), omit “or section 7 of the Data Protection Act 1998,”.
Commencement Information
I398Sch. 19 para. 63 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
64U.K.In section 84 (interpretation), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I399Sch. 19 para. 64 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Political Parties, Elections and Referendums Act 2000 (c. 41)U.K.
65(1)Paragraph 28 of Schedule 19C to the Political Parties, Elections and Referendums Act 2000 (civil sanctions: disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (4)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After sub-paragraph (5) insert—
“(6)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I400Sch. 19 para. 65 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Public Finance and Accountability (Scotland) Act 2000 (asp 1)U.K.
66U.K.The Public Finance and Accountability (Scotland) Act 2000 is amended as follows.
Commencement Information
I401Sch. 19 para. 66 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
67U.K.In section 26B(3)(a) (voluntary disclosure of data to Audit Scotland), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I402Sch. 19 para. 67 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
68U.K.In section 26C(3)(a) (power to require disclosure of data), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I403Sch. 19 para. 68 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
69U.K.In section 29(1) (interpretation), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I404Sch. 19 para. 69 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Criminal Justice and Police Act 2001 (c. 16)U.K.
70U.K.The Criminal Justice and Police Act 2001 is amended as follows.
Commencement Information
I405Sch. 19 para. 70 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
71U.K.In section 57(1) (retention of seized items)—
(a)omit paragraph (m), and
(b)after paragraph (s) insert—
“(t)paragraph 10 of Schedule 15 to the Data Protection Act 2018;”.
Commencement Information
I406Sch. 19 para. 71 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
72U.K.In section 65(7) (meaning of “legal privilege”)—
(a)for “paragraph 1 of Schedule 9 to the Data Protection Act 1998 (c. 29)” substitute “ paragraphs 1 and 2 of Schedule 15 to the Data Protection Act 2018 ”, and
(b)for “paragraph 9” substitute “ paragraph 11 (matters exempt from inspection and seizure: privileged communications) ”.
Commencement Information
I407Sch. 19 para. 72 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
73U.K.In Schedule 1 (powers of seizure)—
(a)omit paragraph 65, and
(b)after paragraph 73R insert—
“Data Protection Act 2018U.K.
73SThe power of seizure conferred by paragraphs 1 and 2 of Schedule 15 to the Data Protection Act 2018 (powers of entry and inspection).”
Commencement Information
I408Sch. 19 para. 73 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Anti-terrorism, Crime and Security Act 2001 (c.24)U.K.
74U.K.The Anti-terrorism, Crime and Security Act 2001 is amended as follows.
Commencement Information
I409Sch. 19 para. 74 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
75(1)Section 19 (disclosure of information held by revenue departments) is amended as follows.U.K.
(2)In subsection (7), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)In subsection (9), after “section” insert “—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I410Sch. 19 para. 75 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Prospective
F276U.K.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Textual Amendments
Health and Personal Social Services Act (Northern Ireland) 2001 (c. 3 (N.I.))U.K.
77(1)Section 7A of the Health and Personal Social Services Act (Northern Ireland) 2001 (power to obtain information etc) is amended as follows.U.K.
(2)In subsection (3), after “provision” insert “ or the GDPR ”.
(3)For subsection (5) substitute—
“(5)In determining for the purposes of subsection (3) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this section.”
(4)After subsection (7) insert—
“(8)In this section, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I411Sch. 19 para. 77 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Justice (Northern Ireland) Act 2002 (c. 26)U.K.
78(1)Section 5A of the Justice (Northern Ireland) Act 2002 (disclosure of information to the Commission) is amended as follows.U.K.
(2)In subsection (3)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (9) insert—
“(10)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I412Sch. 19 para. 78 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Proceeds of Crime Act 2002 (c. 29)U.K.
79U.K.The Proceeds of Crime Act 2002 is amended as follows.
Commencement Information
I413Sch. 19 para. 79 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
80U.K.In section 333C(2)(d) (other permitted disclosures between institutions etc), for “(within the meaning of section 1 of the Data Protection Act 1998)” substitute “ (within the meaning of Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act)) ”.
Commencement Information
I414Sch. 19 para. 80 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
81U.K.In section 436(3)(a) (disclosure of information to certain Directors), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I415Sch. 19 para. 81 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
82U.K.In section 438(8)(a) (disclosure of information by certain Directors), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I416Sch. 19 para. 82 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
83U.K.In section 439(3)(a) (disclosure of information to Lord Advocate and to Scottish Ministers), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I417Sch. 19 para. 83 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
84U.K.In section 441(7)(a) (disclosure of information by Lord Advocate and Scottish Ministers), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I418Sch. 19 para. 84 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
85U.K.After section 442 insert—
“442AData protection legislation
In this Part, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I419Sch. 19 para. 85 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Enterprise Act 2002 (c. 40)U.K.
86(1)Section 237 of the Enterprise Act 2002 (general restriction on disclosure) is amended as follows.U.K.
(2)In subsection (4), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (6) insert—
“(7)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I420Sch. 19 para. 86 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Scottish Public Services Ombudsman Act 2002 (asp 11)U.K.
87(1)In Schedule 5 to the Scottish Public Services Ombudsman Act 2002 (disclosure of information by the Ombudsman), the entry for the Information Commissioner is amended as follows.U.K.
(2)In paragraph 1, for sub-paragraph (a) substitute—
“(a)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement),”.
(3)For paragraph 2 substitute—
“2The commission of an offence under—
(a)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc), or
(b)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I421Sch. 19 para. 87 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Freedom of Information (Scotland) Act 2002 (asp 13)U.K.
88U.K.The Freedom of Information (Scotland) Act 2002 is amended as follows.
Commencement Information
I422Sch. 19 para. 88 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
89U.K.In section 2(2)(e)(ii) (absolute exemptions), omit “by virtue of subsection (2)(a)(i) or (b) of that section”.
Commencement Information
I423Sch. 19 para. 89 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
90(1)Section 38 (personal information) is amended as follows.U.K.
(2)In subsection (1), for paragraph (b) substitute—
“(b)personal data and the first, second or third condition is satisfied (see subsections (2A) to (3A));”.
(3)For subsection (2) substitute—
“(2A)The first condition is that the disclosure of the information to a member of the public otherwise than under this Act—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(2B)The second condition is that the disclosure of the information to a member of the public otherwise than under this Act would contravene Article 21 of the GDPR (general processing: right to object to processing).”
(4)For subsection (3) substitute—
“(3A)The third condition is that—
(a)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018, or
(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section.”
(5)Omit subsection (4).
(6)In subsection (5), for the definitions of “the data protection principles” and of “data subject” and “personal data” substitute—
““the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR, and
(b)section 34(1) of the Data Protection Act 2018;
“data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“the GDPR”, “personal data”, “processing” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4), (10), (11) and (14) of that Act);”.
(7)After that subsection insert—
“(5A)In determining for the purposes of this section whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
Commencement Information
I424Sch. 19 para. 90 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Courts Act 2003 (c. 39)U.K.
91U.K.Schedule 5 to the Courts Act 2003 (collection of fines) is amended as follows.
Commencement Information
I425Sch. 19 para. 91 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
92(1)Paragraph 9C (disclosure of information in connection with making of attachment of earnings orders or applications for benefit deductions: supplementary) is amended as follows.U.K.
(2)In sub-paragraph (5), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After sub-paragraph (5) insert—
“(6)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I426Sch. 19 para. 92 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
93(1)Paragraph 10A (attachment of earnings orders (Justice Act (Northern Ireland) 2016): disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (7), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In sub-paragraph (8), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I427Sch. 19 para. 93 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Sexual Offences Act 2003 (c. 42)U.K.
94(1)Section 94 of the Sexual Offences Act 2003 (Part 2: supply of information to the Secretary of State etc for verification) is amended as follows.U.K.
(2)In subsection (6), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)In subsection (8), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I428Sch. 19 para. 94 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Criminal Justice Act 2003 (c. 44)U.K.
95U.K.The Criminal Justice Act 2003 is amended as follows.
Commencement Information
I429Sch. 19 para. 95 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
96U.K.In section 327A(9) (disclosure of information about convictions etc of child sex offenders to members of the public), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I430Sch. 19 para. 96 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
97U.K.In section 327B (disclosure of information about convictions etc of child sex offenders to members of the public: interpretation), after subsection (4) insert—
“(4A)“The data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I431Sch. 19 para. 97 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Mental Health (Care and Treatment) (Scotland) Act 2003 (asp 13)U.K.
98(1)Section 279 of the Mental Health (Care and Treatment) (Scotland) Act 2003 (information for research) is amended as follows.U.K.
(2)In subsection (2), for “research purposes within the meaning given by section 33 of the Data Protection Act 1998 (c. 29) (research, history and statistics)” substitute “ purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics) ”.
(3)After subsection (9) insert—
“(10)In this section, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I432Sch. 19 para. 98 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Public Audit (Wales) Act 2004 (c. 23)U.K.
99(1)Section 64C of the Public Audit (Wales) Act 2004 (voluntary provision of data) is amended as follows.U.K.
(2)In subsection (3)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)In subsection (5), at the beginning insert “In this section—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I433Sch. 19 para. 99 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Companies (Audit, Investigations and Community Enterprise) Act 2004 (c. 27)U.K.
100U.K.The Companies (Audit, Investigations and Community Enterprise) Act 2004 is amended as follows.
Commencement Information
I434Sch. 19 para. 100 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
101(1)Section 15A (disclosure of information by tax authorities) is amended as follows.U.K.
(2)In subsection (2)—
(a)omit “within the meaning of the Data Protection Act 1998”, and
(b)for “that Act” substitute “ the data protection legislation ”.
(3)After subsection (7) insert—
“(8)In this section—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“personal data” has the same meaning as in Parts 5 to 7 of that Act (see section 3(2) and (14) of that Act).”
Commencement Information
I435Sch. 19 para. 101 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
102(1)Section 15D (permitted disclosure of information obtained under compulsory powers) is amended as follows.U.K.
(2)In subsection (7), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (7) insert—
“(8)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I436Sch. 19 para. 102 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Domestic Violence, Crime and Victims Act 2004 (c. 28)U.K.
103(1)Section 54 of the Domestic Violence, Crime and Victims Act 2004 (disclosure of information) is amended as follows.U.K.
(2)In subsection (7), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (8) insert—
“(9)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I437Sch. 19 para. 103 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Children Act 2004 (c. 31)U.K.
104U.K.The Children Act 2004 is amended as follows.
Commencement Information
I438Sch. 19 para. 104 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
105(1)Section 12 (information databases) is amended as follows.U.K.
(2)In subsection (13)(e) for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (13) insert—
“(14)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I439Sch. 19 para. 105 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
106(1)Section 29 (information databases: Wales) is amended as follows.U.K.
(2)In subsection (14)(e) for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (14) insert—
“(15)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I440Sch. 19 para. 106 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Constitutional Reform Act 2005 (c. 4)U.K.
107(1)Section 107 of the Constitutional Reform Act 2005 (disclosure of information to the Commission) is amended as follows.U.K.
(2)In subsection (3)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (9) insert—
“(10)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I441Sch. 19 para. 107 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Mental Capacity Act 2005 (c. 9)U.K.
108U.K.In section 64 of the Mental Capacity Act 2005 (interpretation), for the definition of “health record” substitute—
““health record” has the same meaning as in the Data Protection Act 2018 (see section 205 of that Act);”.
Commencement Information
I442Sch. 19 para. 108 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Public Services Ombudsman (Wales) Act 2005 (c. 10)U.K.
109(1)Section 34X of the Public Services Ombudsman (Wales) Act 2005 (disclosure of information) is amended as follows.U.K.
(2)In subsection (4), for paragraph (a) substitute—
“(a)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement);”.
(3)For subsection (5) substitute—
“(5)The offences are those under—
(a)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc);
(b)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I443Sch. 19 para. 109 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Commissioners for Revenue and Customs Act 2005 (c. 11)U.K.
110(1)Section 22 of the Commissioners for Revenue and Customs Act 2005 (data protection, etc) is amended as follows.U.K.
(2)The existing text becomes subsection (1).
(3)In that subsection, in paragraph (a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(4)After that subsection insert—
“(2)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I444Sch. 19 para. 110 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Gambling Act 2005 (c. 19)U.K.
111(1)Section 352 of the Gambling Act 2005 (data protection) is amended as follows.U.K.
(2)The existing text becomes subsection (1).
(3)In that subsection, for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(4)After that subsection insert—
“(2)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I445Sch. 19 para. 111 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Commissioner for Older People (Wales) Act 2006 (c. 30)U.K.
112(1)Section 18 of the Commissioner for Older People (Wales) Act 2006 (power to disclose information) is amended as follows.U.K.
(2)In subsection (7), for paragraph (a) substitute—
“(a)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement);”.
(3)For subsection (8) substitute—
“(8)The offences are those under—
(a)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc); or
(b)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I446Sch. 19 para. 112 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Health Service Act 2006 (c. 41)U.K.
113U.K.The National Health Service Act 2006 is amended as follows.
Commencement Information
I447Sch. 19 para. 113 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
114(1)Section 251 (control of patient information) is amended as follows.U.K.
(2)In subsection (7), for “made by or under the Data Protection Act 1998 (c 29)” substitute “ of the data protection legislation ”.
(3)In subsection (13), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I448Sch. 19 para. 114 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
115(1)Section 264C (provision and disclosure of information about health service products: supplementary) is amended as follows.U.K.
(2)In subsection (2), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (3) insert—
“(4)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I449Sch. 19 para. 115 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
116U.K.In paragraph 7B(3) of Schedule 1 (further provision about the Secretary of State and services under the Act), for “has the same meaning as in the Data Protection Act 1998” substitute “ has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act) ”.
Commencement Information
I450Sch. 19 para. 116 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Health Service (Wales) Act 2006 (c. 42)U.K.
117U.K.The National Health Service (Wales) Act 2006 is amended as follows.
Commencement Information
I451Sch. 19 para. 117 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
118(1)Section 201C (provision of information about medical supplies: supplementary) is amended as follows.U.K.
(2)In subsection (2), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (3) insert—
“(4)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I452Sch. 19 para. 118 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
119U.K.In paragraph 7B(3) of Schedule 1 (further provision about the Welsh Ministers and services under the Act), for “has the same meaning as in the Data Protection Act 1998” substitute “ has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act) ”.
Commencement Information
I453Sch. 19 para. 119 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Companies Act 2006 (c. 46)U.K.
120U.K.The Companies Act 2006 is amended as follows.
Commencement Information
I454Sch. 19 para. 120 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
121U.K.In section 458(2) (disclosure of information by tax authorities)—
(a)for “within the meaning of the Data Protection Act 1998 (c. 29)” substitute “ within the meaning of Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act) ”, and
(b)for “that Act” substitute “ the data protection legislation ”.
Commencement Information
I455Sch. 19 para. 121 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
122U.K.In section 461(7) (permitted disclosure of information obtained under compulsory powers), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I456Sch. 19 para. 122 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
123U.K.In section 948(9) (restrictions on disclosure) for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
Commencement Information
I457Sch. 19 para. 123 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
124U.K.In section 1173(1) (minor definitions: general), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I458Sch. 19 para. 124 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
125U.K.In section 1224A(7) (restrictions on disclosure), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I459Sch. 19 para. 125 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
126U.K.In section 1253D(3) (restriction on transfer of audit working papers to third countries), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I460Sch. 19 para. 126 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
127U.K.In section 1261(1) (minor definitions: Part 42), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I461Sch. 19 para. 127 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
128U.K.In section 1262 (index of defined expressions: Part 42), at the appropriate place insert—
“the data protection legislation | section 1261(1)”. |
Commencement Information
I462Sch. 19 para. 128 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
129U.K.In Schedule 8 (index of defined expressions: general), at the appropriate place insert—
“the data protection legislation | section 1173(1)”. |
Commencement Information
I463Sch. 19 para. 129 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Tribunals, Courts and Enforcement Act 2007 (c. 15)U.K.
130U.K.The Tribunals, Courts and Enforcement Act 2007 is amended as follows.
Commencement Information
I464Sch. 19 para. 130 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
131U.K.In section 11(5)(b) (right to appeal to Upper Tribunal), for “section 28(4) or (6) of the Data Protection Act 1998 (c. 29)” substitute “ section 27(3) or (5), 79(5) or (7) or 111(3) or (5) of the Data Protection Act 2018 ”.
Commencement Information
I465Sch. 19 para. 131 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
132U.K.In section 13(8)(a) (right to appeal to the Court of Appeal), for “section 28(4) or (6) of the Data Protection Act 1998 (c. 29)” substitute “ section 27(3) or (5), 79(5) or (7) or 111(3) or (5) of the Data Protection Act 2018 ”.
Commencement Information
I466Sch. 19 para. 132 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Statistics and Registration Service Act 2007 (c. 18)U.K.
133U.K.The Statistics and Registration Service Act 2007 is amended as follows.
Commencement Information
I467Sch. 19 para. 133 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
134(1)Section 45 (information held by HMRC) is amended as follows.U.K.
(2)In subsection (4A), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 ”.
(3)In subsection (4B), for “the Data Protection Act 1998” substitute “ the Data Protection Act 2018 ”.
Commencement Information
I468Sch. 19 para. 134 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
135(1)Section 45A (information held by other public authorities) is amended as follows.U.K.
(2)In subsection (8), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 ”.
(3)In subsection (9), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(4)In subsection (12)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(5)In subsection 12(c), after the first “legislation” insert “ (which is not part of the data protection legislation) ”.
Commencement Information
I469Sch. 19 para. 135 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
136(1)Section 45B(3) (access to information held by Crown bodies etc) is amended as follows.U.K.
(2)In paragraph (a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In paragraph (c), after the first “legislation” insert “ (which is not part of the data protection legislation) ”.
Commencement Information
I470Sch. 19 para. 136 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
137(1)Section 45C(13) (power to require disclosures by other public authorities) is amended as follows.U.K.
(2)In paragraph (b), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In paragraph (d), after the first “legislation” insert “ (which is not part of the data protection legislation) ”.
Commencement Information
I471Sch. 19 para. 137 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
138U.K.In section 45D(9)(b) (power to require disclosure by undertakings), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I472Sch. 19 para. 138 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
139(1)Section 45E (further provision about powers in sections 45B, 45C and 45D) is amended as follows.U.K.
(2)In subsection (6), for “issued under section 52B (data-sharing code) of the Data Protection Act 1998” substitute “ prepared under section 121 of the Data Protection Act 2018 (data-sharing code) and issued under section 125(4) of that Act ”.
(3)In subsection (16), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 ”.
(4)In subsection (17), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I473Sch. 19 para. 139 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
140(1)Section 53A (disclosure by the Statistics Board to devolved administrations) is amended as follows.U.K.
(2)In subsection (9), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 ”.
(3)In subsection (10), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(4)In subsection (12)(b), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I474Sch. 19 para. 140 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
141(1)Section 54 (Data Protection Act 1998 and Human Rights Act 1998) is amended as follows.U.K.
(2)In the heading, omit “Data Protection Act 1998 and”.
(3)Omit paragraph (a) (together with the final “or”).
Commencement Information
I475Sch. 19 para. 141 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
142U.K.In section 67 (general interpretation: Part 1), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I476Sch. 19 para. 142 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Serious Crime Act 2007 (c. 27)U.K.
143U.K.The Serious Crime Act 2007 is amended as follows.
Commencement Information
I477Sch. 19 para. 143 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
144(1)Section 5A (verification and disclosure of information) is amended as follows.U.K.
(2)In subsection (6)—
(a)for “the Data Protection Act 1998” substitute “ the data protection legislation ”, and
(b)for “are” substitute “ is ”.
(3)After subsection (6) insert—
“(7)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I478Sch. 19 para. 144 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
145(1)Section 68 (disclosure of information to prevent fraud) is amended as follows.U.K.
(2)In subsection (4)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)In subsection (8), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I479Sch. 19 para. 145 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
146(1)Section 85 (disclosure of information by Revenue and Customs) is amended as follows.U.K.
(2)In subsection (8)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)In subsection (9), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I480Sch. 19 para. 146 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Legal Services Act 2007 (c. 29)U.K.
147(1)Section 169 of the Legal Services Act 2007 (disclosure of information to the Legal Services Board) is amended as follows.U.K.
(2)In subsection (3)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (8) insert—
“(9)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I481Sch. 19 para. 147 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Adoption and Children (Scotland) Act 2007 (asp 4)U.K.
148U.K.In section 74 of the Adoption and Children (Scotland) Act 2007 (disclosure of medical information about parents), for subsection (5) substitute—
“(5)In subsection (4)(e), “processing” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act).”
Commencement Information
I482Sch. 19 para. 148 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Criminal Justice and Immigration Act 2008 (c. 4)U.K.
149U.K.The Criminal Justice and Immigration Act 2008 is amended as follows.
Commencement Information
I483Sch. 19 para. 149 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
150U.K.Omit—
(a)section 77 (power to alter penalty for unlawfully obtaining etc personal data), and
(b)section 78 (new defence for obtaining etc for journalism and other special purposes).
Commencement Information
I484Sch. 19 para. 150 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
151(1)Section 114 (supply of information to Secretary of State etc) is amended as follows.U.K.
(2)In subsection (5), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (6) insert—
“(6A)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I485Sch. 19 para. 151 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Regulatory Enforcement and Sanctions Act 2008 (c. 13)U.K.
152(1)Section 70 of the Regulatory Enforcement and Sanctions Act 2008 (disclosure of information) is amended as follows.U.K.
(2)In subsection (4)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (5) insert—
“(6)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I486Sch. 19 para. 152 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Health and Social Care Act 2008 (c. 14)U.K.
153U.K.In section 20A(5) of the Health and Social Care Act 2008 (functions relating to processing of information by registered persons), in the definition of “processing”, for “the Data Protection Act 1998” substitute “ Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act); ”.
Commencement Information
I487Sch. 19 para. 153 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Counter-Terrorism Act 2008 (c. 28)U.K.
154(1)Section 20 of the Counter-Terrorism Act 2008 (disclosure and the intelligence services: supplementary provisions) is amended as follows.U.K.
(2)In subsection (2)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (4) insert—
“(5)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I488Sch. 19 para. 154 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Public Health etc. (Scotland) Act 2008 (asp 5)U.K.
155(1)Section 117 of the Public Health etc. (Scotland) Act 2008 (disclosure of information) is amended as follows.U.K.
(2)In subsection (6), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (7) insert—
“(7A)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I489Sch. 19 para. 155 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Banking Act 2009 (c. 1)U.K.
156(1)Section 83ZY of the Banking Act 2009 (special resolution regime: publication of notices etc) is amended as follows.U.K.
(2)In subsection (10), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (11), after “section” insert “—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I490Sch. 19 para. 156 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Borders, Citizenship and Immigration Act 2009 (c. 11)U.K.
157(1)Section 19 of the Borders, Citizenship and Immigration Act 2009 (use and disclosure of customs information: application of statutory provisions) is amended as follows.U.K.
(2)In subsection (1)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (4) insert—
“(5)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I491Sch. 19 para. 157 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Marine and Coastal Access Act 2009 (c. 23)U.K.
158U.K.The Marine and Coastal Access Act 2009 is amended as follows.
Commencement Information
I492Sch. 19 para. 158 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
159(1)Paragraph 13 of Schedule 7 (further provision about civil sanctions under Part 4: disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (5)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After sub-paragraph (6) insert—
“(7)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I493Sch. 19 para. 159 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
160(1)Paragraph 9 of Schedule 10 (further provision about fixed monetary penalties: disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (5)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After sub-paragraph (6) insert—
“(7)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I494Sch. 19 para. 160 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Coroners and Justice Act 2009 (c. 25)U.K.
161U.K.In Schedule 21 to the Coroners and Justice Act 2009 (minor and consequential amendments), omit paragraph 29(3).
Commencement Information
I495Sch. 19 para. 161 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Broads Authority Act 2009 (c. i)U.K.
162(1)Section 38 of the Broads Authority Act 2009 (provision of information) is amended as follows.U.K.
(2)In subsection (3), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)In subsection (6), after “section” insert “—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I496Sch. 19 para. 162 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Health and Social Care (Reform) Act (Northern Ireland) 2009 (c. 1 (N.I.))U.K.
163(1)Section 13 of the Health and Social Care (Reform) Act (Northern Ireland) 2009 (functions of the Regional Agency) is amended as follows.U.K.
(2)In subsection (8), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (8) insert—
“(9)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I497Sch. 19 para. 163 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Terrorist Asset-Freezing etc. Act 2010 (c. 38)U.K.
164(1)Section 25 of the Terrorist Asset-Freezing etc. Act 2010 (application of provisions) is amended as follows.U.K.
(2)In subsection (2)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (6), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I498Sch. 19 para. 164 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Marine (Scotland) Act 2010 (asp 5)U.K.
165(1)Paragraph 12 of Schedule 2 to the Marine (Scotland) Act 2010 (further provision about civil sanctions under Part 4: disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (5)(a), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After sub-paragraph (6) insert—
“(7)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I499Sch. 19 para. 165 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Charities Act 2011 (c. 25)U.K.
166(1)Section 59 of the Charities Act 2011 (disclosure: supplementary) is amended as follows.U.K.
(2)The existing text becomes subsection (1).
(3)In that subsection, in paragraph (a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(4)After that subsection insert—
“(2)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I500Sch. 19 para. 166 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Welsh Language (Wales) Measure 2011 (nawm 1)U.K.
167U.K.The Welsh Language (Wales) Measure 2011 is amended as follows.
Commencement Information
I501Sch. 19 para. 167 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
168(1)Section 22 (power to disclose information) is amended as follows.U.K.
(2)In subsection (4)—
(a)in the English language text, for paragraph (a) substitute—
“(a)sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement);”, and
(b)in the Welsh language text, for paragraph (a) substitute—
“(a)adrannau 142 i 154, 160 i 164, neu 174 i 176 o Ddeddf Diogelu Data 2018 neu Atodlen 15 i'r Ddeddf honno (darpariaethau penodol yn ymwneud â gorfodi);”.
(3)For subsection (5)—
(a)in the English language text substitute—
“(5)The offences referred to under subsection (3)(b) are those under—
(a)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of exercise of warrant etc); or
(b)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”, and
(b)in the Welsh language text substitute—
“(5)Y tramgwyddau y cyfeirir atynt yn is-adran (3)(b) yw'r rhai—
(a)o dan ddarpariaeth yn Neddf Diogelu Data 2018 ac eithrio paragraff 15 o Atodlen 15 (rhwystro gweithredu gwarant etc); neu
(b)o dan adran 77 o Ddeddf Rhyddid Gwybodaeth 2000 (trosedd o altro etc cofnodion gyda'r bwriad o atal datgelu).”
(4)In subsection (8)—
(a)in the English language text, for “the Data Protection Act 1998” substitute “ the data protection legislation ”, and
(b)in the Welsh language text, for “gymhwyso Deddf Diogelu Data 1998” substitute “gymhwyso'r ddeddfwriaeth diogelu data”.
(5)In subsection (9)—
(a)at the appropriate place in the English language text insert—
““the data protection legislation” (“y ddeddfwriaeth diogelu data”) has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”, and
(b)at the appropriate place in the Welsh language text insert—
““mae i “y ddeddfwriaeth diogelu data” yr un ystyr ag a roddir i “the data protection legislation” yn Neddf Diogelu Data 2018 (gweler adran 3 o'r Ddeddf honno);”.
Commencement Information
I502Sch. 19 para. 168 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
169(1)Paragraph 8 of Schedule 2 (inquiries by the Commissioner: reports) is amended as follows.U.K.
(2)In sub-paragraph (7)—
(a)in the English language text, for “the Data Protection Act 1998” substitute “ the data protection legislation ”, and
(b)in the Welsh language text, for “gymhwyso Deddf Diogelu Data 1998” substitute “gymhwyso'r ddeddfwriaeth diogelu data”.
(3)In sub-paragraph (8)—
(a)in the English language text, after “this paragraph” insert “—
“the data protection legislation” (“y ddeddfwriaeth diogelu data”) has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”, and
(b)in the Welsh language text, after “hwn” insert—
““mae i “y ddeddfwriaeth diogelu data” yr un ystyr ag a roddir i “the data protection legislation” yn Neddf Diogelu Data 2018 (gweler adran 3 o'r Ddeddf honno);”.
Commencement Information
I503Sch. 19 para. 169 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Safeguarding Board Act (Northern Ireland) 2011 (c. 7 (N.I))U.K.
170(1)Section 10 of the Safeguarding Board Act (Northern Ireland) 2011 (duty to co-operate) is amended as follows.U.K.
(2)In subsection (3), for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”.
(3)After subsection (3) insert—
“(4)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I504Sch. 19 para. 170 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Health and Social Care Act 2012 (c. 7)U.K.
171U.K.The Health and Social Care Act 2012 is amended as follows.
Commencement Information
I505Sch. 19 para. 171 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
172U.K.In section 250(7) (power to publish information standards), for the definition of “processing” substitute—
““processing” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act);”.
Commencement Information
I506Sch. 19 para. 172 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
173(1)Section 251A (consistent identifiers) is amended as follows.U.K.
(2)In subsection (7)(a), for “made by or under the Data Protection Act 1998” substitute “ of the data protection legislation ”.
(3)After subsection (8) insert—
“(9)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I507Sch. 19 para. 173 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
174(1)Section 251B (duty to share information) is amended as follows.U.K.
(2)In subsection (5)(a), for “made by or under the Data Protection Act 1998” substitute “ of the data protection legislation ”.
(3)After subsection (6) insert—
“(7)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I508Sch. 19 para. 174 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Protection of Freedoms Act 2012 (c. 9)U.K.
175U.K.The Protection of Freedoms Act 2012 is amended as follows.
Commencement Information
I509Sch. 19 para. 175 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
176(1)Section 27 (exceptions and further provision about consent and notification) is amended as follows.U.K.
(2)In subsection (5), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (5) insert—
“(6)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I510Sch. 19 para. 176 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
177U.K.In section 28(1) (interpretation: Chapter 2), for the definition of “processing” substitute—
““processing” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act);”.
Commencement Information
I511Sch. 19 para. 177 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
178U.K.In section 29(7) (code of practice for surveillance camera systems), for the definition of “processing” substitute—
““processing” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(4) and (14) of that Act);”.
Commencement Information
I512Sch. 19 para. 178 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
HGV Road User Levy Act 2013 (c. 7)U.K.
179(1)Section 14A of the HGV Road User Levy Act 2013 (disclosure of information by Revenue and Customs) is amended as follows.U.K.
(2)In subsection (5), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (5) insert—
“(6)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I513Sch. 19 para. 179 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Crime and Courts Act 2013 (c. 22)U.K.
180U.K.The Crime and Courts Act 2013 is amended as follows.
Commencement Information
I514Sch. 19 para. 180 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
181(1)Section 42 (other interpretive provisions) is amended as follows.U.K.
(2)In subsection (5)(a), for “section 13 of the Data Protection Act 1998 (damage or distress suffered as a result of a contravention of a requirement of that Act)” substitute “ Article 82 of the GDPR or section 168 or 169 of the Data Protection Act 2018 (compensation for contravention of the data protection legislation) ”.
(3)After subsection (5) insert—
“(5A)In subsection (5)(a), “the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I515Sch. 19 para. 181 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
182(1)Paragraph 1 of Schedule 7 (statutory restrictions on disclosure) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)In that sub-paragraph, in paragraph (a)—
(a)for “the Data Protection Act 1998” substitute “ the data protection legislation ”, and
(b)for “are” substitute “ is ”.
(4)After that sub-paragraph, insert—
“(2)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I516Sch. 19 para. 182 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Marine Act (Northern Ireland) 2013 (c. 10 (N.I.))U.K.
183(1)Paragraph 8 of Schedule 2 to the Marine Act (Northern Ireland) 2013 (further provision about fixed monetary penalties under section 35: disclosure of information) is amended as follows.U.K.
(2)In sub-paragraph (5)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After sub-paragraph (6) insert—
“(7)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I517Sch. 19 para. 183 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Local Audit and Accountability Act 2014 (c. 2)U.K.
184(1)Paragraph 3 of Schedule 9 to the Local Audit and Accountability Act 2014 (data matching: voluntary provision of data) is amended as follows.U.K.
(2)In sub-paragraph (3)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After sub-paragraph (3) insert—
“(3A)“The data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
(4)In sub-paragraph (4), for “comprise or include” substitute “ comprises or includes ”.
Commencement Information
I518Sch. 19 para. 184 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Anti-social Behaviour, Crime and Policing Act 2014 (c. 12)U.K.
185(1)Paragraph 7 of Schedule 4 to the Anti-social Behaviour, Crime and Policing Act 2014 (anti-social behaviour case reviews: information) is amended as follows.U.K.
(2)In sub-paragraph (4)—
(a)for “the Data Protection Act 1998” substitute “ the data protection legislation ”, and
(b)for “are” substitute “ is ”.
(3)After sub-paragraph (5) insert—
“(6)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I519Sch. 19 para. 185 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Immigration Act 2014 (c. 22)U.K.
186(1)Paragraph 6 of Schedule 6 to the Immigration Act 2014 (information: limitation on powers) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)In that sub-paragraph, in paragraph (a)—
(a)for “the Data Protection Act 1998” substitute “ the data protection legislation ”, and
(b)for “are” substitute “ is ”.
(4)After that sub-paragraph insert—
“(2)In this paragraph, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I520Sch. 19 para. 186 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Care Act 2014 (c. 23)U.K.
187U.K.In section 67(9) of the Care Act 2014 (involvement in assessment, plans etc), for paragraph (a) substitute—
“(a)a health record (within the meaning given in section 205 of the Data Protection Act 2018),”.
Commencement Information
I521Sch. 19 para. 187 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Social Services and Well-being (Wales) Act 2014 (anaw 4)U.K.
188U.K.In section 18(10)(b) of the Social Services and Well-being (Wales) Act 2014 (registers of sight-impaired, hearing-impaired and other disabled people)—
(a)in the English language text, for “(within the meaning of the Data Protection Act 1998)” substitute “ (within the meaning of Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act)) ”, and
(b)in the Welsh language text, for “(o fewn ystyr “personal data” yn Neddf Diogelu Data 1998)” substitute “(o fewn ystyr “ personal data ” yn Rhan 5 i 7 o Ddeddf Diogelu Data 2018 (gweler adran 3(2) a (14) o'r Ddeddf honno))”.
Commencement Information
I522Sch. 19 para. 188 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Counter-Terrorism and Security Act 2015 (c. 6)U.K.
189(1)Section 38 of the Counter-Terrorism and Security Act 2015 (support etc for people vulnerable to being drawn into terrorism: co-operation) is amended as follows.U.K.
(2)In subsection (4)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (4) insert—
“(4A)“The data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I523Sch. 19 para. 189 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Small Business, Enterprise and Employment Act 2015 (c. 26)U.K.
190(1)Section 6 of the Small Business, Enterprise and Employment Act 2015 (application of listed provisions to designated credit reference agencies) is amended as follows.U.K.
(2)In subsection (7)—
(a)for paragraph (b) substitute—
“(b)Article 15(1) to (3) of the GDPR (confirmation of processing, access to data and safeguards for third country transfers);”, and
(b)omit paragraph (c).
(3)After subsection (7) insert—
“(7A)In subsection (7) “the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I524Sch. 19 para. 190 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Modern Slavery Act 2015 (c. 30)U.K.
191(1)Section 54A of the Modern Slavery Act 2015 (Gangmasters and Labour Abuse Authority: information gateways) is amended as follows.U.K.
(2)In subsection (5)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (9), after “section” insert “—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I525Sch. 19 para. 191 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Human Trafficking and Exploitation (Criminal Justice and Support for Victims) Act (Northern Ireland) 2015 (c. 2 (N.I.))U.K.
192U.K.The Human Trafficking and Exploitation (Criminal Justice and Support for Victims) Act (Northern Ireland) 2015 is amended as follows.
Commencement Information
I526Sch. 19 para. 192 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
193U.K.In section 13(5) (duty to notify National Crime Agency about suspected victims of certain offences) for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I527Sch. 19 para. 193 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
194U.K.In section 25(1) (interpretation of this Act), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I528Sch. 19 para. 194 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
195U.K.In paragraph 18(5) of Schedule 3 (supply of information to relevant Northern Ireland departments, Secretary of State, etc) for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I529Sch. 19 para. 195 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Justice Act (Northern Ireland) 2015 (c. 9 (N.I.))U.K.
196(1)Section 72 of the Justice Act (Northern Ireland) 2015 (supply of information to relevant Northern Ireland departments or Secretary of State) is amended as follows.U.K.
(2)In subsection (5), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (7), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I530Sch. 19 para. 196 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Immigration Act 2016 (c. 19)U.K.
197(1)Section 7 of the Immigration Act 2016 (information gateways: supplementary) is amended as follows.U.K.
(2)In subsection (2)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (11), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I531Sch. 19 para. 197 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Investigatory Powers Act 2016 (c. 25)U.K.
198U.K.The Investigatory Powers Act 2016 is amended as follows.
Commencement Information
I532Sch. 19 para. 198 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
199U.K.In section 1(5)(b), for sub-paragraph (ii) substitute—
“(ii)in section 170 of the Data Protection Act 2018 (unlawful obtaining etc of personal data),”.
Commencement Information
I533Sch. 19 para. 199 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
200U.K.In section 199 (bulk personal datasets: interpretation), for subsection (2) substitute—
“(2)In this Part, “personal data” means—
(a)personal data within the meaning of section 3(2) of the Data Protection Act 2018 which is subject to processing described in section 82(1) of that Act, and
(b)data relating to a deceased individual where the data would fall within paragraph (a) if it related to a living individual.”
Commencement Information
I534Sch. 19 para. 200 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Prospective
F3201U.K.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Textual Amendments
202U.K.In section 206 (additional safeguards for health records), for subsection (7) substitute—
“(7)In subsection (6)—
“health professional” has the same meaning as in the Data Protection Act 2018 (see section 204(1) of that Act);
“health service body” has meaning given by section 204(4) of that Act.”
Commencement Information
I535Sch. 19 para. 202 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
203(1)Section 237 (information gateway) is amended as follows.U.K.
(2)In subsection (2), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (2) insert—
“(3)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I536Sch. 19 para. 203 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Public Services Ombudsman Act (Northern Ireland) 2016 (c. 4 (N.I.))U.K.
204(1)Section 49 of the Police Services Ombudsman Act (Northern Ireland) 2016 (disclosure of information) is amended as follows.U.K.
(2)In subsection (4), for paragraph (a) substitute—
“(a)sections 142 to 154, 160 to 164 and 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 (certain provisions relating to enforcement),”.
(3)For subsection (5) substitute—
“(5)The offences are those under—
(a)any provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (powers of entry and inspection: offences),
(b)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
(4)After subsection (6) insert—
“(7)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I537Sch. 19 para. 204 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Health and Social Care (Control of Data Processing) Act (Northern Ireland) 2016 (c. 12 (N.I.))U.K.
205(1)Section 1 of the Health and Social Care (Control of Data Processing) Act (Northern Ireland) 2016 (control of information of a relevant person) is amended as follows.U.K.
(2)In subsection (8), for “made by or under the Data Protection Act 1998” substitute “ of the data protection legislation ”.
(3)After subsection (12) insert—
“(12A)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I538Sch. 19 para. 205 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Mental Capacity Act (Northern Ireland) 2016 (c. 18 (N.I.))U.K.
206U.K.In section 306(1) of the Mental Capacity Act (Northern Ireland) 2016 (definitions for purposes of Act), for the definition of “health record” substitute—
““health record” has the meaning given by section 205 of the Data Protection Act 2018;”.
Commencement Information
I539Sch. 19 para. 206 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Justice Act (Northern Ireland) 2016 (c. 21 (N.I.))U.K.
207U.K.The Justice Act (Northern Ireland) 2016 is amended as follows.
Commencement Information
I540Sch. 19 para. 207 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
208(1)Section 17 (disclosure of information) is amended as follows.U.K.
(2)In subsection (7), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (8), after “section” insert “—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I541Sch. 19 para. 208 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
209U.K.In section 44(3) (disclosure of information)—
(a)in paragraph (a), for “Part 5 of the Data Protection Act 1998” substitute “ sections 142 to 154, 160 to 164 or 174 to 176 of, or Schedule 15 to, the Data Protection Act 2018 ”, and
(b)for paragraph (b) substitute—
“(b)the commission of an offence under—
(i)a provision of the Data Protection Act 2018 other than paragraph 15 of Schedule 15 (obstruction of execution of warrant etc); or
(ii)section 77 of the Freedom of Information Act 2000 (offence of altering etc records with intent to prevent disclosure).”
Commencement Information
I542Sch. 19 para. 209 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Policing and Crime Act 2017 (c. 3)U.K.
210(1)Section 50 of the Policing and Crime Act 2017 (Freedom of Information Act etc: Police Federation for England and Wales) is amended as follows.U.K.
(2)The existing text becomes subsection (1).
(3)In that subsection, in paragraph (b), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(4)After that subsection, insert—
“(2)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I543Sch. 19 para. 210 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Yn ddilys o 02/12/2019
Children and Social Work Act 2017 (c. 12)U.K.
211U.K.In Schedule 5 to the Children and Social Work Act 2017—
(a)in Part 1 (general amendments to do with social workers etc in England), omit paragraph 6, and
(b)in Part 2 (renaming of Health and Social Work Professions Order 2001), omit paragraph 47(g).
Higher Education and Research Act 2017 (c. 29)U.K.
212U.K.The Higher Education and Research Act 2017 is amended as follows.
Commencement Information
I544Sch. 19 para. 212 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
213(1)Section 63 (cooperation and information sharing by the Office for Students) is amended as follows.U.K.
(2)In subsection (6), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)In subsection (7), at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”.
Commencement Information
I545Sch. 19 para. 213 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
214(1)Section 112 (cooperation and information sharing between the Office for Students and UKRI) is amended as follows.U.K.
(2)In subsection (6), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (6) insert —
“(7)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I546Sch. 19 para. 214 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Digital Economy Act 2017 (c. 30)U.K.
215U.K.The Digital Economy Act 2017 is amended as follows.
Commencement Information
I547Sch. 19 para. 215 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
216(1)Section 40 (further provisions about disclosures under sections 35 to 39) is amended as follows.U.K.
(2)In subsection (8)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (10) insert—
“(11)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I548Sch. 19 para. 216 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
217(1)Section 43 (codes of practice) is amended as follows.U.K.
(2)In subsection (2), for “issued under section 52B (data-sharing code) of the Data Protection Act 1998” substitute “ prepared under section 121 of the Data Protection Act 2018 (data-sharing code) and issued under section 125(4) of that Act ”.
(3)In subsection (13), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 ”.
Commencement Information
I549Sch. 19 para. 217 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
218(1)Section 49 (further provision about disclosures under section 48) is amended as follows.U.K.
(2)In subsection (8)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (10) insert—
“(11)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I550Sch. 19 para. 218 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
219(1)Section 52 (code of practice) is amended as follows.U.K.
(2)In subsection (2), for “issued under section 52B (data-sharing code) of the Data Protection Act 1998” substitute “ prepared under section 121 of the Data Protection Act 2018 (data-sharing code) and issued under section 125(4) of that Act ”.
(3)In subsection (13), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 (other codes of practice) ”.
Commencement Information
I551Sch. 19 para. 219 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
220(1)Section 57 (further provision about disclosures under section 56) is amended as follows.U.K.
(2)In subsection (8)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (10) insert—
“(11)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I552Sch. 19 para. 220 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
221(1)Section 60 (code of practice) is amended as follows.U.K.
(2)In subsection (2), for “issued under section 52B (data-sharing code) of the Data Protection Act 1998” substitute “ prepared under section 121 of the Data Protection Act 2018 (data-sharing code) and issued under section 125(4) of that Act ”.
(3)In subsection (13), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 (other codes of practice) ”.
Commencement Information
I553Sch. 19 para. 221 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
222(1)Section 65 (supplementary provision about disclosures under section 64) is amended as follows.U.K.
(2)In subsection (2)(a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After subsection (8) insert—
“(9)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I554Sch. 19 para. 222 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
223(1)Section 70 (code of practice) is amended as follows.U.K.
(2)In subsection (2), for “issued under section 52B (data-sharing code) of the Data Protection Act 1998” substitute “ prepared under section 121 of the Data Protection Act 2018 (data-sharing code) and issued under section 125(4) of that Act ”.
(3)In subsection (15), for “section 51(3) of the Data Protection Act 1998” substitute “ section 128 of the Data Protection Act 2018 (other codes of practice) ”.
Commencement Information
I555Sch. 19 para. 223 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
224U.K.Omit sections 108 to 110 (charges payable to the Information Commissioner).
Commencement Information
I556Sch. 19 para. 224 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Landfill Disposals Tax (Wales) Act 2017 (anaw 3)U.K.
225(1)Section 60 of the Landfill Disposals Tax (Wales) Act 2017 (disclosure of information to the Welsh Revenue Authority) is amended as follows.U.K.
(2)In subsection (4)(a)—
(a)in the English language text, for “the Data Protection Act 1998 (c. 29)” substitute “ the data protection legislation ”, and
(b)in the Welsh language text, for “torri Deddf Diogelu Data 1998 (p. 29)” substitute “torri'r ddeddfwriaeth diogelu data”.
(3)After subsection (7)—
(a)in the English language text insert—
“(8)In this section, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”, and
(b)in the Welsh language text insert—
“(8)Yn yr adran hon, mae i “y ddeddfwriaeth diogelu data” yr un ystyr ag a roddir i “the data protection legislation” yn Neddf Diogelu Data 2018 (gweler adran 3 o'r Ddeddf honno).”
Commencement Information
I557Sch. 19 para. 225 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Additional Learning Needs and Educational Tribunal (Wales) Act 2018 (anaw 2)U.K.
226(1)Section 4 of the Additional Learning Needs and Educational Tribunal (Wales) Act 2018 (additional learning needs code) is amended as follows.U.K.
(2)In the English language text—
(a)in subsection (9), omit from “and in this subsection” to the end, and
(b)after subsection (9) insert—
“(9A)In subsection (9)—
“data subject” (“testun y data”) has the meaning given by section 3(5) of the Data Protection Act 2018;
“personal data” (“data personol”) has the same meaning as in Parts 5 to 7 of that Act (see section 3(2) and (14) of that Act).”
(3)In the Welsh language text—
(a)in subsection (9), omit from “ac yn yr is-adran hon” to the end, and
(b)after subsection (9) insert—
“(9A)Yn is-adran (9)—
mae i “data personol” yr un ystyr ag a roddir i “personal data” yn Rhannau 5 i 7 o Ddeddf Diogelu Data 2018 (gweler adran 3(2) a (14) o'r Ddeddf honno);
mae i “testun y data” yr ystyr a roddir i “data subject” gan adran 3(5) o'r Ddeddf honno.”
Commencement Information
I558Sch. 19 para. 226 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Yn ddilys o 02/12/2019
This ActU.K.
227(1)Section 204 of this Act (meaning of “health professional” and “social work professional”) is amended as follows (to reflect the arrangements for the registration of social workers in England under Part 2 of the Children and Social Work Act 2017).U.K.
(2)In subsection (1)(g)—
(a)omit “and Social Work”, and
(b)omit “, other than the social work profession in England”.
(3)In subsection (2), for paragraph (a) substitute—
“(a)a person registered as a social worker in the register maintained by Social Work England under section 39(1) of the Children and Social Work Act 2017;”.
PART 2 U.K.Amendments of other legislation
Estate Agents (Specified Offences) (No. 2) Order 1991 (S.I. 1991/1091)U.K.
228U.K.In the table in the Schedule to the Estate Agents (Specified Offences) (No. 2) Order 1991 (specified offences), at the end insert—
“Data Protection Act 2018 | Section 144 | False statements made in response to an information notice |
Section 148 | Destroying or falsifying information and documents etc” |
Commencement Information
I559Sch. 19 para. 228 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Channel Tunnel (International Arrangements) Order 1993 (S.I. 1993/1813)U.K.
229(1)Article 4 of the Channel Tunnel (International Arrangements) Order 1993 (application of enactments) is amended as follows.U.K.
(2)In paragraph (2)—
(a)for “section 5 of the Data Protection Act 1998 (“the 1998 Act”), data which are” substitute “ section 207 of the Data Protection Act 2018 (“the 2018 Act”), data which is ”,
(b)for “data controller” substitute “ controller ”,
(c)after “in the context of” insert “ the activities of ”, and
(d)for “and the 1998 Act” substitute “ and the 2018 Act ”.
(3)In paragraph (3)—
(a)for “section 5 of the 1998 Act, data which are” substitute “ section 207 of the 2018 Act, data which is ”,
(b)for “data controller” substitute “ controller ”,
(c)after “in the context of” insert “ the activities of ”, and
(d)for “and the 1998 Act” substitute “ and the 2018 Act ”.
Commencement Information
I560Sch. 19 para. 229 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Access to Health Records (Northern Ireland) Order 1993 (S.I. 1993/1250 (N.I. 4))U.K.
230U.K.The Access to Health Records (Northern Ireland) Order 1993 is amended as follows.
Commencement Information
I561Sch. 19 para. 230 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
231U.K.In Article 4 (health professionals), for paragraph (1) substitute—
“(1)In this Order, “health professional” has the same meaning as in the Data Protection Act 2018 (see section 204 of that Act).”
Commencement Information
I562Sch. 19 para. 231 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
232U.K.In Article 5(4)(a) (fees for access to health records), for “under section 7 of the Data Protection Act 1998” substitute “ made by the Department ”.
Commencement Information
I563Sch. 19 para. 232 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Channel Tunnel (Miscellaneous Provisions) Order 1994 (S.I. 1994/1405)U.K.
233U.K.In article 4 of the Channel Tunnel (Miscellaneous Provisions) Order 1994 (application of enactments), for paragraphs (2) and (3) substitute—
“(2)For the purposes of section 207 of the Data Protection Act 2018 (“the 2018 Act”), data which is processed in a control zone in Belgium, in connection with the carrying out of frontier controls, by an officer belonging to the United Kingdom is to be treated as processed by a controller established in the United Kingdom in the context of the activities of that establishment (and accordingly the 2018 Act applies in respect of such data).
(3)For the purposes of section 207 of the 2018 Act, data which is processed in a control zone in Belgium, in connection with the carrying out of frontier controls, by an officer belonging to the Kingdom of Belgium is to be treated as processed by a controller established in the Kingdom of Belgium in the context of the activities of that establishment (and accordingly the 2018 Act does not apply in respect of such data).”
Commencement Information
I564Sch. 19 para. 233 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
European Primary and Specialist Dental Qualifications Regulations 1998 (S.I. 1998/811)U.K.
234U.K.The European Primary and Specialist Dental Qualifications Regulations 1998 are amended as follows.
Commencement Information
I565Sch. 19 para. 234 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
235(1)Regulation 2(1) (interpretation) is amended as follows.U.K.
(2)Omit the definition of “Directive 95/46/EC”.
(3)At the appropriate place insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I566Sch. 19 para. 235 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
236(1)The table in Schedule A1 (functions of the GDC under Directive 2005/36) is amended as follows.U.K.
(2)In the entry for Article 56(2), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In the entry for Article 56a(4), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I567Sch. 19 para. 236 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Scottish Parliamentary Corporate Body (Crown Status) Order 1999 (S.I. 1999/677)U.K.
237U.K.For article 7 of the Scottish Parliamentary Corporate Body (Crown Status) Order 1999 substitute—
“Data Protection Act 2018U.K.
7(1)The Parliamentary corporation is to be treated as a Crown body for the purposes of the Data Protection Act 2018 to the extent specified in this article.
(2)The Parliamentary corporation is to be treated as a government department for the purposes of the following provisions—
(a)section 8(d) (lawfulness of processing under the GDPR: public interest etc),
(b)section 209 (application to the Crown),
(c)paragraph 6 of Schedule 1 (statutory etc and government purposes),
(d)paragraph 7 of Schedule 2 (exemptions from the GDPR: functions designed to protect the public etc), and
(e)paragraph 8(1)(o) of Schedule 3 (exemptions from the GDPR: health data).
(3)In the provisions mentioned in paragraph (4)—
(a)references to employment by or under the Crown are to be treated as including employment as a member of staff of the Parliamentary corporation, and
(b)references to a person in the service of the Crown are to be treated as including a person so employed.
(4)The provisions are—
(a)section 24(3) (exemption for certain data relating to employment under the Crown), and
(b)section 209(6) (application of certain provisions to a person in the service of the Crown).
(5)In this article, references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(14) of that Act).”
Commencement Information
I568Sch. 19 para. 237 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Northern Ireland Assembly Commission (Crown Status) Order 1999 (S.I. 1999/3145)U.K.
238U.K.For article 9 of the Northern Ireland Assembly Commission (Crown Status) Order 1999 substitute—
“Data Protection Act 2018U.K.
9(1)The Commission is to be treated as a Crown body for the purposes of the Data Protection Act 2018 to the extent specified in this article.
(2)The Commission is to be treated as a government department for the purposes of the following provisions—
(a)section 8(d) (lawfulness of processing under the GDPR: public interest etc),
(b)section 209 (application to the Crown),
(c)paragraph 6 of Schedule 1 (statutory etc and government purposes),
(d)paragraph 7 of Schedule 2 (exemptions from the GDPR: functions designed to protect the public etc), and
(e)paragraph 8(1)(o) of Schedule 3 (exemptions from the GDPR: health data).
(3)In the provisions mentioned in paragraph (4)—
(a)references to employment by or under the Crown are to be treated as including employment as a member of staff of the Commission, and
(b)references to a person in the service of the Crown are to be treated as including a person so employed.
(4)The provisions are—
(a)section 24(3) (exemption for certain data relating to employment under the Crown), and
(b)section 209(6) (application of certain provisions to a person in the service of the Crown).
(5)In this article, references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(14) of that Act).”
Commencement Information
I569Sch. 19 para. 238 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Corporate Finance Exemption) Order 2000 (S.I. 2000/184)U.K.
239U.K.The Data Protection (Corporate Finance Exemption) Order 2000 is revoked.
Commencement Information
I570Sch. 19 para. 239 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Conditions under Paragraph 3 of Part II of Schedule 1) Order 2000 (S.I. 2000/185)U.K.
240U.K.The Data Protection (Conditions under Paragraph 3 of Part II of Schedule 1) Order 2000 is revoked.
Commencement Information
I571Sch. 19 para. 240 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Functions of Designated Authority) Order 2000 (S.I. 2000/186)U.K.
241U.K.The Data Protection (Functions of Designated Authority) Order 2000 is revoked.
Commencement Information
I572Sch. 19 para. 241 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (International Co-operation) Order 2000 (S.I. 2000/190)U.K.
242U.K.The Data Protection (International Co-operation) Order 2000 is revoked.
Commencement Information
I573Sch. 19 para. 242 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Subject Access) (Fees and Miscellaneous Provisions) Regulations 2000 (S.I. 2000/191)U.K.
243U.K.The Data Protection (Subject Access) (Fees and Miscellaneous Provisions) Regulations 2000 are revoked.
Commencement Information
I574Sch. 19 para. 243 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Consumer Credit (Credit Reference Agency) Regulations 2000 (S.I. 2000/290)U.K.
244U.K.In the Consumer Credit (Credit Reference Agency) Regulations 2000, regulation 4(1) and Schedule 1 (statement of rights under section 9(3) of the Data Protection Act 1998) are revoked.
Commencement Information
I575Sch. 19 para. 244 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Subject Access Modification) (Health) Order 2000 (S.I. 2000/413)U.K.
245U.K.The Data Protection (Subject Access Modification) (Health) Order 2000 is revoked.
Commencement Information
I576Sch. 19 para. 245 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Subject Access Modification) (Education) Order 2000 (S.I. 2000/414)U.K.
246U.K.The Data Protection (Subject Access Modification) (Education) Order 2000 is revoked.
Commencement Information
I577Sch. 19 para. 246 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Subject Access Modification) (Social Work) Order 2000 (S.I. 2000/415)U.K.
247U.K.The Data Protection (Subject Access Modification) (Social Work) Order 2000 is revoked.
Commencement Information
I578Sch. 19 para. 247 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Crown Appointments) Order 2000 (S.I. 2000/416)U.K.
248U.K.The Data Protection (Crown Appointments) Order 2000 is revoked.
Commencement Information
I579Sch. 19 para. 248 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Processing of Sensitive Personal Data) Order 2000 (S.I. 2000/417)U.K.
249U.K.The Data Protection (Processing of Sensitive Personal Data) Order 2000 is revoked.
Commencement Information
I580Sch. 19 para. 249 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Miscellaneous Subject Access Exemptions) Order 2000 (S.I. 2000/419)U.K.
250U.K.The Data Protection (Miscellaneous Subject Access Exemptions) Order 2000 is revoked.
Commencement Information
I581Sch. 19 para. 250 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Designated Codes of Practice) (No. 2) Order 2000 (S.I. 2000/1864)U.K.
251U.K.The Data Protection (Designated Codes of Practice) (No. 2) Order 2000 is revoked.
Commencement Information
I582Sch. 19 para. 251 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Representation of the People (England and Wales) Regulations 2001 (S.I. 2001/341)U.K.
252U.K.The Representation of the People (England and Wales) Regulations 2001 are amended as follows.
Commencement Information
I583Sch. 19 para. 252 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
253U.K.In regulation 3(1) (interpretation), at the appropriate places insert—
““Article 89 GDPR purposes” means the purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”;
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”;
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
Commencement Information
I584Sch. 19 para. 253 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
254U.K.In regulation 26(3)(a) (applications for registration), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I585Sch. 19 para. 254 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
255U.K.In regulation 26A(2)(a) (application for alteration of register in respect of name under section 10ZD), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I586Sch. 19 para. 255 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
256U.K.In regulation 32ZA(3)(f) (annual canvass), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I587Sch. 19 para. 256 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
257U.K.In regulation 61A (conditions on the use, supply and inspection of absent voter records or lists), for paragraph (a) (but not the final “or”) substitute—
“(a)Article 89 GDPR purposes;”.
Commencement Information
I588Sch. 19 para. 257 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
258(1)Regulation 92(2) (interpretation and application of Part VI etc) is amended as follows.U.K.
(2)After sub-paragraph (b) insert—
“(ba)“relevant requirement” means the requirement under Article 89 of the GDPR, read with section 19 of the Data Protection Act 2018, that personal data processed for Article 89 GDPR purposes must be subject to appropriate safeguards.”
(3)Omit sub-paragraphs (c) and (d).
Commencement Information
I589Sch. 19 para. 258 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
259U.K.In regulation 96(2A)(b)(i) (restriction on use of the full register), for “section 11(3) of the Data Protection Act 1998” substitute “ section 122(5) of the Data Protection Act 2018 ”.
Commencement Information
I590Sch. 19 para. 259 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
260U.K.In regulation 97(5) and (6) (supply of free copy of full register to the British Library and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I591Sch. 19 para. 260 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
261U.K.In regulation 97A(7) and (8) (supply of free copy of full register to the National Library of Wales and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I592Sch. 19 para. 261 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
262U.K.In regulation 99(6) and (7) (supply of free copy of full register etc to Statistics Board and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I593Sch. 19 para. 262 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
263U.K.In regulation 109A(9) and (10) (supply of free copy of full register to public libraries and local authority archives services and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I594Sch. 19 para. 263 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
264U.K.In regulation 119(2) (conditions on the use, supply and disclosure of documents open to public inspection), for sub-paragraph (i) (but not the final “or”) substitute—
“(i)Article 89 GDPR purposes;”.
Commencement Information
I595Sch. 19 para. 264 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Representation of the People (Scotland) Regulations 2001 (S.I. 2001/497)U.K.
265U.K.The Representation of the People (Scotland) Regulations 2001 are amended as follows.
Commencement Information
I596Sch. 19 para. 265 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
266U.K.In regulation 3(1) (interpretation), at the appropriate places, insert—
““Article 89 GDPR purposes” means the purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”;
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”;
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
Commencement Information
I597Sch. 19 para. 266 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
267U.K.In regulation 26(3)(a) (applications for registration), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I598Sch. 19 para. 267 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
268U.K.In regulation 26A(2)(a) (application for alteration of register in respect of name under section 10ZD), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I599Sch. 19 para. 268 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
269U.K.In regulation 32ZA(3)(f) (annual canvass), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I600Sch. 19 para. 269 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
270U.K.In regulation 61(3) (records and lists kept under Schedule 4), for paragraph (a) (but not the final “or”) substitute—
“(a)Article 89 GDPR purposes;”.
Commencement Information
I601Sch. 19 para. 270 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
271U.K.In regulation 61A (conditions on the use, supply and inspection of absent voter records or lists), for paragraph (a) (but not the final “or”) substitute—
“(a)Article 89 GDPR purposes;”.
Commencement Information
I602Sch. 19 para. 271 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
272(1)Regulation 92(2) (interpretation of Part VI etc) is amended as follows.U.K.
(2)After sub-paragraph (b) insert—
“(ba)“relevant requirement” means the requirement under Article 89 of the GDPR, read with section 19 of the Data Protection Act 2018, that personal data processed for Article 89 GDPR purposes must be subject to appropriate safeguards.”
(3)Omit sub-paragraphs (c) and (d).
Commencement Information
I603Sch. 19 para. 272 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
273U.K.In regulation 95(3)(b)(i) (restriction on use of the full register), for “section 11(3) of the Data Protection Act 1998” substitute “ section 122(5) of the Data Protection Act 2018 ”.
Commencement Information
I604Sch. 19 para. 273 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
274U.K.In regulation 96(5) and (6) (supply of free copy of full register to the National Library of Scotland and the British Library and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I605Sch. 19 para. 274 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
275U.K.In regulation 98(6) and (7) (supply of free copy of full register etc to Statistics Board and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I606Sch. 19 para. 275 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
276U.K.In regulation 108A(9) and (10) (supply of full register to statutory library authorities and local authority archives services and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I607Sch. 19 para. 276 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
277U.K.In regulation 119(2) (conditions on the use, supply and disclosure of documents open to public inspection), for sub-paragraph (i) (but not the final “or”) substitute—
“(i)Article 89 GDPR purposes;”.
Commencement Information
I608Sch. 19 para. 277 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Financial Services and Markets Act 2000 (Disclosure of Confidential Information) Regulations 2001 (S.I. 2001/2188)U.K.
278(1)Article 9 of the Financial Services and Markets 2000 (Disclosure of Confidential Information) Regulations 2001 (disclosure by regulators or regulator workers to certain other persons) is amended as follows.U.K.
(2)In paragraph (2B), for sub-paragraph (a) substitute—
“(a)the disclosure is made in accordance with Chapter V of the GDPR;”.
(3)After paragraph (5) insert—
“(6)In this article, “the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I609Sch. 19 para. 278 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Nursing and Midwifery Order 2001 (S.I. 2002/253)U.K.
279U.K.The Nursing and Midwifery Order 2001 is amended as follows.
Commencement Information
I610Sch. 19 para. 279 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
280(1)Article 3 (the Nursing and Midwifery Council and its Committees) is amended as follows.U.K.
(2)In paragraph (18), after “enactment” insert “ or the GDPR ”.
(3)After paragraph (18) insert—
“(19)In this paragraph, “the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I611Sch. 19 para. 280 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
281(1)Article 25 (the Council's power to require disclosure of information) is amended as follows.U.K.
(2)In paragraph (3), after “enactment” insert “ or the GDPR ”.
(3)In paragraph (6)—
(a)for “paragraph (5),” substitute “ paragraph (3)— ”, and
(b)at the appropriate place insert—
““the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I612Sch. 19 para. 281 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
282U.K.In article 39B (European professional card), after paragraph (2) insert—
“(3)For the purposes of Schedule 2B, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018.”
Commencement Information
I613Sch. 19 para. 282 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
283U.K.In article 40(6) (Directive 2005/36/EC: designation of competent authority etc), at the appropriate place insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I614Sch. 19 para. 283 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
284(1)Schedule 2B (Directive 2005/36/EC: European professional card) is amended as follows.U.K.
(2)In paragraph 8(1) (access to data) for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In paragraph 9 (processing data), omit sub-paragraph (2) (deeming the Society to be the controller for the purposes of Directive 95/46/EC).
Commencement Information
I615Sch. 19 para. 284 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
285(1)The table in Schedule 3 (functions of the Council under Directive 2005/36) is amended as follows.U.K.
(2)In the entry for Article 56(2), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In the entry for Article 56a(4), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I616Sch. 19 para. 285 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
286U.K.In Schedule 4 (interpretation), omit the definition of “Directive 95/46/EC”.
Commencement Information
I617Sch. 19 para. 286 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Electronic Commerce (EC Directive) Regulations 2002 (S.I. 2002/2013)U.K.
287U.K.Regulation 3 of the Electronic Commerce (EC Directive) Regulations 2002 (exclusions) is amended as follows.
Commencement Information
I618Sch. 19 para. 287 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
288U.K.In paragraph (1)(b) for “the Data Protection Directive and the Telecommunications Data Protection Directive” substitute “ the GDPR ”.
Commencement Information
I619Sch. 19 para. 288 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
289U.K.In paragraph (3)—
(a)omit the definitions of “Data Protection Directive” and “Telecommunications Data Protection Directive”, and
(b)at the appropriate place insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
Commencement Information
I620Sch. 19 para. 289 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Processing of Sensitive Personal Data) (Elected Representatives) Order 2002 (S.I. 2002/2905)U.K.
290U.K.The Data Protection (Processing of Sensitive Personal Data) (Elected Representatives) Order 2002 is revoked.
Commencement Information
I621Sch. 19 para. 290 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426)U.K.
291U.K.The Privacy and Electronic Communications (EC Directive) Regulations 2003 are amended as follows.
Commencement Information
I622Sch. 19 para. 291 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
292U.K.In regulation 2(1) (interpretation), in the definition of “the Information Commissioner” and “the Commissioner”, for “section 6 of the Data Protection Act 1998” substitute “ the Data Protection Act 2018 ”.
Commencement Information
I623Sch. 19 para. 292 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
293(1)Regulation 4 (relationship between these Regulations and the Data Protection Act 1998) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)In that sub-paragraph, for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(4)After that sub-paragraph insert—
“(2)In this regulation—
“the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“personal data” and “processing” have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4) and (14) of that Act).
(3)Regulation 2(2) and (3) (meaning of certain expressions) do not apply for the purposes of this regulation.”
(5)In the heading of that regulation, for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
Commencement Information
I624Sch. 19 para. 293 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Nationality, Immigration and Asylum Act 2002 (Juxtaposed Controls) Order 2003 (S.I. 2003/2818)U.K.
294U.K.The Nationality, Immigration and Asylum Act 2002 (Juxtaposed Controls) Order 2003 is amended as follows.
Commencement Information
I625Sch. 19 para. 294 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
295U.K.In article 8(2) (exercise of powers by French officers in a control zone in the United Kingdom: disapplication of law of England and Wales)—
(a)for “The Data Protection Act 1998” substitute “ The Data Protection Act 2018 ”, and
(b)for “are” substitute “ is ”.
Commencement Information
I626Sch. 19 para. 295 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
296U.K.In article 11(4) (exercise of powers by UK immigration officers and constables in a control zone in France: enactments having effect)—
(a)for “The Data Protection Act 1998” substitute “ The Data Protection Act 2018 ”,
(b)for “are” substitute “ is ”,
(c)for “section 5” substitute “ section 207 ”,
(d)for “data controller” substitute “ controller ”, and
(e)after “in the context of” insert “ the activities of ”.
Commencement Information
I627Sch. 19 para. 296 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Pupils' Educational Records (Scotland) Regulations 2003 (S.S.I. 2003/581)U.K.
297U.K.The Pupils' Educational Records (Scotland) Regulations 2003 are amended as follows.
Commencement Information
I628Sch. 19 para. 297 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
298(1)Regulation 2 (interpretation) is amended as follows.U.K.
(2)Omit the definition of “the 1998 Act”.
(3)At the appropriate place insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I629Sch. 19 para. 298 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
299(1)Regulation 6 (circumstances where information should not be disclosed) is amended as follows.U.K.
(2)After “any information” insert “ to the extent that any of the following conditions are satisfied ”.
(3)For paragraphs (a) to (c) substitute—
“(aa)the pupil to whom the information relates would have no right of access to the information under the GDPR;
(ab)the information is personal data described in Article 9(1) or 10 of the GDPR (special categories of personal data and personal data relating to criminal convictions and offences);”.
(4)In paragraph (d), for “to the extent that its disclosure” substitute “ the disclosure of the information ”.
(5)In paragraph (e), for “that” substitute “ the information ”.
Commencement Information
I630Sch. 19 para. 299 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
300U.K.In regulation 9 (fees), for paragraph (1) substitute—
“(1A)In complying with a request made under regulation 5(2), the responsible body may only charge a fee where Article 12(5) or Article 15(3) of the GDPR would permit the charging of a fee if the request had been made by the pupil to whom the information relates under Article 15 of the GDPR.
(1B)Where paragraph (1A) permits the charging of a fee, the responsible body may not charge a fee that—
(a)exceeds the cost of supply, or
(b)exceeds any limit in regulations made under section 12 of the Data Protection Act 2018 that would apply if the request had been made by the pupil to whom the information relates under Article 15 of the GDPR.”
Commencement Information
I631Sch. 19 para. 300 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
European Parliamentary Elections (Northern Ireland) Regulations 2004 (S.I. 2004/1267)U.K.
301U.K.Schedule 1 to the European Parliamentary Elections (Northern Ireland) Regulations 2004 (European Parliamentary elections rules) is amended as follows.
Commencement Information
I632Sch. 19 para. 301 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
302(1)Paragraph 74(1) (interpretation) is amended as follows.U.K.
(2)Omit the definitions of “relevant conditions” and “research purposes”.
(3)At the appropriate places insert—
““Article 89 GDPR purposes” means the purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”;
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
Commencement Information
I633Sch. 19 para. 302 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
303U.K.In paragraph 77(2)(b) (conditions on the use, supply and disclosure of documents open to public inspection), for “research purposes” substitute “ Article 89 GDPR purposes ”.
Commencement Information
I634Sch. 19 para. 303 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004 (S.I. 2004/3244)U.K.
304U.K.In regulation 3(1) of the Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004, omit “the appropriate limit referred to in section 9A(3) and (4) of the 1998 Act and”.
Commencement Information
I635Sch. 19 para. 304 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Environmental Information Regulations 2004 (S.I. 2004/3391)U.K.
305U.K.The Environmental Information Regulations 2004 are amended as follows.
Commencement Information
I636Sch. 19 para. 305 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
306(1)Regulation 2 (interpretation) is amended as follows.U.K.
(2)In paragraph (1), at the appropriate places, insert—
““the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR,
(b)section 34(1) of the Data Protection Act 2018, and
(c)section 85(1) of that Act;”;
““data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”;
““the GDPR” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);”;
““personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act);”.
(3)For paragraph (4) substitute—
“(4A)In these Regulations, references to the Data Protection Act 2018 have effect as if in Chapter 3 of Part 2 of that Act (other general processing)—
(a)the references to an FOI public authority were references to a public authority as defined in these Regulations, and
(b)the references to personal data held by such an authority were to be interpreted in accordance with regulation 3(2).”
Commencement Information
I637Sch. 19 para. 306 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
307(1)Regulation 13 (personal data) is amended as follows.U.K.
(2)For paragraph (1) substitute—
“(1)To the extent that the information requested includes personal data of which the applicant is not the data subject, a public authority must not disclose the personal data if—
(a)the first condition is satisfied, or
(b)the second or third condition is satisfied and, in all the circumstances of the case, the public interest in not disclosing the information outweighs the public interest in disclosing it.”
(3)For paragraph (2) substitute—
“(2A)The first condition is that the disclosure of the information to a member of the public otherwise than under these Regulations—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(2B)The second condition is that the disclosure of the information to a member of the public otherwise than under these Regulations would contravene—
(a)Article 21 of the GDPR (general processing: right to object to processing), or
(b)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).”
(4)For paragraph (3) substitute—
“(3A)The third condition is that—
(a)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018,
(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section, or
(c)on a request under section 94(1)(b) of that Act (intelligence services processing: rights of access by the data subject), the information would be withheld in reliance on a provision of Chapter 6 of Part 4 of that Act.”
(5)Omit paragraph (4).
(6)For paragraph (5) substitute—
“(5A)For the purposes of this regulation a public authority may respond to a request by neither confirming nor denying whether such information exists and is held by the public authority, whether or not it holds such information, to the extent that—
(a)the condition in paragraph (5B)(a) is satisfied, or
(b)a condition in paragraph (5B)(b) to (e) is satisfied and in all the circumstances of the case, the public interest in not confirming or denying whether the information exists outweighs the public interest in doing so.
(5B)The conditions mentioned in paragraph (5A) are—
(a)giving a member of the public the confirmation or denial—
(i)would (apart from these Regulations) contravene any of the data protection principles, or
(ii)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded;
(b)giving a member of the public the confirmation or denial would (apart from these Regulations) contravene Article 21 of the GDPR or section 99 of the Data Protection Act 2018 (right to object to processing);
(c)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for confirmation of whether personal data is being processed, the information would be withheld in reliance on a provision listed in paragraph (3A)(a);
(d)on a request under section 45(1)(a) of the Data Protection Act 2018 (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section;
(e)on a request under section 94(1)(a) of that Act (intelligence services processing: rights of access by the data subject), the information would be withheld in reliance on a provision of Chapter 6 of Part 4 of that Act.”
(7)After that paragraph insert—
“(6)In determining for the purposes of this regulation whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
Commencement Information
I638Sch. 19 para. 307 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
308U.K.In regulation 14 (refusal to disclose information), in paragraph (3)(b), for “regulations 13(2)(a)(ii) or 13(3)” substitute “ regulation 13(1)(b) or (5A) ”.
Commencement Information
I639Sch. 19 para. 308 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
309U.K.In regulation 18 (enforcement and appeal provisions), in paragraph (5), for “regulation 13(5)” substitute “ regulation 13(5A) ”.
Commencement Information
I640Sch. 19 para. 309 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520)U.K.
310U.K.The Environmental Information (Scotland) Regulations 2004 are amended as follows.
Commencement Information
I641Sch. 19 para. 310 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
311(1)Regulation 2 (interpretation) is amended as follows.U.K.
(2)In paragraph (1), at the appropriate places, insert—
““the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR, and
(b)section 34(1) of the Data Protection Act 2018;”;”;
““data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”;
““the GDPR” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);”;
““personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act);”.
(3)For paragraph (3) substitute—
“(3A)In these Regulations, references to the Data Protection Act 2018 have effect as if in Chapter 3 of Part 2 of that Act (other general processing)—
(a)the references to an FOI public authority were references to a Scottish public authority as defined in these Regulations, and
(b)the references to personal data held by such an authority were to be interpreted in accordance with paragraph (2) of this regulation.”
Commencement Information
I642Sch. 19 para. 311 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
312(1)Regulation 11 (personal data) is amended as follows.U.K.
(2)For paragraph (2) substitute—
“(2)To the extent that environmental information requested includes personal data of which the applicant is not the data subject, a Scottish public authority must not make the personal data available if—
(a)the first condition set out in paragraph (3A) is satisfied, or
(b)the second or third condition set out in paragraph (3B) or (4A) is satisfied and, in all the circumstances of the case, the public interest in making the information available is outweighed by that in not doing so.”
(3)For paragraph (3) substitute—
“(3A)The first condition is that the disclosure of the information to a member of the public otherwise than under these Regulations—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(3B)The second condition is that the disclosure of the information to a member of the public otherwise than under these Regulations would contravene Article 21 of the GDPR (general processing: right to object to processing).”
(4)For paragraph (4) substitute—
“(4A)The third condition is that any of the following applies to the information—
(a)it is exempt from the obligation under Article 15(1) of the GDPR (general processing: right of access by the data subject) to provide access to, and information about, personal data by virtue of provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018, or
(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section.”
(5)Omit paragraph (5).
(6)After paragraph (6) insert—
“(7)In determining, for the purposes of this regulation, whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
Commencement Information
I643Sch. 19 para. 312 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Licensing Act 2003 (Personal Licences) Regulations 2005 (S.I. 2005/41)U.K.
313(1)Regulation 7 of the Licensing Act 2003 (Personal Licences) Regulations 2005 (application for grant of a personal licence) is amended as follows.U.K.
(2)In paragraph (1)(b)—
(a)for paragraph (iii) (but not the final “, and”) substitute—
“(iii)the results of a request made under Article 15 of the GDPR or section 45 of the Data Protection Act 2018 (rights of access by the data subject) to the National Identification Service for information contained in the Police National Computer”, and
(b)in the words following paragraph (iii), omit “search”.
(3)After paragraph (2) insert—
“(3)In this regulation, “the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I644Sch. 19 para. 313 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Education (Pupil Information) (England) Regulations 2005 (S.I. 2005/1437)U.K.
314U.K.The Education (Pupil Information) (England) Regulations 2005 are amended as follows.
Commencement Information
I645Sch. 19 para. 314 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
315U.K.In regulation 3(5) (meaning of educational record) for “section 1(1) of the Data Protection Act 1998” substitute “ section 3(4) of the Data Protection Act 2018 ”.
Commencement Information
I646Sch. 19 para. 315 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
316(1)Regulation 5 (disclosure of curricular and educational records) is amended as follows.U.K.
(2)In paragraph (4)—
(a)in sub-paragraph (a), for “the Data Protection Act 1998” substitute “ the GDPR ”, and
(b)in sub-paragraph (b), for “that Act or by virtue of any order made under section 30(2) or section 38(1) of the Act” substitute “ the GDPR ”.
(3)After paragraph (6) insert—
“(7)In this regulation, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018.”
Commencement Information
I647Sch. 19 para. 316 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (S.I. 2005/2042)U.K.
317(1)Regulation 45 of the Civil Contingencies Act 2004 (Contingency Planning) Regulations 2005 (sensitive information) is amended as follows.U.K.
(2)In paragraph (1)(d)—
(a)omit “, within the meaning of section 1(1) of the Data Protection Act 1998”, and
(b)for “(2) or (3)” substitute “ (1A), (1B) or (1C) ”.
(3)After paragraph (1) insert—
“(1A)The condition in this paragraph is that the disclosure of the information to a member of the public—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(1B)The condition in this paragraph is that the disclosure of the information to a member of the public would contravene—
(a)Article 21 of the GDPR (general processing: right to object to processing), or
(b)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).
(1C)The condition in this paragraph is that—
(a)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018,
(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section, or
(c)on a request under section 94(1)(b) of that Act (intelligence services processing: rights of access by the data subject), the information would be withheld in reliance on a provision of Chapter 6 of Part 4 of that Act.
(1D)In this regulation—
“the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR,
(b)section 34(1) of the Data Protection Act 2018, and
(c)section 85(1) of that Act;
“the GDPR” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);
“personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).
(1E)In determining for the purposes of this regulation whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
(4)Omit paragraphs (2) to (4).
Commencement Information
I648Sch. 19 para. 317 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Register of Judgments, Orders and Fines Regulations 2005 (S.I. 2005/3595)U.K.
318U.K.In regulation 3 of the Register of Judgments, Orders and Fines Regulations 2005 (interpretation)—
(a)for the definition of “data protection principles” substitute—
““data protection principles” means the principles set out in Article 5(1) of the GDPR;”, and
(b)at the appropriate place insert—
““the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act);”.
Commencement Information
I649Sch. 19 para. 318 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 (S.S.I. 2005/494)U.K.
319U.K.The Civil Contingencies Act 2004 (Contingency Planning) (Scotland) Regulations 2005 are amended as follows.
Commencement Information
I650Sch. 19 para. 319 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
320(1)Regulation 39 (sensitive information) is amended as follows.U.K.
(2)In paragraph (1)(d)—
(a)omit “, within the meaning of section 1(1) of the Data Protection Act 1998”, and
(b)for “(2) or (3)” substitute “ (1A), (1B) or (1C) ”.
(3)After paragraph (1) insert—
“(1A)The condition in this paragraph is that the disclosure of the information to a member of the public—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(1B)The condition in this paragraph is that the disclosure of the information to a member of the public would contravene—
(a)Article 21 of the GDPR (general processing: right to object to processing), or
(b)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).
(1C)The condition in this paragraph is that—
(a)on a request under Article 15(1) of the GDPR (general processing: right of access by the data subject) for access to personal data, the information would be withheld in reliance on provision made by or under section 15, 16 or 26 of, or Schedule 2, 3 or 4 to, the Data Protection Act 2018,
(b)on a request under section 45(1)(b) of that Act (law enforcement processing: right of access by the data subject), the information would be withheld in reliance on subsection (4) of that section, or
(c)on a request under section 94(1)(b) of that Act (intelligence services processing: rights of access by the data subject), the information would be withheld in reliance on a provision of Chapter 6 of Part 4 of that Act.
(1D)In this regulation—
“the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR,
(b)section 34(1) of the Data Protection Act 2018, and
(c)section 85(1) of that Act;
“data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“the GDPR” and references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);
“personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).
(1E)In determining for the purposes of this regulation whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
(4)Omit paragraphs (2) to (4).
Commencement Information
I651Sch. 19 para. 320 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Processing of Sensitive Personal Data) Order 2006 (S.I. 2006/2068)U.K.
321U.K.The Data Protection (Processing of Sensitive Personal Data) Order 2006 is revoked.
Commencement Information
I652Sch. 19 para. 321 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Assembly for Wales (Representation of the People) Order 2007 (S.I. 2007/236)U.K.
322(1)Paragraph 14 of Schedule 1 to the National Assembly for Wales (Representation of the People) Order 2007 (absent voting at Assembly elections: conditions on the use, supply and inspection of absent vote records or lists) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)For paragraph (a) of that sub-paragraph (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”.
(4)After that sub-paragraph insert—
“(2)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I653Sch. 19 para. 322 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Mental Capacity Act 2005 (Loss of Capacity during Research Project) (England) Regulations 2007 (S.I. 2007/679)U.K.
323U.K.In regulation 3 of the Mental Capacity Act 2005 (Loss of Capacity during Research Project) (England) Regulations 2007 (research which may be carried out despite a participant's loss of capacity), for paragraph (b) substitute—
“(b)any material used consists of or includes human cells or human DNA,”.
Commencement Information
I654Sch. 19 para. 323 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Assembly for Wales Commission (Crown Status) Order 2007 (S.I. 2007/1118)U.K.
324U.K.For article 5 of the National Assembly for Wales Commission (Crown Status) Order 2007 substitute—
“Data Protection Act 2018U.K.
5(1)The Assembly Commission is to be treated as a Crown body for the purposes of the Data Protection Act 2018 to the extent specified in this article.
(2)The Assembly Commission is to be treated as a government department for the purposes of the following provisions—
(a)section 8(d) (lawfulness of processing under the GDPR: public interest etc),
(b)section 209 (application to the Crown),
(c)paragraph 6 of Schedule 1 (statutory etc and government purposes),
(d)paragraph 7 of Schedule 2 (exemptions from the GDPR: functions designed to protect the public etc), and
(e)paragraph 8(1)(o) of Schedule 3 (exemptions from the GDPR: health data).
(3)In the provisions mentioned in paragraph (4)—
(a)references to employment by or under the Crown are to be treated as including employment as a member of staff of the Assembly Commission, and
(b)references to a person in the service of the Crown are to be treated as including a person so employed.
(4)The provisions are—
(a)section 24(3) (exemption for certain data relating to employment under the Crown), and
(b)section 209(6) (application of certain provisions to a person in the service of the Crown).
(5)In this article, references to a provision of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(14) of that Act).”
Commencement Information
I655Sch. 19 para. 324 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Mental Capacity Act 2005 (Loss of Capacity during Research Project) (Wales) Regulations 2007 (S.I. 2007/837 (W.72))U.K.
325U.K.In regulation 3 of the Mental Capacity Act 2005 (Loss of Capacity during Research Project) (Wales) Regulations 2007 (research which may be carried out despite a participant's loss of capacity) —
(a)in the English language text, for paragraph (c) substitute—
“(c)any material used consists of or includes human cells or human DNA; and”, and
(b)in the Welsh language text, for paragraph (c) substitute—
“(c)os yw unrhyw ddeunydd a ddefnyddir yn gelloedd dynol neu'n DNA dynol neu yn eu cynnwys; ac”.
Commencement Information
I656Sch. 19 para. 325 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Representation of the People (Absent Voting at Local Elections) (Scotland) Regulations 2007 (S.S.I. 2007/170)U.K.
326(1)Regulation 18 of the Representation of the People (Absent Voting at Local Elections) (Scotland) Regulations 2007 (conditions on the supply and inspection of absent voter records or lists) is amended as follows.U.K.
(2)In paragraph (1), for sub-paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”.
(3)After paragraph (1) insert—
“(2)In this regulation, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I657Sch. 19 para. 326 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Representation of the People (Post-Local Government Elections Supply and Inspection of Documents) (Scotland) Regulations 2007 (S.S.I. 2007/264)U.K.
327U.K.In regulation 5 of the Representation of the People (Post-Local Government Elections Supply and Inspection of Documents) (Scotland) Regulations 2007 (conditions on the use, supply and disclosure of documents open to public inspection)—
(a)in paragraph (2), for sub-paragraph (i) (but not the final “or”) substitute—
“(i)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”, and
(b)after paragraph (3) insert—
“(4)In this regulation, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I658Sch. 19 para. 327 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Education (Pupil Records and Reporting) (Transitional) Regulations (Northern Ireland) 2007 (S.R. (N.I.) 2007 No. 43)U.K.
328U.K.The Education (Pupil Records and Reporting) (Transitional) Regulations (Northern Ireland) 2007 are amended as follows.
Commencement Information
I659Sch. 19 para. 328 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
329U.K.In regulation 2 (interpretation), at the appropriate place insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I660Sch. 19 para. 329 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
330U.K.In regulation 10(2) (duties of Boards of Governors), for “documents which are the subject of an order under section 30(2) of the Data Protection Act 1998” substitute “ information to which the pupil to whom the information relates would have no right of access under the GDPR ”.
Commencement Information
I661Sch. 19 para. 330 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Representation of the People (Northern Ireland) Regulations 2008 (S.I. 2008/1741)U.K.
331U.K.In regulation 118 of the Representation of the People (Northern Ireland) Regulations 2008 (conditions on the use, supply and disclosure of documents open to public inspection)—
(a)in paragraph (2), for “research purposes within the meaning of that term in section 33 of the Data Protection Act 1998” substitute “ purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics) ”, and
(b)after paragraph (3) insert—
“(4)In this regulation, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I662Sch. 19 para. 331 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Companies Act 2006 (Extension of Takeover Panel Provisions) (Isle of Man) Order 2008 (S.I. 2008/3122)U.K.
332U.K.In paragraph 1(c) of the Schedule to the Companies Act 2006 (Extension of Takeover Panel Provisions) (Isle of Man) Order 2008 (modifications with which Chapter 1 of Part 28 of the Companies Act 2006 extends to the Isle of Man), for “the Data Protection Act 1998 (c 29)” substitute “ the data protection legislation ”.
Commencement Information
I663Sch. 19 para. 332 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Controlled Drugs (Supervision of Management and Use) (Wales) Regulations 2008 (S.I. 2008/3239 (W.286))U.K.
333U.K.The Controlled Drugs (Supervision of Management and Use) (Wales) Regulations 2008 are amended as follows.
Commencement Information
I664Sch. 19 para. 333 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
334U.K.In regulation 2(1) (interpretation)—
(a)at the appropriate place in the English language text insert—
““the GDPR” (“y GDPR”) and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);”, and
(b)at the appropriate place in the Welsh language text insert—
““mae i “y GDPR” a chyfeiriadau at Atodlen 2 i Ddeddf Diogelu Data 2018 yr un ystyr ag a roddir i “the GDPR” a chyfeiriadau at yr Atodlen honno yn Rhannau 5 i 7 o'r Ddeddf honno (gweler adran 3(10), (11) a (14) o'r Ddeddf honno);”.”
Commencement Information
I665Sch. 19 para. 334 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
335(1)Regulation 25 (duty to co-operate by disclosing information as regards relevant persons) is amended as follows.U.K.
(2)In paragraph (7)—
(a)in the English language text, at the end insert “ or the GDPR ”, and
(b)in the Welsh language text, at the end insert “neu'r GDPR”.
(3)For paragraph (8)—
(a)in the English language text substitute—
“(8)In determining for the purposes of paragraph (7) whether disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”, and
(b)in the Welsh language text substitute—
“(8)Wrth benderfynu at ddibenion paragraff (7) a yw datgeliad wedi'i wahardd, mae i'w dybied at ddibenion paragraff 5(2) o Atodlen 2 i Ddeddf Diogelu Data 2018 a pharagraff 3(2) o Atodlen 11 i'r Ddeddf honno (esemptiadau rhag darpariaethau penodol o'r ddeddfwriaeth diogelu data: datgeliadau sy'n ofynnol gan y gyfraith) bod y datgeliad yn ofynnol gan y rheoliad hwn.”
Commencement Information
I666Sch. 19 para. 335 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
336(1)Regulation 26 (responsible bodies requesting additional information be disclosed about relevant persons) is amended as follows.U.K.
(2)In paragraph (6)—
(a)in the English language text, at the end insert “ or the GDPR ”, and
(b)in the Welsh language text, at the end insert “neu'r GDPR”.
(3)For paragraph (7)—
(a)in the English language text substitute—
“(7)In determining for the purposes of paragraph (6) whether disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”, and
(b)in the Welsh language text substitute—
“(7)Wrth benderfynu at ddibenion paragraff (6) a yw datgeliad wedi'i wahardd, mae i'w dybied at ddibenion paragraff 5(2) o Atodlen 2 i Ddeddf Diogelu Data 2018 a pharagraff 3(2) o Atodlen 11 i'r Ddeddf honno (esemptiadau rhag darpariaethau penodol o'r ddeddfwriaeth diogelu data: datgeliadau sy'n ofynnol gan y gyfraith) bod y datgeliad yn ofynnol gan y rheoliad hwn.”
Commencement Information
I667Sch. 19 para. 336 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
337(1)Regulation 29 (occurrence reports) is amended as follows.U.K.
(2)In paragraph (3)—
(a)in the English language text, at the end insert “ or the GDPR ”, and
(b)in the Welsh language text, at the end insert “neu'r GDPR”.
(3)For paragraph (4)—
(a)in the English language text substitute—
“(4)In determining for the purposes of paragraph (3) whether disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”, and
(b)in the Welsh language text substitute—
“(4)Wrth benderfynu at ddibenion paragraff (3) a yw datgeliad wedi'i wahardd, mae i'w dybied at ddibenion paragraff 5(2) o Atodlen 2 i Ddeddf Diogelu Data 2018 a pharagraff 3(2) o Atodlen 11 i'r Ddeddf honno (esemptiadau rhag darpariaethau penodol o'r ddeddfwriaeth diogelu data: datgeliadau sy'n ofynnol gan y gyfraith) bod y datgeliad yn ofynnol gan y rheoliad hwn.”
Commencement Information
I668Sch. 19 para. 337 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Energy Order 2003 (Supply of Information) Regulations (Northern Ireland) 2008 (S.R. (N.I.) 2008 No. 3)U.K.
338(1)Regulation 5 of the Energy Order 2003 (Supply of Information) Regulations (Northern Ireland) 2008 (information whose disclosure would be affected by the application of other legislation) is amended as follows.U.K.
(2)In paragraph (3)—
(a)omit “within the meaning of section 1(1) of the Data Protection Act 1998”, and
(b)for the words from “where” to the end substitute “ if the condition in paragraph (3A) or (3B) is satisfied ”.
(3)After paragraph (3) insert—
“(3A)The condition in this paragraph is that the disclosure of the information to a member of the public—
(a)would contravene any of the data protection principles, or
(b)would do so if the exemptions in section 24(1) of the Data Protection Act 2018 (manual unstructured data held by public authorities) were disregarded.
(3B)The condition in this paragraph is that the disclosure of the information to a member of the public would contravene—
(a)Article 21 of the GDPR (general processing: right to object to processing), or
(b)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).”
(4)After paragraph (4) insert—
“(5)In this regulation—
“the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR,
(b)section 34(1) of the Data Protection Act 2018, and
(c)section 85(1) of that Act;
“the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act);
“personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).”
Commencement Information
I669Sch. 19 para. 338 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Companies (Disclosure of Address) Regulations 2009 (S.I. 2009/214)U.K.
339(1)Paragraph 6 of Schedule 2 to the Companies (Disclosure of Address) Regulations 2009 (conditions for permitted disclosure to a credit reference agency) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)In paragraph (b) of that sub-paragraph, for sub-paragraph (ii) substitute—
“(ii)for the purposes of ensuring that it complies with its data protection obligations;”.
(4)In paragraph (c) of that sub-paragraph—
(a)omit “or” at the end of sub-paragraph (i), and
(b)at the end insert “; or
(iii)section 144 of the Data Protection Act 2018 (false statements made in response to an information notice) or section 148 of that Act (destroying or falsifying information and documents etc);”.
(5)After paragraph (c) of that sub-paragraph insert—
“(d)has not been given a penalty notice under section 155 of the Data Protection Act 2018 in circumstances described in paragraph (c)(ii), other than a penalty notice that has been cancelled.”
(6)After sub-paragraph (1) insert—
“(2)In this paragraph, “data protection obligations”, in relation to a credit reference agency, means—
(a)where the agency carries on business in the United Kingdom, obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018);
(b)where the agency carries on business in a EEA State other than the United Kingdom, obligations under—
(i)the GDPR (as defined in section 3(10) of the Data Protection Act 2018),
(ii)legislation made in exercise of powers conferred on member States under the GDPR (as so defined), and
(iii)legislation implementing the Law Enforcement Directive (as defined in section 3(12) of the Data Protection Act 2018).”
Commencement Information
I670Sch. 19 para. 339 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Overseas Companies Regulations 2009 (S.I. 2009/1801)U.K.
340(1)Paragraph 6 of Schedule 2 to the Overseas Companies Regulations 2009 (conditions for permitted disclosure to a credit reference agency) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)In paragraph (b) of that sub-paragraph, for sub-paragraph (ii) substitute—
“(ii)for the purposes of ensuring that it complies with its data protection obligations;”.
(4)In paragraph (c) of that sub-paragraph—
(a)omit “or” at the end of sub-paragraph (i), and
(b)at the end insert “; or
(iii)section 144 of the Data Protection Act 2018 (false statements made in response to an information notice) or section 148 of that Act (destroying or falsifying information and documents etc);”.
(5)After paragraph (c) of that sub-paragraph insert—
“(d)has not been given a penalty notice under section 155 of the Data Protection Act 2018 in circumstances described in paragraph (c)(ii), other than a penalty notice that has been cancelled.”
(6)After sub-paragraph (1) insert—
“(2)In this paragraph, “data protection obligations”, in relation to a credit reference agency, means—
(a)where the agency carries on business in the United Kingdom, obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018);
(b)where the agency carries on business in a EEA State other than the United Kingdom, obligations under—
(i)the GDPR (as defined in section 3(10) of the Data Protection Act 2018),
(ii)legislation made in exercise of powers conferred on member States under the GDPR (as so defined), and
(iii)legislation implementing the Law Enforcement Directive (as defined in section 3(12) of the Data Protection Act 2018).”
Commencement Information
I671Sch. 19 para. 340 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Processing of Sensitive Personal Data) Order 2009 (S.I. 2009/1811)U.K.
341U.K.The Data Protection (Processing of Sensitive Personal Data) Order 2009 is revoked.
Commencement Information
I672Sch. 19 para. 341 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Provision of Services Regulations 2009 (S.I. 2009/2999)U.K.
342U.K.In regulation 25 of the Provision of Services Regulations 2009 (derogations from the freedom to provide services), for paragraph (d) substitute—
“(d)matters covered by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
Commencement Information
I673Sch. 19 para. 342 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
INSPIRE Regulations 2009 (S.I. 2009/3157)U.K.
343(1)Regulation 9 of the INSPIRE Regulations 2009 (public access to spatial data sets and spatial data services) is amended as follows.U.K.
(2)In paragraph (2)—
(a)omit “or” at the end of sub-paragraph (a),
(b)for sub-paragraph (b) substitute—
“(b)Article 21 of the GDPR (general processing: right to object to processing), or
(c)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).”, and
(c)omit the words following sub-paragraph (b).
(3)After paragraph (7) insert—
“(8)In this regulation—
“the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR,
(b)section 34(1) of the Data Protection Act 2018, and
(c)section 85(1) of that Act;
“the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act);
“personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).
(9)In determining for the purposes of this regulation whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
Commencement Information
I674Sch. 19 para. 343 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
INSPIRE (Scotland) Regulations 2009 (S.S.I. 2009/440)U.K.
344(1)Regulation 10 of the INSPIRE (Scotland) Regulations 2009 (public access to spatial data sets and spatial data services) is amended as follows.U.K.
(2)In paragraph (2)—
(a)omit “or” at the end of sub-paragraph (a),
(b)for sub-paragraph (b) substitute—
“(b)Article 21 of the GDPR (general processing: right to object to processing), or
(c)section 99 of the Data Protection Act 2018 (intelligence services processing: right to object to processing).”, and
(c)omit the words following sub-paragraph (b).
(3)After paragraph (6) insert—
“(7)In this regulation—
“the data protection principles” means the principles set out in—
(a)Article 5(1) of the GDPR,
(b)section 34(1) of the Data Protection Act 2018, and
(c)section 85(1) of that Act;
“the GDPR” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(10), (11) and (14) of that Act);
“personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).
(8)In determining for the purposes of this regulation whether the lawfulness principle in Article 5(1)(a) of the GDPR would be contravened by the disclosure of information, Article 6(1) of the GDPR (lawfulness) is to be read as if the second sub-paragraph (disapplying the legitimate interests gateway in relation to public authorities) were omitted.”
Commencement Information
I675Sch. 19 para. 344 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Controlled Drugs (Supervision of Management and Use) Regulations (Northern Ireland) 2009 (S.R (N.I.) 2009 No. 225)U.K.
345U.K.The Controlled Drugs (Supervision of Management and Use) Regulations (Northern Ireland) 2009 are amended as follows.
Commencement Information
I676Sch. 19 para. 345 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
346U.K.In regulation 2(2) (interpretation), at the appropriate place insert—
““the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);”.”
Commencement Information
I677Sch. 19 para. 346 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
347(1)Regulation 25 (duty to co-operate by disclosing information as regards relevant persons) is amended as follows.U.K.
(2)In paragraph (7), at the end insert “ or the GDPR ”.
(3)For paragraph (8) substitute—
“(8)In determining for the purposes of paragraph (7) whether disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”
Commencement Information
I678Sch. 19 para. 347 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
348(1)Regulation 26 (responsible bodies requesting additional information be disclosed about relevant persons) is amended as follows.U.K.
(2)In paragraph (6), at the end insert “ or the GDPR ”.
(3)For paragraph (7) substitute—
“(7)In determining for the purposes of paragraph (6) whether disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”
Commencement Information
I679Sch. 19 para. 348 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
349(1)Regulation 29 (occurrence reports) is amended as follows.U.K.
(2)In paragraph (3), at the end insert “ or the GDPR ”.
(3)For paragraph (4) substitute—
“(4)In determining for the purposes of paragraph (3) whether disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”
Commencement Information
I680Sch. 19 para. 349 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010 (S.I. 2010/31)U.K.
350U.K.The Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010 are revoked.
Commencement Information
I681Sch. 19 para. 350 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Pharmacy Order 2010 (S.I. 2010/231)U.K.
351U.K.The Pharmacy Order 2010 is amended as follows.
Commencement Information
I682Sch. 19 para. 351 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
352U.K.In article 3(1) (interpretation), omit the definition of “Directive 95/46/EC”.
Commencement Information
I683Sch. 19 para. 352 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
353(1)Article 9 (inspection and enforcement) is amended as follows.U.K.
(2)For paragraph (4) substitute—
“(4)If a report that the Council proposes to publish pursuant to paragraph (3) includes personal data, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure of the personal data is required by paragraph (3) of this article.”
(3)After paragraph (4) insert—
“(5)In this article, “personal data” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(2) and (14) of that Act).”
Commencement Information
I684Sch. 19 para. 353 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
354U.K.In article 33A (European professional card), after paragraph (2) insert—
“(3)In Schedule 2A, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018.”
Commencement Information
I685Sch. 19 para. 354 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
355(1)Article 49 (disclosure of information: general) is amended as follows.U.K.
(2)In paragraph (2)(a), after “enactment” insert “ or the GDPR ”.
(3)For paragraph (3) substitute—
“(3)In determining for the purposes of paragraph (2)(a) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by paragraph (1) of this article.”
(4)After paragraph (5) insert—
“(6)In this article, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I686Sch. 19 para. 355 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
356(1)Article 55 (professional performance assessments) is amended as follows.U.K.
(2)In paragraph (5)(a), after “enactment” insert “ or the GDPR ”.
(3)For paragraph (6) substitute—
“(6)In determining for the purposes of paragraph (5)(a) whether a disclosure is prohibited, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by paragraph (4) of this article.”
(4)After paragraph (8) insert—
“(9)In this article, “the GDPR” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act).”
Commencement Information
I687Sch. 19 para. 356 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
357U.K.In article 67(6) (Directive 2005/36/EC: designation of competent authority etc.), after sub-paragraph (a) insert—
“(aa)“the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I688Sch. 19 para. 357 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
358(1)Schedule 2A (Directive 2005/36/EC: European professional card) is amended as follows.U.K.
(2)In paragraph 8(1) (access to data), for “Directive 95/46/EC)” substitute “ the GDPR ”.
(3)In paragraph 9 (processing data)—
(a)omit sub-paragraph (2) (deeming the Council to be the controller for the purposes of Directive 95/46/EC), and
(b)after sub-paragraph (2) insert—
“(3)In this paragraph, “personal data” has the same meaning as in the Data Protection Act 2018 (see section 3(2) of that Act).”
Commencement Information
I689Sch. 19 para. 358 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
359(1)The table in Schedule 3 (Directive 2005/36/EC: designation of competent authority etc.) is amended as follows.U.K.
(2)In the entry for Article 56(2), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
(3)In the entry for Article 56a(4), in the second column, for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I690Sch. 19 para. 359 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Monetary Penalties) Order 2010 (S.I. 2010/910)U.K.
360U.K.The Data Protection (Monetary Penalties) Order 2010 is revoked.
Commencement Information
I691Sch. 19 para. 360 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Employment Savings Trust Order 2010 (S.I. 2010/917)U.K.
361U.K.The National Employment Savings Trust Order 2010 is amended as follows.
Commencement Information
I692Sch. 19 para. 361 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
362U.K.In article 2 (interpretation)—
(a)omit the definition of “data” and “personal data”, and
(b)at the appropriate place insert—
““personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).”
Commencement Information
I693Sch. 19 para. 362 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
363(1)Article 10 (disclosure of requested data to the Secretary of State) is amended as follows.U.K.
(2)In paragraph (1)—
(a)for “disclosure of data” substitute “ disclosure of information ”, and
(b)for “requested data” substitute “ requested information ”.
(3)In paragraph (2)—
(a)for “requested data” substitute “ requested information ”,
(b)for “those data are” substitute “ the information is ”, and
(c)for “receive those data” substitute “ receive that information ”.
(4)In paragraph (3), for “requested data” substitute “ requested information ”.
(5)In paragraph (4), for “requested data” substitute “ requested information ”.
Commencement Information
I694Sch. 19 para. 363 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Local Elections (Northern Ireland) Order 2010 (S.I. 2010/2977)U.K.
364(1)Schedule 3 to the Local Elections (Northern Ireland) Order 2010 (access to marked registers and other documents open to public inspection after an election) is amended as follows.U.K.
(2)In paragraph 1(1) (interpretation and general)—
(a)omit the definition of “research purposes”, and
(b)at the appropriate places insert—
““Article 89 GDPR purposes” means the purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”;
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
(3)In paragraph 5(3) (restrictions on the use, supply and disclosure of documents open to public inspection), for “research purposes” substitute “ Article 89 GDPR purposes ”.
Commencement Information
I695Sch. 19 para. 364 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Pupil Information (Wales) Regulations 2011 (S.I. 2011/1942 (W.209))U.K.
365(1)Regulation 5 of the Pupil Information (Wales) Regulations 2011 (duties of head teacher - educational records) is amended as follows.U.K.
(2)In paragraph (5)—
(a)in the English language text, for “documents which are subject to any order under section 30(2) of the Data Protection Act 1998” substitute “information—
(a)which the head teacher could not lawfully disclose to the pupil under the GDPR, or
(b)to which the pupil would have no right of access under the GDPR.”, and
(b)in the Welsh language text, for “ddogfennau sy'n ddarostyngedig i unrhyw orchymyn o dan adran 30(2) o Ddeddf Diogelu Data 1998” substitute “wybodaeth—
(a)na allai'r pennaeth ei datgelu'n gyfreithlon i'r disgybl o dan y GDPR, neu
(b)na fyddai gan y disgybl hawl mynediad ati o dan y GDPR.”
(3)After paragraph (5)—
(a)in the English language text insert—
“(6)In this regulation, “the GDPR” (“y GDPR”) means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018.”, and
(b)in the Welsh language text insert—
“(6)Yn y rheoliad hwn, ystyr “y GDPR” (“the GDPR”) yw Rheoliad (EU) 2016/679 Senedd Ewrop a'r Cyngor dyddiedig 27 Ebrill 2016 ar ddiogelu personau naturiol o ran prosesu data personol a rhyddid symud data o'r fath (y Rheoliad Diogelu Data Cyffredinol), fel y'i darllenir ynghyd â Phennod 2 o Ran 2 o Ddeddf Diogelu Data 2018.”
Commencement Information
I696Sch. 19 para. 365 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Debt Arrangement Scheme (Scotland) Regulations 2011 (S.S.I. 2011/141)U.K.
366U.K.In Schedule 4 to the Debt Arrangement Scheme (Scotland) Regulations 2011 (payments distributors), omit paragraph 2.
Commencement Information
I697Sch. 19 para. 366 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Police and Crime Commissioner Elections Order 2012 (S.I. 2012/1917)U.K.
367U.K.The Police and Crime Commissioner Elections Order 2012 is amended as follows.
Commencement Information
I698Sch. 19 para. 367 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
368(1)Schedule 2 (absent voting in Police and Crime Commissioner elections) is amended as follows.U.K.
(2)In paragraph 20 (absent voter lists: supply of copies etc)—
(a)in sub-paragraph (8), for paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”, and
(b)after sub-paragraph (10) insert—
“(11)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
(3)In paragraph 24 (restriction on use of absent voter records or lists or the information contained in them)—
(a)in sub-paragraph (3), for paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics),”, and
(b)after that sub-paragraph insert—
“(4)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I699Sch. 19 para. 368 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
369(1)Schedule 10 (access to marked registers and other documents open to public inspection after an election) is amended as follows.U.K.
(2)In paragraph 1(2) (interpretation), omit paragraphs (c) and (d) (but not the final “and”).
(3)In paragraph 5 (restriction on use of documents or of information contained in them)—
(a)in sub-paragraph (3), for paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics),”, and
(b)after sub-paragraph (4) insert—
“(5)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I700Sch. 19 para. 369 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Processing of Sensitive Personal Data) Order 2012 (S.I. 2012/1978)U.K.
370U.K.The Data Protection (Processing of Sensitive Personal Data) Order 2012 is revoked.
Commencement Information
I701Sch. 19 para. 370 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Neighbourhood Planning (Referendums) Regulations 2012 (S.I. 2012/2031)U.K.
371U.K.Schedule 6 to the Neighbourhood Planning (Referendums) Regulations 2012 (registering to vote in a business referendum) is amended as follows.
Commencement Information
I702Sch. 19 para. 371 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
372(1)Paragraph 29(1) (interpretation of Part 8) is amended as follows.U.K.
(2)At the appropriate places insert—
““Article 89 GDPR purposes” means the purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”;
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation);”.
(3)For the definition of “relevant conditions” substitute—
““relevant requirement” means the requirement under Article 89 of the GDPR, read with section 19 of the Data Protection Act 2018, that personal data processed for Article 89 GDPR purposes must be subject to appropriate safeguards;”.
(4)Omit the definition of “research purposes”.
Commencement Information
I703Sch. 19 para. 372 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
373U.K.In paragraph 32(3)(b)(i), for “section 11(3) of the Data Protection Act 1998” substitute “ section 122(5) of the Data Protection Act 2018 ”.
Commencement Information
I704Sch. 19 para. 373 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
374U.K.In paragraph 33(6) and (7) (supply of copy of business voting register to the British Library and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I705Sch. 19 para. 374 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
375U.K.In paragraph 34(6) and (7) (supply of copy of business voting register to the Office of National Statistics and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I706Sch. 19 para. 375 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
376U.K.In paragraph 39(8) and (97) (supply of copy of business voting register to public libraries and local authority archives services and restrictions on use), for “research purposes in compliance with the relevant conditions” substitute “ Article 89 GDPR purposes in accordance with the relevant requirement ”.
Commencement Information
I707Sch. 19 para. 376 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
377U.K.In paragraph 45(2) (conditions on the use, supply and disclosure of documents open to public inspection), for paragraph (a) (but not the final “or”) substitute—
“(a)Article 89 GDPR purposes (as defined in paragraph 29),”.
Commencement Information
I708Sch. 19 para. 377 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Controlled Drugs (Supervision of Management and Use) Regulations 2013 (S.I. 2013/373)U.K.
378(1)Regulation 20 of the Controlled Drugs (Supervision of Management and Use) Regulations 2013 (information management) is amended as follows.U.K.
(2)For paragraph (4) substitute—
“(4)Where a CDAO, a responsible body or someone acting on their behalf is permitted to share information which includes personal data by virtue of a function under these Regulations, it is to be assumed for the purposes of paragraph 5(2) of Schedule 2 to the Data Protection Act 2018 and paragraph 3(2) of Schedule 11 to that Act (exemptions from certain provisions of the data protection legislation: disclosures required by law) that the disclosure is required by this regulation.”
(3)In paragraph (5), after “enactment” insert “ or the GDPR ”.
(4)After paragraph (6) insert—
“(7)In this regulation, “the GDPR”, “personal data” and references to Schedule 2 to the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (10), (11) and (14) of that Act).”
Commencement Information
I709Sch. 19 para. 378 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Communications Act 2003 (Disclosure of Information) Order 2014 (S.I. 2014/1825)U.K.
379(1)Article 3 of the Communications Act 2003 (Disclosure of Information) Order 2014 (specification of relevant functions) is amended as follows.U.K.
(2)The existing text becomes paragraph (1).
(3)In that paragraph, in sub-paragraph (a), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(4)After that paragraph insert—
“(2)In this article, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I710Sch. 19 para. 379 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Criminal Justice and Data Protection (Protocol No. 36) Regulations 2014 (S.I. 2014/3141)U.K.
380U.K.In the Criminal Justice and Data Protection (Protocol No. 36) Regulations 2014, omit Part 4 (data protection in relation to police and judicial co-operation in criminal matters).
Commencement Information
I711Sch. 19 para. 380 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Assessment Notices) (Designation of National Health Service Bodies) Order 2014 (S.I. 2014/3282)U.K.
381U.K.The Data Protection (Assessment Notices) (Designation of National Health Service Bodies) Order 2014 is revoked.
Commencement Information
I712Sch. 19 para. 381 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
The Control of Explosives Precursors etc Regulations (Northern Ireland) 2014 (S.R. (N.I.) 2014 No. 224)U.K.
382U.K.In regulation 6 of the Control of Explosives Precursors etc Regulations (Northern Ireland) 2014 (applications)—
(a)in paragraph (9), omit sub-paragraph (b) and the word “and” before it, and
(b)in paragraph (11), omit the definition of “processing” and “sensitive personal data” and the word “and” before it.
Commencement Information
I713Sch. 19 para. 382 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Control of Poisons and Explosives Precursors Regulations 2015 (S.I. 2015/966)U.K.
383U.K.In regulation 3 of the Control of Poisons and Explosives Precursors Regulations 2015 (applications in relation to licences under section 4A of the Poisons Act 1972)—
(a)in paragraph (7), omit sub-paragraph (b) and the word “and” before it, and
(b)omit paragraph (8).
Commencement Information
I714Sch. 19 para. 383 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Companies (Disclosure of Date of Birth Information) Regulations 2015 (S.I. 2015/1694)U.K.
384(1)Paragraph 6 of Schedule 2 to the Companies (Disclosure of Date of Birth Information) Regulations 2015 (conditions for permitted disclosure to a credit reference agency) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)In paragraph (b) of that sub-paragraph, for sub-paragraph (ii) substitute—
“(ii)for the purposes of ensuring that it complies with its data protection obligations;”.
(4)In paragraph (c) of that sub-paragraph—
(a)omit “or” at the end of sub-paragraph (i), and
(b)at the end insert “; or
(iii)section 144 of the Data Protection Act 2018 (false statements made in response to an information notice) or section 148 of that Act (destroying or falsifying information and documents etc);”.
(5)After paragraph (c) of that sub-paragraph insert—
“(d)has not been given a penalty notice under section 155 of the Data Protection Act 2018 in circumstances described in paragraph (c)(ii), other than a penalty notice that has been cancelled.”
(6)After sub-paragraph (1) insert—
“(2)In this paragraph, “data protection obligations”, in relation to a credit reference agency, means—
(a)where the agency carries on business in the United Kingdom, obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018);
(b)where the agency carries on business in a EEA State other than the United Kingdom, obligations under—
(i)the GDPR (as defined in section 3(10) of the Data Protection Act 2018),
(ii)legislation made in exercise of powers conferred on member States under the GDPR (as so defined), and
(iii)legislation implementing the Law Enforcement Directive (as defined in section 3(12) of the Data Protection Act 2018).”
Commencement Information
I715Sch. 19 para. 384 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Small and Medium Sized Business (Credit Information) Regulations 2015 (S.I. 2015/1945)U.K.
385U.K.The Small and Medium Sized Business (Credit Information) Regulations 2015 are amended as follows.
Commencement Information
I716Sch. 19 para. 385 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
386(1)Regulation 12 (criteria for the designation of a credit reference agency) is amended as follows.U.K.
(2)In paragraph (1)(b), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)After paragraph (2) insert—
“(3)In this regulation, “the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act).”
Commencement Information
I717Sch. 19 para. 386 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
387(1)Regulation 15 (access to and correction of information for individuals and small firms) is amended as follows.U.K.
(2)For paragraph (1) substitute—
“(1)Section 13 of the Data Protection Act 2018 (rights of the data subject under the GDPR: obligations of credit reference agencies) applies in respect of a designated credit reference agency which is not a credit reference agency within the meaning of section 145(8) of the Consumer Credit Act 1974 as if it were such an agency.”
(3)After paragraph (3) insert—
“(4)In this regulation, the reference to section 13 of the Data Protection Act 2018 has the same meaning as in Parts 5 to 7 of that Act (see section 3(14) of that Act).”
Commencement Information
I718Sch. 19 para. 387 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
European Union (Recognition of Professional Qualifications) Regulations 2015 (S.I. 2015/2059)U.K.
388U.K.The European Union (Recognition of Professional Qualifications) Regulations 2015 are amended as follows.
Commencement Information
I719Sch. 19 para. 388 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
389(1)Regulation 2(1) (interpretation) is amended as follows.U.K.
(2)Omit the definition of “Directive 95/46/EC”.
(3)At the appropriate place insert—
““the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), read with Chapter 2 of Part 2 of the Data Protection Act 2018;”.
Commencement Information
I720Sch. 19 para. 389 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
390U.K.In regulation 5(5) (functions of competent authorities in the United Kingdom) for “Directives 95/46/EC” substitute “ the GDPR and Directive ”.
Commencement Information
I721Sch. 19 para. 390 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
391U.K.In regulation 45(3) (processing and access to data regarding the European Professional Card), for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I722Sch. 19 para. 391 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
392U.K.In regulation 46(1) (processing and access to data regarding the European Professional Card), for “Directive 95/46/EC” substitute “ the GDPR ”.
Commencement Information
I723Sch. 19 para. 392 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
393U.K.In regulation 48(2) (processing and access to data regarding the European Professional Card), omit paragraph (2) (deeming the relevant designated competent authorities to be controllers for the purposes of Directive 95/46/EC).
Commencement Information
I724Sch. 19 para. 393 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
394U.K.In regulation 66(3) (exchange of information), for “Directives 95/46/EC” substitute “ the GDPR and Directive ”.
Commencement Information
I725Sch. 19 para. 394 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Scottish Parliament (Elections etc) Order 2015 (S.S.I. 2015/425)U.K.
395U.K.The Scottish Parliament (Elections etc) Order 2015 is amended as follows.
Commencement Information
I726Sch. 19 para. 395 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
396(1)Schedule 3 (absent voting) is amended as follows.U.K.
(2)In paragraph 16 (absent voting lists: supply of copies etc)—
(a)in sub-paragraph (4), for paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”, and
(b)after sub-paragraph (10) insert—
“(11)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
(3)In paragraph 20 (restriction on use of absent voting lists)—
(a)in sub-paragraph (3), for paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”, and
(b)after that sub-paragraph insert—
“(4)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I727Sch. 19 para. 396 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
397(1)Schedule 8 (access to marked registers and other documents open to public inspection after an election) is amended as follows.U.K.
(2)In paragraph 1(2) (interpretation), omit paragraphs (c) and (d) (but not the final “and”).
(3)In paragraph 5 (restriction on use of documents or of information contained in them)—
(a)in sub-paragraph (3), for paragraph (a) (but not the final “or”) substitute—
“(a)purposes mentioned in Article 89(1) of the GDPR (archiving in the public interest, scientific or historical research and statistics);”, and
(b)after sub-paragraph (4) insert—
“(5)In this paragraph, “the GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).”
Commencement Information
I728Sch. 19 para. 397 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Recall of MPs Act 2015 (Recall Petition) Regulations 2016 (S.I. 2016/295)U.K.
398U.K.In paragraph 1(3) of Schedule 3 to the Recall of MPs Act 2015 (Recall Petition) Regulations 2016 (access to marked registers after a petition), omit the definition of “relevant conditions”.
Commencement Information
I729Sch. 19 para. 398 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Register of People with Significant Control Regulations 2016 (S.I. 2016/339)U.K.
399U.K.Schedule 4 to the Register of People with Significant Control Regulations 2016 (conditions for permitted disclosure) is amended as follows.
Commencement Information
I730Sch. 19 para. 399 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
400(1)Paragraph 6 (disclosure to a credit reference agency) is amended as follows.U.K.
(2)In sub-paragraph (b), for paragraph (ii) (together with the final “; and”) substitute—
“(ii)for the purposes of ensuring that it complies with its data protection obligations;”.
(3)In sub-paragraph (c)—
(a)omit “or” at the end of paragraph (ii), and
(b)at the end insert—
“(iv)section 144 of the Data Protection Act 2018 (false statements made in response to an information notice); or
(v)section 148 of that Act (destroying or falsifying information and documents etc);”
(4)After sub-paragraph (c) insert—
“(d)has not been given a penalty notice under section 155 of the Data Protection Act 2018 in circumstances described in sub-paragraph (c)(iii), other than a penalty notice that has been cancelled.”
Commencement Information
I731Sch. 19 para. 400 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
401U.K.In paragraph 12A (disclosure to a credit institution or a financial institution), for sub-paragraph (b) substitute—
“(b)for the purposes of ensuring that it complies with its data protection obligations.”
Commencement Information
I732Sch. 19 para. 401 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
402U.K.In Part 3 (interpretation), after paragraph 13 insert—
“14In this Schedule, “data protection obligations”, in relation to a credit reference agency, a credit institution or a financial institution, means—
(a)where the agency or institution carries on business in the United Kingdom, obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018);
(b)where the agency or institution carries on business in a EEA State other than the United Kingdom, obligations under—
(i)the GDPR (as defined in section 3(10) of the Data Protection Act 2018),
(ii)legislation made in exercise of powers conferred on member States under the GDPR (as so defined), and
(iii)legislation implementing the Law Enforcement Directive (as defined in section 3(12) of the Data Protection Act 2018).”
Commencement Information
I733Sch. 19 para. 402 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 (S.I. 2016/696)U.K.
403U.K.The Electronic Identification and Trust Services for Electronic Transactions Regulations 2016 are amended as follows.
Commencement Information
I734Sch. 19 para. 403 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
404U.K.In regulation 2(1) (interpretation), omit the definition of “the 1998 Act”.
Commencement Information
I735Sch. 19 para. 404 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
405U.K.In regulation 3(3) (supervision), omit “under the 1998 Act”.
Commencement Information
I736Sch. 19 para. 405 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
406U.K.For Schedule 2 substitute—
“SCHEDULE 2U.K.Information Commissioner's enforcement powers
Provisions applied for enforcement purposesU.K.
1For the purposes of enforcing these Regulations and the eIDAS Regulation, the following provisions of Parts 5 to 7 of the Data Protection Act 2018 apply with the modifications set out in paragraphs 2 to 26—
(a)section 140 (publication by the Commissioner);
(b)section 141 (notices from the Commissioner);
(c)section 142 (information notices);
(d)section 143 (information notices: restrictions);
(e)section 144 (false statements made in response to an information notice);
(f)section 145 (information orders);
(g)section 146 (assessment notices);
(h)section 147 (assessment notices: restrictions);
(i)section 148 (destroying or falsifying information and documents etc);
(j)section 149 (enforcement notices);
(k)section 150 (enforcement notices: supplementary);
(l)section 152 (enforcement notices: restrictions);
(m)section 153 (enforcement notices: cancellation and variation);
(n)section 154 and Schedule 15 (powers of entry and inspection);
(o)section 155 and Schedule 16 (penalty notices);
(p)section 156(4)(a) (penalty notices: restrictions);
(q)section 157 (maximum amount of penalty);
(r)section 159 (amount of penalties: supplementary);
(s)section 160 (guidance about regulatory action);
(t)section 161 (approval of first guidance about regulatory action);
(u)section 162 (rights of appeal);
(v)section 163 (determination of appeals);
(w)section 164 (applications in respect of urgent notices);
(x)section 180 (jurisdiction);
(y)section 182(1), (2), (5), (7) and (13) (regulations and consultation);
(z)section 196 (penalties for offences);
(z1)section 197 (prosecution);
(z2)section 202 (proceedings in the First-tier Tribunal: contempt);
(z3)section 203 (Tribunal Procedure Rules).
General modification of references to the Data Protection Act 2018U.K.
2The provisions listed in paragraph 1 have effect as if—
(a)references to the Data Protection Act 2018 were references to the provisions of that Act as applied by these Regulations;
(b)references to a particular provision of that Act were references to that provision as applied by these Regulations.
Modification of section 142 (information notices)U.K.
3(1)Section 142 has effect as if subsections (9) and (10) were omitted.
(2)In that section, subsection (1) has effect as if—
(a)in paragraph (a)—
(i)for “controller or processor” there were substituted “ trust service provider ”;
(ii)for “the data protection legislation” there were substituted “ the eIDAS Regulation and the EITSET Regulations ”;
(b)paragraph (b) were omitted.
(3)In that section, subsection (2) has effect as if paragraph (a) were omitted.
Modification of section 143 (information notices: restrictions)U.K.
4(1)Section 143 has effect as if subsections (1) and (9) were omitted.
(2)In that section—
(a)subsections (3)(b) and (4)(b) have effect as if for “the data protection legislation” there were substituted “ the eIDAS Regulation or the EITSET Regulations ”;
(b)subsection (7)(a) has effect as if for “this Act” there were substituted “ section 144 or 148 or paragraph 15 of Schedule 15 ”;
(c)subsection (8) has effect as if for “this Act (other than an offence under section 144)” there were substituted “ section 148 or paragraph 15 of Schedule 15 ”.
Modification of section 145 (information orders)U.K.
5Section 145(2)(b) has effect as if for “section 142(2)(b)” there were substituted “ section 142(2) ”.
Modification of section 146 (assessment notices)U.K.
6(1)Section 146 has effect as if subsection (11) were omitted.
(2)In that section—
(a)subsection (1) has effect as if—
(i)for “controller or processor” (in both places) there were substituted “ trust service provider ”;
(ii)for “the data protection legislation” there were substituted “ the eIDAS requirements ”;
(b)subsection (2) has effect as if paragraphs (h) and (i) were omitted;
(c)subsections (7), (8), (9) and (10) have effect as if for “controller or processor” (in each place) there were substituted “trust service provider.
(d)subsection (9)(a) has effect as if for “as described in section 149(2) or that an offence under this Act” there were substituted “ to comply with the eIDAS requirements or that an offence under section 144 or 148 or paragraph 15 of Schedule 15 ”.
Modification of section 147 (assessment notices: restrictions)U.K.
7(1)Section 147 has effect as if subsections (5) and (6) were omitted.
(2)In that section, subsections (2)(b) and (3)(b) have effect as if for “the data protection legislation” there were substituted “ the eIDAS Regulation or the EITSET Regulations ”.
Modification of section 149 (enforcement notices)U.K.
8(1)Section 149 has effect as if subsections (2) to (5) and (7) to (9) were omitted.
(2)In that section—
(a)subsection (1) has effect as if—
(i)for “as described in subsection (2), (3), (4) or (5)” there were substituted “ to comply with the eIDAS requirements ”;
(ii)for “sections 150 and 151” there were substituted “ section 150 ”;
(b)subsection (6) has effect as if the words “given in reliance on subsection (2), (3) or (5)” were omitted.
Modification of section 150 (enforcement notices: supplementary)U.K.
9(1)Section 150 has effect as if subsection (3) were omitted.
(2)In that section, subsection (2) has effect as if the words “in reliance on section 149(2)” and “or distress” were omitted.
Modification of section 152 (enforcement notices: restrictions)U.K.
10Section 152 has effect as if subsections (1), (2) and (4) were omitted.
Withdrawal noticesU.K.
11The provisions listed in paragraph 1 have effect as if after section 153 there were inserted—
“Withdrawal noticesU.K.
153AWithdrawal notices
(1)The Commissioner may, by written notice (a “withdrawal notice”), withdraw the qualified status from a trust service provider, or the qualified status of a service provided by a trust service provider, if—
(a)the Commissioner is satisfied that the trust service provider has failed to comply with an information notice or an enforcement notice, and
(b)the condition in subsection (2) or (3) is met.
(2)The condition in this subsection is met if the period for the trust service provider to appeal against the information notice or enforcement notice has ended without an appeal having been brought.
(3)The condition in this subsection is met if an appeal against the information notice or enforcement notice has been brought and—
(a)the appeal and any further appeal in relation to the notice has been decided or has otherwise ended, and
(b)the time for appealing against the result of the appeal or further appeal has ended without another appeal having been brought.
(4)A withdrawal notice must—
(a)state when the withdrawal takes effect, and
(b)provide information about the rights of appeal under section 162.”
Modification of Schedule 15 (powers of entry and inspection)U.K.
12(1)Schedule 15 has effect as if paragraph 3 were omitted.
(2)Paragraph 1(1) of that Schedule (issue of warrants in connection with non-compliance and offences) has effect as if for paragraph (a) (but not the final “and”) there were substituted—
“(a)there are reasonable grounds for suspecting that—
(i)a trust service provider has failed or is failing to comply with the eIDAS requirements, or
(ii)an offence under section 144 or 148 or paragraph 15 of Schedule 15 has been or is being committed,”.
(3)Paragraph 2 of that Schedule (issue of warrants in connection with assessment notices) has effect as if—
(a)in sub-paragraphs (1) and (2), for “controller or processor” there were substituted “ trust service provider ”;
(b)in sub-paragraph (2), for “the data protection legislation” there were substituted “ the eIDAS requirements ”.
(4)Paragraph 5 of that Schedule (content of warrants) has effect as if—
(a)in sub-paragraph (1)(c), for “the processing of personal data” there were substituted “ the provision of trust services ”;
(b)in sub-paragraph (2)(d)—
(i)for “controller or processor” there were substituted “ trust service provider ”;
(ii)for “as described in section 149(2)” there were substituted “ to comply with the eIDAS requirements ”;
(c)in sub-paragraph (3)(a) and (d)—
(i)for “controller or processor” there were substituted “ trust service provider ”;
(ii)for “the data protection legislation” there were substituted “ the eIDAS requirements ”.
(5)Paragraph 11 of that Schedule (privileged communications) has effect as if, in sub-paragraphs (1)(b) and (2)(b), for “the data protection legislation” there were substituted “ the eIDAS Regulation or the EITSET Regulations ”.
Modification of section 155 (penalty notices)U.K.
13(1)Section 155 has effect as if subsections (1)(a), (2)(a), (3)(g), (4) and (6) to (8) were omitted.
(2)Subsection (2) of that section has effect as if—
(a)the words “Subject to subsection (4),” were omitted;
(b)in paragraph (b), the words “to the extent that the notice concerns another matter,” were omitted.
(3)Subsection (3) of that section has effect as if—
(a)for “controller or processor”, in each place, there were substituted “ trust services provider ”;
(b)in paragraph (c), the words “or distress” were omitted;
(c)in paragraph (c), for “data subjects” there were substituted “ relying parties ”;
(d)in paragraph (d), for “section 57, 66, 103 or 107” there were substituted “ Article 19(1) of the eIDAS Regulation ”.
Modification of Schedule 16 (penalties)U.K.
14Schedule 16 has effect as if paragraphs 3(2)(b) and 5(2)(b) were omitted.
Modification of section 157 (maximum amount of penalty)U.K.
15Section 157 has effect as if subsections (1) to (3) and (6) were omitted.
Modification of section 159 (amount of penalties: supplementary)U.K.
16Section 159 has effect as if—
(a)in subsection (1), the words “Article 83 of the GDPR and” were omitted;
(b)in subsection (2), the words “Article 83 of the GDPR” and “and section 158” were omitted.
Modification of section 160 (guidance about regulatory action)U.K.
17(1)Section 160 has effect as if subsections (5) and (12) were omitted.
(2)In that section, subsection (4)(f) has effect as if for “controllers and processors” there were substituted “ trust service providers ”.
Modification of section 162 (rights of appeal)U.K.
18(1)Section 162 has effect as if subsection (4) were omitted.
(2)In that section, subsection (1) has effect as if, after paragraph (c), there were inserted—
“(ca)a withdrawal notice;”.
Modification of section 163 (determination of appeals)U.K.
19Section 163 has effect as if subsection (6) were omitted.
Modification of section 180 (jurisdiction)U.K.
20(1)Section 180 has effect as if subsections (2)(d) and (e) and (3) were omitted.
(2)Subsection (1) of that section has effect as if for “subsections (3) and (4)” there were substituted “ subsection (4) ”.
Modification of section 182 (regulations and consultation)U.K.
21Section 182 has effect as if subsections (3), (4), (6), (8) to (11) and (14) were omitted.
Modification of section 196 (penalties for offences)U.K.
22(1)Section 196 has effect as if subsections (3) to (5) were omitted.
(2)In that section—
(a)subsection (1) has effect as if the words “section 119 or 173 or” were omitted;
(b)subsection (2) has effect as if for “section 132, 144, 148, 170, 171 or 184” there were substituted “ section 144 or 148 ”.
Modification of section 197 (prosecution)U.K.
23Section 197 has effect as if subsections (3) to (6) were omitted.
Modification of section 202 (proceedings in the First-tier Tribunal: contempt)U.K.
24Section 202 has effect as if in subsection (1)(a), for sub-paragraphs (i) and (ii) there were substituted “ on an appeal under section 162 ”.
Modification of section 203 (Tribunal Procedure Rules)U.K.
25Section 203 has effect as if—
(a)in subsection (1), for paragraphs (a) and (b) there were substituted “ the exercise of the rights of appeal conferred by section 162 ”;
(b)in subsection (2)(a) and (b), for “the processing of personal data” there were substituted “ the provision of trust services ”.
Approval of first guidance about regulatory actionU.K.
26(1)This paragraph applies if the first guidance produced under section 160(1) of the Data Protection Act 2018 and the first guidance produced under that provision as applied by this Schedule are laid before Parliament as a single document (“the combined guidance”).
(2)Section 161 of that Act (including that section as applied by this Schedule) has effect as if the references to “the guidance” were references to the combined guidance, except in subsections (2)(b) and (4).
(3)Nothing in subsection (2)(a) of that section (including as applied by this Schedule) prevents another version of the combined guidance being laid before Parliament.
(4)Any duty under subsection (2)(b) of that section (including as applied by this Schedule) may be satisfied by producing another version of the combined guidance.
InterpretationU.K.
27In this Schedule—
“the eIDAS requirements” means the requirements of Chapter III of the eIDAS Regulation;
“the EITSET Regulations” means these Regulations;
“withdrawal notice” has the meaning given in section 153A of the Data Protection Act 2018 (as inserted in that Act by this Schedule).”
Commencement Information
I737Sch. 19 para. 406 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g) (with reg. 4)
Court Files Privileged Access Rules (Northern Ireland) 2016 (S.R. (N.I.) 2016 No. 123)U.K.
407U.K.The Court Files Privileged Access Rules (Northern Ireland) 2016 are amended as follows.
Commencement Information
I738Sch. 19 para. 407 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
408U.K.In rule 5 (information that may released) for “Schedule 1 of the Data Protection Act 1998” substitute “—
(a)Article 5(1) of the GDPR, and
(b)section 34(1) of the Data Protection Act 2018.”
Commencement Information
I739Sch. 19 para. 408 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
409U.K.In rule 7(2) (provision of information) for “Schedule 1 of the Data Protection Act 1998” substitute “—
(a)Article 5(1) of the GDPR, and
(b)section 34(1) of the Data Protection Act 2018.”
Commencement Information
I740Sch. 19 para. 409 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (S.I. 2017/692)U.K.
410U.K.The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 are amended as follows.
Commencement Information
I741Sch. 19 para. 410 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
411U.K.In regulation 3(1) (interpretation), at the appropriate places insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”;
““the GDPR” and references to provisions of Chapter 2 of Part 2 of the Data Protection Act 2018 have the same meaning as in Parts 5 to 7 of that Act (see section 3(10), (11) and (14) of that Act);”.
Commencement Information
I742Sch. 19 para. 411 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
412U.K.In regulation 16(8) (risk assessment by the Treasury and Home Office), for “the Data Protection Act 1998 or any other enactment” substitute “—
(a)the Data Protection Act 2018 or any other enactment, or
(b)the GDPR.”
Commencement Information
I743Sch. 19 para. 412 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
413U.K.In regulation 17(9) (risk assessment by supervisory authorities), for “the Data Protection Act 1998 or any other enactment” substitute “—
(a)the Data Protection Act 2018 or any other enactment, or
(b)the GDPR.”
Commencement Information
I744Sch. 19 para. 413 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
414U.K.For regulation 40(9)(c) (record keeping) substitute—
“(c)“data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
(d)“personal data” has the same meaning as in Parts 5 to 7 of that Act (see section 3(2) and (14) of that Act).”
Commencement Information
I745Sch. 19 para. 414 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
415(1)Regulation 41 (data protection) is amended as follows.U.K.
(2)Omit paragraph (2).
(3)In paragraph (3)(a), after “Regulations” insert “ or the GDPR ”.
(4)Omit paragraphs (4) and (5).
(5)After those paragraphs insert—
“(6)Before establishing a business relationship or entering into an occasional transaction with a new customer, as well as providing the customer with the information required under Article 13 of the GDPR (information to be provided where personal data are collected from the data subject), relevant persons must provide the customer with a statement that any personal data received from the customer will be processed only—
(a)for the purposes of preventing money laundering or terrorist financing, or
(b)as permitted under paragraph (3).
(7)In Article 6(1) of the GDPR (lawfulness of processing), the reference in point (e) to processing of personal data that is necessary for the performance of a task carried out in the public interest includes processing of personal data in accordance with these Regulations that is necessary for the prevention of money laundering or terrorist financing.
(8)In the case of sensitive processing of personal data for the purposes of the prevention of money laundering or terrorist financing, section 10 of, and Schedule 1 to, the Data Protection Act 2018 make provision about when the processing meets a requirement in Article 9(2) or 10 of the GDPR for authorisation under the law of the United Kingdom (see, for example, paragraphs 10, 11 and 12 of that Schedule).
(9)In this regulation—
“data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);
“personal data” and “processing” have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4) and (14) of that Act);
“sensitive processing” means the processing of personal data described in Article 9(1) or 10 of the GDPR (special categories of personal data and personal data relating to criminal convictions and offences etc).”
Commencement Information
I746Sch. 19 para. 415 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
416(1)Regulation 84 (publication: the Financial Conduct Authority) is amended as follows.U.K.
(2)In paragraph (10), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)For paragraph (11) substitute—
“(11)For the purposes of this regulation, “personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).”
Commencement Information
I747Sch. 19 para. 416 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
417(1)Regulation 85 (publication: the Commissioners) is amended as follows.U.K.
(2)In paragraph (9), for “the Data Protection Act 1998” substitute “ the data protection legislation ”.
(3)For paragraph (10) substitute—
“(10)For the purposes of this regulation, “personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act).”
Commencement Information
I748Sch. 19 para. 417 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
418U.K.For regulation 106(a) (general restrictions) substitute—
“(a)a disclosure in contravention of the data protection legislation; or”.
Commencement Information
I749Sch. 19 para. 418 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
419U.K.After paragraph 27 of Schedule 3 (relevant offences) insert—
“27AAn offence under the Data Protection Act 2018, apart from an offence under section 173 of that Act.”
Commencement Information
I750Sch. 19 para. 419 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Scottish Partnerships (Register of People with Significant Control) Regulations 2017 (S.I. 2017/694)U.K.
420(1)Paragraph 6 of Schedule 5 to the Scottish Partnerships (Register of People with Significant Control) Regulations 2017 (conditions for permitted disclosure to a credit institution or a financial institution) is amended as follows.U.K.
(2)The existing text becomes sub-paragraph (1).
(3)For paragraph (b) of that sub-paragraph substitute—
“(b)for the purposes of ensuring that it complies with its data protection obligations.”
(4)After sub-paragraph (1) insert—
“(2)In this paragraph, “data protection obligations”, in relation to a relevant institution, means—
(a)where the institution carries on business in the United Kingdom, obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018);
(b)where the institution carries on business in a EEA State other than the United Kingdom, obligations under—
(i)the GDPR (as defined in section 3(10) of the Data Protection Act 2018),
(ii)legislation made in exercise of powers conferred on member States under the GDPR (as so defined), and
(iii)legislation implementing the Law Enforcement Directive (as defined in section 3(12) of the Data Protection Act 2018).”
Commencement Information
I751Sch. 19 para. 420 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Data Protection (Charges and Information) Regulations 2018 (S.I. 2018/480)U.K.
421U.K.In regulation 1(2) of the Data Protection (Charges and Information) Regulations 2018 (interpretation), at the appropriate places insert—
““data controller” means a person who is a controller for the purposes of Parts 5 to 7 of the Data Protection Act 2018 (see section 3(6) and (14) of that Act);”;
““personal data” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2) and (14) of that Act);”.
Commencement Information
I752Sch. 19 para. 421 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Health Service (General Medical Services Contracts) (Scotland) Regulations 2018 (S.S.I. 2018/66)U.K.
422U.K.The National Health Service (General Medical Services Contracts) (Scotland) Regulations 2018 are amended as follows.
Commencement Information
I753Sch. 19 para. 422 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
423(1)Regulation 1 (citation and commencement) is amended as follows.U.K.
(2)In paragraph (2), omit “Subject to paragraph (3),”.
(3)Omit paragraph (3).
Commencement Information
I754Sch. 19 para. 423 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
424U.K.In regulation 3(1) (interpretation)—
(a)omit the definition of “the 1998 Act”,
(b)at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”, and
(c)omit the definition of “GDPR”.
Commencement Information
I755Sch. 19 para. 424 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
425(1)Schedule 6 (other contractual terms) is amended as follows.U.K.
(2)In paragraph 63(2) (interpretation: general), for “the 1998 Act or any directly applicable EU instrument relating to data protection” substitute “—
(a)the data protection legislation, or
(b)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection.”
(3)For paragraph 64 (meaning of data controller etc.) substitute—
“Meaning of controller etc.U.K.
64AFor the purposes of this Part—
“controller” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(6) and (14) of that Act);
“data protection officer” means a person designated as a data protection officer under the data protection legislation;
“personal data” and “processing” have the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2), (4) and (14) of that Act).”
(4)In paragraph 65(2)(b) (roles, responsibilities and obligations: general), for “data controllers” substitute “ controllers ”.
(5)In paragraph 69(2)(a) (processing and access of data), for “the 1998 Act, and any directly applicable EU instrument relating to data protection;” substitute “—
(i)the data protection legislation, and
(ii)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection;”.
(6)In paragraph 94(4) (variation of a contract: general)—
(a)omit paragraph (b), and
(b)after paragraph (d) (but before the final “and”) insert—
“(da)the data protection legislation;
(db)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection;”.
Commencement Information
I756Sch. 19 para. 425 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National Health Service (Primary Medical Services Section 17C Agreements) (Scotland) Regulations 2018 (S.S.I. 2018/67)U.K.
426U.K.The National Health Service (Primary Medical Services Section 17C Agreements) (Scotland) Regulations 2018 are amended as follows.
Commencement Information
I757Sch. 19 para. 426 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
427(1)Regulation 1 (citation and commencement) is amended as follows.U.K.
(2)In paragraph (2), omit “Subject to paragraph (3),”.
(3)Omit paragraph (3).
Commencement Information
I758Sch. 19 para. 427 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
428U.K.In regulation 3(1) (interpretation)—
(a)omit the definition of “the 1998 Act”, and
(b)at the appropriate place insert—
““the data protection legislation” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);”, and
(c)omit the definition of “GDPR”.
Commencement Information
I759Sch. 19 para. 428 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
429(1)Schedule 1 (content of agreements) is amended as follows.U.K.
(2)In paragraph 34 (interpretation)—
(a)in sub-paragraph (1)—
(i)omit “Subject to sub-paragraph (3),”,
(ii)before paragraph (a) insert—
“(za)“controller” has the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(6) and (14) of that Act);
(zb)“data protection officer” means a person designated as a data protection officer under the data protection legislation;”, and
(iii)for paragraph (d) substitute—
“(e)“personal data” and “processing” have the same meaning as in Parts 5 to 7 of the Data Protection Act 2018 (see section 3(2), (4) and (14) of that Act).”,
(b)omit sub-paragraphs (2) and (3),
(c)in sub-paragraph (4), for “the 1998 Act and any directly applicable EU instrument relating to data protection” substitute “—
(a)the data protection legislation, or
(b)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection.”, and
(d)in sub-paragraph (6)(b), for “data controllers” substitute “ controllers ”.
(3)In paragraph 37(2)(a) (processing and access of data), for “the 1998 Act, and any directly applicable EU instrument relating to data protection;” substitute “—
(i)the data protection legislation, and
(ii)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection;”.
(4)In paragraph 61(3) (variation of agreement: general)—
(a)omit paragraph (b), and
(b)after paragraph (d) (but before the final “and”) insert—
“(da)the data protection legislation;
(db)any directly applicable EU legislation which is not part of the data protection legislation but which relates to data protection;”.
Commencement Information
I760Sch. 19 para. 429 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 3 U.K.Modifications
IntroductionU.K.
430(1)Unless the context otherwise requires, legislation described in sub-paragraph (2) has effect on and after the day on which this Part of this Schedule comes into force as if it were modified in accordance with this Part of this Schedule.U.K.
(2)That legislation is—
(a)subordinate legislation made before the day on which this Part of this Schedule comes into force;
(b)primary legislation that is passed or made before the end of the Session in which this Act is passed.
(3)In this Part of this Schedule—
“primary legislation” has the meaning given in section 211(7);
“references” includes any references, however expressed.
Commencement Information
I761Sch. 19 para. 430 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
General modificationsU.K.
431(1)References to a particular provision of, or made under, the Data Protection Act 1998 have effect as references to the equivalent provision or provisions of, or made under, the data protection legislation.U.K.
(2)Other references to the Data Protection Act 1998 have effect as references to the data protection legislation.
(3)References to disclosure, use or other processing of information that is prohibited or restricted by an enactment which include disclosure, use or other processing of information that is prohibited or restricted by the Data Protection Act 1998 have effect as if they included disclosure, use or other processing of information that is prohibited or restricted by the GDPR or the applied GDPR.
Commencement Information
I762Sch. 19 para. 431 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Specific modification of references to terms used in the Data Protection Act 1998U.K.
432(1)References to personal data, and to the processing of such data, as defined in the Data Protection Act 1998, have effect as references to personal data, and to the processing of such data, as defined for the purposes of Parts 5 to 7 of this Act (see section 3(2), (4) and (14)).U.K.
(2)References to processing as defined in the Data Protection Act 1998, in relation to information, have effect as references to processing as defined in section 3(4).
(3)References to a data subject as defined in the Data Protection Act 1998 have effect as references to a data subject as defined in section 3(5).
(4)References to a data controller as defined in the Data Protection Act 1998 have effect as references to a controller as defined for the purposes of Parts 5 to 7 of this Act (see section 3(6) and (14)).
(5)References to the data protection principles set out in the Data Protection Act 1998 have effect as references to the principles set out in—
(a)Article 5(1) of the GDPR and the applied GDPR, and
(b)sections 34(1) and 85(1) of this Act.
(6)References to direct marketing as defined in section 11 of the Data Protection Act 1998 have effect as references to direct marketing as defined in section 122 of this Act.
(7)References to a health professional within the meaning of section 69(1) of the Data Protection Act 1998 have effect as references to a health professional within the meaning of section 204 of this Act.
(8)References to a health record within the meaning of section 68(2) of the Data Protection Act 1998 have effect as references to a health record within the meaning of section 205 of this Act.
Commencement Information
I763Sch. 19 para. 432 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 4 U.K.Supplementary
DefinitionsU.K.
433U.K.Section 3(14) does not apply to this Schedule.
Commencement Information
I764Sch. 19 para. 433 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Provision inserted in subordinate legislation by this ScheduleU.K.
434U.K.Provision inserted into subordinate legislation by this Schedule may be amended or revoked as if it had been inserted using the power under which the subordinate legislation was originally made.
Commencement Information
I765Sch. 19 para. 434 in force at Royal Assent for specified purposes, see s. 212(2)(f)
I766Sch. 19 para. 434 in force at 25.5.2018 in so far as not already in force by S.I. 2018/625, reg. 2(1)(g)
Section 213
SCHEDULE 20U.K.Transitional provision etc
PART 1 U.K.General
InterpretationU.K.
1(1)In this Schedule—U.K.
“the 1984 Act” means the Data Protection Act 1984;
“the 1998 Act” means the Data Protection Act 1998;
“the 2014 Regulations” means the Criminal Justice and Data Protection (Protocol No. 36) Regulations 2014 (S.I. 2014/3141);
“data controller” has the same meaning as in the 1998 Act (see section 1 of that Act);
“the old data protection principles” means the principles set out in—
(a)Part 1 of Schedule 1 to the 1998 Act, and
(b)regulation 30 of the 2014 Regulations.
(2)A provision of the 1998 Act that has effect by virtue of this Schedule is not, by virtue of that, part of the data protection legislation (as defined in section 3).
Commencement Information
I767Sch. 20 para. 1 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 2 U.K.Rights of data subjects
Right of access to personal data under the 1998 ActU.K.
2(1)The repeal of sections 7 to 9A of the 1998 Act (right of access to personal data) does not affect the application of those sections after the relevant time in a case in which a data controller received a request under section 7 of that Act (right of access to personal data) before the relevant time.U.K.
(2)The repeal of sections 7 and 8 of the 1998 Act and the revocation of regulation 44 of the 2014 Regulations (which applies those sections with modifications) do not affect the application of those sections and that regulation after the relevant time in a case in which a UK competent authority received a request under section 7 of the 1998 Act (as applied by that regulation) before the relevant time.
(3)The revocation of the relevant regulations, or their amendment by Schedule 19 to this Act, and the repeals and revocation mentioned in sub-paragraphs (1) and (2), do not affect the application of the relevant regulations after the relevant time in a case described in those sub-paragraphs.
(4)In this paragraph—
“the relevant regulations” means—
(a)the Data Protection (Subject Access) (Fees and Miscellaneous Provisions) Regulations 2000 (S.I. 2000/191);
(b)regulation 4 of, and Schedule 1 to, the Consumer Credit (Credit Reference Agency) Regulations 2000 (S.I. 2000/290);
(c)regulation 3 of the Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004 (S.I. 2004/3244);
“the relevant time” means the time when the repeal of section 7 of the 1998 Act comes into force;
“UK competent authority” has the same meaning as in Part 4 of the 2014 Regulations (see regulation 27 of those Regulations).
Commencement Information
I768Sch. 20 para. 2 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Right to prevent processing likely to cause damage or distress under the 1998 ActU.K.
3(1)The repeal of section 10 of the 1998 Act (right to prevent processing likely to cause damage or distress) does not affect the application of that section after the relevant time in a case in which an individual gave notice in writing to a data controller under that section before the relevant time.U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 10 of the 1998 Act comes into force.
Commencement Information
I769Sch. 20 para. 3 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Right to prevent processing for purposes of direct marketing under the 1998 ActU.K.
4(1)The repeal of section 11 of the 1998 Act (right to prevent processing for purposes of direct marketing) does not affect the application of that section after the relevant time in a case in which an individual gave notice in writing to a data controller under that section before the relevant time.U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 11 of the 1998 Act comes into force.
Commencement Information
I770Sch. 20 para. 4 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Automated processing under the 1998 ActU.K.
5(1)The repeal of section 12 of the 1998 Act (rights in relation to automated decision-taking) does not affect the application of that section after the relevant time in relation to a decision taken by a person before that time if—U.K.
(a)in taking the decision the person failed to comply with section 12(1) of the 1998 Act, or
(b)at the relevant time—
(i)the person had not taken all of the steps required under section 12(2) or (3) of the 1998 Act, or
(ii)the period specified in section 12(2)(b) of the 1998 Act (for an individual to require a person to reconsider a decision) had not expired.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 12 of the 1998 Act comes into force.
Commencement Information
I771Sch. 20 para. 5 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Compensation for contravention of the 1998 Act or Part 4 of the 2014 RegulationsU.K.
6(1)The repeal of section 13 of the 1998 Act (compensation for failure to comply with certain requirements) does not affect the application of that section after the relevant time in relation to damage or distress suffered at any time by reason of an act or omission before the relevant time.U.K.
(2)The revocation of regulation 45 of the 2014 Regulations (right to compensation) does not affect the application of that regulation after the relevant time in relation to damage or distress suffered at any time by reason of an act or omission before the relevant time.
(3)“The relevant time” means—
(a)in sub-paragraph (1), the time when the repeal of section 13 of the 1998 Act comes into force;
(b)in sub-paragraph (2), the time when the revocation of regulation 45 of the 2014 Regulation comes into force.
Commencement Information
I772Sch. 20 para. 6 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Rectification, blocking, erasure and destruction under the 1998 ActU.K.
7(1)The repeal of section 14(1) to (3) and (6) of the 1998 Act (rectification, blocking, erasure and destruction of inaccurate personal data) does not affect the application of those provisions after the relevant time in a case in which an application was made under subsection (1) of that section before the relevant time.U.K.
(2)The repeal of section 14(4) to (6) of the 1998 Act (rectification, blocking, erasure and destruction: risk of further contravention in circumstances entitling data subject to compensation under section 13 of the 1998 Act) does not affect the application of those provisions after the relevant time in a case in which an application was made under subsection (4) of that section before the relevant time.
(3)In this paragraph, “the relevant time” means the time when the repeal of section 14 of the 1998 Act comes into force.
Commencement Information
I773Sch. 20 para. 7 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Jurisdiction and procedure under the 1998 ActU.K.
8U.K.The repeal of section 15 of the 1998 Act (jurisdiction and procedure) does not affect the application of that section in connection with sections 7 to 14 of the 1998 Act as they have effect by virtue of this Schedule.
Commencement Information
I774Sch. 20 para. 8 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Exemptions under the 1998 ActU.K.
9(1)The repeal of Part 4 of the 1998 Act (exemptions) does not affect the application of that Part after the relevant time in connection with a provision of Part 2 of the 1998 Act as it has effect after that time by virtue of paragraphs 2 to 7 of this Schedule.U.K.
(2)The revocation of the relevant Orders, and the repeal mentioned in sub-paragraph (1), do not affect the application of the relevant Orders after the relevant time in connection with a provision of Part 2 of the 1998 Act as it has effect as described in sub-paragraph (1).
(3)In this paragraph—
“the relevant Orders” means—
(a)the Data Protection (Corporate Finance Exemption) Order 2000 (S.I. 2000/184);
(b)the Data Protection (Subject Access Modification) (Health) Order 2000 (S.I. 2000/413);
(c)the Data Protection (Subject Access Modification) (Education) Order 2000 (S.I. 2000/414);
(d)the Data Protection (Subject Access Modification) (Social Work) Order 2000 (S.I. 2000/415);
(e)the Data Protection (Crown Appointments) Order 2000 (S.I. 2000/416);
(f)Data Protection (Miscellaneous Subject Access Exemptions) Order 2000 (S.I. 2000/419);
(g)Data Protection (Designated Codes of Practice) (No. 2) Order 2000 (S.I. 2000/1864);
“the relevant time” means the time when the repeal of the provision of Part 2 of the 1998 Act in question comes into force.
(4)As regards certificates issued under section 28(2) of the 1998 Act, see Part 5 of this Schedule.
Commencement Information
I775Sch. 20 para. 9 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Prohibition by this Act of requirement to produce relevant recordsU.K.
10(1)In Schedule 18 to this Act, references to a record obtained in the exercise of a data subject access right include a record obtained at any time in the exercise of a right under section 7 of the 1998 Act.U.K.
(2)In section 184 of this Act, references to a “relevant record” include a record which does not fall within the definition in Schedule 18 to this Act (read with sub-paragraph (1)) but which, immediately before the relevant time, was a “relevant record” for the purposes of section 56 of the 1998 Act.
(3)In this paragraph, “the relevant time” means the time when the repeal of section 56 of the 1998 Act comes into force.
Commencement Information
I776Sch. 20 para. 10 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Avoidance under this Act of certain contractual terms relating to health recordsU.K.
11U.K.In section 185 of this Act, references to a record obtained in the exercise of a data subject access right include a record obtained at any time in the exercise of a right under section 7 of the 1998 Act.
Commencement Information
I777Sch. 20 para. 11 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 3 U.K.The GDPR and Part 2 of this Act
Exemptions from the GDPR: restrictions of rules in Articles 13 to 15 of the GDPRU.K.
12U.K.In paragraph 20(2) of Schedule 2 to this Act (self-incrimination), the reference to an offence under this Act includes an offence under the 1998 Act or the 1984 Act.
Commencement Information
I778Sch. 20 para. 12 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Manual unstructured data held by FOI public authoritiesU.K.
13U.K.Until the first regulations under section 24(8) of this Act come into force, “the appropriate maximum” for the purposes of that section is—
(a)where the controller is a public authority listed in Part 1 of Schedule 1 to the Freedom of Information Act 2000, £600, and
(b)otherwise, £450.
Commencement Information
I779Sch. 20 para. 13 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 4 U.K.Law enforcement and intelligence services processing
LoggingU.K.
14(1)In relation to an automated processing system set up before 6 May 2016, subsections (1) to (3) of section 62 of this Act do not apply if and to the extent that compliance with them would involve disproportionate effort.U.K.
(2)Sub-paragraph (1) ceases to have effect at the beginning of 6 May 2023.
Commencement Information
I780Sch. 20 para. 14 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Regulation 50 of the 2014 Regulations (disapplication of the 1998 Act)U.K.
15U.K.Nothing in this Schedule, read with the revocation of regulation 50 of the 2014 Regulations, has the effect of applying a provision of the 1998 Act to the processing of personal data to which Part 4 of the 2014 Regulations applies in a case in which that provision did not apply before the revocation of that regulation.
Commencement Information
I781Sch. 20 para. 15 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Maximum fee for data subject access requests to intelligence servicesU.K.
16U.K.Until the first regulations under section 94(4)(b) of this Act come into force, the maximum amount of a fee that may be required by a controller under that section is £10.
Commencement Information
I782Sch. 20 para. 16 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 5 U.K.National security certificates
National security certificates: processing of personal data under the 1998 ActU.K.
17(1)The repeal of section 28(2) to (12) of the 1998 Act does not affect the application of those provisions after the relevant time with respect to the processing of personal data to which the 1998 Act (including as it has effect by virtue of this Schedule) applies.U.K.
(2)A certificate issued under section 28(2) of the 1998 Act continues to have effect after the relevant time with respect to the processing of personal data to which the 1998 Act (including as it has effect by virtue of this Schedule) applies.
(3)Where a certificate continues to have effect under sub-paragraph (2) after the relevant time, it may be revoked or quashed in accordance with section 28 of the 1998 Act after the relevant time.
(4)In this paragraph, “the relevant time” means the time when the repeal of section 28 of the 1998 Act comes into force.
Commencement Information
I783Sch. 20 para. 17 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
National security certificates: processing of personal data under the 2018 ActU.K.
18(1)This paragraph applies to a certificate issued under section 28(2) of the 1998 Act (an “old certificate”) which has effect immediately before the relevant time.U.K.
(2)If and to the extent that the old certificate provides protection with respect to personal data which corresponds to protection that could be provided by a certificate issued under section 27, 79 or 111 of this Act, the old certificate also has effect to that extent after the relevant time as if—
(a)it were a certificate issued under one or more of sections 27, 79 and 111 (as the case may be),
(b)it provided protection in respect of that personal data in relation to the corresponding provisions of this Act or the applied GDPR, and
(c)where it has effect as a certificate issued under section 79, it certified that each restriction in question is a necessary and proportionate measure to protect national security.
(3)Where an old certificate also has effect as if it were a certificate issued under one or more of sections 27, 79 and 111, that section has, or those sections have, effect accordingly in relation to the certificate.
(4)Where an old certificate has an extended effect because of sub-paragraph (2), section 130 of this Act does not apply in relation to it.
(5)An old certificate that has an extended effect because of sub-paragraph (2) provides protection only with respect to the processing of personal data that occurs during the period of 1 year beginning with the relevant time (and a Minister of the Crown may curtail that protection by wholly or partly revoking the old certificate).
(6)For the purposes of this paragraph—
(a)a reference to the protection provided by a certificate issued under—
(i)section 28(2) of the 1998 Act, or
(ii)section 27, 79 or 111 of this Act,
is a reference to the effect of the evidence that is provided by the certificate;
(b)protection provided by a certificate under section 28(2) of the 1998 Act is to be regarded as corresponding to protection that could be provided by a certificate under section 27, 79 or 111 of this Act where, in respect of provision in the 1998 Act to which the certificate under section 28(2) relates, there is corresponding provision in this Act or the applied GDPR to which a certificate under section 27, 79 or 111 could relate.
(7)In this paragraph, “the relevant time” means the time when the repeal of section 28 of the 1998 Act comes into force.
Commencement Information
I784Sch. 20 para. 18 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 6 U.K.The Information Commissioner
Appointment etcU.K.
19(1)On and after the relevant day, the individual who was the Commissioner immediately before that day—U.K.
(a)continues to be the Commissioner,
(b)is to be treated as having been appointed under Schedule 12 to this Act, and
(c)holds office for the period—
(i)beginning with the relevant day, and
(ii)lasting for 7 years less a period equal to the individual's pre-commencement term.
(2)On and after the relevant day, a resolution passed by the House of Commons for the purposes of paragraph 3 of Schedule 5 to the 1998 Act (salary and pension of Commissioner), and not superseded before that day, is to be treated as having been passed for the purposes of paragraph 4 of Schedule 12 to this Act.
(3)In this paragraph—
“pre-commencement term”, in relation to an individual, means the period during which the individual was the Commissioner before the relevant day;
“the relevant day” means the day on which Schedule 12 to this Act comes into force.
Commencement Information
I785Sch. 20 para. 19 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
AccountsU.K.
20(1)The repeal of paragraph 10 of Schedule 5 to the 1998 Act does not affect the duties of the Commissioner and the Comptroller and Auditor General under that paragraph in respect of the Commissioner's statement of account for the financial year beginning with 1 April 2017.U.K.
(2)The Commissioner's duty under paragraph 11 of Schedule 12 to this Act to prepare a statement of account for each financial year includes a duty to do so for the financial year beginning with 1 April 2018.
Commencement Information
I786Sch. 20 para. 20 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Annual reportU.K.
21(1)The repeal of section 52(1) of the 1998 Act (annual report) does not affect the Commissioner's duty under that subsection to produce a general report on the exercise of the Commissioner's functions under the 1998 Act during the period of 1 year beginning with 1 April 2017 and to lay it before Parliament.U.K.
(2)The repeal of section 49 of the Freedom of Information Act 2000 (annual report) does not affect the Commissioner's duty under that section to produce a general report on the exercise of the Commissioner's functions under that Act during the period of 1 year beginning with 1 April 2017 and to lay it before Parliament.
(3)The first report produced by the Commissioner under section 139 of this Act must relate to the period of 1 year beginning with 1 April 2018.
Commencement Information
I787Sch. 20 para. 21 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Fees etc received by the CommissionerU.K.
22(1)The repeal of Schedule 5 to the 1998 Act (Information Commissioner) does not affect the application of paragraph 9 of that Schedule after the relevant time to amounts received by the Commissioner before the relevant time.U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of Schedule 5 to the 1998 Act comes into force.
Commencement Information
I788Sch. 20 para. 22 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
23U.K.Paragraph 10 of Schedule 12 to this Act applies only to amounts received by the Commissioner after the time when that Schedule comes into force.
Commencement Information
I789Sch. 20 para. 23 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Functions in connection with the Data Protection ConventionU.K.
24(1)The repeal of section 54(2) of the 1998 Act (functions to be discharged by the Commissioner for the purposes of Article 13 of the Data Protection Convention), and the revocation of the Data Protection (Functions of Designated Authority) Order 2000 (S.I. 2000/186), do not affect the application of articles 1 to 5 of that Order after the relevant time in relation to a request described in those articles which was made before that time.U.K.
(2)The references in paragraph 9 of Schedule 14 to this Act (Data Protection Convention: restrictions on use of information) to requests made or received by the Commissioner under paragraph 6 or 7 of that Schedule include a request made or received by the Commissioner under article 3 or 4 of the Data Protection (Functions of Designated Authority) Order 2000 (S.I. 2000/186).
(3)The repeal of section 54(7) of the 1998 Act (duty to notify the European Commission of certain approvals and authorisations) does not affect the application of that provision after the relevant time in relation to an approval or authorisation granted before the relevant time.
(4)In this paragraph, “the relevant time” means the time when the repeal of section 54 of the 1998 Act comes into force.
Commencement Information
I790Sch. 20 para. 24 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Co-operation with the European Commission: transfers of personal data outside the EEAU.K.
25(1)The repeal of section 54(3) of the 1998 Act (co-operation by the Commissioner with the European Commission etc), and the revocation of the Data Protection (International Co-operation) Order 2000 (S.I. 2000/190), do not affect the application of articles 1 to 4 of that Order after the relevant time in relation to transfers that took place before the relevant time.U.K.
(2)In this paragraph—
“the relevant time” means the time when the repeal of section 54 of the 1998 Act comes into force;
“transfer” has the meaning given in article 2 of the Data Protection (International Co-operation) Order 2000 (S.I. 2000/190).
Commencement Information
I791Sch. 20 para. 25 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Charges payable to the Commissioner by controllersU.K.
26(1)The Data Protection (Charges and Information) Regulations 2018 (S.I. 2018/480) have effect after the relevant time (until revoked) as if they were made under section 137 of this Act.U.K.
(2)In this paragraph, “the relevant time” means the time when section 137 of this Act comes into force.
Commencement Information
I792Sch. 20 para. 26 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Requests for assessmentU.K.
27(1)The repeal of section 42 of the 1998 Act (requests for assessment) does not affect the application of that section after the relevant time in a case in which the Commissioner received a request under that section before the relevant time, subject to sub-paragraph (2).U.K.
(2)The Commissioner is only required to make an assessment of acts and omissions that took place before the relevant time.
(3)In this paragraph, “the relevant time” means the time when the repeal of section 42 of the 1998 Act comes into force.
Commencement Information
I793Sch. 20 para. 27 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Codes of practiceU.K.
28(1)The repeal of section 52E of the 1998 Act (effect of codes of practice) does not affect the application of that section after the relevant time in relation to legal proceedings or to the exercise of the Commissioner's functions under the 1998 Act as it has effect by virtue of this Schedule.U.K.
(2)In section 52E of the 1998 Act, as it has effect by virtue of this paragraph, the references to the 1998 Act include that Act as it has effect by virtue of this Schedule.
(3)For the purposes of subsection (3) of that section, as it has effect by virtue of this paragraph, the data-sharing code and direct marketing code in force immediately before the relevant time are to be treated as having continued in force after that time.
(4)In this paragraph—
“the data-sharing code” and “the direct marketing code” mean the codes respectively prepared under sections 52A and 52AA of the 1998 Act and issued under section 52B(5) of that Act;
“the relevant time” means the time when the repeal of section 52E of the 1998 Act comes into force.
Commencement Information
I794Sch. 20 para. 28 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 7 U.K.Enforcement etc under the 1998 Act
Interpretation of this PartU.K.
29(1)In this Part of this Schedule, references to contravention of the sixth data protection principle sections are to relevant contravention of any of sections 7, 10, 11 or 12 of the 1998 Act, as they continue to have effect by virtue of this Schedule after their repeal (and references to compliance with the sixth data protection principle sections are to be read accordingly).U.K.
(2)In sub-paragraph (1), “relevant contravention” means contravention in a manner described in paragraph 8 of Part 2 of Schedule 1 to the 1998 Act (sixth data protection principle).
Commencement Information
I795Sch. 20 para. 29 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Information noticesU.K.
30(1)The repeal of section 43 of the 1998 Act (information notices) does not affect the application of that section after the relevant time in a case in which—U.K.
(a)the Commissioner served a notice under that section before the relevant time (and did not cancel it before that time), or
(b)the Commissioner requires information after the relevant time for the purposes of—
(i)responding to a request made under section 42 of the 1998 Act before that time,
(ii)determining whether a data controller complied with the old data protection principles before that time, or
(iii)determining whether a data controller complied with the sixth data protection principle sections after that time.
(2)In section 43 of the 1998 Act, as it has effect by virtue of this paragraph—
(a)the reference to an offence under section 47 of the 1998 Act includes an offence under section 144 of this Act, and
(b)the references to an offence under the 1998 Act include an offence under this Act.
(3)In this paragraph, “the relevant time” means the time when the repeal of section 43 of the 1998 Act comes into force.
Commencement Information
I796Sch. 20 para. 30 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Special information noticesU.K.
31(1)The repeal of section 44 of the 1998 Act (special information notices) does not affect the application of that section after the relevant time in a case in which—U.K.
(a)the Commissioner served a notice under that section before the relevant time (and did not cancel it before that time), or
(b)the Commissioner requires information after the relevant time for the purposes of—
(i)responding to a request made under section 42 of the 1998 Act before that time, or
(ii)ascertaining whether section 44(2)(a) or (b) of the 1998 Act was satisfied before that time.
(2)In section 44 of the 1998 Act, as it has effect by virtue of this paragraph—
(a)the reference to an offence under section 47 of the 1998 Act includes an offence under section 144 of this Act, and
(b)the references to an offence under the 1998 Act include an offence under this Act.
(3)In this paragraph, “the relevant time” means the time when the repeal of section 44 of the 1998 Act comes into force.
Commencement Information
I797Sch. 20 para. 31 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Assessment noticesU.K.
32(1)The repeal of sections 41A and 41B of the 1998 Act (assessment notices) does not affect the application of those sections after the relevant time in a case in which—U.K.
(a)the Commissioner served a notice under section 41A of the 1998 Act before the relevant time (and did not cancel it before that time), or
(b)the Commissioner considers it appropriate, after the relevant time, to investigate—
(i)whether a data controller complied with the old data protection principles before that time, or
(ii)whether a data controller complied with the sixth data protection principle sections after that time.
(2)The revocation of the Data Protection (Assessment Notices) (Designation of National Health Service Bodies) Order 2014 (S.I. 2014/3282), and the repeals mentioned in sub-paragraph (1), do not affect the application of that Order in a case described in sub-paragraph (1).
(3)Sub-paragraph (1) does not enable the Secretary of State, after the relevant time, to make an order under section 41A(2)(b) or (c) of the 1998 Act (data controllers on whom an assessment notice may be served) designating a public authority or person for the purposes of that section.
(4)Section 41A of the 1998 Act, as it has effect by virtue of sub-paragraph (1), has effect as if subsections (8) and (11) (duty to review designation orders) were omitted.
(5)The repeal of section 41C of the 1998 Act (code of practice about assessment notice) does not affect the application, after the relevant time, of the code issued under that section and in force immediately before the relevant time in relation to the exercise of the Commissioner's functions under and in connection with section 41A of the 1998 Act, as it has effect by virtue of sub-paragraph (1).
(6)In this paragraph, “the relevant time” means the time when the repeal of section 41A of the 1998 Act comes into force.
Commencement Information
I798Sch. 20 para. 32 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Enforcement noticesU.K.
33(1)The repeal of sections 40 and 41 of the 1998 Act (enforcement notices) does not affect the application of those sections after the relevant time in a case in which—U.K.
(a)the Commissioner served a notice under section 40 of the 1998 Act before the relevant time (and did not cancel it before that time), or
(b)the Commissioner is satisfied, after that time, that a data controller —
(i)contravened the old data protection principles before that time, or
(ii)contravened the sixth data protection principle sections after that time.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 40 of the 1998 Act comes into force.
Commencement Information
I799Sch. 20 para. 33 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Determination by Commissioner as to the special purposesU.K.
34(1)The repeal of section 45 of the 1998 Act (determination by Commissioner as to the special purposes) does not affect the application of that section after the relevant time in a case in which—U.K.
(a)the Commissioner made a determination under that section before the relevant time, or
(b)the Commissioner considers it appropriate, after the relevant time, to make a determination under that section.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 45 of the 1998 Act comes into force.
Commencement Information
I800Sch. 20 para. 34 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Restriction on enforcement in case of processing for the special purposesU.K.
35(1)The repeal of section 46 of the 1998 Act (restriction on enforcement in case of processing for the special purposes) does not affect the application of that section after the relevant time in relation to an enforcement notice or information notice served under the 1998 Act—U.K.
(a)before the relevant time, or
(b)after the relevant time in reliance on this Schedule.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 46 of the 1998 Act comes into force.
Commencement Information
I801Sch. 20 para. 35 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
OffencesU.K.
36(1)The repeal of sections 47, 60 and 61 of the 1998 Act (offences of failing to comply with certain notices and of providing false information etc in response to a notice) does not affect the application of those sections after the relevant time in connection with an information notice, special information notice or enforcement notice served under Part 5 of the 1998 Act—U.K.
(a)before the relevant time, or
(b)after that time in reliance on this Schedule.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 47 of the 1998 Act comes into force.
Commencement Information
I802Sch. 20 para. 36 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Powers of entryU.K.
37(1)The repeal of sections 50, 60 and 61 of, and Schedule 9 to, the 1998 Act (powers of entry) does not affect the application of those provisions after the relevant time in a case in which—U.K.
(a)a warrant issued under that Schedule was in force immediately before the relevant time,
(b)before the relevant time, the Commissioner supplied information on oath for the purposes of obtaining a warrant under that Schedule but that had not been considered by a circuit judge or a District Judge (Magistrates' Courts), or
(c)after the relevant time, the Commissioner supplies information on oath to a circuit judge or a District Judge (Magistrates' Courts) in respect of—
(i)a contravention of the old data protection principles before the relevant time;
(ii)a contravention of the sixth data protection principle sections after the relevant time;
(iii)the commission of an offence under a provision of the 1998 Act (including as the provision has effect by virtue of this Schedule);
(iv)a failure to comply with a requirement imposed by an assessment notice issued under section 41A the 1998 Act (including as it has effect by virtue of this Schedule).
(2)In paragraph 16 of Schedule 9 to the 1998 Act, as it has effect by virtue of this paragraph, the reference to an offence under paragraph 12 of that Schedule includes an offence under paragraph 15 of Schedule 15 to this Act.
(3)In this paragraph, “the relevant time” means the time when the repeal of Schedule 9 to the 1998 Act comes into force.
(4)Paragraphs 14 and 15 of Schedule 9 to the 1998 Act (application of that Schedule to Scotland and Northern Ireland) apply for the purposes of this paragraph as they apply for the purposes of that Schedule.
Commencement Information
I803Sch. 20 para. 37 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Monetary penaltiesU.K.
38(1)The repeal of sections 55A, 55B, 55D and 55E of the 1998 Act (monetary penalties) does not affect the application of those provisions after the relevant time in a case in which—U.K.
(a)the Commissioner served a monetary penalty notice under section 55A of the 1998 Act before the relevant time,
(b)the Commissioner served a notice of intent under section 55B of the 1998 Act before the relevant time, or
(c)the Commissioner considers it appropriate, after the relevant time, to serve a notice mentioned in paragraph (a) or (b) in respect of—
(i)a contravention of section 4(4) of the 1998 Act before the relevant time, or
(ii)a contravention of the sixth data protection principle sections after the relevant time.
(2)The revocation of the relevant subordinate legislation, and the repeals mentioned in sub-paragraph (1), do not affect the application of the relevant subordinate legislation (or of provisions of the 1998 Act applied by them) after the relevant time in a case described in sub-paragraph (1).
(3)Guidance issued under section 55C of the 1998 Act (guidance about monetary penalty notices) which is in force immediately before the relevant time continues in force after that time for the purposes of the Commissioner's exercise of functions under sections 55A and 55B of the 1998 Act as they have effect by virtue of this paragraph.
(4)In this paragraph—
“the relevant subordinate legislation” means—
(a)the Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010 (S.I. 2010/31);
(b)the Data Protection (Monetary Penalties) Order 2010 (S.I. 2010/910);
“the relevant time” means the time when the repeal of section 55A of the 1998 Act comes into force.
Commencement Information
I804Sch. 20 para. 38 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
AppealsU.K.
39(1)The repeal of sections 48 and 49 of the 1998 Act (appeals) does not affect the application of those sections after the relevant time in relation to a notice served under the 1998 Act or a determination made under section 45 of that Act—U.K.
(a)before the relevant time, or
(b)after that time in reliance on this Schedule.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 48 of the 1998 Act comes into force.
Commencement Information
I805Sch. 20 para. 39 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
ExemptionsU.K.
40(1)The repeal of section 28 of the 1998 Act (national security) does not affect the application of that section after the relevant time for the purposes of a provision of Part 5 of the 1998 Act as it has effect after that time by virtue of the preceding paragraphs of this Part of this Schedule.U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of the provision of Part 5 of the 1998 Act in question comes into force.
(3)As regards certificates issued under section 28(2) of the 1998 Act, see Part 5 of this Schedule.
Commencement Information
I806Sch. 20 para. 40 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Tribunal Procedure RulesU.K.
41(1)The repeal of paragraph 7 of Schedule 6 to the 1998 Act (Tribunal Procedure Rules) does not affect the application of that paragraph, or of rules made under that paragraph, after the relevant time in relation to the exercise of rights of appeal conferred by section 28 or 48 of the 1998 Act, as they have effect by virtue of this Schedule.U.K.
(2)Part 3 of Schedule 19 to this Act does not apply for the purposes of Tribunal Procedure Rules made under paragraph 7(1)(a) of Schedule 6 to the 1998 Act as they apply, after the relevant time, in relation to the exercise of rights of appeal described in sub-paragraph (1).
(3)In this paragraph, “the relevant time” means the time when the repeal of paragraph 7 of Schedule 6 to the 1998 Act comes into force.
Commencement Information
I807Sch. 20 para. 41 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Obstruction etcU.K.
42(1)The repeal of paragraph 8 of Schedule 6 to the 1998 Act (obstruction etc in proceedings before the Tribunal) does not affect the application of that paragraph after the relevant time in relation to an act or omission in relation to proceedings under the 1998 Act (including as it has effect by virtue of this Schedule).U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of paragraph 8 of Schedule 6 to the 1998 Act comes into force.
Commencement Information
I808Sch. 20 para. 42 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Enforcement etc under the 2014 RegulationsU.K.
43(1)The references in the preceding paragraphs of this Part of this Schedule to provisions of the 1998 Act include those provisions as applied, with modifications, by regulation 51 of the 2014 Regulations (other functions of the Commissioner).U.K.
(2)The revocation of regulation 51 of the 2014 Regulations does not affect the application of those provisions of the 1998 Act (as so applied) as described in those paragraphs.
Commencement Information
I809Sch. 20 para. 43 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 8 U.K.Enforcement etc under this Act
Information noticesU.K.
44U.K.In section 143 of this Act—
(a)the reference to an offence under section 144 of this Act includes an offence under section 47 of the 1998 Act (including as it has effect by virtue of this Schedule), and
(b)the references to an offence under this Act include an offence under the 1998 Act (including as it has effect by virtue of this Schedule) or the 1984 Act.
Commencement Information
I810Sch. 20 para. 44 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Powers of entryU.K.
45U.K.In paragraph 16 of Schedule 15 to this Act (powers of entry: self-incrimination), the reference to an offence under paragraph 15 of that Schedule includes an offence under paragraph 12 of Schedule 9 to the 1998 Act (including as it has effect by virtue of this Schedule).
Commencement Information
I811Sch. 20 para. 45 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Tribunal Procedure RulesU.K.
46(1)Tribunal Procedure Rules made under paragraph 7(1)(a) of Schedule 6 to the 1998 Act (appeal rights under the 1998 Act) and in force immediately before the relevant time have effect after that time as if they were also made under section 203 of this Act.U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of paragraph 7(1)(a) of Schedule 6 to the 1998 Act comes into force.
Commencement Information
I812Sch. 20 para. 46 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
PART 9 U.K.Other enactments
Powers to disclose information to the CommissionerU.K.
47(1)The following provisions (as amended by Schedule 19 to this Act) have effect after the relevant time as if the matters they refer to included a matter in respect of which the Commissioner could exercise a power conferred by a provision of Part 5 of the 1998 Act, as it has effect by virtue of this Schedule—U.K.
(a)section 11AA(1)(a) of the Parliamentary Commissioner Act 1967 (disclosure of information by Parliamentary Commissioner);
(b)sections 33A(1)(a) and 34O(1)(a) of the Local Government Act 1974 (disclosure of information by Local Commissioner);
(c)section 18A(1)(a) of the Health Service Commissioners Act 1993 (disclosure of information by Health Service Commissioner);
(d)paragraph 1 of the entry for the Information Commissioner in Schedule 5 to the Scottish Public Services Ombudsman Act 2002 (asp 11) (disclosure of information by the Ombudsman);
(e)section 34X(3)(a) of the Public Services Ombudsman (Wales) Act 2005 (disclosure of information by the Ombudsman);
(f)section 18(6)(a) of the Commissioner for Older People (Wales) Act 2006 (disclosure of information by the Commissioner);
(g)section 22(3)(a) of the Welsh Language (Wales) Measure 2011 (nawm 1) (disclosure of information by the Welsh Language Commissioner);
(h)section 49(3)(a) of the Public Services Ombudsman Act (Northern Ireland) 2016 (c. 4 (N.I.))(disclosure of information by the Ombudsman);
(i)section 44(3)(a) of the Justice Act (Northern Ireland) 2016 (c. 21 (N.I.)) (disclosure of information by the Prison Ombudsman for Northern Ireland).
(2)The following provisions (as amended by Schedule 19 to this Act) have effect after the relevant time as if the offences they refer to included an offence under any provision of the 1998 Act other than paragraph 12 of Schedule 9 to that Act (obstruction of execution of warrant)—
(a)section 11AA(1)(b) of the Parliamentary Commissioner Act 1967;
(b)sections 33A(1)(b) and 34O(1)(b) of the Local Government Act 1974;
(c)section 18A(1)(b) of the Health Service Commissioners Act 1993;
(d)paragraph 2 of the entry for the Information Commissioner in Schedule 5 to the Scottish Public Services Ombudsman Act 2002 (asp 11);
(e)section 34X(5) of the Public Services Ombudsman (Wales) Act 2005 (disclosure of information by the Ombudsman);
(f)section 18(8) of the Commissioner for Older People (Wales) Act 2006;
(g)section 22(5) of the Welsh Language (Wales) Measure 2011 (nawm 1);
(h)section 49(5) of the Public Services Ombudsman Act (Northern Ireland) 2016 (c. 4 (N.I.));
(i)section 44(3)(b) of the Justice Act (Northern Ireland) 2016 (c. 21 (N.I.)).
(3)In this paragraph, “the relevant time”, in relation to a provision of a section or Schedule listed in sub-paragraph (1) or (2), means the time when the amendment of the section or Schedule by Schedule 19 to this Act comes into force.
Commencement Information
I813Sch. 20 para. 47 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Codes etc required to be consistent with the Commissioner's data-sharing codeU.K.
48(1)This paragraph applies in relation to the code of practice issued under each of the following provisions—U.K.
(a)section 19AC of the Registration Service Act 1953 (code of practice about disclosure of information by civil registration officials);
(b)section 43 of the Digital Economy Act 2017 (code of practice about disclosure of information to improve public service delivery);
(c)section 52 of that Act (code of practice about disclosure of information to reduce debt owed to the public sector);
(d)section 60 of that Act (code of practice about disclosure of information to combat fraud against the public sector);
(e)section 70 of that Act (code of practice about disclosure of information for research purposes).
(2)During the relevant period, the code of practice does not have effect to the extent that it is inconsistent with the code of practice prepared under section 121 of this Act (data-sharing code) and issued under section 125(4) of this Act (as altered or replaced from time to time).
(3)In this paragraph, “the relevant period”, in relation to a code issued under a section mentioned in sub-paragraph (1), means the period—
(a)beginning when the amendments of that section in Schedule 19 to this Act come into force, and
(b)ending when the code is first reissued under that section.
Commencement Information
I814Sch. 20 para. 48 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
49(1)This paragraph applies in relation to the original statement published under section 45E of the Statistics and Registration Service Act 2007 (statement of principles and procedures in connection with access to information by the Statistics Board).U.K.
(2)During the relevant period, the statement does not have effect to the extent that it is inconsistent with the code of practice prepared under section 121 of this Act (data-sharing code) and issued under section 125(4) of this Act (as altered or replaced from time to time).
(3)In this paragraph, “the relevant period” means the period—
(a)beginning when the amendments of section 45E of the Statistics and Registration Service Act 2007 in Schedule 19 to this Act come into force, and
(b)ending when the first revised statement is published under that section.
Commencement Information
I815Sch. 20 para. 49 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Consumer Credit Act 1974U.K.
50U.K.In section 159(1)(a) of the Consumer Credit Act 1974 (correction of wrong information) (as amended by Schedule 19 to this Act), the reference to information given under Article 15(1) to (3) of the GDPR includes information given at any time under section 7 of the 1998 Act.
Commencement Information
I816Sch. 20 para. 50 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Freedom of Information Act 2000U.K.
51U.K.Paragraphs 52 to 55 make provision about the Freedom of Information Act 2000 (“the 2000 Act”).
Commencement Information
I817Sch. 20 para. 51 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
52(1)This paragraph applies where a request for information was made to a public authority under the 2000 Act before the relevant time.U.K.
(2)To the extent that the request is dealt with after the relevant time, the amendments of sections 2 and 40 of the 2000 Act in Schedule 19 to this Act have effect for the purposes of determining whether the authority deals with the request in accordance with Part 1 of the 2000 Act.
(3)To the extent that the request was dealt with before the relevant time—
(a)the amendments of sections 2 and 40 of the 2000 Act in Schedule 19 to this Act do not have effect for the purposes of determining whether the authority dealt with the request in accordance with Part 1 of the 2000 Act, but
(b)the powers of the Commissioner and the Tribunal, on an application or appeal under the 2000 Act, do not include power to require the authority to take steps which it would not be required to take in order to comply with Part 1 of the 2000 Act as amended by Schedule 19 to this Act.
(4)In this paragraph—
“public authority” has the same meaning as in the 2000 Act;
“the relevant time” means the time when the amendments of sections 2 and 40 of the 2000 Act in Schedule 19 to this Act come into force.
Commencement Information
I818Sch. 20 para. 52 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
53(1)Tribunal Procedure Rules made under paragraph 7(1)(b) of Schedule 6 to the 1998 Act (appeal rights under the 2000 Act) and in force immediately before the relevant time have effect after that time as if they were also made under section 61 of the 2000 Act (as inserted by Schedule 19 to this Act).U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of paragraph 7(1)(b) of Schedule 6 to the 1998 Act comes into force.
Commencement Information
I819Sch. 20 para. 53 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
54(1)The repeal of paragraph 8 of Schedule 6 to the 1998 Act (obstruction etc in proceedings before the Tribunal) does not affect the application of that paragraph after the relevant time in relation to an act or omission before that time in relation to an appeal under the 2000 Act.U.K.
(2)In this paragraph, “the relevant time” means the time when the repeal of paragraph 8 of Schedule 6 to the 1998 Act comes into force.
Commencement Information
I820Sch. 20 para. 54 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
55(1)The amendment of section 77 of the 2000 Act in Schedule 19 to this Act (offence of altering etc record with intent to prevent disclosure: omission of reference to section 7 of the 1998 Act) does not affect the application of that section after the relevant time in relation to a case in which—U.K.
(a)the request for information mentioned in section 77(1) of the 2000 Act was made before the relevant time, and
(b)when the request was made, section 77(1)(b) of the 2000 Act was satisfied by virtue of section 7 of the 1998 Act.
(2)In this paragraph, “the relevant time” means the time when the repeal of section 7 of the 1998 Act comes into force.
Commencement Information
I821Sch. 20 para. 55 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Freedom of Information (Scotland) Act 2002U.K.
56(1)This paragraph applies where a request for information was made to a Scottish public authority under the Freedom of Information (Scotland) Act 2002 (“the 2002 Act”) before the relevant time.U.K.
(2)To the extent that the request is dealt with after the relevant time, the amendments of the 2002 Act in Schedule 19 to this Act have effect for the purposes of determining whether the authority deals with the request in accordance with Part 1 of the 2002 Act.
(3)To the extent that the request was dealt with before the relevant time—
(a)the amendments of the 2002 Act in Schedule 19 to this Act do not have effect for the purposes of determining whether the authority dealt with the request in accordance with Part 1 of the 2002 Act, but
(b)the powers of the Scottish Information Commissioner and the Court of Session, on an application or appeal under the 2002 Act, do not include power to require the authority to take steps which it would not be required to take in order to comply with Part 1 of the 2002 Act as amended by Schedule 19 to this Act.
(4)In this paragraph—
“Scottish public authority” has the same meaning as in the 2002 Act;
“the relevant time” means the time when the amendments of the 2002 Act in Schedule 19 to this Act come into force.
Commencement Information
I822Sch. 20 para. 56 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Access to Health Records (Northern Ireland) Order 1993 (S.I. 1993/1250 (N.I. 4))U.K.
57U.K.Until the first regulations under Article 5(4)(a) of the Access to Health Records (Northern Ireland) Order 1993 (as amended by Schedule 19 to this Act) come into force, the maximum amount of a fee that may be required for giving access under that Article is £10.
Commencement Information
I823Sch. 20 para. 57 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2450)U.K.
58(1)The repeal of a provision of the 1998 Act does not affect its operation for the purposes of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“the PECR 2003”) (see regulations 2, 31 and 31B of, and Schedule 1 to, those Regulations).U.K.
(2)Where subordinate legislation made under a provision of the 1998 Act is in force immediately before the repeal of that provision, neither the revocation of the subordinate legislation nor the repeal of the provision of the 1998 Act affect the application of the subordinate legislation for the purposes of the PECR 2003 after that time.
(3)Part 3 of Schedule 19 to this Act (modifications) does not have effect in relation to the PECR 2003.
(4)Part 7 of this Schedule does not have effect in relation to the provisions of the 1998 Act as applied by the PECR 2003.
Commencement Information
I824Sch. 20 para. 58 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Health and Personal Social Services (Quality, Improvement and Regulation) (Northern Ireland) Order 2003 (S.I. 2003/431 (N.I. 9))U.K.
59U.K.Part 3 of Schedule 19 to this Act (modifications) does not have effect in relation to the reference to an accessible record within the meaning of section 68 of the 1998 Act in Article 43 of the Health and Personal Social Services (Quality, Improvement and Regulation) (Northern Ireland) Order 2003.
Commencement Information
I825Sch. 20 para. 59 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Environmental Information Regulations 2004 (S.I. 2004/3391)U.K.
60(1)This paragraph applies where a request for information was made to a public authority under the Environmental Information Regulations 2004 (“the 2004 Regulations”) before the relevant time.U.K.
(2)To the extent that the request is dealt with after the relevant time, the amendments of the 2004 Regulations in Schedule 19 to this Act have effect for the purposes of determining whether the authority deals with the request in accordance with Parts 2 and 3 of those Regulations.
(3)To the extent that the request was dealt with before the relevant time—
(a)the amendments of the 2004 Regulations in Schedule 19 to this Act do not have effect for the purposes of determining whether the authority dealt with the request in accordance with Parts 2 and 3 of those Regulations, but
(b)the powers of the Commissioner and the Tribunal, on an application or appeal under the 2000 Act (as applied by the 2004 Regulations), do not include power to require the authority to take steps which it would not be required to take in order to comply with Parts 2 and 3 of those Regulations as amended by Schedule 19 to this Act.
(4)In this paragraph—
“public authority” has the same meaning as in the 2004 Regulations;
“the relevant time” means the time when the amendments of the 2004 Regulations in Schedule 19 to this Act come into force.
Commencement Information
I826Sch. 20 para. 60 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)
Environmental Information (Scotland) Regulations 2004 (S.S.I. 2004/520)U.K.
61(1)This paragraph applies where a request for information was made to a Scottish public authority under the Environmental Information (Scotland) Regulations 2004 (“the 2004 Regulations”) before the relevant time.U.K.
(2)To the extent that the request is dealt with after the relevant time, the amendments of the 2004 Regulations in Schedule 19 to this Act have effect for the purposes of determining whether the authority deals with the request in accordance with those Regulations.
(3)To the extent that the request was dealt with before the relevant time—
(a)the amendments of the 2004 Regulations in Schedule 19 to this Act do not have effect for the purposes of determining whether the authority dealt with the request in accordance with those Regulations, but
(b)the powers of the Scottish Information Commissioner and the Court of Session, on an application or appeal under the 2002 Act (as applied by the 2004 Regulations), do not include power to require the authority to take steps which it would not be required to take in order to comply with those Regulations as amended by Schedule 19 to this Act.
(4)In this paragraph—
“Scottish public authority” has the same meaning as in the 2004 Regulations;
“the relevant time” means the time when the amendments of the 2004 Regulations in Schedule 19 to this Act come into force.
Commencement Information
I827Sch. 20 para. 61 in force at 25.5.2018 by S.I. 2018/625, reg. 2(1)(g)