7.4 Data Protection Act 2018, UK GDPR, and Compliance
Key Takeaways
- The UK GDPR and Data Protection Act 2018 govern the processing of personal data, imposing strict accountability and compliance documentation obligations on data controllers and processors.
- The seven data protection principles mandate lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity/confidentiality, and verifiable accountability.
- Under UK GDPR, notifiable personal data breaches presenting a risk to individual rights must be reported to the Information Commissioner's Office (ICO) within 72 hours of discovery.
- Subject Access Requests (SARs) must be fulfilled free of charge within one calendar month, though the right to erasure is bounded by statutory accounting record-keeping requirements under UK tax law.
7.4 Data Protection Act 2018, UK GDPR, and Compliance
Modern accounting and payroll systems hold extensive repositories of personal data. Accounting professionals process employee bank accounts, National Insurance numbers, home addresses, salary histories, tax deductions, pension contributions, and sole trader supplier records. Consequently, understanding data protection law is not merely an IT concern; it is a fundamental statutory obligation and a cornerstone of professional accounting ethics.
The Legislative Framework
Following the United Kingdom's withdrawal from the European Union, the statutory data protection regime in the UK is governed by two complementary instruments:
- The UK General Data Protection Regulation (UK GDPR): The retained EU Regulation (EU) 2016/679, as amended by UK statutory instruments, defining the core principles, data subject rights, and statutory obligations.
- The Data Protection Act 2018 (DPA 2018): UK domestic legislation that sits alongside the UK GDPR, setting out national derogations, specific exemptions, and the enforcement powers of the national supervisory authority.
Extraterritorial Scope
The UK GDPR applies to any commercial business, charity, or public body established in the UK that processes personal data. It also applies to overseas organisations offering goods or services to, or monitoring the behavior of, individuals located within the UK.
Key Legal Definitions
Navigating compliance requires precise understanding of statutory terms:
- Personal Data: Any information relating to an identified or identifiable living individual (the data subject). Identifiers include names, identification numbers (e.g., National Insurance numbers, passport numbers), location data, online identifiers (IP addresses), or factors specific to physical, physiological, economic, or social identity.
- Special Category Data: Personal data deemed particularly sensitive under Article 9, requiring heightened statutory safeguards. It encompasses data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for unique identification, health data, and data concerning an individual's sex life or sexual orientation. Processing special category data is prohibited unless a specific Article 6 lawful basis and an Article 9 condition (such as explicit consent or statutory employment/social security obligations) are satisfied.
- Data Controller: The natural or legal person, public authority, or commercial body that determines the purposes and means of processing personal data. A company acting as an employer is the data controller of its workforce payroll data.
- Data Processor: A natural or legal person that processes personal data strictly on behalf of and under the instruction of the data controller. An external outsourced payroll bureau or cloud software vendor hosting employee records acts as a data processor. Processors must be bound by formal, legally binding written contracts (Data Processing Agreements) specifying data security and compliance duties.
- Processing: Any operation performed on personal data, whether automated or manual, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
The Seven Core Data Protection Principles
Article 5 of the UK GDPR establishes seven foundational principles that must govern all personal data processing activities:
1. Lawfulness, Fairness, and Transparency
Data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Organisations must identify a valid lawful basis before processing and communicate their processing practices clearly through accessible, transparent privacy notices.
2. Purpose Limitation
Personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those initial purposes. An accounting firm collecting client financial records solely to prepare annual tax returns cannot sell those client contact lists to third-party mortgage brokers.
3. Data Minimisation
Personal data collected must be adequate, relevant, and limited strictly to what is necessary in relation to the purposes for which it is processed. Finance teams must not collect superfluous personal information (such as marital history or medical records) when processing standard supplier invoices or trade credit applications.
4. Accuracy
Personal data must be accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that is inaccurate—having regard to the purposes for which it is processed—is erased or rectified without delay.
5. Storage Limitation
Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. Personal records must undergo secure destruction or permanent anonymisation once their operational purpose ceases, subject to statutory retention obligations.
6. Integrity and Confidentiality (Security)
Personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (such as encryption, role-based access control, and staff training).
7. Accountability
The Accountability Principle requires that the data controller is responsible for, and must be able to demonstrate compliance with, all the principles above. This requires maintaining written Records of Processing Activities (ROPA), executing Data Protection Impact Assessments (DPIAs) for high-risk systems, establishing written internal policies, and appointing a Data Protection Officer (DPO) where mandated.
Lawful Bases for Processing Personal Data
Under Article 6 of the UK GDPR, processing is lawful only if at least one of the six statutory bases applies:
- Consent: The data subject has given clear, unambiguous, affirmative consent for a specific purpose. Consent must be freely given, specific, informed, and capable of being withdrawn at any time.
- Contract: Processing is necessary for the performance of a contract to which the data subject is party (e.g., paying an employee's salary into their bank account pursuant to an employment contract) or to take pre-contractual steps.
- Legal Obligation: Processing is necessary for compliance with a statutory or common-law legal obligation to which the controller is subject (e.g., deducting PAYE income tax and reporting payroll data to HMRC, or retaining commercial accounting records under the Companies Act 2006).
- Vital Interests: Processing is necessary to protect someone's life in an emergency.
- Public Task: Processing is necessary to perform a task in the public interest or under official statutory authority.
- Legitimate Interests: Processing is necessary for the legitimate commercial interests of the controller or a third party, provided those interests are not overridden by the fundamental rights, freedoms, and interests of the individual.
Crucial Accounting Context: In payroll and tax administration, the lawful basis for processing is Legal Obligation and Contractual Performance, not consent. An employee cannot withdraw "consent" to stop their employer from reporting payroll deductions to HMRC, because statutory tax law obligates the employer to process that data.
Individual Data Subject Rights
The UK GDPR grants individuals specific legal rights regarding their personal data:
- Right to be Informed: Individuals have the right to know how their data is collected, used, stored, and shared, fulfilled via transparent privacy notices.
- Right of Access (Subject Access Request - SAR): An individual can submit a SAR requesting confirmation that their data is being processed, along with a full copy of their personal data and supplementary explanatory details. Key rules:
- Timescale: Controllers must respond without undue delay and at the latest within one calendar month of receipt. This deadline may be extended by up to two additional months for exceptionally complex or numerous requests.
- Cost: Information must be provided free of charge. A reasonable administrative fee may only be charged if the request is demonstrably manifestly unfounded or excessive.
- Right to Rectification: Individuals can mandate the correction of inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Individuals can request deletion of their personal data under specific conditions (e.g., if the data is no longer necessary for its original purpose or consent is withdrawn). However, this right is strictly bounded: a former employee cannot demand the immediate deletion of their historical payroll records, because the business must retain those records to satisfy statutory tax obligations under HMRC rules.
- Right to Restrict Processing: An individual can require the controller to halt active processing of their data while disputes regarding accuracy or lawful basis are resolved.
- Right to Data Portability: This right applies to personal data the individual provided where processing is automated and based on consent or contract. The individual can receive it in a structured, commonly used, machine-readable format or ask for transmission to another controller where technically feasible.
- Right to Object: Individuals have an absolute right to object to processing for direct marketing purposes, as well as rights to object to processing based on legitimate interests or public tasks.
The Information Commissioner's Office (ICO) and Breach Reporting
The Information Commissioner's Office (ICO) is the independent UK statutory supervisory authority responsible for upholding data privacy rights and enforcing data protection legislation. The ICO possesses investigative powers (conducting compliance audits, issuing information notices), corrective powers (issuing enforcement notices, ordering processing halts), and punitive financial powers.
Personal Data Breach Notification Rules
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- Notification to the ICO: In the event of a personal data breach, the data controller must notify the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. If reporting is delayed beyond 72 hours, the notification must be accompanied by reasoned justifications for the delay.
- Notification to Data Subjects: If the breach is likely to result in a high risk to the rights and freedoms of individuals (e.g., exposure of customer bank details or unencrypted payroll records creating immediate risks of identity theft, fraud, or financial ruin), the controller must also inform the affected data subjects without undue delay in clear, plain language.
Statutory Penalty Regimes
The ICO has the statutory authority to impose administrative fines for data protection infringements under a two-tiered statutory structure:
- Standard Maximum Penalty: For infringements of administrative, technical, or record-keeping provisions (such as failure to maintain processing records, failure to report a breach within 72 hours, or failure to execute a formal Data Processing Agreement with a processor). Fines can reach up to £8.7 million or 2% of the enterprise's total worldwide annual turnover of the preceding financial year, whichever is higher.
- Higher Maximum Penalty: For infringements of foundational provisions (such as breaching the seven core data protection principles, violating lawful processing bases, infringing individual data subject rights, unlawful international data transfers, or failing to comply with an ICO enforcement order). Fines can reach up to £17.5 million or 4% of the enterprise's total worldwide annual turnover of the preceding financial year, whichever is higher.
The 7 UK GDPR Principles and Accounting Practice Applications
| Data Protection Principle | Statutory Operational Meaning | Practical Accounting & Payroll Application |
|---|---|---|
| 1. Lawfulness, Fairness & Transparency | Process data under a valid legal basis; provide clear privacy notices | Relying on 'Legal Obligation' for PAYE reporting; issuing privacy notices to staff |
| 2. Purpose Limitation | Collect data for specified, legitimate purposes; no incompatible use | Restricting employee payroll data to payroll tasks; not selling data to brokers |
| 3. Data Minimisation | Restrict collection strictly to what is adequate, relevant, and necessary | Collecting only essential bank details and NI numbers; omitting irrelevant data |
| 4. Accuracy | Maintain accurate data; erase or rectify inaccuracies without delay | Promptly updating employee addresses and banking details upon notification |
| 5. Storage Limitation | Retain data no longer than necessary; balance against statutory rules | Applying the correct schedule: PAYE records are generally kept for 3 years from the end of the relevant tax year, while VAT records are generally kept for at least 6 years |
| 6. Integrity & Confidentiality | Implement robust physical and technical security measures | Enforcing MFA, role-based access, and AES-256 encryption on financial databases |
| 7. Accountability | Maintain documentation demonstrating active regulatory compliance | Maintaining written Records of Processing Activities (ROPA) and staff training logs |
A former employee who resigned four months ago submits a formal Subject Access Request (SAR) to their former employer's finance and HR department. The individual requests a complete, unredacted copy of all digital and physical records concerning their employment, including their complete payroll history, internal performance appraisal notes, and disciplinary hearing transcripts. The finance manager suggests charging the former employee an administrative fee of £50 to cover staff copying time, and proposes delaying the response for six months until the annual statutory audit is concluded. What are the legal requirements under the UK GDPR for responding to this SAR?
On a Friday evening, a payroll supervisor leaves an unencrypted work laptop on the back seat of their car while stopping at a supermarket. The car is broken into, and the laptop is stolen. The laptop's local solid-state drive contains unencrypted spreadsheets detailing the names, residential addresses, National Insurance numbers, salary histories, and personal bank account sort codes and account numbers of all 1,200 company employees. The theft is discovered immediately. What are the statutory breach reporting obligations of the company under the UK GDPR?
A commercial business retains (1) detailed CVs, interview notes, and passport scans from unsuccessful applicants for nine years and (2) VAT returns and sales invoices from four years ago. What approach best applies the UK GDPR data-minimisation and storage-limitation principles alongside tax obligations?