9.3 Data Protection and Data Security

Key Takeaways

  • UK GDPR and DPA 2018 are built on seven principles including lawfulness, fairness, transparency and accountability
  • Lawful bases under Article 6 are required for all processing; special category data needs an Article 9 condition
  • Personal data breaches likely to risk individuals' rights must be notified to the ICO within 72 hours
  • SYSC 13 complements the UK GDPR by requiring technical and organisational security measures
  • PECR requires consent for non-essential cookies and electronic marketing, with a soft opt-in for existing similar-product customers
Last updated: July 2026

9.3 Data Protection and Data Security

Personal data is one of the most valuable assets a financial services firm holds. Customers trust advisers with their income details, health information, account numbers and life plans. UK data protection law has two layers: the UK GDPR (the retained EU General Data Protection Regulation, as amended), and the Data Protection Act 2018 (DPA 2018), which supplements the UK GDPR and provides the UK's specific framework. The regulator is the Information Commissioner's Office (ICO).

The Seven Data Protection Principles

The UK GDPR is built around seven principles set out in Article 5. They are not legalistic hurdles but design principles — firms must show they have considered each one in every processing activity.

PrincipleIn plain terms
1. Lawfulness, fairness and transparencyHave a valid legal basis and tell people what you do
2. Purpose limitationUse data only for the purpose you collected it for
3. Data minimisationCollect only what you need
4. AccuracyKeep data accurate and up to date
5. Storage limitationKeep data no longer than necessary
6. Integrity and confidentiality (security)Protect data with appropriate technical and organisational measures
7. AccountabilityBe able to demonstrate compliance with the other six principles

The accountability principle is the most distinctive feature of the modern framework — it is not enough to comply; firms must be able to evidence their compliance through policies, records of processing activities (ROPAs), privacy notices, DPIAs and training logs.

Data Subject Rights

The UK GDPR gives individuals (data subjects) specific rights:

  1. The right to be informed (privacy notices).
  2. The right of access (subject access requests, free of charge in most cases, response within one month).
  3. The right to rectification of inaccurate data.
  4. The right to erasure (the right to be forgotten) — subject to exemptions such as legal compliance and legal claims.
  5. The right to restrict processing.
  6. The right to data portability.
  7. The right to object to processing based on legitimate interests or direct marketing.
  8. Rights in relation to automated decision-making and profiling, including the right not to be subject to a decision based solely on automated processing that significantly affects them.

Lawful Bases and Special Category Data

Every processing activity must rest on at least one lawful basis set out in Article 6:

  • Consent — freely given, specific, informed and unambiguous.
  • Contract — necessary to perform a contract with the data subject.
  • Legal obligation — e.g., AML record-keeping obligations under MLR 2017.
  • Vital interests — to protect someone's life.
  • Public task — exercise of official authority.
  • Legitimate interests — a balance between the firm's interests and the data subject's rights.

For special category data (Article 9) — health, racial or ethnic origin, religious beliefs, biometric data, sexual orientation — a further condition is required (e.g., explicit consent, or necessary for insurance purposes with safeguards). Financial advice files frequently contain health information for life insurance and critical illness underwriting, so this second tier is highly relevant.

Data Security — SYSC 13

The FCA's SYSC 13 sourcebook complements the UK GDPR's security principle. Firms must:

  • Take appropriate technical and organisational measures to safeguard information, including encryption, access controls, firewalls and patch management.
  • Test security regularly (penetration tests, vulnerability scans).
  • Train staff on cyber risks, phishing and social engineering.
  • Maintain a business continuity plan that covers data recovery.

Personal Data Breaches — The 72-Hour Rule

A personal data breach is any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. When a controller becomes aware of a breach that is likely to result in a risk to individuals' rights and freedoms, it must notify the ICO within 72 hours of becoming aware. If the breach is high risk, the affected individuals must also be informed without undue delay. Processors must notify controllers without undue delay. Even where no notification is required, the breach must be recorded in the firm's breach log.

Freedom of Information Act 2000

The Freedom of Information Act 2000 applies to public authorities, not to private financial firms. However, where a firm holds data on behalf of a public body (for example, a contractor processing pension scheme data for a government department), the data may be subject to FOI requests. Advisers should be aware of this when contracting with public-sector clients.

Retention, Cookies and PECR

The UK GDPR's storage limitation principle requires firms to set retention periods tied to the purpose. Advisers typically retain client files for the duration of the relationship plus the SYSC 9 / MLR 2017 retention period (at least five to seven years), then securely destroy or anonymise them.

The Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) govern electronic marketing and cookies. Firms must obtain consent before setting non-essential cookies and before sending marketing emails or SMS to individuals. The soft opt-in rule permits marketing to existing customers for similar products, provided they are given a simple opt-out at the point of collection and in every message.

Practical Compliance Checklist

  • Maintain a Record of Processing Activities (ROPA).
  • Issue clear, layered privacy notices to customers at the point of data collection.
  • Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing such as automated advice tools.
  • Appoint a Data Protection Officer (DPO) where required by Article 37 (large-scale special category processing is a typical trigger).
  • Train staff at least annually and on induction, with phishing simulations and breach drills.

Good data protection is more than a compliance exercise — it is part of the trust relationship at the heart of financial advice.

Test Your Knowledge

A controller discovers a personal data breach that is likely to result in a risk to individuals' rights and freedoms. Under UK GDPR, by when must it notify the ICO?

A
B
C
D
Test Your Knowledge

Which of the following is a special category of personal data under Article 9 of the UK GDPR?

A
B
C
D
Test Your Knowledge

Which principle of the UK GDPR requires firms to be able to evidence their compliance through policies, ROPAs and training logs?

A
B
C
D