Legal sources with official primary sources

Printed ·

Hoppa till innehåll
Hoppa till svaret

When is a data protection impact assessment required in the UK?

Before processing that is likely to result in a high risk to individuals, in particular systematic and extensive automated evaluation with legal or similarly significant effects, large scale processing of special category data, and large scale systematic monitoring of a publicly accessible area. The Information Commissioner's own list adds innovative technology, biometric and genetic data, tracking and targeting of children among others. Where the residual risk stays high after mitigation, the Commissioner must be consulted before processing begins.

Dela sidan

Source

Source
UK GDPR Articles 35 and 36
Acts
Data Protection Act 2018
Area
Data protection and online duties
Checked
2026-09-22

Questions

When must a personal data breach be reported to the ICO?UK GDPR Articles 33 and 34, with the Data Protection Act 2018How long does a UK organisation have to answer a subject access request?UK GDPR Article 15 and Article 12(3)How can personal data be transferred out of the UK lawfully?UK GDPR Articles 44 to 49 and Data Protection Act 2018, sections 17A to 18Must a UK organisation pay a fee to the Information Commissioner?Data Protection (Charges and Information) Regulations 2018, made under the Data Protection Act 2018When must a UK organisation appoint a data protection officer?UK GDPR Articles 37 to 39What is the maximum fine under UK data protection law?Data Protection Act 2018, sections 155 to 157 and UK GDPR Article 83When is consent required for cookies in the UK?Privacy and Electronic Communications Regulations 2003, regulation 6Can a UK business send marketing email without consent?Privacy and Electronic Communications Regulations 2003, regulations 22 and 23What are the illegal content duties under the Online Safety Act?Online Safety Act 2023, sections 9 to 10When must an online service check the age of its users in the UK?Online Safety Act 2023, Part 3, Chapter 2 and section 81What penalties can Ofcom impose under the Online Safety Act?Online Safety Act 2023, sections 140 to 146 and Schedule 13What counts as unauthorised access to a computer in the UK?Computer Misuse Act 1990, sections 1 to 3AWhat security measures does UK data protection law require?UK GDPR Articles 28 and 32

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift