UKGI Compliance Manual

The rules and principles which apply

As explained in Section K.6 Article 5 (2) of the UK GDPR established the accountability principle, requiring firms not only to comply with data protection principles but also to demonstrate that compliance.

Firms must complete appropriate risk assessments in certain circumstances particularly where the processing may have a higher risk of impacting an individual’s rights and freedoms the risk assessments firms must document and retain are:

  • Data Protection Impact Assessment (DPIA) – must be completed where processing is likely to results in a high risk to individuals’ rights and freedoms, firms must also
  • Legitimate Interest Assessment (LIA) – must be undertaken where the lawful basis of legitimate interest under Article 6(1)(f) UK GDPR is relied upon for any processing activity.
  • Transfer Risk Assessment – to be completed when transferring data outside of the UK where no adequacy arrangements apply.

How this may affect firms

Data Protection Impact Assessment (DPIA)

A DPIA is a structured assessment designed to identify, evaluate, and minimise privacy risks arising from personal data processing. A DPIA is required where processing is likely to result in a high risk to individuals’ rights and freedoms for example:

  • Large scale processing of special category data
  • New technologies
  • Systematic monitoring systems
  • Profiling producing significant effects
  • CCTV deployment
  • Biometric processing
  • Extensive data matching
  • Deploying Artificial Intelligence (AI)
  • Processing involving vulnerable individuals

Typically, the DPIA process will involve:

  1. Describing the proposed processing
  2. Identifying the purposes
  3. Assessing necessity and proportionality
  4. Identifying risks to individuals
  5. Identifying mitigating measures
  6. Assessing residual risk
  7. Consulting DPO or other specialist advice
  8. Obtaining management approval before implementation

Where residual risks remain despite mitigation, the firm must consider whether prior consultation with the ICO is required before processing commences.

DPIAs should be reviewed whenever processing materially changes (including where the risks materially change) or when new technology is introduced. They should also be subject to review legal requirements change or significant incidents occur.

We have included more information on completing DPIAs in Section K.7.2. The ICO provide a template DPIA which can be accessed here,

Legitimate Interest Assessments (LIA)

Where the lawful basis for processing relied upon is legitimate interests and organisation must have completed a LIA before the processing commences. This assessment demonstrates that reliance on legitimate interests is appropriate and that individuals’ rights have been properly considered.

The LIA is made up of a three-part test which is based on:

  1. Purpose Test – Identify the legitimate interest being pursued and explain why the processing is necessary
  2. Necessity Test – Assess whether the processing is necessary to achieve the identified purpose and whether a less intrusive alternative exists.
  3. Balancing test – this must consider:
    1. Would the individual reasonably expect their data to be used in this way?
    2. What is the nature of the data i.e. does it involve special category data?
    3. What safeguards have been implemented?
    4. Does the individual have the ability to object?
    5. How will we ensure transparency i.e. that the customer is informed?
    6. Does the activity involve vulnerable individuals, or could it create/exacerbate vulnerabilities? Are any additional measures required to protect vulnerable individuals?

While legitimate interest is the most flexible of the lawful bases, a firm must not rely on legitimate interests where the interests or fundamental rights and freedoms of the individual overrise the interests of the firm. Where firms are in doubt whether to rely on legitimate interests, they may prefer to rely on consent, particularly where an individual can object to the processing. We explain legitimate interest in more detail in Section XX with examples of when it is likely to be appropriate to rely on legitimate interest in Section XX, firms wishing to rely on legitimate interest for direct marketing should also see Section K.3.2. as there are some types of marketing where legitimate interest may not be an appropriate lawful basis.

Transfer Risk Assessments (TRA)

Where personal data is transferred outside the UK and no adequacy regulations apply, the firm must complete a TRA before the transfer takes place. The purpose of the TRA is to assess whether the transferred data will continue to receive protection that is materially equivalent to UK GDPR standards. The assessment should cover:

  • Destination country
  • Applicable transfer mechanism
  • Legal framework of the receiving country
  • Government access powers
  • Enforceability of contractual safeguards
  • Technical and organisational measures
  • Encryption arrangements
  • Access controls
  • Onward transfers
  • Residual risks

Additional safeguards should be implemented where necessary and transfers should not proceed where appropriate protection cannot be achieved. For more information on international transfers see Section K.6.4..

The ICO has also published guidance on completing a TRA including a TRA Tool which can be accessed here.

Risk Based Approach

Firms are able to adopt a risk-based approach, and the level of assessment and documentation should be proportionate to the:

  • Sensitivity of the data
  • Volume of processing
  • Vulnerability of individuals
  • Complexity of processing
  • Use of new technologies
  • Likelihood of harm
  • Severity of potential impact

Higher risk processing requires more detailed assessment, data mapping, enhanced governance, and senior management oversight. Firms should also consider what level of approval may be required i.e. DPO or SMF Responsible, Senior Management Team and governing body approval.

Records of assessments should be retained for as long as necessary to demonstrate compliance so for as long as the processing continues and for a suitable period thereafter to address any subsequent regulatory queries, complaints, disputes etc. We suggest that in accordance with other regulatory governance record keeping requirements that superseded versions should be retained for a period of at least six years to demonstrate historical compliance decisions.