Search Legislation

Data Protection Act 1998

 Help about what version

What Version

 Help about advanced features

Advanced Features

Status:

Point in time view as at 01/03/2000. This version of this part contains provisions that are not valid for this point in time. Help about Status

Close

Status

Not valid for this point in time generally means that a provision was not in force for the point in time you have selected to view it on.

Changes to legislation:

Data Protection Act 1998, Part IV is up to date with all changes known to be in force on or before 28 March 2024. There are changes that may be brought into force at a future date. Changes that have been made appear in the content and are referenced with annotations. Help about Changes to Legislation

Close

Changes to Legislation

Changes and effects yet to be applied by the editorial team are only applicable when viewing the latest version or prospective version of legislation. They are therefore not accessible when viewing legislation as at a specific point in time. To view the ‘Changes to Legislation’ information for this provision return to the latest version view using the options provided in the ‘What Version’ box above.

Part IVU.K. Exemptions

27 Preliminary.U.K.

(1)References in any of the data protection principles or any provision of Parts II and III to personal data or to the processing of personal data do not include references to data or processing which by virtue of this Part are exempt from that principle or other provision.

(2)In this Part “the subject information provisions” means—

(a)the first data protection principle to the extent to which it requires compliance with paragraph 2 of Part II of Schedule 1, and

(b)section 7.

(3)In this Part “the non-disclosure provisions” means the provisions specified in subsection (4) to the extent to which they are inconsistent with the disclosure in question.

(4)The provisions referred to in subsection (3) are—

(a)the first data protection principle, except to the extent to which it requires compliance with the conditions in Schedules 2 and 3,

(b)the second, third, fourth and fifth data protection principles, and

(c)sections 10 and 14(1) to (3).

(5)Except as provided by this Part, the subject information provisions shall have effect notwithstanding any enactment or rule of law prohibiting or restricting the disclosure, or authorising the withholding, of information.

28 National security.U.K.

(1)Personal data are exempt from any of the provisions of—

(a)the data protection principles,

(b)Parts II, III and V, and

(c)section 55,

if the exemption from that provision is required for the purpose of safeguarding national security.

(2)Subject to subsection (4), a certificate signed by a Minister of the Crown certifying that exemption from all or any of the provisions mentioned in subsection (1) is or at any time was required for the purpose there mentioned in respect of any personal data shall be conclusive evidence of that fact.

(3)A certificate under subsection (2) may identify the personal data to which it applies by means of a general description and may be expressed to have prospective effect.

(4)Any person directly affected by the issuing of a certificate under subsection (2) may appeal to the Tribunal against the certificate.

(5)If on an appeal under subsection (4), the Tribunal finds that, applying the principles applied by the court on an application for judicial review, the Minister did not have reasonable grounds for issuing the certificate, the Tribunal may allow the appeal and quash the certificate.

(6)Where in any proceedings under or by virtue of this Act it is claimed by a data controller that a certificate under subsection (2) which identifies the personal data to which it applies by means of a general description applies to any personal data, any other party to the proceedings may appeal to the Tribunal on the ground that the certificate does not apply to the personal data in question and, subject to any determination under subsection (7), the certificate shall be conclusively presumed so to apply.

(7)On any appeal under subsection (6), the Tribunal may determine that the certificate does not so apply.

(8)A document purporting to be a certificate under subsection (2) shall be received in evidence and deemed to be such a certificate unless the contrary is proved.

(9)A document which purports to be certified by or on behalf of a Minister of the Crown as a true copy of a certificate issued by that Minister under subsection (2) shall in any legal proceedings be evidence (or, in Scotland, sufficient evidence) of that certificate.

(10)The power conferred by subsection (2) on a Minister of the Crown shall not be exercisable except by a Minister who is a member of the Cabinet or by the Attorney General or the Lord Advocate.

(11)No power conferred by any provision of Part V may be exercised in relation to personal data which by virtue of this section are exempt from that provision.

(12)Schedule 6 shall have effect in relation to appeals under subsection (4) or (6) and the proceedings of the Tribunal in respect of any such appeal.

Modifications etc. (not altering text)

C1S. 28(8)(9)(10)(12) applied (with modifications) (1.3.2000) by S.I. 1999/2093, reg. 32(8)(a)

S. 28(8)(9)(10)(12) applied (11.12.2003) by The Privacy and Electronic Communications (EC Directive) Regulations 2003 (2003/2426), {reg. 28(8)(b)} (with regs. 4, 15(3), 28, 29)

C2S. 28(10): functions of the Lord Advocate transferred to the Advocate General for Scotland, and all property, rights and liabilities to which the Lord Advocate is entitled or subject in connection with any such function transferred to the Advocate General for Scotland (20.5.1999) by S.I. 1999/679, arts. 2, 3, Sch; S.I. 1998/3178, art. 2(2), Sch. 4

29 Crime and taxation.U.K.

(1)Personal data processed for any of the following purposes—

(a)the prevention or detection of crime,

(b)the apprehension or prosecution of offenders, or

(c)the assessment or collection of any tax or duty or of any imposition of a similar nature,

are exempt from the first data protection principle (except to the extent to which it requires compliance with the conditions in Schedules 2 and 3) and section 7 in any case to the extent to which the application of those provisions to the data would be likely to prejudice any of the matters mentioned in this subsection.

(2)Personal data which—

(a)are processed for the purpose of discharging statutory functions, and

(b)consist of information obtained for such a purpose from a person who had it in his possession for any of the purposes mentioned in subsection (1),

are exempt from the subject information provisions to the same extent as personal data processed for any of the purposes mentioned in that subsection.

(3)Personal data are exempt from the non-disclosure provisions in any case in which—

(a)the disclosure is for any of the purposes mentioned in subsection (1), and

(b)the application of those provisions in relation to the disclosure would be likely to prejudice any of the matters mentioned in that subsection.

(4)Personal data in respect of which the data controller is a relevant authority and which—

(a)consist of a classification applied to the data subject as part of a system of risk assessment which is operated by that authority for either of the following purposes—

(i)the assessment or collection of any tax or duty or any imposition of a similar nature, or

(ii)the prevention or detection of crime, or apprehension or prosecution of offenders, where the offence concerned involves any unlawful claim for any payment out of, or any unlawful application of, public funds, and

(b)are processed for either of those purposes,

are exempt from section 7 to the extent to which the exemption is required in the interests of the operation of the system.

(5)In subsection (4)— “public funds” includes funds provided by any Community institution; “relevant authority” means—

(a)a government department,

(b)a local authority, or

(c)any other authority administering housing benefit or council tax benefit.

30 Health, education and social work.U.K.

(1)The Secretary of State may by order exempt from the subject information provisions, or modify those provisions in relation to, personal data consisting of information as to the physical or mental health or condition of the data subject.

(2)The Secretary of State may by order exempt from the subject information provisions, or modify those provisions in relation to—

(a)personal data in respect of which the data controller is the proprietor of, or a teacher at, a school, and which consist of information relating to persons who are or have been pupils at the school, or

(b)personal data in respect of which the data controller is an education authority in Scotland, and which consist of information relating to persons who are receiving, or have received, further education provided by the authority.

(3)The Secretary of State may by order exempt from the subject information provisions, or modify those provisions in relation to, personal data of such other descriptions as may be specified in the order, being information—

(a)processed by government departments or local authorities or by voluntary organisations or other bodies designated by or under the order, and

(b)appearing to him to be processed in the course of, or for the purposes of, carrying out social work in relation to the data subject or other individuals;

but the Secretary of State shall not under this subsection confer any exemption or make any modification except so far as he considers that the application to the data of those provisions (or of those provisions without modification) would be likely to prejudice the carrying out of social work.

(4)An order under this section may make different provision in relation to data consisting of information of different descriptions.

(5)In this section—

  • education authority” and “further education” have the same meaning as in the M1Education (Scotland) Act 1980 (“the 1980 Act”), and

  • proprietor”—

    (a)

    in relation to a school in England or Wales, has the same meaning as in the M2Education Act 1996,

    (b)

    in relation to a school in Scotland, means—

    (i)

    in the case of a self-governing school, the board of management within the meaning of the M3Self-Governing Schools etc. (Scotland) Act 1989,

    (ii)

    in the case of an independent school, the proprietor within the meaning of the 1980 Act,

    (iii)

    in the case of a grant-aided school, the managers within the meaning of the 1980 Act, and

    (iv)

    in the case of a public school, the education authority within the meaning of the 1980 Act, and

    (c)

    in relation to a school in Northern Ireland, has the same meaning as in the M4Education and Libraries (Northern Ireland) Order 1986 and includes, in the case of a controlled school, the Board of Governors of the school.

Modifications etc. (not altering text)

C3S. 30: transfer of functions (1.7.1999) by S.I. 1999/672, arts. 2, 3, Sch. 1

Commencement Information

I1S. 30 wholly in force at 1.3.2000; s. 30 in force for certain purposes at Royal Assent see s. 75(2)(i); s. 30 in force at 1.3.2000 insofar as not already in force by S.I. 2000/183, art. 2(1)

Marginal Citations

31 Regulatory activity.U.K.

(1)Personal data processed for the purposes of discharging functions to which this subsection applies are exempt from the subject information provisions in any case to the extent to which the application of those provisions to the data would be likely to prejudice the proper discharge of those functions.

(2)Subsection (1) applies to any relevant function which is designed—

(a)for protecting members of the public against—

(i)financial loss due to dishonesty, malpractice or other seriously improper conduct by, or the unfitness or incompetence of, persons concerned in the provision of banking, insurance, investment or other financial services or in the management of bodies corporate,

(ii)financial loss due to the conduct of discharged or undischarged bankrupts, or

(iii)dishonesty, malpractice or other seriously improper conduct by, or the unfitness or incompetence of, persons authorised to carry on any profession or other activity,

(b)for protecting charities against misconduct or mismanagement (whether by trustees or other persons) in their administration,

(c)for protecting the property of charities from loss or misapplication,

(d)for the recovery of the property of charities,

(e)for securing the health, safety and welfare of persons at work, or

(f)for protecting persons other than persons at work against risk to health or safety arising out of or in connection with the actions of persons at work.

(3)In subsection (2) “relevant function” means—

(a)any function conferred on any person by or under any enactment,

(b)any function of the Crown, a Minister of the Crown or a government department, or

(c)any other function which is of a public nature and is exercised in the public interest.

(4)Personal data processed for the purpose of discharging any function which—

(a)is conferred by or under any enactment on—

(i)the Parliamentary Commissioner for Administration,

(ii)the Commission for Local Administration in England, the Commission for Local Administration in Wales or the Commissioner for Local Administration in Scotland,

(iii)the Health Service Commissioner for England, the Health Service Commissioner for Wales or the Health Service Commissioner for Scotland,

(iv)the Welsh Administration Ombudsman,

(v)the Assembly Ombudsman for Northern Ireland, or

(vi)the Northern Ireland Commissioner for Complaints, and

(b)is designed for protecting members of the public against—

(i)maladministration by public bodies,

(ii)failures in services provided by public bodies, or

(iii)a failure of a public body to provide a service which it was a function of the body to provide,

are exempt from the subject information provisions in any case to the extent to which the application of those provisions to the data would be likely to prejudice the proper discharge of that function.

(5)Personal data processed for the purpose of discharging any function which—

(a)is conferred by or under any enactment on the Director General of Fair Trading, and

(b)is designed—

(i)for protecting members of the public against conduct which may adversely affect their interests by persons carrying on a business,

(ii)for regulating agreements or conduct which have as their object or effect the prevention, restriction or distortion of competition in connection with any commercial activity, or

(iii)for regulating conduct on the part of one or more undertakings which amounts to the abuse of a dominant position in a market,

are exempt from the subject information provisions in any case to the extent to which the application of those provisions to the data would be likely to prejudice the proper discharge of that function.

Modifications etc. (not altering text)

32 Journalism, literature and art.U.K.

(1)Personal data which are processed only for the special purposes are exempt from any provision to which this subsection relates if—

(a)the processing is undertaken with a view to the publication by any person of any journalistic, literary or artistic material,

(b)the data controller reasonably believes that, having regard in particular to the special importance of the public interest in freedom of expression, publication would be in the public interest, and

(c)the data controller reasonably believes that, in all the circumstances, compliance with that provision is incompatible with the special purposes.

(2)Subsection (1) relates to the provisions of—

(a)the data protection principles except the seventh data protection principle,

(b)section 7,

(c)section 10,

(d)section 12, and

[F1(dd)section 12A,]

(e)section 14(1) to (3).

(3)In considering for the purposes of subsection (1)(b) whether the belief of a data controller that publication would be in the public interest was or is a reasonable one, regard may be had to his compliance with any code of practice which—

(a)is relevant to the publication in question, and

(b)is designated by the Secretary of State by order for the purposes of this subsection.

(4)Where at any time (“the relevant time”) in any proceedings against a data controller under section 7(9), 10(4), 12(8) [F2, 12A(3)]or 14 or by virtue of section 13 the data controller claims, or it appears to the court, that any personal data to which the proceedings relate are being processed—

(a)only for the special purposes, and

(b)with a view to the publication by any person of any journalistic, literary or artistic material which, at the time twenty-four hours immediately before the relevant time, had not previously been published by the data controller,

the court shall stay the proceedings until either of the conditions in subsection (5) is met.

(5)Those conditions are—

(a)that a determination of the Commissioner under section 45 with respect to the data in question takes effect, or

(b)in a case where the proceedings were stayed on the making of a claim, that the claim is withdrawn.

(6)For the purposes of this Act “publish”, in relation to journalistic, literary or artistic material, means make available to the public or any section of the public.

Textual Amendments

F1S. 32(2)(dd) inserted (temp. from 1.3.2000 to 23.10.2007) by 1998 c. 29, s. 75(3), Sch. 13 para. 2(a); S.I. 2000/183, art. 2(1)

F2Words in s. 32(4) inserted (temp. from 1.3.2000 to 23.10.2007) by 1998 c. 29, s. 72, Sch. 13 para. 2(b); S.I. 2000/183, art. 2(1)

Commencement Information

I2S. 32 wholly in force at 1.3.2000; s. 32 in force for certain purposes at Royal Assent see s. 75(2)(i); s. 32 in force at 1.3.2000 insofar as not already in force by S.I. 2000/183, art. 2(1)

33 Research, history and statistics.U.K.

(1)In this section— “research purposes” includes statistical or historical purposes; “the relevant conditions”, in relation to any processing of personal data, means the conditions—

(a)that the data are not processed to support measures or decisions with respect to particular individuals, and

(b)that the data are not processed in such a way that substantial damage or substantial distress is, or is likely to be, caused to any data subject.

(2)For the purposes of the second data protection principle, the further processing of personal data only for research purposes in compliance with the relevant conditions is not to be regarded as incompatible with the purposes for which they were obtained.

(3)Personal data which are processed only for research purposes in compliance with the relevant conditions may, notwithstanding the fifth data protection principle, be kept indefinitely.

(4)Personal data which are processed only for research purposes are exempt from section 7 if—

(a)they are processed in compliance with the relevant conditions, and

(b)the results of the research or any resulting statistics are not made available in a form which identifies data subjects or any of them.

(5)For the purposes of subsections (2) to (4) personal data are not to be treated as processed otherwise than for research purposes merely because the data are disclosed—

(a)to any person, for research purposes only,

(b)to the data subject or a person acting on his behalf,

(c)at the request, or with the consent, of the data subject or a person acting on his behalf, or

(d)in circumstances in which the person making the disclosure has reasonable grounds for believing that the disclosure falls within paragraph (a), (b) or (c).

Valid from 01/01/2005

[F333A Manual data held by public authorities.U.K.

(1)Personal data falling within paragraph (e) of the definition of “data” in section 1(1) are exempt from—

(a)the first, second, third, fifth, seventh and eighth data protection principles,

(b)the sixth data protection principle except so far as it relates to the rights conferred on data subjects by sections 7 and 14,

(c)sections 10 to 12,

(d)section 13, except so far as it relates to damage caused by a contravention of section 7 or of the fourth data protection principle and to any distress which is also suffered by reason of that contravention,

(e)Part III, and

(f)section 55.

(2)Personal data which fall within paragraph (e) of the definition of “data” in section 1(1) and relate to appointments or removals, pay, discipline, superannuation or other personnel matters, in relation to—

(a)service in any of the armed forces of the Crown,

(b)service in any office or employment under the Crown or under any public authority, or

(c)service in any office or employment, or under any contract for services, in respect of which power to take action, or to determine or approve the action taken, in such matters is vested in Her Majesty, any Minister of the Crown, the National Assembly for Wales, any Northern Ireland Minister (within the meaning of the Freedom of Information Act 2000) or any public authority,

are also exempt from the remaining data protection principles and the remaining provisions of Part II.]

Textual Amendments

34 Information available to the public by or under enactment.U.K.

Personal data are exempt from—

(a)the subject information provisions,

(b)the fourth data protection principle and [F4sections 12A and 14(1) to (3).], and

(c)the non-disclosure provisions,

if the data consist of information which the data controller is obliged by or under any enactment to make available to the public, whether by publishing it, by making it available for inspection, or otherwise and whether gratuitously or on payment of a fee.

Textual Amendments

F4Words in s. 34(b) substituted (temp. from 1.3.2000 to 23.10.2007) by 1998 c. 29, s. 72, Sch. 13 para. 3; S.I. 2000/183, art. 2(1)

35 Disclosures required by law or made in connection with legal proceedings etc.U.K.

(1)Personal data are exempt from the non-disclosure provisions where the disclosure is required by or under any enactment, by any rule of law or by the order of a court.

(2)Personal data are exempt from the non-disclosure provisions where the disclosure is necessary—

(a)for the purpose of, or in connection with, any legal proceedings (including prospective legal proceedings), or

(b)for the purpose of obtaining legal advice,

or is otherwise necessary for the purposes of establishing, exercising or defending legal rights.

Valid from 01/01/2005

[F535A Parliamentary privilege.U.K.

Personal data are exempt from—

(a)the first data protection principle, except to the extent to which it requires compliance with the conditions in Schedules 2 and 3,

(b)the second, third, fourth and fifth data protection principles,

(c)section 7, and

(d)sections 10 and 14(1) to (3),

if the exemption is required for the purpose of avoiding an infringement of the privileges of either House of Parliament.]

Textual Amendments

36 Domestic purposes.U.K.

Personal data processed by an individual only for the purposes of that individual’s personal, family or household affairs (including recreational purposes) are exempt from the data protection principles and the provisions of Parts II and III.

37 Miscellaneous exemptions.U.K.

Schedule 7 (which confers further miscellaneous exemptions) has effect.

38 Powers to make further exemptions by order.U.K.

(1)The Secretary of State may by order exempt from the subject information provisions personal data consisting of information the disclosure of which is prohibited or restricted by or under any enactment if and to the extent that he considers it necessary for the safeguarding of the interests of the data subject or the rights and freedoms of any other individual that the prohibition or restriction ought to prevail over those provisions.

(2)The Secretary of State may by order exempt from the non-disclosure provisions any disclosures of personal data made in circumstances specified in the order, if he considers the exemption is necessary for the safeguarding of the interests of the data subject or the rights and freedoms of any other individual.

Commencement Information

I3S. 38 wholly in force at 1.3.2000; s. 38 in force for certain purposes at Royal Assent see s. 75(2)(i); s. 38 in force at 1.3.2000 insofar as not already in force by S.I. 2000/183, art. 2(1)

39 Transitional relief.U.K.

Schedule 8 (which confers transitional exemptions) has effect.

Back to top

Options/Help

Print Options

You have chosen to open The Whole Act

The Whole Act you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

You have chosen to open The Whole Act as a PDF

The Whole Act you have selected contains over 200 provisions and might take some time to download.

Would you like to continue?

You have chosen to open the Whole Act

The Whole Act you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.

Would you like to continue?

Close

Legislation is available in different versions:

Latest Available (revised):The latest available updated version of the legislation incorporating changes made by subsequent legislation and applied by our editorial team. Changes we have not yet applied to the text, can be found in the ‘Changes to Legislation’ area.

Original (As Enacted or Made): The original version of the legislation as it stood when it was enacted or made. No changes have been applied to the text.

Point in Time: This becomes available after navigating to view revised legislation as it stood at a certain point in time via Advanced Features > Show Timeline of Changes or via a point in time advanced search.

Close

See additional information alongside the content

Geographical Extent: Indicates the geographical area that this provision applies to. For further information see ‘Frequently Asked Questions’.

Show Timeline of Changes: See how this legislation has or could change over time. Turning this feature on will show extra navigation options to go to these specific points in time. Return to the latest available version by using the controls above in the What Version box.

Close

Opening Options

Different options to open legislation in order to view more content on screen at once

Close

More Resources

Access essential accompanying documents and information for this legislation item from this tab. Dependent on the legislation item being viewed this may include:

  • the original print PDF of the as enacted version that was used for the print copy
  • lists of changes made by and/or affecting this legislation item
  • confers power and blanket amendment details
  • all formats of all associated documents
  • correction slips
  • links to related legislation and further information resources
Close

Timeline of Changes

This timeline shows the different points in time where a change occurred. The dates will coincide with the earliest date on which the change (e.g an insertion, a repeal or a substitution) that was applied came into force. The first date in the timeline will usually be the earliest date when the provision came into force. In some cases the first date is 01/02/1991 (or for Northern Ireland legislation 01/01/2006). This date is our basedate. No versions before this date are available. For further information see the Editorial Practice Guide and Glossary under Help.

Close

More Resources

Use this menu to access essential accompanying documents and information for this legislation item. Dependent on the legislation item being viewed this may include:

  • the original print PDF of the as enacted version that was used for the print copy
  • correction slips

Click 'View More' or select 'More Resources' tab for additional information including:

  • lists of changes made by and/or affecting this legislation item
  • confers power and blanket amendment details
  • all formats of all associated documents
  • links to related legislation and further information resources