Apply to access ONS data
Data owned by the Office for National Statistics (ONS) include major government surveys, such as the Labour Force Survey and the Crime Survey for England and Wales, as well as business microdata, such as the Business Structure Database, 1997-2023: Secure Access and the Annual Survey of Hours and Earnings, 1997-2025: Secure Access.
The legal gateway for accessing these data in SecureLab is the Digital Economy Act, 2017 (DEA).
Projects accessing data under this gateway are accredited in accordance with the Research Code of Practice and Accreditation Criteria, which is overseen by the Research Accreditation Panel (RAP). The RAP ensures that research projects, researchers, and data processors meet the required standards for ethical and legal compliance.
Please download the application guidance (PDF) for accessing Controlled/Secure data under the Digital Economy Act 2017 (DEA), via our SecureLab environment.
Researcher requirements
- The purpose of the use of the data for your project must provide a public benefit/serve the public good.
- You must be able to meet all criteria for each dataset you are applying to access. The specific access criteria for each dataset can be found within its own data catalogue page (section ‘Access study data’).
- With the exception of some non-ONS datasets made available via our IDAN agreements, controlled datasets are only available to researchers who are both physically based in the UK and affiliated to a UK organisation that would take legal responsibility for their data access.
- PhD students must apply jointly with their supervisor(s). We recommend that any students studying for a qualification below PhD level should limit themselves to using open access or safeguarded datasetsfor their dissertations or other individual data work and plan their work around using these readily available data.
- You must complete Safe Researcher training and become an accredited researcher under the Digital Economy Act 2017 (DEA), before the project can be approved and access can be granted (it is recommended you apply for this as soon as possible to speed up the application).
System requirements
Connection to SecureLab can be made from either:
i) a device located at and owned by your institution
ii) a SafePod or SafePoint in the SafePod Network
ii) via our Safe Room located at the University of Essex.
Please view section 3.1 of our SecureLab user guide for the technical requirements you must comply with and the security measures which must be observed at all times.
Some projects may be eligible for homeworking access. Additional conditions and application procedures apply.
The use of personal devices for SecureLab access is strictly prohibited.
Project application
- Login/Register with the UK Data Service.
- Add the required Secure Access dataset(s) to your account, then follow the prompts to assign the dataset(s) to the relevant project.
- Within the project, click ‘Request access’ to display the steps to be completed.
- Click ‘Complete actions’; instructions and links to any forms that must be submitted will be displayed under each step.
- The Project Coordinator must download and complete the DEA Research Project Application.
Each team member (including the Project Coordinator) must download and complete the Secure Access User Agreement. If we already have a completed user agreement on record for you, this step will already be marked as complete. - The Project Coordinator must collect the completed documents and email them to secure.applications@ukdataservice.ac.uk referencing the Project ID in the email subject line.
Add team members to projects
Each team member must be registered with the UK Data Service. The Project Coordinator can then add each team member to the project. To do this the Project Coordinator should:
- Log into their UK Data Service account.
- Expand the Data section and then click on Projects.
- Click the relevant project title, where a number of tabs will be visible, e.g. Projects, Datasets, Members.
- Click Members, then New member.
- Enter the UK Data Service registered email address for the team member you want to add.
- Click Add member and their details will be shown in the ‘Project team invitations’ section of the screen. An invitation will automatically be sent.
- Each team member will receive an invitation email to ask whether they wish to be added to the project.
- Once a team member accepts the invitation to join the project, the Project Coordinator should check their details are correctly displayed in section ‘Project team members’.
Each project member will be able to see the project and associated datasets within their own account and should complete any individual actions required for each dataset. The Project Coordinator should collect the Secure Access User Agreements from all team members and email them together with the DEA Research Project Application to: secure.applications@ukdataservice.ac.uk.
Completing the Secure Access User Agreement
Before access is given to the SecureLab, each team member and a suitable delegated authority in their institution must sign our Secure Access User Agreement. The form can be downloaded under the step “Complete Secure Access User Agreement”.
What is the Secure Access User Agreement?
The User Agreement is a legally binding contract between you, your organisation and the University of Essex, which is the legal entity for the UK Data Service.
The User Agreement was written by the University of Essex’s legal team, so we are not a signatory party to the Agreement and we are unable to accept edited versions of the Agreement.
The Agreement outlines the terms and conditions of use of SecureLab and includes:
- Agreement that you will complete our training.
- Information about your security responsibilities, e.g. not sharing your password, nor disclosing or compromising any personal information.
- Information about penalties and breaches, set out in our Licence Compliance Policy.
- Our outputs release policy.
- Our citation and copyright requirements.
The Agreement is a per person, per organisation agreement. You therefore only need to complete it once whilst you are at your current institution — if you were to move organisation and still require access to SecureLab, then you would need to complete and submit a new agreement.
Whom should I ask to countersign the agreement at my organisation?
Your Agreement must be countersigned by an appropriate officer with the authority to sign on behalf of the organisation from which you will be accessing the UK Data Service SecureLab.
The signatory must be sufficiently senior within the organisation and authorised to accept legal responsibility for your data access on behalf of the entire organisation. By signing, they acknowledge and accept the rigour of the statements within the agreement, confirming their status as an authorised signatory.
We advise you to get in touch with your Research and Contracts Office, Legal and Contracts Department, or similar entity, to identify an authorised signatory for your organisation. Suitable signatories for the agreement typically include Head of Research Contracts, Director of Research, Head of Research Support, Contracts Director and the Head of Department.
Applying for DEA AR status
To access data made available for research under the Digital Economy Act 2017 (DEA), each team member must have DEA Accredited Researcher (AR) Status. This is administered by the Office for National Statistics (ONS).
Applications for AR Status must be made through the ONS Hub.
Completion of a Safe Researcher Training (SRT) course is required to gain AR Status.
The UK Data Service is a Safe Researcher Training (SRT) provider.
Completing Safe Researcher Training
The Safe Researcher Training (SRT) course covers.
- Data security and personal responsibility, including legal background, security model, breaches and penalties.
- Statistical Disclosure Control — how to make statistical outputs safe and what principles are used.
- Using the SecureLab (included in the SRT training provided by the UK Data Service) — how to use the interface and how to prepare and request data imports and suitable statistical outputs.
If you have not attended SRT you will be invited to book on one of our courses. We run these online approximately every three weeks.
If you have trained with another SRT provider within the past three years, then we will verify your attendance and you will be asked to complete a short Moodle course that covers the use of our SecureLab.
The SRT course we deliver is valid for DEA Accredited Researcher (AR) applications made via the ONS Hub. If you’re applying for DEA AR status and are attending training with us, then you can confirm your training date to the ONS and they will verify your attendance and successful pass with us, before issuing you with DEA AR status. DEA AR status is valid for a period of five years.
If you completed SURE researcher training with the UK Data Service before 1 January 2019 you will need to complete the SRT course as this is the most up-to-date and relevant SRT course to protect data privacy and required to access SecureLab.
If you have not logged into SecureLab for more than 2.5 years, you must complete a short online refresher course before accessing SecureLab again. Our Data Access team will invite you to complete this training.
Please view section 3.1 of our SecureLab user guide for the technical requirements you must comply with and the security measures which must be observed at all times.
You will agree to comply with the technical requirements via your Secure Access User Agreement.
Please speak to your IT department if you are unsure whether your device can meet our requirements.
During the initial screening stages of your application, you will be individually invited to complete technical checks.
If you are applying to connect to SecureLab from a device located at and owned by your institution, you will be asked to attach screenshots of the following:
- For Windows PCs – the output of running the command “ipconfig /all” in Command Prompt.
- For Mac/Linux – the output of running the command “ifconfig -a” in Terminal.
- The web page at What’s My IP.
Some projects may be eligible for homeworking access. Additional conditions and application procedures apply.
Following receipt of your application, our Access team will screen it as soon as possible. The team reviews your application for completeness while ensuring that all required documents have been received.
You will be assigned with an application handler who will support and guide you throughout the process.
The following actions will take place in parallel:
- The DEA Research Project Application form journey:
- Our User Support and Training team (UST) will conduct validity and methodology checks on your application, including what you intend to do with the data, whether your proposed use of the data is justified, and whether your project will deliver clear public benefit.
- Following the completion of those checks your application form will be sent to the UK Statistics Authority (UKSA) for Ethics checks and sign-off. You may be contacted directly by the UKSA for clarifications and potential updates on your application form.
- Next, your application will be sent to the data owners seeking their decision. The data owner/s may provide feedback and may require you to change/update your application.
- Once approvals from all data owners have been secured, your application will be sent to the UK Statistics Authority seeking final approval and accreditation of your research project under the Digital Economy Act 2017 (DEA). Minor or major revisions might be requested from the UKSA Research Accreditation Panel (RAP).
- Your training needs will be assessed and you will be invited to complete any required training course/s.
- Our Technical Team will set up your SecureLab project and contact each applicant separately to set up their SecureLab account and conduct device technical checks, when applicable.
Following project accreditation, and once all the above steps have been completed, each applicant will receive their own SecureLab account credentials enabling them to access this specific SecureLab project.
If the application is well prepared and approval is granted by the data owners with no changes required, you can expect to gain access to the data in approximately 3–4 months.