Data producer support home page

The UK GDPR

Researchers must adhere to data protection requirements when managing or sharing personal data. The UK General Data Protection Regulation (GDPR) applies, if:

  • A researcher based in the UK collects personal data about people anywhere in the world.
  • A researcher outside the UK collects personal data on UK citizens.

Personal data is defined within the legislation as ‘any information relating to an identified or identifiable natural person’, whereby the person can be identified directly or indirectly.

It is important to remember that not all research data obtained from people count as personal data. If data are anonymised and an individual is no longer identifiable then the Act and Regulation will not apply, as the information no longer constitutes ‘personal data’. The Medical Research Council has produced clear guidance on identifiability, anonymisation and pseudonymisation.

The Data Protection Act 2018 (DPA) and the UK General Data Protection Regulation (UK GDPR) provide some exceptions for research data when the necessary safeguards are in place, and applies only to personal or special categories data, and not to all research data in general, nor to anonymised data.

When researchers are undertaking research projects, which span across the EU, then the General Data Protection Regulation (GDPR) will also need to be considered and adhered to. It will therefore be important for researchers to ensure that they gain local support from their university Data Protection Officer (DPO) when their research project will span across the EU. Please find out more about the main areas involved:

The UK GDPR and sharing data

The UK GDPR makes provisions for processing personal data for research and archiving purposes, so long as certain safeguards are in place such as technical and organisational measures, data minimisation, anonymisation and pseudonymisation.

Further processing of personal data, for the purposes of archiving, scientific, historical research and statistical collection, is not considered to be incompatible with the initial purposes of data collection, even when this purpose has not been expressly mentioned earlier. Also, in research, personal data may be stored for longer periods.

We provide here practical guidance, examples and question/answers on how to apply the UK GDPR in research:

The DPA and the UK GDPR define six principles that need to be complied with when processing personal data. All personal data must:

  1. Be processed lawfully, fairly and transparently.
  2. Be kept to the original purpose.
  3. Be minimised (i.e. only the personal data that is necessary is collected).
  4. Have the accuracy upheld.
  5. Be removed if they are not necessary.
  6. Be kept confidential and their integrity maintained.

Researchers will also need to have a lawful basis for processing personal data, of which there are six possible grounds:

  1. Consent of the data subject.
  2. Necessary for the performance of a contract.
  3. Legal obligation placed upon controller.
  4. Necessary to protect the vital interests of the data subject.
  5. Carried out in the public interest or is in the exercise of official authority.
  6. Legitimate interest pursued by controller.

Under the UK General Data Protection Regulation (UK GDPR), organisations must identify a lawful basis before collecting or processing personal data. There are six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Each basis reflects a different justification for processing data and must be appropriate to the context in which the data is used.

In practice, the most widely used lawful bases vary depending on the type of organisation. Public bodies, such as government departments and universities, commonly rely on the public task basis, as they process data to carry out official functions or tasks in the public interest. They may also rely on legal obligation where data processing is required by law.

In contrast, non-public bodies, including private companies and charities, often rely on legitimate interests, particularly where processing is necessary for their operational activities and does not override individuals’ rights. Consent is also used, especially in research or where individuals are given a clear choice about how their data is used. Additionally, contract is commonly applied where data processing is necessary to fulfil an agreement with an individual, such as providing a service.

Overall, selecting the correct lawful basis is essential, as it determines how personal data can be used, shared, and retained, and ensures that data processing remains fair, transparent, and compliant with UK GDPR requirements.

The UK GDPR specifies the rights a data subject has when their personal data are processed:

  • The right to be informed.
  • The right of access.
  • The right of rectification.
  • The right to erasure (the ‘right to be forgotten’).
  • The right to restrict processing.
  • The right to data portability.
  • The right to object.
  • Rights in relation to automated individual decision-making and profiling.

The rights that will be relevant to processing personal data for your research project will depend on the nature of the project; the chosen processing ground; and the country that the research takes place in.

EU Member States can apply certain ‘derogations’ (or exemptions) of data subjects’ rights, such as in relation to research and archiving. Researchers will therefore need to refer to national legislation, whilst consulting with their local DPO to identify which rights can be derogated locally.