UK GDPR
The UK text follows the EU one article for article for CCTV, with two differences worth knowing: transfers now run through Art. 44A (which replaced Art. 44) and Art. 45A (transfer regulations), and Schedule 1 of the Data Protection Act supplies the conditions some special category processing needs. The ICO guidance on video surveillance is named, not quoted.
- Where it is placed
- Placed for sites in the United Kingdom (England, Scotland, Wales and Northern Ireland).
- Date last read
- 29 Sep 2026
- Clauses cited
- 12 of 44 held
- The standard itself
- UK GDPR on compliance.theartofservice.com
- Places
- United Kingdom
Clauses cited, and the findings that cite them
| Clause | Title | Findings |
|---|---|---|
| UK GDPR Art. 5 | Principles relating to processing of personal data | 5, 10, 11, 14, 15 |
| UK GDPR Art. 6 | Lawfulness of processing | 9 |
| UK GDPR Art. 9 | Processing of special categories of personal data | 1, 16 |
| UK GDPR Art. 13 | Information to be provided where personal data are collected from the data subject | 6, 15 |
| UK GDPR Art. 26 | Joint controllers | 8 |
| UK GDPR Art. 28 | Processor | 8 |
| UK GDPR Art. 30 | Records of processing activities | 14 |
| UK GDPR Art. 32 | Security of processing | 13 |
| UK GDPR Art. 35 | Data protection impact assessment | 1, 4, 16 |
| UK GDPR Art. 44A | General principles for transfers | 7 |
| UK GDPR Art. 45A | Transfers under transfer regulations | 7 |
| UK GDPR Art. 46 | Transfers subject to appropriate safeguards | 7 |
UK GDPR Art. 5Principles relating to processing of personal dataArticle 5 Principles relating to processing of personal data. Personal data must be processed lawfully, fairly and transparently; collected, whether from the data subject or otherwise, for specified, explicit and legitimate purposes and not further processed by or for the controller in a way incompatible with the purposes for which the controller collected it (Article 8A decides compatibility); adequate, relevant and limited to what is necessary; accurate and kept up to date, with inaccurate data erased or rectified without delay; kept in identifiable form no longer than necessary, with longer storage only for archiving, research or statistics carried out under Article 84B; and secured against unauthorised or unlawful processing and accidental loss, destruction or damage. The controller is responsible for, and must be able to demonstrate, compliance (accountability). Article 5(3) adds that processing is not lawful merely because it is compatible with the original purpose: a lawful basis under Article 6 is still needed.
UK GDPR Art. 6Lawfulness of processingArticle 6 Lawfulness of processing. Processing is lawful only if at least one basis applies: consent for specific purposes, contract with the data subject, legal obligation, vital interests, a public task laid down in domestic law or relevant international law (section 9A of the 2018 Act), a recognised legitimate interest, or legitimate interests not overridden by the data subject's interests, rights and freedoms (particularly where the data subject is a child). Neither legitimate-interest basis is open to public authorities performing their tasks. A recognised legitimate interest (Article 6(1)(ea)) applies only where a condition in Annex 1 is met: disclosure on request to a body that states it needs the data for a public task, national security, public security or defence, responding to an emergency, detecting or preventing crime or prosecuting offenders, and safeguarding a vulnerable individual (under 18, or 18 or over and at risk); no balancing test is required for these. Article 6(11) gives direct marketing, intra-group transmission for internal administration and network and information security as examples of processing that may be necessary for legitimate interests, which still need the balancing test.
UK GDPR Art. 9Processing of special categories of personal dataArticle 9 Processing of special categories of personal data. Processing data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used to identify a person uniquely, health data, or data about sex life or sexual orientation is prohibited unless a lawful basis under Article 6 applies together with a condition in Article 9(2): explicit consent, employment, social security and social protection law, vital interests where consent is impossible, not-for-profit bodies' members, data manifestly made public, legal claims and courts, substantial public interest, health and social care, public health, or archiving, research and statistics under Article 84B. Where the condition needs a basis in domestic law, section 10 and Schedule 1 of the 2018 Act supply it (often with an appropriate policy document); health and social care processing must be by or under the responsibility of a professional bound by secrecy. Article 11A lets regulations add descriptions of processing to the prohibition and set which exceptions apply to them.
UK GDPR Art. 13Information to be provided where personal data are collected from the data subjectArticle 13 Information to be provided where personal data are collected from the data subject. At the time of collection the controller must give its identity and contact details (and any representative's), the data protection officer's contact details, the purposes and lawful basis, the legitimate interests where Article 6(1)(f) is relied on, the recipients, and any intended transfer abroad with whether transfer regulations under Article 45A cover it or which safeguards are relied on and how to get a copy. It must also give the retention period or criteria, the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw consent, the right to complain to the controller and to the Commissioner, whether provision of the data is required and the consequences of not providing it, and the existence of automated decision-making subject to Article 22C safeguards with meaningful information about the logic and consequences. Before further processing for a new purpose the data subject must be told of it, unless the further processing is for research, archiving or statistics under Article 84B and telling them is impossible or disproportionate, in which case the controller must protect their interests, including by publishing the information.
UK GDPR Art. 26Joint controllersArticle 26 Joint controllers. Joint controllers must determine their respective responsibilities, in particular for data subject rights and the information duties, by an arrangement that reflects their roles and relationships, may designate a contact point, and must make the essence of the arrangement available to data subjects, who may exercise their rights against each of them.
UK GDPR Art. 28ProcessorArticle 28 Processor. A controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.
UK GDPR Art. 30Records of processing activitiesArticle 30 Records of processing activities. Each controller (and representative) must keep a written, including electronic, record of its processing with its name and contacts, purposes, categories of data subjects and data, recipients, transfers abroad with Article 49(1) second-subparagraph safeguards documented, erasure time limits where possible, and a general description of security measures. Each processor must keep a record of the categories of processing it carries out for each controller, transfers and security measures. Records must be made available to the Commissioner on request. Organisations with fewer than 250 employees are exempt unless the processing is likely to result in a risk, is not occasional, or includes special category or criminal offence data.
UK GDPR Art. 32Security of processingArticle 32 Security of processing. Controllers and processors must implement technical and organisational measures ensuring security appropriate to the risk, taking into account the state of the art, costs, the nature and purposes of processing and the risks, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely way after an incident, and a process for regularly testing, assessing and evaluating the measures. The assessment must weigh the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Codes or certification may help demonstrate compliance, and anyone acting under the controller's or processor's authority must process data only on instructions.
UK GDPR Art. 35Data protection impact assessmentArticle 35 Data protection impact assessment. Before processing likely to result in a high risk, particularly with new technologies, the controller must assess the impact, seeking the DPO's advice. A DPIA is required in particular for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special category or criminal offence data, and large-scale systematic monitoring of public areas, and for the kinds of processing on the Commissioner's published list. The DPIA must contain a description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures to address them; approved codes are taken into account, data subjects' views sought where appropriate, and the assessment reviewed when the risk changes.
UK GDPR Art. 44AGeneral principles for transfersArticle 44A General principles for transfers. A controller or processor may transfer personal data to a third country or international organisation only if the transfer complies with the rest of the Regulation and is approved by transfer regulations under Article 45A in force at the time, is made subject to appropriate safeguards under Article 46, or relies on an Article 49 derogation; safeguards or derogations cannot be used where regulations under Article 49A restrict the transfer. This replaced Article 44 on 5 February 2026.
UK GDPR Art. 45ATransfers under transfer regulationsArticle 45A Transfers approved by regulations (with Articles 45B and 45C). The Secretary of State may approve transfers to a country, a sector or area within it, an international organisation or specified transfers by regulations, only where the data protection test is met: the protection for data subjects there, taken as a whole, is not materially lower than under the UK GDPR, Part 2 and Parts 5 to 7 of the 2018 Act, considering the rule of law and human rights, an enforcing authority, redress, onward transfer rules, international obligations and the country's constitution, traditions and culture. The Secretary of State must monitor developments, amend or revoke regulations when the test is no longer met, and publish lists of approved and formerly approved destinations. Adequacy regulations and retained adequacy decisions in force before 5 February 2026 are treated as made under Article 45A (Schedule 9 transitional provision). A controller relying on this route must check the destination and the transfer are covered by regulations in force at the time of transfer.
UK GDPR Art. 46Transfers subject to appropriate safeguardsArticle 46 Transfers subject to appropriate safeguards. A transfer is subject to appropriate safeguards only where safeguards are provided and the controller or processor, acting reasonably and proportionately, considers the data protection test met: after transfer the protection for the data subject, taken as a whole and considering the nature and volume of data, would not be materially lower than under the UK regime. Safeguards not needing the Commissioner's authorisation are a binding instrument between public bodies, binding corporate rules, standard data protection clauses specified by the Secretary of State in regulations or issued by the Commissioner under section 119A of the 2018 Act (such as the international data transfer agreement and addendum), and approved codes or certification with binding commitments; contractual clauses and administrative arrangements need the Commissioner's authorisation. Regulations under Article 47A may add further safeguards.