GDPR and data protection

Data protection support for regulated firms: UK GDPR obligations, records of processing, privacy information at the point of collection, and ICO registration.

⚠ UNSIGNED-OFF COPY. This page was written during the build so the section could exist and its routes could resolve. It makes no claim about outcomes, timescales, prices or the FCA’s decisions, but claim-free is not the same as signed off. Recorded at docs/content-removals-for-review.md § 7.

Regulated firms handle personal data as a matter of course - customer records, credit information, and in many cases special category data. UK GDPR applies alongside the FCA’s rules rather than instead of them, and the two sets of obligations are assessed separately.

What the work covers

  • Establishing the lawful basis for each processing activity, and recording it
  • The record of processing activities required by Article 30
  • Privacy information provided at the point of collection, as Article 13 requires
  • Data subject rights, and a process that can answer a request inside the statutory period
  • Retention periods, and deleting data when they expire
  • Registration with the Information Commissioner’s Office

Where it meets the FCA’s rules

Record-keeping obligations under the two regimes do not always align - the FCA may require a record to be kept for a period that outlasts the purpose the data was collected for. That tension is resolved deliberately, in the retention schedule, rather than by whichever rule is remembered first.

Guidance on registration is published by the Information Commissioner’s Office (opens ico.org.uk in a new tab).

Interested in seeing how The Compliance Guys
can help your business?

Talk to us