GDPR and data protection
Data protection support for regulated firms: UK GDPR obligations, records of processing, privacy information at the point of collection, and ICO registration.
⚠ UNSIGNED-OFF COPY. This page was written during the build so the section could exist and its routes could resolve. It makes no claim about outcomes, timescales, prices or the FCA’s decisions, but claim-free is not the same as signed off. Recorded at
docs/content-removals-for-review.md § 7.
Regulated firms handle personal data as a matter of course - customer records, credit information, and in many cases special category data. UK GDPR applies alongside the FCA’s rules rather than instead of them, and the two sets of obligations are assessed separately.
What the work covers
- Establishing the lawful basis for each processing activity, and recording it
- The record of processing activities required by Article 30
- Privacy information provided at the point of collection, as Article 13 requires
- Data subject rights, and a process that can answer a request inside the statutory period
- Retention periods, and deleting data when they expire
- Registration with the Information Commissioner’s Office
Where it meets the FCA’s rules
Record-keeping obligations under the two regimes do not always align - the FCA may require a record to be kept for a period that outlasts the purpose the data was collected for. That tension is resolved deliberately, in the retention schedule, rather than by whichever rule is remembered first.
Guidance on registration is published by the Information Commissioner’s Office (opens ico.org.uk in a new tab).
