In this article we explore how a statutory duty and data processing work together as set out in the General Data Protection Regulations (GDPR). Understanding the lawful bases for processing is paramount whatever lawful basis you are using. This article delves into the often nuanced yet powerful concept of statutory duty as a legal foundation for data processing.
Contents
What Does the GDPR Say?
Article 6 of the GDPR says “Processing shall be lawful only if and to the extent that… processing is necessary for compliance with a legal obligation to which the controller is subject”
What Does This Mean?
This means:
-
there must be a specific legal duty requiring you to process personal data
-
fulfilling a contract does not fall under this heading
-
the processing must be necessary. If you can comply without processing the personal information then you cannot rely on this lawful basis.
What is a Statutory Duty?
Statutory duty refers to obligations imposed by law. It becomes a compelling lawful basis when data processing is necessary to fulfill a legal requirement. This helps organisations with a robust framework for GDPR compliance.
Example
An example of a statutory duty relates to the world of employment.
Employers must by law:
-
ensure their employees are legally entitled to work in the UK
-
share salary information with HMRC for tax and benefits purposes
-
conduct various assessments for health and safety and other purposes
What is Necessary?
Necessary means you must process personal data in this way, because if you don’t you will not be able to achieve your objectives or comply with your statutory duties. Therefore it is not “necessary” to collect and process personal data for things you want to do.

Important Considerations:
While a statutory duty and data processing work together for GDPR purposes, the GDPR still requires organisations to:
-
Minimise data collection: Only collect the personal data necessary for fulfilling the legal obligation (learn more about data minimisation here).
-
Ensure data security: Implement appropriate technical and organisational measures to protect the collected data.
-
Respect individual rights: Individuals have the right to access, rectify, erase, or restrict the processing of their data. This applies even if collected under a statutory duty.
It’s crucial to remember that simply citing a statutory duty isn’t enough. Organisations must demonstrate the necessity and proportionality of the data processing for fulfilling the specific legal obligation and ensure they’re upholding individual rights and data protection principles.
By understanding these elements and applying them responsibly, organisations can leverage compliance with a statutory duty as a valid and transparent basis for data processing under the GDPR, contributing to a balance between societal objectives and individual data privacy.
Knowing your statutory duty
To successfully rely on a statutory duty and data processing you must be able to identify and explain the statutory duty or duties that apply to the proposed data processing.
This is important not only for compliance purposes. Because of legal requirements such as having a Record of Processing Activity or having a clear and accessible privacy statement you have to be able to clearly explain the statutory duty that is relevant so you can include it in both of these documents.
Sign Up Here:
Sign Up Here:
When organisations rely on compliance with a statutory duty as a lawful basis for processing personal data under the GDPR, individual rights under the regulation still apply, albeit with some nuances. Here’s how these rights work: Individuals have the right to access their personal data processed under a statutory duty, but the scope may be limited. Access might not extend to all data. This is because disclosing certain information could hinder the fulfillment of the legal obligation (e.g., ongoing criminal investigations). Individuals can still request rectification of inaccurate or incomplete personal data used for fulfilling the statutory duty. However, organisations need to consider the potential impact on fulfilling their legal obligation when responding to rectification requests. The right to erasure (right to be forgotten) may be limited or unavailable for data processed under a statutory duty. Erasing data could impede the organisation’s ability to comply with the relevant legal obligation, especially if the data is essential for recordkeeping or reporting purposes. Individuals can still request restriction of processing for their personal data even under a statutory duty. This may be relevant if the individual disputes the accuracy of the data or objects to its processing for specific reasons. However, organisations need to assess the feasibility of restricting processing while still complying with their legal obligations. The right to data portability typically doesn’t apply to data processed under a statutory duty. This right applies to data processed for business purposes or personal contracts. Nuances and Considerations: Organisations relying on a statutory duty basis should clarify these limitations in their privacy notices and explain how individual rights might be affected in specific situations. Individuals exercising their rights should understand that limitations may apply within the context of statutory duties. Data protection authorities and courts play a crucial role in balancing individual rights with the fulfillment of statutory duties, assessing limitations on a case-by-case basis. So, while GDPR rights still apply under the statutory duty basis, they may be subject to limitations due to the organisation’s legal obligations. Transparency, proportionality, and careful consideration of individual rights are key principles to ensure a balanced approach when processing personal data under this lawful basis. 1. Tax Authorities: Example: The tax authority collects personal income information from individuals and businesses to comply with tax laws and assess tax liabilities. Justification: This processing is necessary for the fulfilment of a legal obligation (collecting taxes) and serves a legitimate public interest (funding public services). 2. Law Enforcement Agencies: Example: Police may collect and process personal data of suspects and witnesses during investigations to comply with criminal code requirements for gathering evidence and protecting public safety. Justification: This processing is necessary for the performance of a task carried out in the public interest (law enforcement) and complies with legal obligations laid out in criminal investigation procedures. 3. Healthcare Providers: Example: Hospitals and clinics collect and process patient data like medical history and diagnoses to comply with healthcare regulations regarding recordkeeping and reporting of infectious diseases. Justification: This processing is necessary for the fulfilment of a legal obligation (reporting infectious diseases) and is essential for public health protection. 4. Schools: Example: Educational institutions collect and process student data such as attendance records and grades to comply with education regulations and reporting requirements. Justification: This processing is necessary for the performance of a task carried out in the public interest (educating students) and complies with legal obligations regarding education reporting. 5. Data Protection Authorities: Example: Data protection authorities collect and process personal data during investigations of data breaches or complaints to comply with regulations governing data protection enforcement. Justification: This processing is necessary for the performance of a task carried out in the public interest (data protection enforcement) and complies with legal obligations regarding investigations and sanctions. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
In conclusion, a statutory duty and data processing are a way of complying with the GDPR if you can identify and describe the statutory duty you are relying on. You must still only use the minimum necessary data and ensure appropriate information security. You also need to understand how people’s rights work if you are relying on a statutory duty as your lawful basis for data processing.People’s GDPR Rights
The Right of Access
The Right to Rectification
The Right to Erasure
The Right to Restrict Processing
The Right to Data Portability
Further Examples
Conclusion
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: