Statutory Duty and Data Processing for GDPR

In this article we explore how a statutory duty and data processing work together as set out in the General Data Protection Regulations (GDPR). Understanding the lawful bases for processing is paramount whatever lawful basis you are using. This article delves into the often nuanced yet powerful concept of statutory duty as a legal foundation for data processing.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

What Does the GDPR Say?

Article 6 of the GDPR says “Processing shall be lawful only if and to the extent that… processing is necessary for compliance with a legal obligation to which the controller is subject

What Does This Mean?

This means:

  • there must be a specific legal duty requiring you to process personal data

  • fulfilling a contract does not fall under this heading

  • the processing must be necessary. If you can comply without processing the personal information then you cannot rely on this lawful basis.

What is a Statutory Duty?

Statutory duty refers to obligations imposed by law. It becomes a compelling lawful basis when data processing is necessary to fulfill a legal requirement. This helps organisations with a robust framework for GDPR compliance.

Example

An example of a statutory duty relates to the world of employment.

Employers must by law:

  • ensure their employees are legally entitled to work in the UK

  • share salary information with HMRC for tax and benefits purposes

  • conduct various assessments for health and safety and other purposes

What is Necessary?

Necessary means you must process personal data in this way, because if you don’t you will not be able to achieve your objectives or comply with your statutory duties. Therefore it is not “necessary” to collect and process personal data for things you want to do.

legal requirement

 

Important Considerations:

While a statutory duty and data processing work together for GDPR purposes, the GDPR still requires organisations to:

  • Minimise data collection: Only collect the personal data necessary for fulfilling the legal obligation (learn more about data minimisation here).

  • Ensure data security: Implement appropriate technical and organisational measures to protect the collected data.

  • Respect individual rights: Individuals have the right to access, rectify, erase, or restrict the processing of their data. This applies even if collected under a statutory duty.

It’s crucial to remember that simply citing a statutory duty isn’t enough. Organisations must demonstrate the necessity and proportionality of the data processing for fulfilling the specific legal obligation and ensure they’re upholding individual rights and data protection principles.

By understanding these elements and applying them responsibly, organisations can leverage compliance with a statutory duty as a valid and transparent basis for data processing under the GDPR, contributing to a balance between societal objectives and individual data privacy.

Knowing your statutory duty

To successfully rely on a statutory duty and data processing you must be able to identify and explain the statutory duty or duties that apply to the proposed data processing.

This is important not only for compliance purposes. Because of legal requirements such as having a Record of Processing Activity or having a clear and accessible privacy statement you have to be able to clearly explain the statutory duty that is relevant so you can include it in both of these documents.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

People’s GDPR Rights

When organisations rely on compliance with a statutory duty as a lawful basis for processing personal data under the GDPR, individual rights under the regulation still apply, albeit with some nuances. Here’s how these rights work:

The Right of Access

  • Individuals have the right to access their personal data processed under a statutory duty, but the scope may be limited. Access might not extend to all data. This is because disclosing certain information could hinder the fulfillment of the legal obligation (e.g., ongoing criminal investigations).

The Right to Rectification

  • Individuals can still request rectification of inaccurate or incomplete personal data used for fulfilling the statutory duty. However, organisations need to consider the potential impact on fulfilling their legal obligation when responding to rectification requests.

The Right to Erasure

  • The right to erasure (right to be forgotten) may be limited or unavailable for data processed under a statutory duty. Erasing data could impede the organisation’s ability to comply with the relevant legal obligation, especially if the data is essential for recordkeeping or reporting purposes.

The Right to Restrict Processing

  • Individuals can still request restriction of processing for their personal data even under a statutory duty. This may be relevant if the individual disputes the accuracy of the data or objects to its processing for specific reasons. However, organisations need to assess the feasibility of restricting processing while still complying with their legal obligations.

The Right to Data Portability

  • The right to data portability typically doesn’t apply to data processed under a statutory duty. This right applies to data processed for business purposes or personal contracts.

Nuances and Considerations:

  • Organisations relying on a statutory duty basis should clarify these limitations in their privacy notices and explain how individual rights might be affected in specific situations.

  • Individuals exercising their rights should understand that limitations may apply within the context of statutory duties.

  • Data protection authorities and courts play a crucial role in balancing individual rights with the fulfillment of statutory duties, assessing limitations on a case-by-case basis.

So, while GDPR rights still apply under the statutory duty basis, they may be subject to limitations due to the organisation’s legal obligations. Transparency, proportionality, and careful consideration of individual rights are key principles to ensure a balanced approach when processing personal data under this lawful basis.

Further Examples

1. Tax Authorities:

  • Example: The tax authority collects personal income information from individuals and businesses to comply with tax laws and assess tax liabilities.

  • Justification: This processing is necessary for the fulfilment of a legal obligation (collecting taxes) and serves a legitimate public interest (funding public services).

2. Law Enforcement Agencies:

  • Example: Police may collect and process personal data of suspects and witnesses during investigations to comply with criminal code requirements for gathering evidence and protecting public safety.

  • Justification: This processing is necessary for the performance of a task carried out in the public interest (law enforcement) and complies with legal obligations laid out in criminal investigation procedures.

3. Healthcare Providers:

  • Example: Hospitals and clinics collect and process patient data like medical history and diagnoses to comply with healthcare regulations regarding recordkeeping and reporting of infectious diseases.

  • Justification: This processing is necessary for the fulfilment of a legal obligation (reporting infectious diseases) and is essential for public health protection.

4. Schools:

  • Example: Educational institutions collect and process student data such as attendance records and grades to comply with education regulations and reporting requirements.

  • Justification: This processing is necessary for the performance of a task carried out in the public interest (educating students) and complies with legal obligations regarding education reporting.

5. Data Protection Authorities:

  • Example: Data protection authorities collect and process personal data during investigations of data breaches or complaints to comply with regulations governing data protection enforcement.

  • Justification: This processing is necessary for the performance of a task carried out in the public interest (data protection enforcement) and complies with legal obligations regarding investigations and sanctions.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion

In conclusion, a statutory duty and data processing are a way of complying with the GDPR if you can identify and describe the statutory duty you are relying on. You must still only use the minimum necessary data and ensure appropriate information security. You also need to understand how people’s rights work if you are relying on a statutory duty as your lawful basis for data processing.