lexiara

Schedule 2, Part 1, paragraph 2

DPA 2018
Data Protection Act 2018 · United Kingdom

The listed GDPR provisions and Article 34(1) and (4) of the UK GDPR (communication of personal data breach to the data subject) do not apply to personal data processed for any of the following purposes— to the extent that the application of those provisions would be likely to prejudice any of the matters mentioned in paragraphs (a) to (c). the prevention , investigation or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of a tax or duty or an imposition of a similar nature, Sub-paragraph (3) applies where— personal data is processed by a person (“Controller 1”) for any of the purposes mentioned in sub-paragraph (1)(a) to (c), and another person (“Controller 2”) obtains the data from Controller 1 for the purpose of discharging statutory functions and processes it for the purpose of discharging statutory functions. Controller 2 is exempt from the obligations in the following provisions of the UK GDPR— to the same extent that Controller 1 is exempt from those obligations by virtue of sub-paragraph (1). Article 13(1) to (3) (personal data collected from data subject: information to be provided), Article 14(1) to (4) (personal data collected other than from data subject: information to be provided), Article 15(1) to (3) (confirmation of processing, access to data and safeguards for third country transfers), and Article 5 (general principles) so far as its provisions correspond to the rights and obligations provided for in the provisions mentioned in paragraphs (a) to (c),

· All articles ·

Source: legislation.gov.uk · retrieved 2026-09-04