Register of data controllers explained

The register of data controllers was a United Kingdom database under the control of the UK Information Commissioner's Office (ICO) mandated by section 19 of the Data Protection Act 1998.[1]

The register of fee payers is the name of an equivalent register established under the Data Protection Act 2018, which implements the European Union's General Data Protection Regulation (GDPR).

Registration under either Act carries a fee, the proceeds of which fund the costs of the ICO. Any entry may be inspected by the public at any time at no cost to the enquirer.

Data Protection Act 1998

Under the 1998 Act, the name of the data controller was recorded [2] with the purpose(s) for the processing of the data processed by that controller within the meaning of the Act.[3] [4] [5]

The 1998 Act established a distinction between data controllers and data processors, to whom distinct legal and governance obligations applied:[6] data controllers determined the purposes for which personal data was held or processed, whereas data process data on behalf of another data controller.

A data controller may, under some circumstances, be exempt from registration (previously termed notification).[7] When not exempt,[8] failure to notify the Information Commissioner's Office formally before the start of processing data was a strict liability offence for which a prosecution may be brought by the Information Commissioner's Office in the criminal court of the UK.[9] Failure to notify was a criminal offence unless exempt. Exemption from registration does not exempt a data controller from compliance with The Act.

Amendments to a data controller's notification could be made at any time, and must have been made before the start of a new processing purpose.

Data Protection Act 2018

Under the 2018 Act, the register is called the register of fee payers, and the purposes for processing are nor supplied, though other trading names and the name of a Data Protection Officer may be given.[10] [11] The distinction between data controllers and data processors remains in place.[12] the ICO reports that there are over one million registered fee payers.

The enforcement of the Act by the Information Commissioner's Office is supported by a data protection charge on UK data controllers under the Data Protection (Charges and Information) Regulations 2018. Exemptions from the charge were left broadly the same as for 1998 Act: largely some businesses and non-profits internal core purposes (staff or members, marketing and accounting), household affairs, some public purposes, and non-automated processing.[13] [14] Under the 2018 Act, the enforcement regime for registration changed from criminal to civil monetary penalties.[15]

See also

External links

Notes and References

  1. UK Legislation, Data Protection Act 1998, accessed 15 January 2024
  2. Web site: Data Protection Act 1998 - Part 1, Basic Interpretive Provisions - Section 1 . . 2009-11-18 . 'data controller' means, subject to subsection (4), a person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed;.
  3. Web site: Register of data controllers . UK Information Commissioner's Office. https://web.archive.org/web/20150317044857/https://ico.org.uk/about-the-ico/what-we-do/register-of-data-controllers/. 17 March 2015 . 2015-07-16 . We publish the name and address of these data controllers, as well as a description of the kind of processing they do..
  4. Web site: Register of Data Controllers. The Advertising Protection Agency. 22 March 2012. The ICO then publishes certain details from the registration data in the register of data controllers which is available to the public for inspection.. dead. https://web.archive.org/web/20110107040423/http://www.theadvertisingprotectionagency.co.uk/register-of-data-controllers.php. 7 January 2011.
  5. Web site: Notifying the Information Commissioner's Office about personal information . Business Link. 22 March 2012. The Data Protection Act 1998 requires businesses to give details about the way they process personal information to the Information Commissioner's Office (ICO) for inclusion in a public register, unless they are exempt. This is called notification..
  6. Information Commissioner's Office, Data controllers and data processors: what the difference is and what the governance implications are, published 2014, archived on 16 May 2015, accessed on 15 July 2024
  7. Web site: Register (notify) under the Data Protection Act . . 2015-07-16 . The Data Protection Act 1998 requires every data controller (eg organisation, sole trader) who is processing personal information to register with the ICO, unless they are exempt..
  8. Web site: In brief – are there any exemptions from the Data Protection Act? . . 16 July 2015 . https://web.archive.org/web/20150716235000/https://ico.org.uk/for-organisations/guide-to-data-protection/exemptions/ . 16 July 2015 . ... there are some exemptions from the Act to accommodate special circumstances. .
  9. Web site: Register of Data Controllers - University of Strathclyde. University of Strathclyde. 22 March 2012. Every organisation that processes, i.e. holds and uses, personal information must be registered with the UK Information Commissioner's Office (ICO), unless they are exempt. This registration is a statutory requirement under the Data Protection Act and failure to notify the ICO is a criminal offence..
  10. Web site: Register of fee payers . Information Commissioner’s Office . 1 May 2020.
  11. Web site: Add a Data Protection Officer . Information Commissioner’s Office . 1 May 2020.
  12. Web site: A guide to controllers and processors. Information Commissioner’s Office. 19 May 2023 . 15 July 2024.
  13. Review of exemptions from paying charges to the Information Commissioner's Office . Department for Digital, Culture, Media and Sport . November 2018 . 30 April 2020.
  14. Web site: The Data Protection (Charges and Information) Regulations 2018 - Schedule Exempt Processing . legislation.gov.uk . 30 April 2020.
  15. Web site: ICO issues the first fines to organisations that have not paid the data protection fee . Information Commissioner’s Office . 28 November 2018 . 1 May 2020.