Home United Kingdom UK Parliament SI 2025/1128 - The Data Protection Act 2018 (Qualifying Comp...
Date: 2025-10-28 Category: Not Applicable State: Union Government Country: United Kingdom

SI 2025/1128 - The Data Protection Act 2018 (Qualifying Competent Authorities) Regulations 2025

Issued by UK Parliament · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task
Official Source Record View Original Source →
See Full Document Text
Status: This is the original version (as it was originally made). This item of legislation is currently only available in its original format. STATUTORY INSTRUMENTS 2025 No. 1128 DATA PROTECTION The Data Protection Act 2018 (Qualifying Competent Authorities) Regulations 2025 Made - - - - 27th October 2025 Coming into force - - 17th November 2025 The Secretary of State makes these Regulations in exercise of the powers conferred by section 82(2A) of the Data Protection Act 2018(1). In accordance with section 182(2) of that Act, the Secretary of State has consulted the Commissioner(2) and such other persons as the Secretary of State considers appropriate. In accordance with sections 82(4) and 182(7) of that Act(3), a draft of the Regulations has been laid before Parliament and approved by a resolution of each House of Parliament. Citation, commencement and extent 1.—(1) These Regulations may be cited as the Data Protection Act 2018 (Qualifying Competent Authorities) Regulations 2025. (2) These Regulations come into force on the twenty-first day after the day on which they are made. (3) These Regulations extend to England and Wales, Scotland and Northern Ireland. Qualifying competent authorities 2. The following competent authorities are qualifying competent authorities(4) for the purposes of the Data Protection Act 2018— (a) any United Kingdom government department other than a non-ministerial government department; (b) the chief constable of a police force maintained under section 2 of the Police Act 1996(5); (c) the Commissioner of Police of the Metropolis; (1) 2018 c. 12; subsection (2A) was inserted by the Data (Use and Access) Act 2025 (c. 18), section 89(2). (2) “The Commissioner” is defined in section 3 of the Data Protection Act 2018. (3) Subsection (4) was inserted by the Data (Use and Access) Act 2025, section 89(2)(d). (4) “Qualifying competent authority” is defined in section 82(2A) of the Data Protection Act 2018. (5) 1996 c. 16; section 2 was amended by the Police Reform and Social Responsibility Act 2011 (c. 13), Schedule 16, paragraph 4.Document Generated: 2025-11-17 Status: This is the original version (as it was originally made). This item of legislation is currently only available in its original format. (d) the Commissioner of Police for the City of London; (e) the Chief Constable of the Police Service of Northern Ireland; (f) the chief constable of the Police Service of Scotland; (g) the chief constable of the British Transport Police; (h) the chief constable of the Civil Nuclear Constabulary; (i) the chief constable of the Ministry of Defence Police; (j) the Provost Marshal of the Royal Navy Police; (k) the Provost Marshal of the Royal Military Police; (l) the Provost Marshal of the Royal Air Force Police; (m) the Provost Marshal for serious crime; (n) the chief officer of— (i)a body of constables appointed under provision incorporating section 79 of the Harbours, Docks and Piers Clauses Act 1847(6); (ii)a body of constables appointed under an order made under section 14 of the Harbours Act 1964(7); (iii)the body of constables appointed under section 154 of the Port of London Act 1968(8); (o) a body established in accordance with a collaboration agreement under section 22A of the Police Act 1996(9); (p) the Commissioners for His Majesty’s Revenue and Customs; (q) the Director General of the National Crime Agency; (r) His Majesty’s Land Registry; (s) the Parole Board for England and Wales; (t) the Parole Board for Scotland; (u) the Parole Commissioners for Northern Ireland; (v) the Probation Board for Northern Ireland; (w) a person who is, under or by virtue of any enactment, responsible for securing the electronic monitoring of an individual. Sarah Jones Minister of State 27th October 2025 Home Office (6) 1847 c. 27. (7) 1964 c. 40; section 14 was amended by the Planning Act 2008 (c. 29), Schedule 2, paragraph 9; the Transport and Works Act 1992 (c. 42), Schedule 3, paragraph 1; the Transport Act 1981 (c. 56), section 40 and Schedule 6, paragraphs 2, 3, 4 and 14 and Schedule 12 (Part 2); the Criminal Justice Act 1982 (c. 48), section 46; the Criminal Procedure (Scotland) Act 1975 (c. 21), section 289G (as inserted by section 54 of the Criminal Justice Act 1982 (c. 48)); S.I. 2006/1177 and S.I. 2009/1941. (8) 1968 c. 32; section 154 was amended by the Criminal Justice Act 1972 (c. 71), Schedule 6 (Part 1). (9) Section 22A was inserted by the Police Reform and Social Responsibility Act 2011 (c. 13), section 89(1) and (2), and was amended by the Policing and Crime Act 2017 (c. 3), section 157(1), (2)(a) and (2)(b). 2Document Generated: 2025-11-17 Status: This is the original version (as it was originally made). This item of legislation is currently only available in its original format. EXPLANATORY NOTE (This note is not part of the Regulations) Sections 89 and 90 of the Data (Use and Access) Act (c. 18) (“the DUAA”) amend the Data Protection Act 2018 (c. 12) (“the DPA”) to enable joint processing between qualifying competent authorities and intelligence services, under Part 4 of the DPA. This enables the controllers, previously unable to process jointly, to process personal data within a single, common regime. The controls and safeguards under Part 4 of the DPA will apply to all such joint processing. Section 89(2) of the DUAA amends section 82 of the DPA, widening the scope of Part 4 of the DPA. Previously, Part 4 of the DPA only applied to processing by or on behalf of the intelligence services. As amended, section 82 also applies Part 4 of the DPA to the processing of personal data by a qualifying competent authority where the processing is the subject of a designation notice. Section 89(2) of the DUAA inserts new subsection (2A) into section 82 of the DPA, which grants a power to the Secretary of State to make regulations to specify and describe which competent authorities (as defined in section 30 of the DPA) are “qualifying competent authorities”, and so able to apply for or be issued with a designation notice. These Regulations specify and describe which competent authorities are “qualifying competent authorities” for the purposes of the DPA. The qualifying competent authorities will be able to apply jointly with the intelligence services for a designation notice under section 82A of the DPA. The Secretary of State may give a notice designating processing of personal data by a qualifying competent authority where this is required for the purposes of safeguarding national security, and subject to compliance with application requirements in the DPA. Before making these Regulations, the Secretary of State consulted the Commissioner and such other persons as the Secretary of State considers appropriate. A full impact assessment has not been produced for this instrument as no, or no significant, impact on the private, voluntary or public sector is foreseen. 3

Continue your research