DPA Part 3 Codes: A UK Guide for Law Enforcement Data

The ICO has introduced DPA Part 3 codes for law enforcement data. Our guide explains what this means for UK businesses and public sector suppliers.

· GDPR Compliance

Navigating a New Era of Data Protection for Law Enforcement

The Information Commissioner’s Office (ICO) has announced a significant development in the UK’s data protection landscape, extending its framework for codes of conduct to cover data processed for law enforcement purposes. Previously a tool reserved for general processing under the UK GDPR, these voluntary accountability frameworks are now available to organisations governed by Part 3 of the Data Protection Act 2018 (DPA 2018). For small businesses, freelancers, and specialist contractors in the public sector supply chain, this is far more than a technical update. It signals a strategic shift towards sector-led standards, creating clear, practical rulebooks for handling some of the nation’s most sensitive information. This guide explains what the new DPA Part 3 codes are, who they affect, and why they represent a crucial opportunity for demonstrating compliance and building trust.

Demystifying the Legal Landscape: UK GDPR vs. DPA Part 3

Before exploring the new codes, it is essential to understand the jurisdictional distinction. The UK General Data Protection Regulation (UK GDPR) governs the majority of personal data processing that businesses handle daily—from customer databases and employee records to marketing communications. However, it does not apply when personal data is processed for “law enforcement purposes.”

This specific, high-stakes area is regulated by Part 3 of the DPA 2018. According to the Act, law enforcement purposes include the prevention, investigation, detection, or prosecution of criminal offences, as well as executing criminal penalties. This processing is carried out by “competent authorities,” which are bodies with statutory functions in these areas.

Examples of competent authorities include:

  • Police forces across the UK
  • The National Crime Agency
  • The Crown Prosecution Service
  • Government departments such as the Home Office and HMRC
  • Local authorities with powers to prosecute, for instance, in trading standards or environmental health cases

Think of it this way: the UK GDPR is the standard Highway Code that applies to all road users. DPA Part 3 is the specialised, advanced driver’s handbook for emergency services. Both rulebooks prioritise safety and responsibility, but the 'blue-light' services operate under different conditions, with specific powers and stricter limitations that do not apply to the everyday driver. Until now, only the “standard drivers” had access to ICO-approved codes of conduct. This update provides a tailored framework for the “emergency services” and those who support them. For a detailed overview, the ICO Guide to UK GDPR provides a baseline for general processing rules.

What Are DPA Part 3 Codes of Conduct?

At their core, DPA Part 3 codes are voluntary sets of rules designed to help organisations comply with the complex requirements of law enforcement data processing. The ICO’s updated guidance invites expert bodies—such as professional associations, regulatory agencies, and sector-specific groups—to develop and submit these codes for official approval.

An approved code of conduct serves several vital functions:

  • Tailors Compliance: It translates the dense, legalistic text of the DPA 2018 into practical, sector-specific actions. For example, a code for digital forensics providers could offer precise guidance on handling biometric data from seized devices.
  • Builds Public Trust: Adherence to an ICO-approved code demonstrates a clear commitment to the core data protection principles, such as lawfulness, fairness, and security. It shows that sensitive information is being handled with integrity.
  • Simplifies Complex Law: Codes can break down challenging obligations into clear checklists, workflows, and best practice examples, making compliance more accessible for non-lawyers.

Once a code is approved by the ICO and published on its register, organisations can choose to sign up. While membership is voluntary, the ICO must take it into account when considering enforcement action. This effectively creates a “safe harbour” for members, proving they have adopted a gold standard of data protection recognised by the regulator itself.

Why This Matters for Small Businesses and Freelancers

While the term “law enforcement data” might evoke images of major police operations, the reality is that a vast network of small businesses and specialist freelancers are integral to the public sector supply chain. If your organisation provides goods or services to a competent authority, you are often acting as a “data processor” on their behalf, and the rules of DPA Part 3 apply directly to your work.

Real-World Scenarios for SMEs and Sole Traders

Consider these examples:

  • An IT consultancy is contracted by a regional police force to analyse mobile phone data as part of a criminal investigation.
  • A software development company builds and maintains a case management system for a local council’s anti-fraud team.
  • A private investigation firm is hired by a government agency to gather evidence for a potential prosecution.
  • A transcription service is tasked with transcribing witness interviews for the Crown Prosecution Service.

In each case, the SME is a data processor handling highly sensitive personal data for law enforcement purposes. The risks of a data breach are significant, and the consequences—both reputational and financial—can be severe. This is where adhering to approved DPA Part 3 codes becomes a strategic advantage. It clarifies responsibilities and builds a foundation for secure collaboration. Understanding these dynamics is crucial, much like grasping the principles of UK GDPR data sharing when working with public sector partners.

The Benefits of Adherence

For a small business, aligning with a relevant code of conduct offers tangible benefits:

  1. Competitive Edge: Public bodies are under immense pressure to ensure their supply chain is secure and compliant. Being able to demonstrate adherence to an ICO-approved code makes your business a more attractive and trustworthy partner.
  2. Risk Mitigation: The codes will provide a clear, vetted framework for your operations, reducing the likelihood of accidental non-compliance or a data breach.
  3. Clarity and Confidence: Instead of interpreting complex legislation, your team can follow a practical, sector-specific rulebook, giving them the confidence to handle sensitive data correctly.

Practical Implications: Handling Data Subject Rights Under Part 3

One of the most challenging areas of data protection is managing individuals' rights, such as the right to access their data through a Data Subject Access Request (DSAR). Under DPA Part 3, these rights are not absolute and are subject to significant restrictions to avoid prejudicing law enforcement activities. This is a critical distinction from the UK GDPR framework.

The key differences include:

  • Exemptions to Access: A competent authority can refuse or restrict a DSAR if providing the information would be likely to prejudice the prevention, detection, investigation, or prosecution of criminal offences.
  • The “Neither Confirm Nor Deny” Response: In certain sensitive cases, an organisation may not even have to acknowledge whether it holds any data on the individual, if doing so would reveal a covert investigation or compromise intelligence sources.
  • Restrictions on Other Rights: The rights to erasure, rectification, and restriction of processing are also limited. For instance, data that forms part of an evidence log for an ongoing case cannot simply be deleted upon request.

Navigating these exemptions requires careful judgement and robust procedures. The new codes of conduct are expected to provide clear, step-by-step guidance on how to assess and respond to these requests lawfully, ensuring that both individual rights and the integrity of investigations are protected. This is supported by the broader legal framework laid out in the Data Protection Act 2018 itself.

A Proactive Approach: Getting Ready for the New Codes

With the ICO now inviting applications, it is time for organisations in the law enforcement ecosystem to be proactive. Whether you are a competent authority or a supplier, here are practical steps to take now.

Checklist for Your Organisation

  1. Identify Your Role: Formally clarify whether you are operating as a data controller (a competent authority) or a data processor under DPA Part 3 for any of your activities.
  2. Analyse Your Data Processing: Document all activities that involve handling personal data for law enforcement purposes. A Data Protection Impact Assessment (DPIA) is often a mandatory and invaluable tool for this type of high-risk processing.
  3. Engage with Your Sector Body: Identify the professional or trade associations relevant to your work. Enquire whether they are considering developing a DPA Part 3 code. Encourage them to do so, as it will benefit the entire sector.
  4. Review Contracts and Agreements: Examine your Data Processing Agreements (DPAs) with public sector clients to ensure they accurately reflect the requirements of DPA Part 3.

For many organisations, the first step is simply understanding their obligations beyond the standard UK GDPR. Our breakdown of the ICO's general compliance guidance can help clarify the baseline from which DPA Part 3 diverges.

Looking Ahead: A Future of Clarity and Trust

The introduction of DPA Part 3 codes marks a positive and pragmatic evolution in the UK’s data protection regime. It empowers sectors with deep expertise to create their own best practices, fostering a culture of accountability that goes beyond mere box-ticking. For small businesses and freelancers, these codes promise to demystify a complex area of law, reduce compliance burdens, and provide a clear path to becoming a trusted partner in the public sector.

As the ICO begins to approve and publish these codes, we will monitor developments closely. In the meantime, organisations should begin the internal work of understanding their role and advocating for clarity within their sectors. If you feel overwhelmed by these requirements or need expert guidance on your specific situation, specialist support is available. An on-call data protection helpdesk can provide the tailored advice needed to navigate these complex rules with confidence.