The Privacy and Electronic Communications (EC Directive) Regulations 2003

Type Statutory-Instrument
Publication 2003-09-18
Last updated 2026-02-05
State In force
Department King's Printer of Acts of Parliament
PDF Download
articles Not indexed
Reform history JSON API

[^key-af0225b65dc292cdddb8de6c1f840b94]: Words in reg. 4(1) substituted (25.5.2018) by Data Protection Act 2018 (c. 12), s. 212(1), Sch. 19 para. 293(3) (with ss. 117, 209, 210); S.I. 2018/625, reg. 2(1)(g)

[^key-16bb4404680541ba58679cd9fff8d108]: Reg. 21A inserted (8.9.2018) by Financial Guidance and Claims Act 2018 (c. 10), ss. 35(3), 37(5); S.I. 2018/987, reg. 3 (with reg. 4)

[^key-e0aea672fcc4cc7be105178ec3bdfbc2]: Reg. 21(6) inserted (8.9.2018) by Financial Guidance and Claims Act 2018 (c. 10), ss. 35(2), 37(5); S.I. 2018/987, reg. 3 (with reg. 4)

[^key-9f6a59a7e5f7465b82d2920d87811a9d]: Words in reg. 24 heading substituted (8.9.2018) by Financial Guidance and Claims Act 2018 (c. 10), ss. 35(4)(a), 37(5); S.I. 2018/987, reg. 3 (with reg. 4)

[^key-88e59bcaa55811a569ca0f5222845a70]: Words in reg. 24(1)(b) inserted (8.9.2018) by Financial Guidance and Claims Act 2018 (c. 10), ss. 35(4)(b), 37(5); S.I. 2018/987, reg. 3 (with reg. 4)

[^key-02a88eedc8044c31ba2ff93fe4714488]: Reg. 21B inserted (9.1.2019) by The Privacy and Electronic Communications (Amendment) (No. 2) Regulations 2018 (S.I. 2018/1396), regs. 1(1), 2(3)

[^key-d507fcffc6f01de9bacaf46c061870af]: Words in reg. 21(6) inserted (9.1.2019) by The Privacy and Electronic Communications (Amendment) (No. 2) Regulations 2018 (S.I. 2018/1396), regs. 1(1), 2(2)

[^key-b9217a3f7ccbe2845e12cccb814046db]: Words in reg. 2(1) inserted (29.3.2019) by The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (S.I. 2019/419), regs. 1(3), 8(2)

[^key-5b0c788aad1e1da1443735b7d08f6b1a]: Reg. 2(3) omitted (29.3.2019) by virtue of The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (S.I. 2019/419), regs. 1(3), 8(3)

[^key-79a21c42880d342de51329113378ee84]: Words in reg. 2(1) substituted (31.12.2020) by The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (S.I. 2019/419), reg. 1(2), Sch. 3 para. 44 (with Sch. 3 para. 112); 2020 c. 1, Sch. 5 para. 1(1)

[^key-230110403505145df068de153232a7c5]: Words in reg. 37(1)(a) substituted (31.12.2020) by The Electronic Communications (Amendment etc.) (EU Exit) Regulations 2019 (S.I. 2019/919), regs. 1(2), 3(2); 2020 c. 1, Sch. 5 para. 1(1)

[^key-b973136ef3c0db84c8f670988986d41f]: Reg. 37(1A) inserted (31.12.2020) by The Electronic Communications (Amendment etc.) (EU Exit) Regulations 2019 (S.I. 2019/919), regs. 1(2), 3(3); 2020 c. 1, Sch. 5 para. 1(1)

[^key-95e86f52b81b7a7f4009c56468251953]: Reg. 37(2) omitted (31.12.2020) by virtue of The Electronic Communications (Amendment etc.) (EU Exit) Regulations 2019 (S.I. 2019/919), regs. 1(2), 3(4); 2020 c. 1, Sch. 5 para. 1(1)

[^key-03a29d68871ecb7d80048525a1ac8bd5]: Words in reg. 37(3)(a) substituted (31.12.2020) by The Electronic Communications (Amendment etc.) (EU Exit) Regulations 2019 (S.I. 2019/919), regs. 1(2), 3(5); 2020 c. 1, Sch. 5 para. 1(1)

[^key-2c04e8381f80510a535ca2f5d139615c]: Reg. 5A(9) omitted (14.10.2024) by virtue of Investigatory Powers (Amendment) Act 2024 (c. 9), ss. 11(5), 32(2); S.I. 2024/1021, reg. 2(k)

[^key-fbfdc8ec5b3e560ffb7225019c68adab]: Words in reg. 2(1) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 110(2)(c), 142(1); S.I. 2025/904, reg. 2(o)

[^key-f0896d15680c41737bd83ddf9f7fb84c]: Words in reg. 2(4) omitted (20.8.2025) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 110(4), 142(1); S.I. 2025/904, reg. 2(o)

[^key-0802beb41839471e10002b267b13d48e]: Reg. 2(5)(6) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 110(5), 142(1); S.I. 2025/904, reg. 2(o)

[^key-8b48e333790ae72d37365998d50bbd93]: Reg. 5A(3A) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 111(1)(b), 142(1); S.I. 2025/904, reg. 2(p)

[^key-9d08189889299b4c476ad2742acb569d]: Words in reg. 5A(2) inserted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 111(1)(a), 142(1); S.I. 2025/904, reg. 2(p)

[^key-62dc25ea55c1d3106214efc8f7281b2e]: Words in reg. 5C(4)(f) substituted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 111(2)(a), 142(1); S.I. 2025/904, reg. 2(p)

[^key-40e547b4ce5894471a3c773fcd4365cf]: Words in reg. 5C(5) substituted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 111(2)(b), 142(1); S.I. 2025/904, reg. 2(p)

[^key-afafd76bbe92bff2344551bf1f270117]: Words in reg. 16A(6) substituted (20.8.2025) by Data (Use and Access) Act 2025 (c. 18), ss. 113, 142(1); S.I. 2025/904, reg. 2(q)

[^key-4c13753483d5f0c3f06e5a6a23603c28]: Reg. 5C(12)-(16) inserted (19.6.2025 for specified purposes, 5.2.2026 in so far as not already in force) by Data (Use and Access) Act 2025 (c. 18), ss. 115(4)(b), 142(1)(2)(h) (with s. 115(10)); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-056820daafcc3aad9384cf1d7366c6d6]: Reg. 6A inserted (19.6.2025 for specified purposes, 5.2.2026 in so far as not already in force) by Data (Use and Access) Act 2025 (c. 18), ss. 112(3), 142(1)(2)(h) (with s. 112(5)); S.I. 2026/82, reg. 2(w)

[^key-42c4aebc5561617e52b6780dc006a1e8]: Regs. 32A-32C inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 116(2), 142(1); S.I. 2026/82, reg. 2(z)

[^key-2841fad1c010fc13a24c29174ebafb4b]: Sch. 1 substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 13; S.I. 2026/82, reg. 2(z14) (with regs. 8-11)

[^key-f3b3860f8f5a09ed4b3de5bede25c6c4]: Sch. A1 inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), s. 142(1), Sch. 12; S.I. 2026/82, reg. 2(z13)

[^key-d129e415bf9082bd139ed205c32bf800]: Word in reg. 2(1) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 110(2)(b)(ii), 142(1); S.I. 2026/82, reg. 2(v)

[^key-66265a2992241a9d83a76b71a765e4fe]: Reg. 2(1A) inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 110(3), 142(1); S.I. 2026/82, reg. 2(v)

[^key-013b80b8e3507184e0f27fcba811e749]: Words in reg. 2(1) inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 110(2)(a), 142(1); S.I. 2026/82, reg. 2(v)

[^key-343eb8c295a659d08709880c9bea56cb]: Words in reg. 2(1) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 110(2)(b)(i), 142(1); S.I. 2026/82, reg. 2(v)

[^key-f42927312b00de62ffcdae49f4e20501]: Reg. 5(6) omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 115(2), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-109b2b9a1e7db4fcebb0d90435812bc8]: Reg. 5B omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 115(3), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-251f53803b1755084f7a4e645c7059b1]: Words in reg. 5C(10) omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 115(4)(a)(i), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-95bc9d7c3947881cf248b080eb9755c5]: Words in reg. 5C(10)(a) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 115(4)(a)(ii), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-de2c41298eff18b7ebd8317797f7540f]: Reg. 6 substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 112(2), 142(1); S.I. 2026/82, reg. 2(w)

[^key-4608e19055bf06fa849812fd3e793ab9]: Reg. 22(3A) inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 114(3), 142(1); S.I. 2026/82, reg. 2(x)

[^key-0fe821e4fcc6a9cf5135f7c16854c221]: Reg. 22(5) inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 114(4), 142(1); S.I. 2026/82, reg. 2(x)

[^key-063a3b81926e5a05988540690bf5557a]: Words in reg. 22(2) inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 114(2), 142(1); S.I. 2026/82, reg. 2(x)

[^key-87449cdabe61a222473cbae6dd81a69a]: Reg. 31 substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 115(5), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-942610872263c91f10436a924a09d706]: Reg. 31A omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 115(6), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-ef28ec159cdcb0984e2d88e082416432]: Reg. 31B omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 115(7), 142(1); S.I. 2026/82, reg. 2(y) (with regs. 8-11)

[^key-fa3cb5d61e0fc7947b323a23242a8a99]: Words in reg. 33 omitted (5.2.2026) by virtue of Data (Use and Access) Act 2025 (c. 18), ss. 116(3)(a), 142(1); S.I. 2026/82, reg. 2(z)

[^key-d4ab97f6a0efb29fae7cb13d3947f1d6]: Words in reg. 33 inserted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 116(3)(b), 142(1); S.I. 2026/82, reg. 2(z)

[^key-e556dce58280ee73ae4977fe64306362]: Words in Sch. 1 para. 18(b)(ii) substituted (5.2.2026) by Data (Use and Access) Act 2025 (c. 18), ss. 116(4), 142(1); S.I. 2026/82, reg. 2(z)

Personal data breach

5A
  • (1) In this regulation and in regulations 5B and 5C, “service provider” has the meaning given in regulation 5(1).
  • (2) If a personal data breach occurs, the service provider shall, without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify that breach to the Information Commissioner.
  • (3) Subject to paragraph (6), if a personal data breach is likely to adversely affect the personal data or privacy of a subscriber or user, the service provider shall also, without undue delay, notify that breach to the subscriber or user concerned.
  • (3A) Where notification under paragraph (2) is not made within 72 hours, it must be accompanied by reasons for the delay.
  • (4) The notification referred to in paragraph (2) shall contain at least a description of—
  • (a) the nature of the breach;
  • (b) the consequences of the breach; and
  • (c) the measures taken or proposed to be taken by the provider to address the breach.
  • (5) The notification referred to the paragraph (3) shall contain at least—
  • (a) a description of the nature of the breach;
  • (b) information about contact points within the service provider’s organisation from which more information may be obtained; and
  • (c) recommendations of measures to allow the subscriber to mitigate the possible adverse impacts of the breach.
  • (6) The notification referred to in paragraph (3) is not required if the service provider has demonstrated, to the satisfaction of the Information Commissioner that—
  • (a) it has implemented appropriate technological protection measures which render the data unintelligible to any person who is not authorised to access it, and
  • (b) that those measures were applied to the data concerned in that breach.
  • (7) If the service provider has not notified the subscriber or user in compliance with paragraph (3), the Information Commissioner may, having considered the likely adverse effects of the breach, require it to do so.
  • (8) Service providers shall maintain an inventory of personal data breaches comprising —
  • (a) the facts surrounding the breach,
  • (b) the effects of that breach, and
  • (c) remedial action taken

which shall be sufficient to enable the Information Commissioner to verify compliance with the provisions of this regulation. The inventory shall only include information necessary for this purpose.

  • (9) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Personal data breach: audit

5B

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Personal data breach: enforcement

5C
  • (1) If a service provider fails to comply with the notification requirements of regulation 5A, the Information Commissioner may issue a fixed monetary penalty notice in respect of that failure.
  • (2) The amount of a fixed monetary penalty under this regulation shall be £1,000.
  • (3) Before serving such a notice, the Information Commissioner must serve the service provider with a notice of intent.
  • (4) The notice of intent must—
  • (a) state the name and address of the service provider;
  • (b) state the nature of the breach;
  • (c) indicate the amount of the fixed monetary penalty;
  • (d) include a statement informing the service provider of the opportunity to discharge liability for the fixed monetary penalty;
  • (e) indicate the date on which the Information Commissioner proposes to serve the fixed monetary penalty notice; and
  • (f) inform the service provider that he may make written representations in relation to the proposal to serve a fixed monetary penalty notice within the period of 21 days beginning when the notice of intent is served.
  • (5) A service provider may discharge liability for the fixed monetary penalty if he pays to the Information Commissioner the amount of £800 within the period of 21 days beginning when the notice of intent is received.
  • (6) The Information Commissioner may not serve a fixed monetary penalty notice until the time within which representations may be made has expired.
  • (7) The fixed monetary penalty notice must state—
  • (a) the name and address of the service provider;
  • (b) details of the notice of intent served on the service provider;
  • (c) whether there have been any written representations;
  • (d) details of any early payment discounts;
  • (e) the grounds on which the Information Commissioner imposes the fixed monetary penalty;
  • (f) the date by which the fixed monetary penalty is to be paid; and
  • (g) details of, including the time limit for, the service provider’s right of appeal against the imposition of the fixed monetary penalty.
  • (8) A service provider on whom a fixed monetary penalty is served may appeal to the Tribunal against the issue of the fixed monetary penalty notice.
  • (9) Any sum received by the Information Commissioner by virtue of this regulation must be paid into the Consolidated Fund.
  • (10) In England and Wales ..., the penalty is recoverable—
  • (a) if the county court so orders, as if it were payable under an order of that court;
  • (b) if the High Court so orders, as if it were payable under an order of that court.
  • (11) In Scotland, the penalty may be enforced in the same manner as an extract registered decree arbitral bearing a warrant for execution issued by the sheriff court of any sheriffdom in Scotland.
  • (12) In Northern Ireland, the penalty is recoverable—
  • (a) if a county court so orders, as if it were payable under an order of that court;
  • (b) if the High Court so orders, as if it were payable under an order of that court.
  • (13) The Secretary of State may by regulations made by statutory instrument amend this regulation so as to substitute a different amount for the amount for the time being specified in paragraph (2) or (5).
  • (14) Regulations under paragraph (13) may make transitional provision.
  • (15) Before making regulations under paragraph (13), the Secretary of State must consult—
  • (a) the Information Commissioner, and
  • (b) such other persons as the Secretary of State considers appropriate.
  • (16) A statutory instrument containing regulations under this regulation may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament.

Confidentiality of communications

Restrictions on the processing of certain traffic data

Further provisions relating to the processing of traffic data under regulation 7

Itemised billing and privacy

Prevention of calling line identification – outgoing calls

Prevention of calling or connected line identification – incoming calls

Publication of information for the purposes of regulations 10 and 11

Co-operation of communications providers for the purposes of regulations 10 and 11

Restrictions on the processing of location data

Tracing of malicious or nuisance calls

Emergency calls

Termination of automatic call forwarding

Directories of subscribers

Use of automated calling systems

Use of facsimile machines for direct marketing purposes

Unsolicited calls for direct marketing purposes

Use of electronic mail for direct marketing purposes

Use of electronic mail for direct marketing purposes

Information to be provided for the purposes of regulations 19, 20 and 21

Register to be kept for the purposes of regulation 20

Register to be kept for the purposes of regulation 20

Modification of contracts

National security

29A
  • (1) Where regulations 28 and 29 apply, communications providers must establish and maintain internal procedures for responding to requests for access to users’ personal data.
  • (2) Communications providers shall on demand provide the Information Commissioner with information about—
  • (a) those procedures;
  • (b) the number of requests received;
  • (c) the legal justification for the request; and
  • (d) the communications provider’s response.

Proceedings for compensation for failure to comply with requirements of the Regulations

Enforcement – extension of Part V of the Data Protection Act 1998

Enforcement: third party information notices

31A

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Enforcement: appeals

31B

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Request that the Commissioner exercise his enforcement functions

Technical advice to the Commissioner

Amendment to the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000

Amendment to the Electronic Communications (Universal Service) Order 2003

Transitional provisions

Review of implementation

37
  • (1) Before the end of each review period, the Secretary of State must—
  • (a) carry out a review of the implementing provisions;
  • (b) set out the conclusions of the review in a report; and
  • (c) publish the report.
  • (1A) “The implementing provisions” means the provisions contained in or made under an Act that were relied on by the United Kingdom immediately before exit day to implement the Directive, so far as those provisions remain in force.
  • (2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
  • (3) The report must in particular—
  • (a) set out the objectives intended to be achieved by the implementing provisions;
  • (b) assess the extent to which those objectives are achieved; and
  • (c) assess whether those objectives remain appropriate and, if so, the extent to which they could be achieved with a system that imposes less regulation.
  • (4) “Review period” means—
  • (a) the period of five years beginning with the 26th May 2011; and
  • (b) subject to paragraph (5), each successive period of 5 years.
  • (5) If a report under this regulation is published before the last day of the review period to which it relates, the following review period is to being with the day on which that report is published.
2A

Sections 41A to 41C shall be omitted.

8A

Except where paragraph 8AA applies, in section 55A—

  • (a) in subsection (1)—
  • (i) for “data controller” there shall be substituted “person”, and
  • (ii) for “of section 4(4) by the data controller” there shall be substituted “of the requirements of the Privacy and Electronic Communications (EC Directive) Regulations 2003”;
  • (b) in subsection (3), for “data controller” there shall be substituted “person”;
  • (c) subsection (3A) shall be omitted;
  • (d) in subsection (4), for “data controller” there shall be substituted “person”;
  • (e) in subsection (9), the definition of “data controller” shall be omitted.
8B

In section 55B, for the words “data controller” (in subsections (1), (3) and (4)), there shall be substituted the word “person”.

10A

In paragraph 2(1A) of Schedule 9 for “assessment notice” there shall be substituted “audit notice”.

Emergency alerts

16A
  • (1) A relevant public communications provider (P) may, for the purpose of providing an emergency alert service, disregard the restrictions on the processing of data relating to users or subscribers set out in paragraph (2) if the conditions set out in paragraph (3) are met.
  • (2) The restrictions are—
  • (a) the restrictions on the processing of traffic data under regulations 7(1) and 8(2); and
  • (b) the restrictions on the processing of location data under regulations 14(2) and 14(5).
  • (3) The conditions are—
  • (a) P is notified by a relevant public authority that—
  • (i) an emergency within the meaning of section 1(1) of the Civil Contingencies Act 2004 has occurred, is occurring or is about to occur; and
  • (ii) it is expedient to use an emergency alert service;
  • (b) P is directed by the relevant public authority to convey a specified communication over a specified time period to users or subscribers of P’s public electronic communications network whom P considers—
  • (i) are in one or more specified places in the United Kingdom which is or may be affected by the emergency; or
  • (ii) have been in a specified place affected by the emergency since the emergency occurred but are no longer in the place; and
  • (c) P complies with that direction.
  • (4) P may, for the purpose of testing an emergency alert service, disregard the restrictions on the processing of data relating to users or subscribers set out in paragraph (2) if the conditions set out in paragraph (5) are met.
  • (5) The conditions are—
  • (a) P is notified by a Minister of the Crown that, in the Minister’s opinion, it is necessary to test an emergency alert service for the purpose of ensuring that the service is maintained in good working order and is an effective means of communicating with users and subscribers in an emergency;
  • (b) the Minister gives directions as to how the test is to be conducted; and
  • (c) P complies with the directions in sub-paragraph (b).
  • (6) Traffic data or location data which relate to users or subscribers of a public electronic communications network and are processed in accordance with this regulation must, within the period of 7 days beginning with the day on which the time period specified by the relevant public authority pursuant to paragraph (3)(b) expires or, as the case may be, within 48 hours of receipt of the Minister’s directions pursuant to paragraph (5)(b), be—
  • (a) erased; or
  • (b)
  • (i) in the case of an individual, modified so that they cease to constitute personal data of that user or subscriber; or
  • (ii) in the case of a corporate subscriber, modified so that they cease to be data that would be personal data if that user or subscriber was an individual.
  • (7) The processing of traffic data or location data in accordance with this regulation shall be carried out only by P or by a person acting under P’s authority.
  • (8) For the purposes of this regulation—
  • (a) “emergency alert service” means a service comprising one or more communications to mobile telecommunications devices over a public electronic communications network to warn, advise or inform users or subscribers in relation to an aspect or effect of an emergency which may affect or have affected them by reason of their location;
  • (b) “relevant public authority” means—
  • (i) a Minister of the Crown;
  • (ii) the Scottish Ministers;
  • (iii) the Welsh Ministers;
  • (iv) a Northern Ireland department;
  • (v) a chief officer of police within the meaning of section 101(1) of the Police Act 1996;
  • (vi) the chief constable of the Police Service of Scotland;
  • (vii) the chief constable of the Police Service of Northern Ireland;
  • (viii) the chief constable of the British Transport Police Force;
  • (ix) the Environment Agency;
  • (x) the Scottish Environment Protection Agency;
  • (xi) the Natural Resources Body for Wales;
  • (c) “relevant public communications provider” means a person who—
  • (i) provides a public electronic communications network;
  • (ii) provides cellular mobile electronic communications services; and
  • (iii) holds a wireless telegraphy licence granted under section 8 of the Wireless Telegraphy Act 2006.

Termination of automatic call forwarding

Directories of subscribers

Use of automated calling systems

Use of facsimile machines for direct marketing purposes

Unsolicited calls for direct marketing purposes

Use of electronic mail for direct marketing purposes

Information to be provided for the purposes of regulations 19, 20 and 21

Register to be kept for the purposes of regulation 20

Modification of contracts

National security

Proceedings for compensation for failure to comply with requirements of the Regulations

Enforcement – extension of Part V of the Data Protection Act 1998

Enforcement: third party information notices

Enforcement: appeals

Request that the Commissioner exercise his enforcement functions

Technical advice to the Commissioner

Amendment to the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000

Amendment to the Electronic Communications (Universal Service) Order 2003

Transitional provisions

Review of implementation

8AA

In section 55A, when applied to regulations 19 to 24 of these Regulations—

  • (a) in subsection (1)—
  • (i) for “data controller” there shall be substituted “person”;
  • (ii) in paragraph (a), for “of section 4(4) by the data controller” there shall be substituted “of the requirements of the Privacy and Electronic Communications (EC Directive) Regulations 2003, and”; and
  • (iii) for paragraphs (b) and (c) there shall be substituted—

(b) subsection (2) or (3) applies.

  • (b) in subsection (3)—
  • (i) for “data controller” there shall be substituted “person”; and
  • (ii) for paragraph (a) substitute—

(a) knew or ought to have known that there was a risk that the contravention would occur, but

  • (c) subsection (3A) shall be omitted;
  • (ca) before subsection (4) there shall be inserted the following subsections—

(3B) If a monetary penalty notice has been served under this section on a body, the Commissioner may also serve a monetary penalty notice on an officer of the body if the Commissioner is satisfied that the contravention in respect of which the monetary penalty notice was served on the body— (a) took place with the consent or connivance of the officer, or (b) was attributable to any neglect on the part of the officer. (3C) In subsection (3B)— - “body” means a body corporate or a Scottish partnership; - “officer” in relation to a body means—in relation to a body corporate—a director, manager, secretary or other similar officer of the body or any person purporting to act in such capacity, orwhere the affairs of the body are managed by its members, a member; orin relation to a Scottish partnership, a partner or any person purporting to act as a partner.

  • (d) in subsection (4), for “data controller” there shall be substituted “person on whom it is served”; and
  • (e) in subsection (9), the definition of “data controller” shall be omitted.
8C

In section 55E, for the words “data controller” in subsection (2), there shall be substituted the word “person”.

Calls for direct marketing purposes

Calls for direct marketing of claims management services

21A
  • (1) A person must not use, or instigate the use of, a public electronic communications service to make unsolicited calls for the purposes of direct marketing in relation to claims management services except in the circumstances referred to in paragraph (2).
  • (2) Those circumstances are where the called line is that of a subscriber who has previously notified the caller that for the time being the subscriber consents to such calls being made by, or at the instigation of, the caller on that line.
  • (3) A subscriber must not permit the subscriber's line to be used in contravention of paragraph (1).
  • (4) In this regulation, “claims management services” means the following services in relation to the making of a claim—
  • (a) advice;
  • (b) financial services or assistance;
  • (c) acting on behalf of, or representing, a person;
  • (d) the referral or introduction of one person to another;
  • (e) the making of inquiries.
  • (5) In paragraph (4), “claim” means a claim for compensation, restitution, repayment or any other remedy or relief in respect of loss or damage or in respect of an obligation, whether the claim is made or could be made—
  • (a) by way of legal proceedings,
  • (b) in accordance with a scheme of regulation (whether voluntary or compulsory), or
  • (c) in pursuance of a voluntary undertaking.

Use of electronic mail for direct marketing purposes

Information to be provided for the purposes of regulations 19 to 21A

Register to be kept for the purposes of regulation 20

Modification of contracts

National security

Proceedings for compensation for failure to comply with requirements of the Regulations

Enforcement – extension of Part V of the Data Protection Act 1998

Enforcement: third party information notices

Enforcement: appeals

Request that the Commissioner exercise his enforcement functions

Technical advice to the Commissioner

Amendment to the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000

Amendment to the Electronic Communications (Universal Service) Order 2003

Transitional provisions

Review of implementation

Modifications of the Data Protection Act 1998

Modifications of secondary legislation

Modification of the Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010

12
  • (1) Section 150 has effect as if subsection (3) were omitted.
  • (2) In that section, subsection (2) has effect as if the words “in reliance on section 149(2)” were omitted.

Modification of the Data Protection (Monetary Penalties) Order 2010

13

Section 152 has effect as if subsections (1), (2) and (4) were omitted.

Calls for direct marketing in relation to pension schemes

21B
  • (1) A person must not use, or instigate the use of, a public electronic communications service to make unsolicited calls to an individual for the purpose of direct marketing in relation to occupational pension schemes or personal pension schemes, except where paragraph (2) or (3) applies.
  • (2) This paragraph applies where—
  • (a) the caller is an authorised person or a person who is the trustee or manager of an occupational pension scheme or a personal pension scheme; and
  • (b) the called line is that of an individual who has previously notified the caller that for the time being the individual consents to such calls being made by the caller on that line.
  • (3) This paragraph applies where—
  • (a) the caller is an authorised person or a person who is the trustee or manager of an occupational pension scheme or a personal pension scheme;
  • (b) the recipient of the call has an existing client relationship with the caller on the line and the relationship is such that the recipient might reasonably envisage receiving unsolicited calls for the purpose of direct marketing in relation to occupational pension schemes or personal pension schemes; and
  • (c) the recipient of the call has been given a simple means of refusing (free of charge except for the costs of the transmission of the refusal) the use of the recipient’s contact details for the purpose of such direct marketing, at the time that the details were initially collected and, where the recipient did not initially refuse the use of the details, at the time of each subsequent communication.
  • (4) A subscriber must not permit the subscriber’s line to be used in contravention of paragraph (1).
  • (5) In this regulation—
  • (a) “authorised person” has the meaning given in section 31 of the Financial Services and Markets Act 2000;
  • (b) “direct marketing in relation to occupational pension schemes or personal pension schemes” includes—
  • (i) the marketing of a product or service to be acquired using funds held, or previously held, in an occupational pension scheme or a personal pension scheme,
  • (ii) the offer of any advice or other service that promotes, or promotes the consideration of, the withdrawal or transfer of funds from an occupational pension scheme or a personal pension scheme, and
  • (iii) the offer of any advice or other service to enable the assessment of the performance of an occupational pension scheme or a personal pension scheme (including its performance in comparison with other forms of investment);
  • (c) “existing client relationship” does not include a relationship established at the instigation of the caller primarily for the purpose of avoiding the restriction in paragraph (1); and
  • (d) “occupational pension scheme” and “personal pension scheme” have the meanings given in section 1(1) of the Pension Schemes Act 1993.

Use of electronic mail for direct marketing purposes

Information to be provided for the purposes of regulations 19 to 21A

Register to be kept for the purposes of regulation 20

Modification of contracts

National security

Proceedings for compensation for failure to comply with requirements of the Regulations

Enforcement – extension of Part V of the Data Protection Act 1998

Enforcement: third party information notices

Enforcement: appeals

Request that the Commissioner exercise his enforcement functions

Technical advice to the Commissioner

Amendment to the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000

Amendment to the Electronic Communications (Universal Service) Order 2003

Transitional provisions

Review of implementation

Power to provide exceptions to regulation 6(1)

6A
  • (1) The Secretary of State may by regulations made by statutory instrument—
  • (a) amend these Regulations—
  • (i) by adding an exception to the prohibition in regulation 6(1), or
  • (ii) by omitting or varying an exception to that prohibition, and
  • (b) make consequential, supplementary, incidental, transitional, transitory or saving provision, including provision amending these Regulations.
  • (2) Regulations under paragraph (1) may make different provision for different purposes.
  • (3) Before making regulations under paragraph (1), the Secretary of State must consult—
  • (a) the Information Commissioner, and
  • (b) such other persons as the Secretary of State considers appropriate.
  • (4) A statutory instrument containing regulations under paragraph (1) may not be made unless a draft of the instrument has been laid before, and approved by a resolution of, each House of Parliament.

Restrictions on the processing of certain traffic data

Further provisions relating to the processing of traffic data under regulation 7

Itemised billing and privacy

Prevention of calling line identification – outgoing calls

Prevention of calling or connected line identification – incoming calls

Publication of information for the purposes of regulations 10 and 11

Co-operation of communications providers for the purposes of regulations 10 and 11

Restrictions on the processing of location data

Tracing of malicious or nuisance calls

Emergency calls

Emergency alerts

Termination of automatic call forwarding

Directories of subscribers

Use of automated calling systems

Use of facsimile machines for direct marketing purposes

Calls for direct marketing purposes

Calls for direct marketing of claims management services

Calls for direct marketing in relation to pension schemes

Use of electronic mail for direct marketing purposes where the identity or address of the sender is concealed

Information to be provided for the purposes of regulations 19 to 21A

Register to be kept for the purposes of regulation 21

Modification of contracts

National security

Proceedings for compensation for failure to comply with requirements of the Regulations

Enforcement – extension of Part V of the Data Protection Act 1998

Enforcement: third party information notices

Enforcement: appeals

Request that the Commissioner exercise his enforcement functions

Technical advice to the Commissioner

Amendment to the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000

Amendment to the Electronic Communications (Universal Service) Order 2003

Transitional provisions

Review of implementation

Storing information in the terminal equipment of a subscriber or user

Information Commissioner’s enforcement powers

Codes of conduct

32A
  • (1) The Commissioner must encourage representative bodies to produce codes of conduct intended to contribute to compliance with these Regulations.
  • (2) Under paragraph (1), the Commissioner must encourage representative bodies to produce codes which take account of, among other things, the specific features of different sectors.
  • (3) A code of conduct described in paragraph (1) may, for example, make provision with regard to—
  • (a) rights and obligations under these Regulations;
  • (b) out-of-court proceedings and other dispute resolution procedures for resolving disputes arising in connection with these Regulations.
  • (4) The Commissioner must encourage representative bodies to submit codes of conduct described in paragraph (1) to the Commissioner in draft.
  • (5) Where a representative body does so, the Commissioner must—
  • (a) provide the representative body with an opinion on whether the code correctly reflects the requirements of these Regulations,
  • (b) decide whether to approve the code, and
  • (c) if the code is approved, register and publish the code.
  • (6) The Commissioner may only approve a code if, among other things—
  • (a) the code contains a mechanism for monitoring whether persons who undertake to apply the code comply with its provisions, and
  • (b) in relation to persons other than public bodies, the mechanism involves monitoring by a body which is accredited for that purpose by the Commissioner under regulation 32B.
  • (7) In relation to amendments of a code of conduct that is for the time being approved under this regulation—
  • (a) paragraphs (4) and (5) apply as they apply in relation to a code, and
  • (b) the requirements in paragraph (6) must be satisfied by the code as amended.
  • (8) A code of conduct described in paragraph (1) may be contained in the same document as a code of conduct described in Article 40 of the UK GDPR (and a provision contained in such a document may be a provision of both codes).
  • (9) In this regulation—
  • public body” has the meaning given in section 7 of the Data Protection Act 2018 (for the purposes of the UK GDPR);
  • representative body” means an association or other body representing categories of—communications providers, orother persons engaged in activities regulated by these Regulations;
  • the UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018.

Accreditation of bodies monitoring compliance with codes of conduct

32B
  • (1) The Commissioner may, in accordance with this regulation, accredit a body for the purpose of monitoring whether persons other than public bodies comply with a code of conduct described in regulation 32A(1).
  • (2) The Commissioner may accredit a body only where the Commissioner is satisfied that the body has—
  • (a) demonstrated its independence,
  • (b) demonstrated that it has an appropriate level of expertise in relation to the subject matter of the code,
  • (c) established procedures which allow it—
  • (i) to assess a person’s eligibility to apply the code,
  • (ii) to monitor compliance with the code, and
  • (iii) to review the operation of the code periodically,
  • (d) established procedures and structures to handle complaints about infringements of the code or about the manner in which the code has been, or is being, implemented by a person,
  • (e) made arrangements to publish information about the procedures and structures described in sub-paragraph (d), and
  • (f) demonstrated that it does not have a conflict of interest.
  • (3) The Commissioner must prepare and publish guidance about how the Commissioner proposes to take decisions about accreditation under this regulation.
  • (4) A body accredited under this regulation in relation to a code must take appropriate action where a person infringes the code.
  • (5) If the action taken by a body under paragraph (4) consists of suspending or excluding a person from the code, the body must inform the Commissioner, giving reasons for taking that action.
  • (6) The Commissioner must revoke the accreditation of a body under this regulation if the Commissioner considers that the body—
  • (a) no longer meets the requirements for accreditation, or
  • (b) has failed, or is failing, to comply with paragraph (4) or (5).
  • (7) In this regulation, “public body” has the same meaning as in regulation 32A.

Effect of codes of conduct

32C

Adherence to a code of conduct approved under regulation 32A may be used by a person as a means of demonstrating compliance with these Regulations.

Technical advice to the Commissioner

Amendment to the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000

Amendment to the Electronic Communications (Universal Service) Order 2003

Transitional provisions

Review of implementation

Schedule A1 — Storing information in the terminal equipment of a subscriber or user

Interpretation

1
  • (1) In this Schedule, “website” includes a mobile application and any other platform by means of which an information society service is provided.
  • (2) For further provision about the interpretation of this Schedule, see regulation 6(2).
2
  • (1) Regulation 6(1) does not prevent a person storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user if the subscriber or user—
  • (a) is provided with clear and comprehensive information about the purpose of the storage or access, and
  • (b) gives consent to the storage or access.
  • (2) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user for the same purpose on more than one occasion, it is sufficient that the requirements of sub-paragraph (1) are met in respect of the initial use.
  • (3) For the purposes of sub-paragraph (1)(b), the means by which the subscriber or user may signify consent include—
  • (a) amending or setting controls on the internet browser which the subscriber or user uses;
  • (b) using another application or programme.

Transmission of a communication over an electronic communications network

3

Regulation 6(1) does not apply to—

  • (a) technical storage of information in the terminal equipment of a subscriber or user, or
  • (b) technical access to information stored in such equipment,

for the sole purpose of carrying out the transmission of a communication over an electronic communications network.

Storage or access strictly necessary to provide an information society service

4
  • (1) Regulation 6(1) does not apply to—
  • (a) technical storage of information in the terminal equipment of a subscriber or user, or
  • (b) technical access to information stored in such equipment,

where the storage or access is strictly necessary for the provision of an information society service requested by the subscriber or user.

  • (2) For the purposes of this paragraph, the technical storage of, or technical access to, information is strictly necessary for the provision of an information society service requested by the subscriber or user if, for example, the storage or access is strictly necessary—
  • (a) to protect information provided in connection with, or relating to, the provision of the service requested,
  • (b) to ensure that the security of the terminal equipment of the subscriber or user is not adversely affected by the provision of the service requested,
  • (c) to prevent or detect fraud in connection with the provision of the service requested,
  • (d) to prevent or detect technical faults in connection with the provision of the service requested, or
  • (e) to enable either of the following things to be done where necessary for the provision of the service requested—
  • (i) automatically authenticating the identity of the subscriber or user, or
  • (ii) maintaining a record of selections made on a website, or information put into a website, by the subscriber or user.

Collecting information for statistical purposes

5
  • (1) Regulation 6(1) does not prevent a person storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user if—
  • (a) the person provides an information society service,
  • (b) the sole purpose of the storage or access is to enable the person—
  • (i) to collect information for statistical purposes about how the service is used with a view to making improvements to the service, or
  • (ii) to collect information for statistical purposes about how a website by means of which the service is provided is used with a view to making improvements to the website,
  • (c) any information that the storage or access enables the person to collect is not shared with any other person except for the purpose of enabling that other person to assist with making improvements to the service or website,
  • (d) the subscriber or user is provided with clear and comprehensive information about the purpose of the storage or access, and
  • (e) the subscriber or user is given a simple means of objecting, free of charge, to the storage or access and does not object.
  • (2) In sub-paragraph (1), the reference to gaining access to information stored in the terminal equipment of a subscriber or user does not include a reference to collecting or monitoring information automatically emitted by the terminal equipment.
  • (3) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user for the same purpose on more than one occasion, it is sufficient that the requirements of sub-paragraph (1)(d) and (e) are met in respect of the initial use.

Website appearance etc

6
  • (1) Regulation 6(1) does not prevent a person storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user if—
  • (a) the person provides an information society service by means of a website,
  • (b) the sole purpose of the storage or access is—
  • (i) to enable the way the website appears or functions when displayed on, or accessed by, the terminal equipment to adapt to the preferences of the subscriber or user, or
  • (ii) to otherwise enable an enhancement of the appearance or functionality of the website when displayed on, or accessed by, the terminal equipment,
  • (c) the subscriber or user is provided with clear and comprehensive information about the purpose of the storage or access, and
  • (d) the subscriber or user is given a simple means of objecting, free of charge, to the storage or access and does not object.
  • (2) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user for the same purpose on more than one occasion, it is sufficient that the requirements of sub-paragraph (1)(c) and (d) are met in respect of the initial use.

Emergency assistance

7

Regulation 6(1) does not prevent a person storing information, or gaining access to information stored, in the terminal equipment of a subscriber or user if—

  • (a) the person receives a communication from the terminal equipment,
  • (b) the communication is a request from the subscriber or user for emergency assistance or otherwise indicates that the subscriber or user is in need of emergency assistance, and
  • (c) the sole purpose of the storage or access is to enable the geographical position of the subscriber or user to be ascertained with a view to the emergency assistance being provided.

Provisions applied for enforcement purposes

General modification of references to the Data Protection Act 2018

Modification of section 142 (information notices)

Modification of section 143 (information notices: restrictions)

Modification of section 145 (information orders)

Modification of section 146 (assessment notices)

Modification of section 146A (assessment notices: approval of person to prepare report)

Modification of section 147 (assessment notices: restrictions)

Modification of section 148A (interview notices)

Modification of section 148B (interview notices: restrictions)

Modification of section 149 (enforcement notices)

Modification of section 150 (enforcement notices: supplementary)

Modification of section 152 (enforcement notices: restrictions)

Modification of Schedule 15 (powers of entry and inspection)

14
  • (1) Schedule 15 has effect as if paragraph 3 were omitted.
  • (2) Paragraph 1(1) of that Schedule (issue of warrants in connection with non-compliance and offences) has effect as if for paragraph (a) (but not the final “and”) there were substituted—

(a) there are reasonable grounds for suspecting that— (i) a person has failed or is failing to comply with a requirement of the PEC Regulations, or (ii) an offence under section 144, 148, or 148C or paragraph 15 of this Schedule has been or is being committed,

  • (3) Paragraph 2 of that Schedule (issue of warrants in connection with assessment notices) has effect as if—
  • (a) in sub-paragraphs (1) and (2), for “controller or processor” there were substituted “person”;
  • (b) in sub-paragraph (2), for “the data protection legislation” there were substituted “the PEC Regulations”.
  • (4) Paragraph 5 of that Schedule (content of warrants) has effect as if—
  • (a) in sub-paragraph (1)(c), for “the processing of personal data” there were substituted “an activity regulated by the PEC Regulations”;
  • (b) in sub-paragraph (2)(d), for the words from “controller or processor” to the end there were substituted “person mentioned in paragraph 1(1)(a) has failed or is failing to comply with a requirement of the PEC Regulations”;
  • (c) in sub-paragraph (3)(a) and (d)—
  • (i) for “controller or processor” there were substituted “person mentioned in paragraph 2(1)”;
  • (ii) for “the data protection legislation” there were substituted “the requirements of the PEC Regulations”.
  • (5) Paragraph 11 of that Schedule (privileged communications) has effect as if, in sub-paragraphs (1)(b) and (2)(b), for “the data protection legislation” there were substituted “the PEC Regulations”.

Modification of section 155 (penalty notices)

15

Section 155 has effect as if—

  • (a) in subsection (1)—
  • (i) in paragraph (a), for “as described in section 149(2), (3), (4), (5) or (5A)” there were substituted “to comply with a requirement of the PEC Regulations”;
  • (ii) after paragraph (c), there were inserted

, or (d) has failed to comply with the prohibition in section 142(8B),

  • (b) after subsection (1) there were inserted—

(1A) But the Commissioner may not give a penalty notice to a person in respect of a failure to comply with regulation 5A of the PEC Regulations.

  • (c) for subsection (2) there were substituted—

(2) When deciding whether to give a penalty notice to a person and determining the amount of the penalty, the Commission must have regard to the matters listed in subsection (3), so far as relevant.

  • (d) in subsection (3)—
  • (i) for “the controller or processor” (in each place) there were substituted “the person”;
  • (ii) in paragraph (c), for the words from “data subjects” to the end there were substituted “subscribers or users”;
  • (iii) in paragraph (d), for the words “in accordance with section 57, 66, 103 or 107” there were substituted “with a view to securing compliance with the requirements of the PEC Regulations”;
  • (iv) paragraph (g) were omitted;
  • (v) in paragraph (j), the words “or certification mechanism” were omitted;
  • (e) subsection (4) were omitted;
  • (f) after subsection (4) there were inserted—

(4A) If a penalty notice is given to a body in respect of a failure to comply with any of regulations 19 to 24 of the PEC Regulations, the Commissioner may also give a penalty notice to an officer of the body if the Commissioner is satisfied that the failure— (a) took place with the consent or connivance of the officer, or (b) was attributable to any neglect on the part of the officer. (4B) In subsection (4A)— - “body” means a body corporate or a Scottish partnership; - “officer”, in relation to a body, means—in relation to a body corporate—a director, manager, secretary or other similar officer of the body or any person purporting to act in such capacity, andwhere the affairs of the body are managed by its members, a member; orin relation to a Scottish partnership, a partner or any person purporting to act as a partner.

  • (g) subsections (6) to (8) were omitted.

Modification of Schedule 16 (penalties)

16

Schedule 16 has effect as if paragraphs 3(2)(b) and 5(2)(b) were omitted.

Modification of section 156 (penalty notices: restrictions)

17
  • (1) Section 156 has effect as if subsections (1), (2), (4)(b) and (5) were omitted.
  • (2) In that section, subsection (3) has effect as if for the words from “controller” to “determined by or” there were substituted “penalty notice to a person who acts”.

Modification of section 157 (maximum amount of penalty)

18

Section 157 has effect as if—

  • (a) subsection (1) were omitted;
  • (b) in subsection (2)—
  • (i) for “Part 3 of this Act” there were substituted “the PEC Regulations”;
  • (ii) in paragraph (a), for the words from “section 35” to “or 78” there were substituted “regulation 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23 , 24 or 32B(4) or (5)”;
  • (c) subsections (3) and (4A) were omitted;
  • (d) after subsection (4A) there were inserted—

(4B) In relation to an infringement of section 142(8B) of this Act, the maximum amount of the penalty that may be imposed by a penalty notice is the higher maximum amount.

Modification of section 159 (amount of penalties: supplementary)

19

Section 159 has effect as if—

  • (a) in subsection (1), the words “Article 83 of the UK GDPR and” were omitted;
  • (b) in subsection (2), the words “Article 83 of the UK GDPR,” and “and section 158” were omitted.

Modification of section 160 (guidance)

20

Section 160 has effect as if, in subsection (4)(f), for “controllers and processors” there were substituted “persons”.

Modification of section 162 (rights of appeal)

21

Section 162 has effect as if subsection (4) were omitted.

Modification of section 163 (determination of appeals)

22

Section 163 has effect as if subsection (6) were omitted.

Modification of section 180 (jurisdiction)

23
  • (1) Section 180 has effect as if subsections (2)(b), (c), (d) and (e) and (3) were omitted.
  • (2) Subsection (1) of that section has effect as if for “subsections (3) and (4)” there were substituted “subsection (4)”.

Modification of section 181 (interpretation of Part 6)

24

Section 181 has effect as if the definition of “certification provider” were omitted.

Modification of section 182 (regulations and consultation)

25
  • (1) Section 182 has effect as if subsections (3), (6), (8), (11), (12) and (14) were omitted.
  • (2) Subsection (13) of that section has effect as if for “provision comes into force” there were substituted “coming into force of section 115 of the Data (Use and Access) Act 2025”.

Modification of section 196 (penalties for offences)

26
  • (1) Section 196 has effect as if subsections (3) to (5) were omitted.
  • (2) In that section—
  • (a) subsection (1) has effect as if the words “section 119 or 173 or” were omitted;
  • (b) subsection (2) has effect as if for “section 132, 144, 148, 148C, 170, 171 or 184” there were substituted “section 144, 148 or 148C”.

Modification of section 200 (guidance about PACE codes of practice)

27

Section 200 has effect as if, in subsection (1), for “this Act” there were substituted “section 144, 148 and 148C and paragraph 15 of Schedule 15”.

Modification of section 202 (proceedings in the First-tier Tribunal: contempt)

28

Section 202 has effect as if, in subsection (1)(a), for sub-paragraphs (i) and (ii) there were substituted “on an appeal under section 162”.

Modification of section 203 (tribunal procedure rules)

29

Section 203 has effect as if—

  • (a) in subsection (1), for paragraphs (a) and (b) there were substituted “the exercise of the rights of appeal conferred by section 162”;
  • (b) in subsection (2)—
  • (i) in paragraph (a), for “the processing of personal data” there were substituted “any activity regulated by the PEC Regulations”;
  • (ii) in paragraph (b), for “the processing of personal data” there were substituted “any such activity”.

Interpretation

30

In this Schedule, “the PEC Regulations” means these Regulations.

Reading this document does not replace reading the official text published on legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. We assume no responsibility for any inaccuracies arising from the conversion of the original CLML XML to this format.

This text is published under legislation.gov.uk's own terms of reuse, not a Legalize or public-domain licence. legislation.gov.uk
Open Government Licence v3.0 (attribution required)
© Crown and database right. Derived from content available under the Open Government Licence v3.0 from legislation.gov.uk.