惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Proofpoint News Feed
G
Google Developers Blog
B
Blog
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志
The Register - Security
The Register - Security
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 叶小钗
The Cloudflare Blog
The Hacker News
The Hacker News
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
雷峰网
雷峰网
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
T
Threat Research - Cisco Blogs
A
About on SuperTechFans
量子位
Recorded Future
Recorded Future
博客园 - 三生石上(FineUI控件)
H
Help Net Security
Help Net Security
Help Net Security
P
Palo Alto Networks Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Troy Hunt's Blog
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
Know Your Adversary
Know Your Adversary
Apple Machine Learning Research
Apple Machine Learning Research
Scott Helme
Scott Helme
N
News | PayPal Newsroom
AWS News Blog
AWS News Blog
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
MongoDB | Blog
MongoDB | Blog
B
Blog RSS Feed
腾讯CDC
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
TaoSecurity Blog
TaoSecurity Blog
GbyAI
GbyAI
Y
Y Combinator Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
D
Docker

UK ICO Publishes Guidance on Recognized Legitimate Interest Basis

UK ICO Publishes Guidance on Recognized Legitimate Interest Basis CalPrivacy Reaches Settlement with Ford Motor Company Over CCPA Opt-Out Right Violations
UK ICO Launches Consultation on New Guidance on Research, Archiving and Statistics Provisions
2026-03-06 · via UK ICO Publishes Guidance on Recognized Legitimate Interest Basis

UK ICO Launches Consultation on New Guidance on Research, Archiving and Statistics Provisions

On February 27, 2026, the UK Information Commissioner’s Office (“ICO”) announced a public consultation on proposed updates to its guidance concerning the Research, Archiving and Statistics Provisions (the “Guidance”). The updates reflect the changes introduced by the Data (Use and Access) Act 2025 (the “DUAA”). In particular, the Guidance revises the ICO’s criteria for scientific research and introduces the new “disproportionate effort” exemption related to informing data subjects about the reuse of previously collected data for research, as set out under Section 77 of the DUAA.

Scientific Research

The DUAA introduces a statutory definition of what constitutes “scientific research” under the UK General Data Protection Regulation. Namely, “scientific research” is defined as “any research that can reasonably be described as scientific, whether publicly or privately funded and whether carried out as a commercial or non-commercial activity.” In response to the updates introduced by the DUAA, the UK ICO has revised its criteria for scientific research, focussing on four elements: (i) scientific objective, (ii) scientific method, (iii) uncertainty and (iv) transferability. Each criterion is supported by indicative evidence (such as involvement of skilled professionals or use of recognized research methods) and exclusionary evidence (such as research causing harm or merely replicating existing technology). According to an example given by the ICO, a research project aiming to reduce bias in facial recognition algorithms by a technology company would be considered scientific research if it seeks genuine improvement, follows ethical standards, and documents its process.

Disproportionate Effort Exemption

Among setting out other exemptions, the Guidance clarifies the “disproportionate effort” exemption to the right to be informed, as introduced by the DUAA. This exemption permits organizations to refrain from directly providing notice to individuals when reusing personal data for research, archiving, or statistical purposes, but only where doing so would be impossible or would require disproportionate effort. The Guidance notes that in assessing whether the exemption applies, organizations should carefully weigh the effort involved against the potential impact on individuals, considering factors such as the number of people affected, the age of the information, and any safeguards in place. Importantly, even where this exemption is relied upon, organizations must still make privacy information accessible to the public (for example, via their website) and carry out a data protection impact assessment to ensure appropriate protection of individuals’ rights and interests.

The ICO consultation on the Guidance is open until April 27, 2026, and may be completed via an online survey here.

Read the ICO press release here. Read the Guidance here.