惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
SecWiki News
SecWiki News
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
量子位
M
MIT News - Artificial intelligence
GbyAI
GbyAI
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
TaoSecurity Blog
TaoSecurity Blog
博客园 - 【当耐特】
H
Heimdal Security Blog
腾讯CDC
The Last Watchdog
The Last Watchdog
Security Archives - TechRepublic
Security Archives - TechRepublic
Hacker News: Ask HN
Hacker News: Ask HN
S
Schneier on Security
Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
博客园 - 司徒正美
Recent Commits to openclaw:main
Recent Commits to openclaw:main
C
Cybersecurity and Infrastructure Security Agency CISA
S
SegmentFault 最新的问题
大猫的无限游戏
大猫的无限游戏
Application and Cybersecurity Blog
Application and Cybersecurity Blog
F
Full Disclosure
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Threatpost
月光博客
月光博客
A
Arctic Wolf
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
雷峰网
雷峰网
T
Troy Hunt's Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Cloudflare Blog
D
DataBreaches.Net
O
OpenAI News
L
LINUX DO - 最新话题
宝玉的分享
宝玉的分享
小众软件
小众软件
V
Vulnerabilities – Threatpost
A
About on SuperTechFans
人人都是产品经理
人人都是产品经理
T
The Exploit Database - CXSecurity.com
Martin Fowler
Martin Fowler
美团技术团队
P
Privacy International News Feed

UK ICO Publishes Guidance on Recognized Legitimate Interest Basis

UK ICO Publishes Guidance on Recognized Legitimate Interest Basis CalPrivacy Reaches Settlement with Ford Motor Company Over CCPA Opt-Out Right Violations
UK ICO Launches Consultation on New Guidance on Research, Archiving and Statistics Provisions
2026-03-06 · via UK ICO Publishes Guidance on Recognized Legitimate Interest Basis

UK ICO Launches Consultation on New Guidance on Research, Archiving and Statistics Provisions

On February 27, 2026, the UK Information Commissioner’s Office (“ICO”) announced a public consultation on proposed updates to its guidance concerning the Research, Archiving and Statistics Provisions (the “Guidance”). The updates reflect the changes introduced by the Data (Use and Access) Act 2025 (the “DUAA”). In particular, the Guidance revises the ICO’s criteria for scientific research and introduces the new “disproportionate effort” exemption related to informing data subjects about the reuse of previously collected data for research, as set out under Section 77 of the DUAA.

Scientific Research

The DUAA introduces a statutory definition of what constitutes “scientific research” under the UK General Data Protection Regulation. Namely, “scientific research” is defined as “any research that can reasonably be described as scientific, whether publicly or privately funded and whether carried out as a commercial or non-commercial activity.” In response to the updates introduced by the DUAA, the UK ICO has revised its criteria for scientific research, focussing on four elements: (i) scientific objective, (ii) scientific method, (iii) uncertainty and (iv) transferability. Each criterion is supported by indicative evidence (such as involvement of skilled professionals or use of recognized research methods) and exclusionary evidence (such as research causing harm or merely replicating existing technology). According to an example given by the ICO, a research project aiming to reduce bias in facial recognition algorithms by a technology company would be considered scientific research if it seeks genuine improvement, follows ethical standards, and documents its process.

Disproportionate Effort Exemption

Among setting out other exemptions, the Guidance clarifies the “disproportionate effort” exemption to the right to be informed, as introduced by the DUAA. This exemption permits organizations to refrain from directly providing notice to individuals when reusing personal data for research, archiving, or statistical purposes, but only where doing so would be impossible or would require disproportionate effort. The Guidance notes that in assessing whether the exemption applies, organizations should carefully weigh the effort involved against the potential impact on individuals, considering factors such as the number of people affected, the age of the information, and any safeguards in place. Importantly, even where this exemption is relied upon, organizations must still make privacy information accessible to the public (for example, via their website) and carry out a data protection impact assessment to ensure appropriate protection of individuals’ rights and interests.

The ICO consultation on the Guidance is open until April 27, 2026, and may be completed via an online survey here.

Read the ICO press release here. Read the Guidance here.