1-20 of 39,339 results for subject:"Data protection"
Librarians' tools
- Search time
- 0.43 seconds
- Solr query time
- 0.043 seconds
- Search query
- subject:"Data protection"
- We searched for
- subject_t:"Data protection" OR subject_t:"Computer privacy" OR subject_t:"Data breaches" OR subject_ses:90820
Type
House
Session
More
Year
More
Department
More
Member
More
Primary member
More
Answering member
More
Legislative stage
Legislation
More
Subject
More
Publisher
How can consumer technology support women's health? What is the evidence base for existing FemTech products, and how can new products be developed safely and equitably?
How can consumer technology support women's health? What is the evidence base for existing FemTech products, and how can new products be developed safely and equitably?
To ask the Secretary of State for Education, whether her Department has produced a Data Protection Impact Assessment for the Children Not in School register provisions in the Children’s Wellbeing and Schools Act.
To ask the Secretary of State for Education, whether her Department has produced a Data Protection Impact Assessment for the Children Not in School register provisions in the Children’s Wellbeing and Schools Act.
The department is conducting a Data Protection Impact Assessment for the Children Not in School registers provisions in the Act. However, the assessment cannot be completed until the statutory guidance, which we intend to publicly consult on, and secondary legislation is settled.
The department is continuing to engage with the Information Commissioner’s Office on the assessment to ensure that all data protection risks have been identified and mitigated before any processing of data begins.
To ask the Secretary of State for Education, how her Department ensures compliance with data protection requirements relating to the processing of special category data, including data relating to health or protected characteristics.
To ask the Secretary of State for Education, how her Department ensures compliance with data protection requirements relating to the processing of special category data, including data relating to health or protected characteristics.
The department ensures compliance with data protection requirements relating to the processing of special category personal data, including data concerning health and protected characteristics, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and Data (Use and Access) Act 2025.
The department processes special category data only where there is a lawful basis and a relevant condition for processing under Articles 6 and 9 and of the UK GDPR. The department has appropriate technical and organisational measures to safeguard data, including access controls, data minimisation, secure storage arrangements, and regular monitoring of compliance.
Where processing is likely to present a high risk to individual’s rights, the department undertakes Data Protection Impact Assessments to identify and mitigate risks. Staff receive mandatory data protection and information security training, supported by specialist advice from the department's Data Protection team.
The department also maintains privacy notices and an Appropriate Policy Document, where required, to support transparency and accountability. Compliance arrangements are kept under regular review to ensure processing remains necessary, proportionate and consistent with legal requirements.
To ask His Majesty's Government what the current policy and practice is for (1) requesting independent advice, oversight, and assurance on potential internal data disseminations within NHS England and the Department of Health and Social Care, and (2) deciding which projects do not require such advice.
To ask His Majesty's Government what the current policy and practice is for (1) requesting independent advice, oversight, and assurance on potential internal data disseminations within NHS England and the Department of Health and Social Care, and (2) deciding which projects do not require such advice.
To ask His Majesty's Government what plans they have to direct Cambridge University Hospitals NHS Foundation Trust to inform patients that their records were inappropriately accessed by staff members.
To ask His Majesty's Government what plans they have to direct Cambridge University Hospitals NHS Foundation Trust to inform patients that their records were inappropriately accessed by staff members.
To ask His Majesty's Government what assessment they have made of the risks to patient confidentiality of digital medical records being shared across multiple healthcare trusts.
To ask His Majesty's Government what assessment they have made of the risks to patient confidentiality of digital medical records being shared across multiple healthcare trusts.
Where medical records are shared across National Health Service organisations, such as the Shared Care Record program, organisations should complete a Data Protection Impact Assessment. This allows them to consider the data protection and confidentiality risks involved, and outlines what actions they can take to mitigate the risk to an acceptable level. NHS England has published guidance on this subject, Information Governance Framework: Shared Care Records, a copy of which is attached.
To ask the Secretary of State for Housing, Communities and Local Government, what assessment she has made of the potential impact of digital property logbooks under home buying and selling reforms on the a) privacy and b) security of homeowners’ data.
To ask the Secretary of State for Housing, Communities and Local Government, what assessment she has made of the potential impact of digital property logbooks under home buying and selling reforms on the a) privacy and b) security of homeowners’ data.
The home buying and selling reform roadmap, which can be found on gov.uk here, sets out an ambitious package of reform for the sector including improving upfront information in listings and through the introduction of sales packs, introducing binding contracts. and professionalising property agents.
We recognise the central importance of privacy and security for data held in digital logbooks. In the roadmap, we set out that we will work with the property technology industry and other technology specialists to ensure our plans incorporate robust technology and digital security systems. We will work with representatives and regulatory bodies to set an agreed level of digital security that these products must meet.
The requirement to use digital logbooks in transactions for certain government home ownership schemes will begin in 2027. We will introduce legislation to mandate the use of these products when Parliamentary time allows.
To ask the Minister for the Cabinet Office, pursuant to the answer of 30 June 2026, to Question 12787, on Government Departments: Public Appointments, whether the approach on GDPR applies to declarations in relation to ministerial appointments.
To ask the Minister for the Cabinet Office, pursuant to the answer of 30 June 2026, to Question 12787, on Government Departments: Public Appointments, whether the approach on GDPR applies to declarations in relation to ministerial appointments.
Ministerial appointments are distinct to public appointments and subject to separate processes. Ministers are appointed by the Sovereign on the advice of the Prime Minister. The process for the declaration and management of ministers’ interests is set out in the Ministerial Code. Relevant interests are published in the List of Ministers’ Interests on a quarterly basis.
To ask the Secretary of State for Science, Innovation and Technology, whether the (a) National Cyber Security Centre and (b) National Security Unit for Procurement have provided advice to (i) Ministers and (ii) officials on risks associated with the use of Chinese-manufactured Cellular Internet of Things modules in consumer products,...
To ask the Secretary of State for Science, Innovation and Technology, whether the (a) National Cyber Security Centre and (b) National Security Unit for Procurement have provided advice to (i) Ministers and (ii) officials on risks associated with the use of Chinese-manufactured Cellular Internet of Things modules in consumer products,...
The UK Government takes an actor-agnostic approach to supply chain resilience, focusing on the characteristics and behaviours of technologies and suppliers rather than their country of origin. This ensures that our regulatory frameworks remain objective, proportionate, and resilient to evolving threats.
Ministers receive technical advice from National Cyber Security Centre (NCSC) on a wide range of cyber threats, including on IoT products. Their assessment is that a compromised cellular internet of things module would not, by itself, enable an end-to-end attack. From a cyber security perspective, risk is managed through the broader set of controls supporting monitoring, resilience and recovery across the system. Advice on managing the security of cellular internet of things modules technology is provided to industry and government by the NCSC.
To ask the Secretary of State for Science, Innovation and Technology, pursuant to Answer of 7 July 2026 to Question 14208, what guidance her Department has issued on the maximum period for which personal data collected for age assurance purposes should be retained.
To ask the Secretary of State for Science, Innovation and Technology, pursuant to Answer of 7 July 2026 to Question 14208, what guidance her Department has issued on the maximum period for which personal data collected for age assurance purposes should be retained.
The government takes the threats of cyber-attacks and data breaches very seriously, which is why the ICO has the power to investigate any concerns raised about the misuse or mishandling of data. It can issue enforcement notices and substantial fines where organisations are found to be in breach of their obligations.
Organisations are required under UK GDPR and the Data Protection Act to keep personal data secure and process it fairly, lawfully, and transparently. Whilst the law does not set specific time limits on how long personal data can be held, it stipulates that it cannot be kept for longer than needed.
To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the potential impact of personal data retained by age-assurance providers on levels of a) cyber attacks and b) data breaches.
To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the potential impact of personal data retained by age-assurance providers on levels of a) cyber attacks and b) data breaches.
The government takes the threats of cyber-attacks and data breaches very seriously, which is why the ICO has the power to investigate any concerns raised about the misuse or mishandling of data. It can issue enforcement notices and substantial fines where organisations are found to be in breach of their obligations.
Organisations are required under UK GDPR and the Data Protection Act to keep personal data secure and process it fairly, lawfully, and transparently. Whilst the law does not set specific time limits on how long personal data can be held, it stipulates that it cannot be kept for longer than needed.
To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the effectiveness of a) the US Cloud Act and b) the EU AI Act; and whether she has plans to bring forward similar legislation.
To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the effectiveness of a) the US Cloud Act and b) the EU AI Act; and whether she has plans to bring forward similar legislation.
The UK’s starting point is relying on existing rules and regulations and empowering our regulators to consider how best to manage the opportunities and risks of AI. We continue to refine our approach to regulating AI and ensuring our law enforcement authorities have the powers they need to keep people safe. DSIT closely monitors international AI legislation from across the US, EU and elsewhere to ensure the UK’s regulatory approach remains suitable.
To ask the Secretary of State for Science, Innovation and Technology, what assessment her Department has made of the (a) potential impact of the use of Cellular Internet of Things modules in consumer products, including internet-connected vaping devices, on national security and (b) risk of interception, unauthorised access and transfer...
To ask the Secretary of State for Science, Innovation and Technology, what assessment her Department has made of the (a) potential impact of the use of Cellular Internet of Things modules in consumer products, including internet-connected vaping devices, on national security and (b) risk of interception, unauthorised access and transfer...
Consumer connected devices fall within scope of the Product Security and Telecommunications Act 2022 and must comply with the requirements of that Act and its underlying Regulations. This includes consumer devices that use cellular internet of things modules and the use of internet-connected vaping devices.
Consumer connected devices, by their nature as consumer goods, would not typically pose a national security threat. Our assessment is that a compromised cellular internet of things module would not, by itself, enable an end-to-end attack. From a cyber security perspective, risk is managed through the broader set of controls supporting monitoring, resilience and recovery across the system. Advice on managing the security of cellular internet of things modules technology is provided to industry and government by the National Cyber Security Centre.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 30 June (HL570), whether all the guidance referred to has now been published by NHS England; and whether that published guidance covers accesses for which NHS England, general practices, or pharmacies are the responsible employers.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 30 June (HL570), whether all the guidance referred to has now been published by NHS England; and whether that published guidance covers accesses for which NHS England, general practices, or pharmacies are the responsible employers.
To ask the Secretary of State for Science, Innovation and Technology, what steps her Department is taking through its cross-government data strategy to develop a secure, unified data-sharing framework with the Department for (a) Energy Security and Net Zero and (b) Work and Pensions to map and mitigate fuel poverty.
To ask the Secretary of State for Science, Innovation and Technology, what steps her Department is taking through its cross-government data strategy to develop a secure, unified data-sharing framework with the Department for (a) Energy Security and Net Zero and (b) Work and Pensions to map and mitigate fuel poverty.
The Digital Economy Act 2017 (‘DEA’) Part 5, Chapter 1 Public Service Delivery Powers enable information sharing between certain public authorities and gas and electricity suppliers. This information sharing power enables government departments (such as the DWP or DESNZ) to match household data against energy supplier records to deliver financial assistance and other targeted support.
Additionally, the Government’s forthcoming strategic data roadmap will set out the plan to transform how data is protected, shared and used across the public sector so it delivers more value for citizens, businesses, public services and the economy.
To ask the Minister for the Cabinet Office, given the passage of the Data (Use and Access) Act 2025, how does the Department ensure compliance with data protection requirements relating to the processing of special category data, including data relating to health or protected characteristics.
To ask the Minister for the Cabinet Office, given the passage of the Data (Use and Access) Act 2025, how does the Department ensure compliance with data protection requirements relating to the processing of special category data, including data relating to health or protected characteristics.
The Cabinet Office maintains a robust data protection governance framework to ensure all personal data, including special category data and data relating to protected characteristics, is processed in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
Following the passage of the 2025 Act, the Department continues to mandate rigorous Data Protection Impact Assessments (DPIAs) for high-risk processing, alongside a standard practice of conducting comprehensive data protection compliance audits across the entire Cabinet Office.
How can the upcoming Health Data Research Service simplify access to national health data for research opportunities, while addressing technical challenges, security, governance and public trust?
How can the upcoming Health Data Research Service simplify access to national health data for research opportunities, while addressing technical challenges, security, governance and public trust?
To ask His Majesty's Government whether the data described in the UK Biobank Data Statement on 28 April (HL Deb cols 1117–18) would be considered identifiable human genomic data under the Safeguarding UK human genomic data guidance, published on 2 July.
To ask His Majesty's Government whether the data described in the UK Biobank Data Statement on 28 April (HL Deb cols 1117–18) would be considered identifiable human genomic data under the Safeguarding UK human genomic data guidance, published on 2 July.
The Government understands that some of the data described in UK Biobank's statement from 28th April would be in scope of the Government's recent guidance on safeguarding UK human genomic data, however it is for the Information Commissioner's Office to determine if this may be potentially identifiable data. UK Biobank’s dataset is critical in supporting scientific discoveries that improve patient health, and we expect UK Biobank to remain one of the leading health research resources. Government continues to engage with Biobank to ensure that they are working to both protect the data of participants while ensuring that researchers who have a legitimate need to use the datasets can once again resume their research as soon as possible.
To ask the Secretary of State for Justice, what measures are being taken to protect sensitive court and prison data from cyber threats.
To ask the Secretary of State for Justice, what measures are being taken to protect sensitive court and prison data from cyber threats.
The Ministry of Justice's (MoJ) approach to protecting the department and its data against cyber threats is contained in the MoJ's cyber security strategy (MoJ Cyber Security Strategy). This sets out how we aim to achieve our ambition to be government-leading in the provision of secure services, which includes prisons and courts data.
To ask the Secretary of State for Health and Social Care, if he will ensure that records from the UK National Breast Implant Registry for 1993 to 2006 are retained and preserved.
To ask the Secretary of State for Health and Social Care, if he will ensure that records from the UK National Breast Implant Registry for 1993 to 2006 are retained and preserved.