Examples
Worked examples
- Is an instance
A university running a five-year longitudinal health cohort relies on paragraph 27 to decline a participant's mid-study Article 16 rectification request where correcting the historical record would compromise the integrity of already-collected longitudinal measures, while still honouring the request going forward for new data collection.
- Is an instance
A research team publishing aggregate statistics from a survey dataset disapplies the Article 15 access right for individual respondents because the published outputs report only group-level statistics and do not identify any data subject -- satisfying the condition attached to that specific disapplication.
Counter-examples
Looks similar, but isn't
- Not an instance
A controller cannot rely on paragraph 27 to ignore an access request purely because responding is administratively inconvenient or time-consuming -- the test is whether compliance would prevent or seriously impair the research purposes, not general burden.
- Not an instance
A controller processing identifiable data for operational service-improvement purposes, rather than research or statistics, cannot invoke paragraph 27 at all -- the exemption is scoped to the research/statistics purpose, not to the sector or institution doing the processing.
Editorial commentary
The provision in Part 6 of Schedule 2 to the UK Data Protection Act 2018 that lets a controller processing personal data for research or statistical purposes disapply specific UK GDPR data-subject rights — the right of access (Article 15(1)-(3)), rectification (Article 16), restriction of processing (Article 18(1)), and objection (Article 21(1)) — to the extent that applying them would prevent or seriously impair achievement of the research or statistical purposes, provided the processing also satisfies the UK GDPR’s research-safeguards requirements. The access-right disapplication carries an additional, narrower condition: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject.
Which rights it disapplies, and the conditions attached
Paragraph 27 sits in Part 6 of Schedule 2 to the UK Data Protection Act 2018. It lets a controller processing personal data for research or statistical purposes disapply four specific UK GDPR data-subject rights, to the extent that applying them would prevent or seriously impair achieving the research or statistical purpose:
- Article 15(1)-(3) — the right of access.
- Article 16 — the right to rectification.
- Article 18(1) — the right to restriction of processing.
- Article 21(1) — the right to object.
The access-right disapplication (Article 15) carries an additional, narrower condition beyond the other three: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject. A controller cannot invoke paragraph 27 to withhold access where its outputs do, in fact, identify individuals.
The gate: research safeguards, not just a stated purpose
Paragraph 27 is not available merely because a controller labels its processing “research.” The processing must also satisfy the UK GDPR’s research-safeguards requirement — historically anchored in DPA 2018 section 19, which required technical and organisational measures ensuring data minimisation and that processing would not cause substantial damage or distress, and would not be used for measures or decisions about a particular identifiable data subject except for approved medical research. Section 19 itself was omitted with effect from 5 February 2026 by the Data (Use and Access) Act 2025; the substantive safeguards moved into new UK GDPR Articles 84B and 84C, covering “RAS purposes” (research, archiving, statistics) on materially the same substance — non-identifiable-where-possible processing, data-minimisation measures, no substantial damage/distress, and no use for decisions about a particular identifiable individual except approved medical research.
What “prevent or seriously impair” means in practice
This is a purpose-specific necessity test, not a general convenience standard. A controller must be able to show that applying the right in question — for example, correcting a specific historical data point mid-study, or halting processing on request — would genuinely prevent or seriously impair the research or statistical purpose, not merely make compliance administratively burdensome or time-consuming.
Worked examples
- A university running a five-year longitudinal health cohort relies on paragraph 27 to decline a participant’s mid-study Article 16 rectification request where correcting the historical record would compromise the integrity of already-collected longitudinal measures, while still honouring the request going forward for new data collection.
- A research team publishing aggregate statistics from a survey dataset disapplies the Article 15 access right for individual respondents because the published outputs report only group-level statistics and do not identify any data subject — satisfying the condition attached to that specific disapplication.
Counter-examples
- A controller cannot rely on paragraph 27 to ignore an access request purely because responding is administratively inconvenient or time-consuming — the test is whether compliance would prevent or seriously impair the research purposes, not general burden.
- A controller processing identifiable data for operational service-improvement purposes, rather than research or statistics, cannot invoke paragraph 27 at all — the exemption is scoped to the research/statistics purpose, not to the sector or institution doing the processing.
Related terms and guides
- GDPR Recital 33 — broad consent for scientific research.
- GDPR Article 5(1)(b) — purpose limitation and the research compatible-use carve-out.
- GDPR Article 6(1)(e) — the public-task lawful basis.
- Data Protection Impact Assessment (DPIA).
- Data Protection Act 2018 in Health and Social Care Research — broader DPA 2018 Schedule 1/Schedule 2 walkthrough for health-research controllers.
Frequently Asked Questions
Does paragraph 27 mean researchers never have to respond to a data subject’s access request?
No. It only disapplies the access right to the extent that responding would prevent or seriously impair the research/statistical purpose, and only where the research results/statistics themselves do not identify a data subject. It is a conditional, purpose-linked exemption, not a blanket opt-out.
Can any organisation use paragraph 27 for any processing it calls “research”?
No. The exemption is scoped specifically to processing for research or statistical purposes, and it also requires the processing to satisfy the UK GDPR’s research-safeguards requirement (now UK GDPR Articles 84B/84C, following the Data (Use and Access) Act 2025’s omission of DPA 2018 section 19 from 5 February 2026). Processing for operational or service-improvement purposes cannot rely on paragraph 27 even if identifiable data is involved.
What changed with the Data (Use and Access) Act 2025?
DPA 2018 section 19, which previously set out the research safeguards a controller had to meet to use the Schedule 1 paragraph 4 research condition, was omitted effective 5 February 2026. The substantive safeguards moved into new UK GDPR Articles 84B and 84C, covering “RAS purposes” (research, archiving, statistics) — the practical requirements are materially similar, but the correct citation changed.
Which rights are NOT covered by paragraph 27?
Paragraph 27 covers only Article 15(1)-(3) access, Article 16 rectification, Article 18(1) restriction, and Article 21(1) objection. It does not disapply other UK GDPR rights, such as the right to erasure (Article 17) or data portability (Article 20), which are addressed by different Schedule 2 provisions or not exempted for research at all.
Last verified 2026-07-17 against the DPA 2018 text (legislation.gov.uk/ukpga/2018/12/schedule/2/paragraph/27 and …/section/19) and corroborating commentary on the Data (Use and Access) Act 2025’s Article 84B/84C changes (Handley Gill, Kennedys Law). Re-verify if reused after roughly 12 months, or sooner if further DUA Act 2025 commencement regulations or ICO guidance on Articles 84B/84C are published.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)"
vocab-term-identifier="https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
"name": "Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)",
"identifier": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
"description": "The provision in Part 6 of Schedule 2 to the UK Data Protection Act 2018 that lets a controller processing personal data for research or statistical purposes disapply specific UK GDPR data-subject rights -- the right of access (Article 15(1)-(3)), rectification (Article 16), restriction of processing (Article 18(1)), and objection (Article 21(1)) -- to the extent that applying them would prevent or seriously impair achievement of the research or statistical purposes, provided the processing also satisfies the UK GDPR's research-safeguards requirements. The access-right disapplication carries an additional, narrower condition: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-08-17T01:33:12",
"inLanguage": "en"
}






