Skip to main content
v2026.11,610 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)

The provision in Part 6 of Schedule 2 to the UK Data Protection Act 2018 that lets a controller processing personal data for research or statistical purposes disapply specific UK GDPR data-subject rights -- the right of access (Article 15(1)-(3)), rectification (Article 16), restriction of processing (Article 18(1)), and objection (Article 21(1)) -- to the extent that applying them would prevent or seriously impair achievement of the research or statistical purposes, provided the processing also satisfies the UK GDPR's research-safeguards requirements. The access-right disapplication carries an additional, narrower condition: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject.

ByCASRAI Editorial Board
· Last updated 17 Aug 2026

Ask about Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)

Answers are drawn from this dictionary entry and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Examples

Worked examples

  • Is an instance

    A university running a five-year longitudinal health cohort relies on paragraph 27 to decline a participant's mid-study Article 16 rectification request where correcting the historical record would compromise the integrity of already-collected longitudinal measures, while still honouring the request going forward for new data collection.

  • Is an instance

    A research team publishing aggregate statistics from a survey dataset disapplies the Article 15 access right for individual respondents because the published outputs report only group-level statistics and do not identify any data subject -- satisfying the condition attached to that specific disapplication.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A controller cannot rely on paragraph 27 to ignore an access request purely because responding is administratively inconvenient or time-consuming -- the test is whether compliance would prevent or seriously impair the research purposes, not general burden.

  • Not an instance

    A controller processing identifiable data for operational service-improvement purposes, rather than research or statistics, cannot invoke paragraph 27 at all -- the exemption is scoped to the research/statistics purpose, not to the sector or institution doing the processing.

Editorial commentary

The provision in Part 6 of Schedule 2 to the UK Data Protection Act 2018 that lets a controller processing personal data for research or statistical purposes disapply specific UK GDPR data-subject rights — the right of access (Article 15(1)-(3)), rectification (Article 16), restriction of processing (Article 18(1)), and objection (Article 21(1)) — to the extent that applying them would prevent or seriously impair achievement of the research or statistical purposes, provided the processing also satisfies the UK GDPR’s research-safeguards requirements. The access-right disapplication carries an additional, narrower condition: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject.

Which rights it disapplies, and the conditions attached

Paragraph 27 sits in Part 6 of Schedule 2 to the UK Data Protection Act 2018. It lets a controller processing personal data for research or statistical purposes disapply four specific UK GDPR data-subject rights, to the extent that applying them would prevent or seriously impair achieving the research or statistical purpose:

  • Article 15(1)-(3) — the right of access.
  • Article 16 — the right to rectification.
  • Article 18(1) — the right to restriction of processing.
  • Article 21(1) — the right to object.

The access-right disapplication (Article 15) carries an additional, narrower condition beyond the other three: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject. A controller cannot invoke paragraph 27 to withhold access where its outputs do, in fact, identify individuals.

The gate: research safeguards, not just a stated purpose

Paragraph 27 is not available merely because a controller labels its processing “research.” The processing must also satisfy the UK GDPR’s research-safeguards requirement — historically anchored in DPA 2018 section 19, which required technical and organisational measures ensuring data minimisation and that processing would not cause substantial damage or distress, and would not be used for measures or decisions about a particular identifiable data subject except for approved medical research. Section 19 itself was omitted with effect from 5 February 2026 by the Data (Use and Access) Act 2025; the substantive safeguards moved into new UK GDPR Articles 84B and 84C, covering “RAS purposes” (research, archiving, statistics) on materially the same substance — non-identifiable-where-possible processing, data-minimisation measures, no substantial damage/distress, and no use for decisions about a particular identifiable individual except approved medical research.

What “prevent or seriously impair” means in practice

This is a purpose-specific necessity test, not a general convenience standard. A controller must be able to show that applying the right in question — for example, correcting a specific historical data point mid-study, or halting processing on request — would genuinely prevent or seriously impair the research or statistical purpose, not merely make compliance administratively burdensome or time-consuming.

Worked examples

  • A university running a five-year longitudinal health cohort relies on paragraph 27 to decline a participant’s mid-study Article 16 rectification request where correcting the historical record would compromise the integrity of already-collected longitudinal measures, while still honouring the request going forward for new data collection.
  • A research team publishing aggregate statistics from a survey dataset disapplies the Article 15 access right for individual respondents because the published outputs report only group-level statistics and do not identify any data subject — satisfying the condition attached to that specific disapplication.

Counter-examples

  • A controller cannot rely on paragraph 27 to ignore an access request purely because responding is administratively inconvenient or time-consuming — the test is whether compliance would prevent or seriously impair the research purposes, not general burden.
  • A controller processing identifiable data for operational service-improvement purposes, rather than research or statistics, cannot invoke paragraph 27 at all — the exemption is scoped to the research/statistics purpose, not to the sector or institution doing the processing.

Related terms and guides

Frequently Asked Questions

Does paragraph 27 mean researchers never have to respond to a data subject’s access request?

No. It only disapplies the access right to the extent that responding would prevent or seriously impair the research/statistical purpose, and only where the research results/statistics themselves do not identify a data subject. It is a conditional, purpose-linked exemption, not a blanket opt-out.

Can any organisation use paragraph 27 for any processing it calls “research”?

No. The exemption is scoped specifically to processing for research or statistical purposes, and it also requires the processing to satisfy the UK GDPR’s research-safeguards requirement (now UK GDPR Articles 84B/84C, following the Data (Use and Access) Act 2025’s omission of DPA 2018 section 19 from 5 February 2026). Processing for operational or service-improvement purposes cannot rely on paragraph 27 even if identifiable data is involved.

What changed with the Data (Use and Access) Act 2025?

DPA 2018 section 19, which previously set out the research safeguards a controller had to meet to use the Schedule 1 paragraph 4 research condition, was omitted effective 5 February 2026. The substantive safeguards moved into new UK GDPR Articles 84B and 84C, covering “RAS purposes” (research, archiving, statistics) — the practical requirements are materially similar, but the correct citation changed.

Which rights are NOT covered by paragraph 27?

Paragraph 27 covers only Article 15(1)-(3) access, Article 16 rectification, Article 18(1) restriction, and Article 21(1) objection. It does not disapply other UK GDPR rights, such as the right to erasure (Article 17) or data portability (Article 20), which are addressed by different Schedule 2 provisions or not exempted for research at all.

Last verified 2026-07-17 against the DPA 2018 text (legislation.gov.uk/ukpga/2018/12/schedule/2/paragraph/27 and …/section/19) and corroborating commentary on the Data (Use and Access) Act 2025’s Article 84B/84C changes (Handley Gill, Kennedys Law). Re-verify if reused after roughly 12 months, or sooner if further DUA Act 2025 commencement regulations or ICO guidance on Articles 84B/84C are published.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)"
      vocab-term-identifier="https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
  "name": "Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)",
  "identifier": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
  "description": "The provision in Part 6 of Schedule 2 to the UK Data Protection Act 2018 that lets a controller processing personal data for research or statistical purposes disapply specific UK GDPR data-subject rights -- the right of access (Article 15(1)-(3)), rectification (Article 16), restriction of processing (Article 18(1)), and objection (Article 21(1)) -- to the extent that applying them would prevent or seriously impair achievement of the research or statistical purposes, provided the processing also satisfies the UK GDPR's research-safeguards requirements. The access-right disapplication carries an additional, narrower condition: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-08-17T01:33:12",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →