Examples
Worked examples
- Is an instance
A university running a five-year longitudinal health cohort relies on paragraph 27 to decline a participant's mid-study Article 16 rectification request where correcting the historical record would compromise the integrity of already-collected longitudinal measures, while still honouring the request going forward for new data collection.
- Is an instance
A research team publishing aggregate statistics from a survey dataset disapplies the Article 15 access right for individual respondents because the published outputs report only group-level statistics and do not identify any data subject -- satisfying the condition attached to that specific disapplication.
Counter-examples
Looks similar, but isn't
- Not an instance
A controller cannot rely on paragraph 27 to ignore an access request purely because responding is administratively inconvenient or time-consuming -- the test is whether compliance would prevent or seriously impair the research purposes, not general burden.
- Not an instance
A controller processing identifiable data for operational service-improvement purposes, rather than research or statistics, cannot invoke paragraph 27 at all -- the exemption is scoped to the research/statistics purpose, not to the sector or institution doing the processing.
Editorial commentary
Schedule 2 to the UK Data Protection Act 2018 (DPA 2018) sets out exemptions from parts of the UK GDPR that Parliament judged necessary for specific public interests. Part 6 of that Schedule, paragraph 27, is the research and statistics exemption: it allows a controller to disapply certain data-subject rights when complying with them would prevent or seriously impair the research or statistical purpose being pursued, and the processing meets the UK GDPR’s own safeguards for research, archiving and statistics (RAS) processing.
The rights paragraph 27 can disapply are specific, not blanket: the right of access (UK GDPR Article 15(1)-(3)), the right to rectification (Article 16), the right to restriction of processing (Article 18(1)), and the right to object (Article 21(1)). Rights not listed — including the core lawfulness/fairness/transparency principles, the right to erasure in most circumstances, and the general accountability obligations — are unaffected. The access-right disapplication has an extra condition attached: it is only available where the results of the research, or any resulting statistics, are not made available in a form that identifies a data subject. A controller publishing individually-identifiable outputs cannot rely on the Article 15 limb of paragraph 27, even if the other conditions are met.
The ‘seriously impair’ test
Paragraph 27 is not a general carve-out for research convenience. The statutory test is that applying the right in question would ‘prevent or seriously impair the achievement’ of the research or statistical purposes. This is a purpose-specific, evidence-based threshold: a controller relying on the exemption should be able to explain concretely why, for example, honouring a rectification request on already-collected longitudinal data would compromise the research (rather than simply being burdensome or inconvenient to action). Institutional data protection offices and research ethics/governance bodies typically expect this reasoning to be documented at the point the exemption is relied on, not reconstructed after the fact if challenged.
The safeguards precondition
Paragraph 27 does not operate on its own — it is only available where the underlying processing satisfies the UK GDPR’s separate safeguards requirement for research, archiving and statistics purposes. Historically that safeguards test sat in DPA 2018 section 19, which required processing not likely to cause substantial damage or substantial distress to a data subject, and not used to support measures or decisions about a particular individual (subject to a further exception for approved medical research). Section 19 was omitted with effect from 5 February 2026 by the Data (Use and Access) Act 2025, and its substance was moved into new UK GDPR Articles 84B and 84C, which set out the safeguards for what the amended framework now labels ‘RAS purposes’ (research, archiving in the public interest, and statistics): data limited to what will be made non-identifiable or is otherwise strictly necessary, technical and organisational measures for data minimisation, no processing likely to cause substantial damage or distress, and no use for measures or decisions about an identifiable individual outside the approved-medical-research exception. A controller invoking paragraph 27 needs to be satisfied the Article 84B/84C conditions are met, not just that a right would be inconvenient to honour. For the fuller picture of how these safeguards interact with the special-category lawful basis in health and social care research, see Data Protection Act 2018 in Health and Social Care Research.
How this differs from the Schedule 1 special category conditions
Paragraph 27 is easily confused with, but distinct from, the conditions in Schedule 1, Part 1 to the DPA 2018 that provide a domestic lawful basis for processing special category data (health data, for example) under UK GDPR Article 9(2) — notably paragraph 4, the archiving/research/statistics condition. Schedule 1 paragraph 4 answers ‘is there a lawful basis to process this special category data at all’; Schedule 2 paragraph 27 answers a separate question — ‘given that the processing is lawful and ongoing, can specific data-subject rights be limited because exercising them would seriously impair the research’. A study can rely on the Schedule 1 paragraph 4 condition to process special category data and still owe data subjects the full set of GDPR rights if none of the Schedule 2 paragraph 27 conditions are met.
Practical application
In practice, paragraph 27 is most often invoked for large-scale, longitudinal, or population-level research and official/national statistics where re-identifying individuals to action a request, or altering historical records mid-study, would undermine the scientific validity or comparability of the dataset. It is applied right-by-right and request-by-request rather than as a blanket institutional policy — a controller must still be able to justify reliance on the exemption for the specific right and the specific processing at issue, and must still comply with any right not covered by the exemption (for example, most reliance on paragraph 27 does not touch the right to erasure or the right to be informed). See also CASRAI’s overview of GDPR and Data Protection Compliance in Research Involving Personal Data.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)"
vocab-term-identifier="https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
"name": "Data Protection Act 2018, Schedule 2, Paragraph 27 (Research Exemption)",
"identifier": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
"description": "The provision in Part 6 of Schedule 2 to the UK Data Protection Act 2018 that lets a controller processing personal data for research or statistical purposes disapply specific UK GDPR data-subject rights -- the right of access (Article 15(1)-(3)), rectification (Article 16), restriction of processing (Article 18(1)), and objection (Article 21(1)) -- to the extent that applying them would prevent or seriously impair achievement of the research or statistical purposes, provided the processing also satisfies the UK GDPR's research-safeguards requirements. The access-right disapplication carries an additional, narrower condition: it applies only where the results of the research or any resulting statistics are not made available in a form that identifies a data subject.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/data-protection-act-2018-schedule-2-paragraph-27",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T06:12:23",
"inLanguage": "en"
}






