Back to Insights
Regulatory Update

UK GDPR and Financial Data: What Changed After the DPDI Act

Pierre Ferran 9 min read
UK GDPR and financial data compliance

UK GDPR has been the baseline data protection framework for UK financial firms since the UK's departure from the EU. The Data Protection and Digital Information Act (DPDI Act) received Royal Assent and made targeted amendments to that framework. Some of those amendments were substantive; others clarified existing positions the ICO had already taken in guidance. For financial firms, the practical question is which changes require a review of current compliance policies and which do not.

This article covers the changes most relevant to UK financial services compliance teams, based on the text of the DPDI Act and subsequent ICO guidance. It is not a complete guide to UK GDPR compliance; it focuses on what changed and what that means for firms that have existing compliance frameworks.

Lawful Basis: What the DPDI Act Clarified

One of the DPDI Act's clearest changes for financial firms concerns the legitimate interests basis under Article 6 of UK GDPR. The Act introduced a list of recognised legitimate interests that controllers may rely on without conducting the balancing test that is otherwise required. Fraud prevention and crime detection are among the recognised legitimate interests listed. For financial firms that have historically relied on the legitimate interests basis for fraud screening and AML-related processing, this provides a firmer statutory footing than the pre-Act position, which required demonstrating the full three-part test.

The Act also made changes to the accountability framework, adjusting requirements around data protection officers, records of processing activities, and data protection impact assessments. The threshold for when a formal DPIA is required has been adjusted; the ICO has published updated guidance on when the revised threshold applies. Financial firms that conduct DPIAs as a routine part of project governance should check the current threshold against their existing DPIA policy.

The Financial Data Retention Challenge

Retention schedules remain one of the highest-risk areas of UK GDPR compliance for financial firms, and the DPDI Act did not simplify the underlying tension between data minimisation principles and regulatory retention obligations. The core principle under UK GDPR Article 5(1)(e) is storage limitation: personal data should be kept no longer than necessary for the purposes for which it is processed.

In financial services, regulatory obligations impose minimum retention periods across multiple frameworks. AML records under the Money Laundering Regulations must be retained for five years after the end of the customer relationship. Transaction records under MiFID II must be retained for five years (or seven years on FCA request). CASS records have their own retention requirements. These regulatory minimums interact with the storage limitation principle in a specific way: the regulatory obligation creates a lawful basis (legal obligation under Article 6(1)(c)) for retention up to the minimum period, but not necessarily beyond it.

The practical problem compliance teams encounter is that legacy systems do not always distinguish between data retained because of a specific regulatory obligation and data retained because it happened to exist in the same system. A data map that shows "client transaction records: retained 7 years" without specifying which records attract that period under which regulation, and which records are being retained beyond their minimum period, does not demonstrate compliance with the storage limitation principle. It describes a default retention period applied system-wide.

Subject Access Requests: Unchanged Deadline, Increasing Volume

The one-month response deadline for subject access requests under Article 15 was not changed by the DPDI Act. What has changed is the volume of SARs reaching financial firms. The ICO has reported consistent year-on-year increases in SARs across regulated sectors, with financial services among the highest-volume sectors. SAR handling that was manageable at lower volumes is becoming a compliance risk at current volumes for firms that have not invested in systematic processes.

A SAR process that relies on a small number of named individuals manually searching each system is fragile. Staff changes, system changes, and volume increases all degrade its reliability. The ICO's enforcement record in this area includes cases where response quality deteriorated as volumes increased, and the firm lacked the process visibility to identify the degradation before the ICO contacted them. The standard the ICO expects is a documented process with defined search protocols, an escalation path for complex cases, and evidence of on-time response rates across the request volume.

Automated Decision-Making: The Article 22 Position After DPDI

The DPDI Act made changes to the rules on automated decision-making, replacing the original UK GDPR Article 22 framework with a modified version. The changes affect the conditions under which solely automated decisions with significant effects on individuals are permitted. For financial firms, the most relevant application is in credit scoring, insurance underwriting, and fraud detection, all of which may involve automated decisions with significant effects on applicants or customers.

The ICO published guidance on the DPDI Act's changes to automated decision-making requirements in 2025. Compliance teams that have existing Article 22 policies and human review procedures should check those policies against the ICO's updated guidance. The changes do not fundamentally alter the position that significant automated decisions require either human review or explicit consent, but the DPDI Act adjusted the conditions and exemptions, and a policy written against the pre-Act version of Article 22 may not accurately describe the current legal position.

Machine Learning Models and Personal Data

The DPDI Act did not introduce a specific ML or AI provision, but ICO guidance published alongside and since the Act has addressed how UK GDPR applies to ML models trained on personal data. This is increasingly relevant for financial firms using ML in credit risk, fraud detection, AML, and customer analytics. The ICO's position covers lawful basis for training data use, data minimisation in the context of ML model development, and the interaction between Article 22 and model-based decisions.

We are not saying that every financial firm using ML models needs a complete data protection review. The question is whether the models in use were developed under a compliance framework that addressed the ICO's current expectations. Models developed before the ICO's 2025 guidance updates may have been developed without explicit consideration of the training data minimisation question or the current Article 22 interaction analysis. That gap is worth assessing now, before an ICO enquiry makes it visible.

ICO Guidance and the Monitoring Gap

The DPDI Act is important, but the ongoing stream of ICO guidance publications is equally important for financial firms to track. The ICO publishes guidance on specific issues regularly, and that guidance refines the ICO's interpretation of UK GDPR in ways that can affect compliance policies even when the legislation itself has not changed. A compliance team that only tracks legislative changes will miss the guidance layer.

Kalipso monitors ICO publications alongside FCA and PRA publications. When the ICO updates its guidance on a topic relevant to financial services data protection, the compliance team receives an alert describing what changed and what, if anything, it implies for existing policies. ICO monitoring does not need to be a separate workstream from financial regulatory monitoring.

Stay ahead of every change

Get regulatory updates before they become compliance gaps.

Kalipso monitors 45+ UK and EU regulatory feeds continuously. Request access and your team starts receiving plain-English alerts with remediation steps drafted.