Digital Economy Act 2017 - Consultation Regarding Proposed Changes to Research Accreditation Criteria
Accreditation criteria
Part 2: Accreditation Criteria
|
The text within this box is contextual and has not changed since original publication: 10.1 The Digital Economy Act 2017 (‘the Act’) permits the disclosure of data held by public authorities for the purpose of conducting research in the public interest under the Research power in Chapter 5 of Part 5 of the Act (‘the Research power‘). This disclosure is conditional on the persons involved, and the research being carried out, being accredited by the UK Statistics Authority (’the Authority‘). The Act requires the Authority to establish and publish:
10.2 This document sets out those conditions and grounds. Section A: Accreditation of processors 11.1 The use of the Research power is conditional on the data being processed by an accredited processor. A processor must also be accredited for the functions of:
11.2 Any person(s) involved in the preparation, storing and provision of access to de-identified data must be accredited for the appropriate function. Accreditation documents will clearly state which of these functions the processor has been accredited for. The UK Statistics Authority will also publish details of accredited processors, along with details of which function(s) the accreditation covers. In some cases, the processor could be the public authority whose data has been requested if they have the necessary expertise. Public authorities undertaking any aspect of the processing of their own data for accredited research purposes – or indeed, linking and matching their data to that held by another public authority – must be appropriately accredited for the processing function they are performing. This will maintain standards of consistency throughout the accreditation process. If the researcher or any of the persons involved in processing the data do not, in the view of the Authority, act in a way that means they should remain accredited, the Authority may decide to withdraw their accreditation (see paragraph 24.1 below). 11.3 The Act introduces new criminal offences where personal information is received under the Research power and disclosed in breach of sections 66, 67, 68 or 69 of the Act. 11.4 By default, an accredited processor will retain accredited status for up to five years with periodic reassessments, for as long as they continue to meet the conditions for accreditation set out below. After this time an accredited processor will need to apply for a renewal of its accredited status. From time to time emerging data threats and challenges may make it necessary to change the conditions required for accreditation as a processor. In such circumstances the Authority may decide to provide notice of its intention to suspend and reassess the accreditation status of processors. |
12.1 To secure accreditation, processors (individuals involved in processing and the organisations to which they belong) must meet the following conditions:
The processor must be a fit and proper person to perform the functions of a processor
13.1 Under section 71(3) of the Act, a person must be ‘a fit and proper person’ to be involved in processing before the Authority will accredit them as a processor. For this criterion, a ‘person’ is the processor. In assessing this, the Authority will expect an applicant to provide appropriate evidence to confirm:
- the necessary skills and experience relevant to the nature, scale and complexity of the proposed processing activities;
- adequate technical and organisational infrastructure, including systems, controls and security arrangements; and
- appropriate policies and procedures to support lawful, secure and effective processing.
The Authority’s assessment under this paragraph will also consider individuals employed or engaged by the applicant who would be involved in, or have responsibility for, the proposed processing activities.
The processor must act within the UK and comply with UK laws
14.1 Access to data, made available to accredited researchers in a secure environment, must take place from within the United Kingdom. Processors must ensure that technical and organisational measures are in place to ensure that data access is confined to users physically present in the UK, with all access from outside the UK prohibited. Processors must take reasonable steps to detect, prevent, and respond to attempts to access data from overseas locations, including through the use of technologies intended to obscure or misrepresent a user’s location, such as virtual private networks (VPNs) or other privacy enhancing or anonymisation technologies.
14.2 Processors must have an official address or registered office within the UK. All processing of data for disclosure under section 64 DEA must take place solely within the UK.
Applicants must be able to demonstrate application of all relevant UK law, including:
- Digital Economy Act 2017;
- Data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018, Data (Use and Access) Act 2025;
- the Human Rights Act 1998; and
- the Investigatory Powers Act 2016 and any subordinate legislation made under it.
The processor must meet cross‑government security standards appropriate to the sensitivity of the data
15.1 Processors must meet appropriate cross government security standards that are proportionate to the sensitivity and risk profile of the data they handle. For the purposes of this criterion, data sensitivity is not limited to personal data or to “special category data” under data protection legislation. Sensitivity may arise from the nature, content or context of the data, and may include, for example:
- personal data, including special category data;
- data about companies and commercially sensitive information;
- policy sensitive, market sensitive or prerelease information; and
- other data whose unauthorised disclosure, misuse or loss could result in harm, distress, or prejudice to individuals, organisations or the public interest.
The UK Government maintains cross-government security standards outlined on Security.gov.uk website setting out minimum requirements for physical, personnel and information security. These requirements must be applied proportionately, having regard to the classification, sensitivity and risk associated with the data.
Processors must report any actual or suspected security breaches relating to processing data or the environment where data are processed, without undue delay, to the Authority.
An applicant seeking accreditation as a processor must provide evidence that it assesses and understands the sensitivity of data it processes and meets cross-government security controls applicable to the sensitivity of that data.
The processor must ensure that relevant staff have appropriate skills, experience and capability to operate their services
16.1 Processors must ensure that individuals they employ or engage to carry out processing activities have the skills, experience and training necessary to perform their roles to an appropriate standard. In particular:
- individuals involved in the preparation of data must have received appropriate training and be able to demonstrate their understanding of safe data processing techniques, including linking, matching and de‑identification;
- individuals involved in the storage, management or provision of data must be able to demonstrate the skills and experience required to store, manage and make de‑identified data available securely; and
- where the processor prepares or provisions data under the DEA, staff responsible for the operation, support and administration of that preparation and provision must have the appropriate technical, analytical and user support skills to deliver these services effectively and consistently, including supporting researchers to fulfil their obligations under Section C of these Criteria, and managing access in line with accreditation requirements.
16.2 For assurance and audit purposes, processors must maintain an up-to-date record of individuals who are authorised to undertake processing activities under this accreditation, including their roles and the basis on which they meet the requirements of paragraph 16.3.
16.3 Processors must also ensure that all individuals involved in any aspect of the processing:
- receive appropriate induction and ongoing training relevant to their role, including training necessary to support researchers and operate TRE services effectively where applicable; and
- formally acknowledge their responsibilities, including their obligation to comply with applicable conditions of access and to protect the confidentiality and security of any data they access under the legislation.
The processor must consider ethical and public interest risks of its processing activities
17.1 Processors must implement and maintain proportionate measures to identify and assess the ethical, social, and public interest implications arising from datasets accepted for processing under this accreditation. These measures should include:
- assessing whether the intended processing activity is consistent with public expectations and the statutory purposes of the Act; and
- escalating concerns to data owners or the Authority where the Processor identifies material risks, uncertainties, or potential harms.
The processor must make use of appropriate, resilient and emerging technical infrastructure
18.1 Processors must use technical infrastructure that is appropriate to the processing functions they perform and capable of supporting those functions securely, reliably and effectively over time, including the use of appropriate and up‑to‑date statistical and analytical tools where analysis is undertaken.
For the purposes of this criterion, appropriate technical infrastructure means infrastructure that:
- enables the secure linking, matching, de‑identification, storage and provision of data, as relevant to the processor’s accredited functions;
- is proportionate to the nature, scale, sensitivity and risk profile of the data being processed; and
- reflects current good practice in the use of technology for secure data processing, recognising that such practice may evolve over time.
Technical infrastructure may include, where relevant, on‑premise systems, cloud‑based services, and tools supporting advanced processing techniques, including automated, algorithmic or AI‑enabled methods and modern statistical disclosure control approaches.
Processors must be able to demonstrate that their infrastructure:
- incorporates appropriate security, access control and monitoring measures;
- is maintained and updated to address emerging risks and technological change; and
- supports compliance with applicable legal, security and accreditation requirements, including ensuring that statistical and analytical tooling remains current and well‑supported.
The processor must agree to publish and maintains proportionate data governance policies
19.1 At the point of application, and for as long as accreditation is maintained, processors must publish and maintain documented data governance policies that demonstrate, to the Authority’s satisfaction, how they meet the requirements for the lawful, secure and responsible handling of data processed for research under the Act. Policies must be proportionate to the processor’s accredited functions and the sensitivity of the data handled. For the purposes of this criterion, data sensitivity is to be understood broadly as described in Criterion 15.1.
Processors must ensure that their published policies are easily accessible online, so that researchers and data owners can readily understand the controls and standards that apply, without unnecessary administrative burden. Policies must collectively address, as a minimum, the following topic areas:
- Secure environments and access controls, including physical, technical and organisational measures, and (where applicable) the operation of data access services;
- Incident and breach management, including procedures for identifying, managing and reporting data security, confidentiality or privacy incidents;
- De‑identification and disclosure control, including the approaches used to reduce disclosure risk, such as statistical disclosure control techniques where relevant;
- Data retention and secure destruction, including criteria for retention and methods for disposal; and
- Confidentiality and user responsibilities, including expectations placed on staff and authorised users.
The Authority will assess whether these topic areas are adequately covered, rather than requiring policies to follow specific titles or formats.
19.2 Processors must ensure that appropriate data processing agreements or other lawful arrangements are in place with public authorities or other data providers before processing data received from them. Where a data‑holding public authority requires specific conditions to be met as a prerequisite for processing its data, processors must be able to demonstrate that those conditions are compatible with, and supported by, their policies, systems and practices. Processors must also comply with any additional policies, procedures or conditions issued by the Authority in its accreditation capacity. The Authority will provide reasonable advance notice proportionate to the nature and impact of the change, where it intends to introduce new or materially revised policy or procedural requirements.
The processor must operate effective, transparent and timely processing services
20.1 Processors must operate their processing services in a manner that enables timely, efficient and proportionate access to data for accredited research purposes.
Where Processors do not process data prior to accreditation, they must demonstrate that they have appropriate systems, processes and arrangements in place to enable delivery of the requirements below once accredited.
Processors should be able to demonstrate that they:
- have defined and reasonable service timescales for key processing activities, including data preparation, access enablement and output checking;
- monitor performance against those service timescales; and
- publish high level information on service delivery performance, where appropriate, to support transparency and continuous improvement.
The processor must agree to inclusion on the public register of accredited processors
21.1 The Authority is required to maintain a public register of accredited processors for the purposes of transparency, assurance and public accountability. An applicant seeking to act as a processor under this power must agree to the publication of its details on the public register, including the fact and scope of its accreditation.
The processor must agree to a programme of assessment, audit and notification
22.1 Processors must agree to audit as a condition of accreditation and must fully cooperate with any audit the Authority undertakes to assess ongoing compliance. Audit outcomes will be communicated to the processor. Processors must also disclose any past data security or confidentiality incidents relevant to the Authority’s assessment of their suitability, including incidents that did not lead to regulatory action. In reviewing disclosures, the Authority will consider the nature and severity of the incident, when it occurred, and the steps taken to remediate and prevent recurrence.
The processor must have regard to the Research Code of Practice
23.1 Processors must have regard to the Research Code of Practice (“the Code”) and its principles when carrying out any processing functions under this accreditation.
For the purposes of this criterion, having regard to the Code means that processors must:
- consider the relevant principles of the Code when designing, operating and reviewing their processing activities; and
- be able to demonstrate how those principles are reflected, where appropriate, in their policies, procedures, systems and day‑to‑day practices.
Withdrawal or suspension of accreditation
24.1 The Authority may suspend or withdraw accreditation from a processor, in whole or in part, where it is satisfied that this is necessary and proportionate, including where the processor:
- no longer meets one or more of the accreditation requirements;
- fails to have appropriate regard to the Code of Practice governing data sharing for research purposes;
- has breached data protection legislation or other relevant UK legislation applicable to the processing activities for which it is accredited;
- has been convicted of an offence under the Act, data protection legislation, or other relevant legislation, where that offence is relevant to its role as an accredited processor;
- has been subject to regulatory enforcement action or penalties imposed by any regulatory authority in relation to the processing activities for which it is accredited;
- has ceased to provide, or has unreasonably refused to provide, the processing services for which it has been accredited;
- has acted in a way that materially undermines trust in, or brings into disrepute, the accreditation scheme;
- refuses to cooperate with assessment, audit or assurance activity, or obstructs the Authority in the exercise of its accreditation functions; and/or
- has applied charging or fee arrangements in connection with accredited processing activities that are not lawful or not consistent with the processor’s statutory powers, legal status, or applicable legal obligations.
In deciding whether to suspend or withdraw accreditation, the Authority may take account of the seriousness of the issue, the risks arising from continued accreditation, any remedial action taken, and any representations made by the processor.
Other considerations: guidance, procedures and appeals
25.1 The Authority will publish and maintain guidance setting out the procedures and processes governing the accreditation of processors for the preparation or provision of data under the Act. This guidance may include information on application processes, assessment stages, assurance, assessment and audit activity, and ongoing accreditation requirements.
An applicant who is refused accreditation, or a processor whose accreditation is suspended or withdrawn, will have a right to appeal that decision to the Authority in its capacity as the accrediting body. The Authority will set out, in published guidance, the process for bringing an appeal, including applicable time limits and the grounds on which an appeal may be made.
An applicant who is refused accreditation, or a processor whose accreditation is withdrawn, may apply for accreditation again in the future.
Section B: Accreditation of researchers
26.1 Researchers undertaking research using data provided under the Research power must secure accreditation by meeting the conditions below. These conditions also apply equally to individuals seeking access to the data held by the processor for the purpose of reviewing that research prior to the publication of research outputs.
The researcher must provide evidence of suitable research qualifications and/or research experience
27.1 A researcher must demonstrate they have suitable research qualifications and/or experience.
An individual must have either:
- an undergraduate degree (or higher), including relevant analytical or research methods training (e.g., quantitative, statistical, or mixed methods); or
- at least 2 years applied research experience.
The researcher must agree to complete compulsory training
28.1 A researcher must complete training on the safe handling of data and statistical disclosure control rules. Researchers may be required to undertake additional training throughout their period of accreditation.
The researcher must agree to their inclusion on a public record
29.1 The Authority must maintain a public register of accredited researchers. The Authority may also choose to publish a high-level overview of accredited research projects and accredited researchers associated with these projects. Researchers must agree to their details being published on the register unless the Authority agrees that there are exceptional reasons not to do so.
The researcher must sign a declaration
30.1 The researcher must sign a declaration confirming that they have understood their responsibilities and will abide by the conditions imposed upon them, including protecting the confidentiality of information they access under the Act. Reaffirmation of this declaration may be required by the Authority.
Withdrawal or suspension of accreditation
31.1 Accreditation may be suspended or withdrawn from an accredited researcher for one or more of the following reasons, where the researcher:
- no longer meets the accreditation requirements;
- fails to have regard to the Code of Practice governing data sharing for research purposes;
- has failed to disclose information that could materially affect the accreditation process or has otherwise dishonestly completed the application;
- fails to adhere to the terms of any data access agreement between the data holding public authority and the researcher;
- has acted unlawfully in relation to activities for which they are accredited;
- has brought the accreditation scheme into disrepute;
- fails to undertake, complete, or pass the appropriate training;
- has breached the data protection legislation, or other relevant UK legislation;
- has been convicted of a relevant offence under the Act, the data protection legislation, or other relevant UK legislation;
- has facilitated or negligently enabled access to identifiable data by a non-accredited person.
Details of those researchers who have had their accreditation suspended or removed may be shared with accredited processors.
Other considerations
32.1 In addition to the criteria set out above, applicants should note the following:
- accreditation as a researcher will be for a default period of five years. Researchers are required to re-apply once this term has expired in order to maintain their accreditation;
- applicants will be asked to include any relevant information which they think adds or detracts from the application;
- steps will be taken during the application process to verify the identity of the applicant;
- researchers only need to be accredited once (subject to renewal requirements), but every project requires accreditation. In line with principle 6 of the Research Code of Practice, accredited researchers can only use data for the purpose of an accredited research project;
- if an individual is working towards acquiring the level of skills stated above, they may be eligible to apply for provisional accreditation. This is applicable where a fully accredited researcher has agreed to direct, supervise and take responsibility for all work undertaken by the applicant, and on condition the applicant meets the criteria set out above in a reasonable period of time. This provision does not apply to individuals seeking access to the data held by the processor for the purpose of reviewing that research prior to the publication of research outputs, who must be fully qualified in their own right;
- a researcher who is refused accreditation, or who has their accreditation suspended or removed, will have a right to appeal to the Authority as the accrediting body; and
- a researcher who is refused accreditation, or who has their accreditation removed may apply for accreditation again in the future.
Section C: Accreditation of research projects
33.1 Research projects making use of data provided under the Research power must secure accreditation by meeting the following conditions:
The research must comply with UK law
34.1 The research must comply with all aspects of UK law, whether enacted by the UK Parliament or, where processing is taking place within the jurisdiction of a devolved government by the appropriate devolved legislature. This includes:
- the Digital Economy Act 2017;
- Data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018; and
- the Human Rights Act 1998.
The research must be in the public interest
35.1 For the purposes of accrediting research the Authority interprets public interest in the same way as ‘public good’, as set out in the Statistics and Registration Service Act 2007. The primary purpose of a research project must therefore be to serve the public interest in one or more of the following ways, to:
- provide an evidence base for public policy decision-making;
- provide an evidence base for public service delivery;
- provide an evidence base for decisions which are likely to significantly benefit the economy, society or quality of life of people in the UK, UK nationals or people born in the UK now living abroad;
- replicate, validate, challenge or review existing research and proposed research publications, including official statistics;
- significantly extend understanding of social or economic trends or events by improving knowledge or challenging widely accepted analyses; and/or
- improve the quality, coverage or presentation of existing research, including official or National Statistics.
The research and its results must be transparent
36.1 The intention and anticipated impact of the research should be set out to the satisfaction of the Authority as part of the application. Outcomes of the research must be made openly and accessibly available within a reasonable timeframe and in a way that could reasonably be expected to be permanent.
The public authority which is the source of the data should be acknowledged to allow others to verify the research. The applicant must also set out how they intend to engage with core stakeholders on findings from the research to maximise the research’s contributions to the public interest.
In exceptional circumstances, the Authority may allow for:
- adjustments to the timeframe in which outcomes are made available; and
- details to be omitted from publicly available outcomes where their inclusion would jeopardise the research’s contributions to the public interest.
In this case, the justification for this adjustment or omission will be made openly and accessibly available on a public register.
The research must meet appropriate ethical standards
37.1 The research must meet ethical standards appropriate to the nature and intended use of personal information. The research proposal must set out to the satisfaction of the Authority, consideration of ethical issues pertaining to the research, including an appropriate strategy for mitigating or minimising anticipated adverse impacts.
The data requested must be appropriate for the research that is proposed
38.1 The application must demonstrate that the data requested is suitable for the research that is proposed, and that the data requested are necessary and proportionate to the requirements of the research project.
All researchers must be named and accredited
39.1 The project application must name all the researchers who will be accessing the data. No researcher may access the data before they are accredited (including provisional accreditation) under this scheme. When researchers leave or are added to the research project the change must be communicated to the Authority.
Withdrawal or suspension of accreditation
40.1 Accreditation may be suspended or withdrawn from an accredited research project for one or more of the following reasons, where:
- the research project is no longer conducted in compliance with the Code of Practice;
- the research project is no longer covered by ethical approval where previously granted;
- the research project is no longer in the public interest;
- there has been a data breach relating to the research project;
- a court has ordered that the research be halted; and/or
- all researchers on the project are no longer accredited.
Other considerations
41.1 In addition to the criteria set out above, applicants should note the following:
- the application must include an indication of how long the project will take;
- a project can be accredited for a maximum duration of five years, after which the research will require accreditation to be renewed if ongoing access to the data is required;
- the accreditation of research projects can be granted, maintained or withdrawn independently of the accreditation status of researchers or processors involved in the use or processing of data for the project, provided the research project does not breach any of the criteria set out above. This means that withdrawal or refusal of accreditation to a researcher does not necessitate the withdrawal or refusal of accreditation to a research project. Nonetheless, in accordance with Principle 6 of the Research Code of Practice, research can only be conducted where all relevant parties are suitably accredited and only for as long as all relevant parties remain so accredited;
- where a research project is refused accreditation, or a project’s accreditation is suspended or removed, the applicant(s) will have a right to appeal to the Authority as the accrediting body; and
- where a research project is refused accreditation, or a project’s accreditation is removed, the applicant(s) may submit a new project application.