Section 62: Logging

Data Protection Act 2018 · 2018 c. 12View on legislation.gov.uk

Part 3: Law enforcement processing — CHAPTER 4: Controller and processor

A controller (or, where personal data is processed on behalf of the controller by a processor, the processor) must keep logs for at least the following processing operations in automated processing systems—

collection;
alteration;
consultation;
disclosure (including transfers);
combination;
erasure.

The logs of consultation must make it possible to establish—

the justification for, and date and time of, the consultation, and
so far as possible, the identity of the person who consulted the data.

The logs of disclosure must make it possible to establish—

the justification for, and date and time of, the disclosure, and
so far as possible—
the identity of the person who disclosed the data, and
the identity of the recipients of the data.

The logs kept under subsection (1) may be used only for one or more of the following purposes—

to verify the lawfulness of processing;
to assist with self-monitoring by the controller or (as the case may be) the processor, including the conduct of internal disciplinary proceedings;
to ensure the integrity and security of personal data;
the purposes of criminal proceedings.

The controller or (as the case may be) the processor must make the logs available to the Commissioner on request.

About this text

This legislation text comes from legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. These source and reuse terms cover the legislation text, not Remedy's commentary.

Reuse reviewed 21 August 2026 under Open Government Licence v3.0.