Section 66: Security of processing

Data Protection Act 2018 · 2018 c. 12View on legislation.gov.uk

Part 3: Law enforcement processing — CHAPTER 4: Controller and processor

Each controller and each processor must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks arising from the processing of personal data.

In the case of automated processing, each controller and each processor must, following an evaluation of the risks, implement measures designed to—

prevent unauthorised processing or unauthorised interference with the systems used in connection with it,
ensure that it is possible to establish the precise details of any processing that takes place,
ensure that any systems used in connection with the processing function properly and may, in the case of interruption, be restored, and
ensure that stored personal data cannot be corrupted if a system used in connection with the processing malfunctions.

Adherence to a code of conduct approved under section 71A may be used by a controller or processor as a means of demonstrating compliance with subsection (1).

About this text

This legislation text comes from legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. These source and reuse terms cover the legislation text, not Remedy's commentary.

Reuse reviewed 21 August 2026 under Open Government Licence v3.0.