We are currently consulting on this draft guidance.
Standard maximum amount
UK GDPR provision 102 | Part 3 DPA: Law Enforcement processing 103 | Part 4 DPA: Intelligence Services processing 104 | |
Obligations of controller and processor | Articles 8, 11, 25-39, 42 | Sections 64-65 and Sections 67-68 | Section 108 |
Obligations of the certification body | Articles 42 and 43 | N/A | N/A |
Obligations of the monitoring body | Article 41(4) | N/A | N/A |
Higher maximum amount
UK GDPR provision 105 | Part 3 DPA: Law Enforcement processing 106 | Part 4 DPA: Intelligence Services processing 107 | |
The basic principles for processing, including conditions for consent | Articles 5,6,7 and 9 | Sections 35-37, Section 38(1), Section 39(1), Section 40 | Sections 86-91 |
Data subject rights | Articles 12-22 | Sections 44-49 and Sections 52-53 | Sections 93-94 and Section 100 |
Transfers of personal data to a recipient in a third country or an international organisation | Articles 44-49 | Section 73 and Sections 75-78 | Section 109 |
Non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the Commissioner | Article 58(2)(f) and Article 58(2)(j) | Section 157(4) | Section 157(4) |
Failure to comply with an information notice, assessment notice or enforcement notice | Article 58(5)(e) and Article 58(6) 108 | Section 157(4) | Section 157(4) |
108 See also section 157(4) DPA 2018.