juris

Section 27: Duty to destroy personal data

Data Protection Act 2017 · PART IV: OBLIGATIONS ON CONTROLLERS AND PROCESSORS

as enacted (not consolidated). juris shows this Act from a copy that is not the official consolidation, so it may not carry every amendment; the amendments juris holds are listed. It does not confirm that this is the law in force today.

27. Duty to destroy personal data (1) Where the purpose for keeping personal data has lapsed, every controller shall – (a) destroy the data as soon as is reasonably practicable; and (b) notify any processor holding the data. (2) Any processor who receives a notification under subsection (1)(b) shall, as soon as is reasonably practicable, destroy the data specified by the controller.

Ask juris about this section Official source