juris

Section 32: Data matching

Data Protection Act · PART IV: OBLIGATION ON DATA CONTROLLERS

repealed (no longer in force). juris shows the text as it was consolidated; it does not confirm that this is the law in force today. The records juris holds show this law as repealed.

32. Data matching (1) No data controller shall carry out a data matching procedure unless— (a) (i) the data subject whose personal data is the subject of that procedure has given his consent to the procedure being carried out; (ii) the Commissioner has consented to the procedure being carried out; and (iii) the procedure is carried out in accordance with such conditions as the Commissioner may impose; or (b) it is required or permitted under any other enactment. (2) Subject to subsection (3), a data controller shall not take any adverse action against any data subject as a consequence of the carrying out of a data matching procedure— (a) unless the data controller has served a notice in writing on the data subject— (i) specifying the adverse action it proposes to take and the reasons therefor; (ii) stating that the data subject has 7 days after the receipt of the notice to show cause why the adverse action should not be taken; and (b) until the expiry of the 7 days specified in paragraph (a). D3 – 19 [Issue 3] Data Protection Act (3) Subsection (2) shall not preclude a data controller from taking any adverse action against any data subject if compliance with the requirements of that subsection shall prejudice any investigation into the commission of any offence which has been, is being or is likely to be committed. (S. 32 came into operation on 16 February 2009.) PART V – THE DATA PROTECTION REGISTER

Ask juris about this section Official source