Guidance

HMRC appropriate policy document

The HMRC appropriate policy document provides information about the legal basis and safeguards that the department has put in place for sensitive processing, the processing of special categories of personal data and criminal offence data.

Documents

Details

The Data Protection Act 2018 requires organisations who process personal data to meet certain legal obligations.

This document outlines where the processing of special categories of personal data, criminal offence data and sensitive personal data is required for:

  • performing or exercising obligations or rights, which are imposed or conferred by law on the controller or the data subject in connection with employment, social security or social protection
  • reasons of substantial public interest
  • archiving, research and statistical purposes
  • law enforcement purposes

Additionally it provides information about the safeguards that HMRC has put in place in accordance with the Data Protection principles, including our policy for the retention and erasure of personal data.

Updates to this page

Published 8 May 2019
Last updated 30 April 2026 + show all updates
  1. Technical changes were made to reflect the introduction of UK GDPR in January 2021 and further technical changes were made to reflect updates to the UK GDPR following the implementation of the Data (Use and Access) Act 2025. We have updated the HTML attachment to include information in section 3 relating to Article 6(f). Sections 4 and 7 have also been updated to refer to Article 84B instead of Article 89(1).

  2. A section with information about 'Lawful basis for Processing' has been added.

  3. First published.

Sign up for emails or print this page