xmlns:atom="http://www.w3.org/2005/Atom" xmlns:atom="http://www.w3.org/2005/Atom"

Regulations 22(2), 23(1) and 34(3)

SCHEDULE 4U.K.CONDITIONS FOR PERMITTED DISCLOSURE

PART 1U.K.Disclosure to Specified Public Authorities

1.  The specified public authority has delivered to the registrar a statement that it intends to use the information only for the purpose of facilitating the carrying out by that specified public authority of a public function (“the permitted purpose”).U.K.

2.  Subject to paragraph 3, the specified public authority has delivered to the registrar a statement that, where it supplies a copy of the information to a processor for the purpose of processing the information for use in respect of the permitted purpose, the specified public authority will—U.K.

(a)ensure that the processor is one who carries on business [F1in the United Kingdom or] in the European Economic Area;

(b)require that the processor does not transmit the information outside the [F2area comprising the United Kingdom and the European Economic Area]; and

(c)require that the processor does not disclose the information except to that specified public authority or an employee of that specified public authority.

3.  Paragraph 2 does not apply where the specified public authority is the National Crime Agency, Secret Intelligence Service, Security Service or Government Communications Headquarters.U.K.

4.  The specified public authority has delivered any information or evidence required by the registrar for the purpose of enabling the registrar to determine in accordance with these Regulations whether to disclose the information.U.K.

5.  The specified public authority has complied with any requirement by the registrar to confirm the accuracy of the statements, information or evidence delivered to the registrar pursuant to this Part of this Schedule.U.K.

PART 2U.K.Disclosure to a Credit Reference Agency

6.  The credit reference agency—U.K.

(a)is carrying on in the United Kingdom F3... a business comprising the furnishing of information relevant to the financial standing of individuals, being information collected by the agency for that purpose;

(b)maintains appropriate procedures—

(i)to ensure that an independent person can investigate and audit the measures maintained by the agency for the purposes of ensuring the security of any information within section 790ZF(2) of the Act disclosed to that agency; and

[F4(ii)for the purposes of ensuring that it complies with its [F5obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018)];]

(c)has not been found guilty of an offence under—

(i)[F6section 1112 (false statements: basic offence) or 1112A (false statements: aggravated offence) of the Act];

(ii)section 2 of the Fraud Act 2006 M1 (fraud by false representation); F7...

(iii)section 47 of the Data Protection Act 1998 (failure to comply with enforcement notice) in circumstances where it has used the information within section 790ZF(2) of the Act for purposes other than those described in sub-paragraphs (a) to (e) of paragraph 8;

[F8(iv)section 144 of the Data Protection Act 2018 (false statements made in response to an information notice); or

(v)section 148 of that Act (destroying or falsifying information and documents etc);]

[F9(d)has not been given a penalty notice under section 155 of the Data Protection Act 2018 in circumstances described in sub-paragraph (c)(iii), other than a penalty notice that has been cancelled.]

Textual Amendments

Marginal Citations

7.  The credit reference agency has delivered to the registrar a statement that it meets the conditions in paragraph 6.U.K.

8.  The credit reference agency has delivered to the registrar a statement that it intends to use the information within section 790ZF(2) of the Act only for the purposes of—U.K.

(a)providing an assessment of the financial standing of a person;

(b)meeting any obligations contained in—

(i)[F10the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017]; [F11or]

(ii)any rules made pursuant to section 137A of the Financial Services and Markets Act 2000 M2 which relate to the prevention and detection of money laundering in connection with the carrying on of regulated activities by authorised persons; F12...

F12(iii). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

(c)conducting conflict of interest checks required or made necessary by any enactment;

(d)providing information within section 790ZF(2) of the Act to—

[F13(i)a person to whom the registrar could disclose information under section 1110F (disclosure by the registrar) of the Act; or]

(ii)a credit reference agency which has satisfied the requirements of this Part of this Schedule; or

(e)conducting checks for the prevention and detection of crime and fraud.

9.  The credit reference agency has delivered to the registrar a statement that it intends to take delivery of and to use the information within section 790ZF(2) of the Act only in the United Kingdom F14....U.K.

10.  The credit reference agency has delivered to the registrar a statement that it will, where it supplies a copy of the information within section 790ZF(2) of the Act to a processor for the purpose of processing the information for use in respect of the purposes referred to in paragraph 8—U.K.

(a)ensure that the processor is one who carries on business in the [F15United Kingdom];

(b)require that the processor does not transmit the information outside the [F16United Kingdom]; and

(c)require that the processor does not disclose the information except to the credit reference agency or an employee of the credit reference agency.

11.  The credit reference agency has delivered any information or evidence required by the registrar for the purpose of enabling the registrar to determine in accordance with these Regulations whether to disclose the information within section 790ZF(2) of the Act.U.K.

12.  The credit reference agency has complied with any requirement by the registrar to confirm the accuracy of the statements, information or evidence delivered to the registrar pursuant to this Part of this Schedule.U.K.

[F17PART 2AU.K.Disclosure to a Credit Institution or a Financial Institution

12A.  The credit institution or financial institution maintains appropriate procedures—U.K.

(a)to ensure that an independent person can investigate and audit the measures maintained by that institution for the purposes of ensuring the security of any information disclosed to it; and

[F18(b)for the purposes of ensuring that it complies with its [F19obligations under the data protection legislation (as defined in section 3 of the Data Protection Act 2018)].]

12B.  The credit institution or financial institution has delivered to the registrar a statement confirming that it is a credit institution or, as the case may be, a financial institution, and that it meets the conditions in paragraph 12A.U.K.

12C.  The credit institution or financial institution has delivered to the registrar a statement that it intends to use information only for the purpose of applying customer due diligence measures to the company in relation to which the information is secured, in accordance with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.U.K.

12D.  The credit institution or financial institution has delivered to the registrar a statement that confirms the name and registered number of the company it is entering a transaction with which requires the institution to apply customer due diligence measures under those Regulations.U.K.

12E.  The credit institution or financial institution has delivered to the registrar a statement that it intends to take delivery of and to use the information only in the United Kingdom.U.K.

12F.  The credit institution or financial institution has delivered to the registrar a statement that it will, where it supplies a copy of the information to a processor for the purpose of processing the information for use in respect of the purpose referred to in paragraph 12C—U.K.

(a)ensure that the processor is one who carries on business in the [F20United Kingdom];

(b)require that the processor does not transmit the information outside the [F21United Kingdom]; and

(c)require that the processor does not disclose the information except to the credit institution or financial institution.

12G.  The credit institution or financial institution has delivered any information or evidence required by the registrar for the purpose of enabling the registrar to determine in accordance with these Regulations whether to disclose the information.U.K.

12H.  The credit institution or financial institution has complied with any requirement by the registrar to confirm the accuracy of the statements, information or evidence delivered to the registrar pursuant to this Part.]U.K.

PART 3U.K.Interpretation of this Schedule

13.  In this Schedule—U.K.

(a)processor” means any person who provides a service which consists of putting information into data form or processing information in data form and any reference to a processor includes a reference to the processor's employees;

(b)public function” includes—

(i)any function conferred by or in accordance with any provision contained in any enactment M3;

F22(ii). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

(iii)any similar function conferred on persons by or under provisions having effect as part of the law of a country or territory outside the United Kingdom; and

(iv)any function exercisable in relation to the investigation of any criminal offence or for the purpose of any criminal proceedings;

(c)any reference to an employee of any person who has access to information within section 790ZF(2) of the Act includes any person working or providing services for the purposes of that person or employed by or on behalf of, or working for, any person who is so working or who is supplying such a service; and

(d)any reference to the disclosure for the purpose of facilitating the carrying out of a public function includes disclosure in relation to, and for the purpose of, any proceedings whether civil, criminal or disciplinary in which the specified public authority engages while carrying out its public functions.

Textual Amendments

Marginal Citations

M3See section 1293 of the Act for the meaning of “enactment”; section 1293 was amended by section 90(4) of the Small Business, Enterprise and Employment Act 2015 (c.26).

F2314  . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .U.K.