Skip to main content
GDPR Accessioning: What Changed on 25 May 2018Laws & Regulations
5 min readFor Archivists and Digital Preservation Specialists

GDPR Accessioning: What Changed on 25 May 2018

When the Data Protection Act 2018 replaced its 1998 predecessor on 25 May 2018, archivists gained something unexpected: explicit recognition in data protection law. The new framework, aligned with GDPR, introduces "Accessioning in the public interest" as a distinct legal basis with adapted compliance requirements. If you manage archival collections containing personal data, you're now operating under different rules than standard data controllers.

Scope

This guide covers archival processing of personal data under the Data Protection Act 2018 and GDPR. It applies to:

  • Archive services transferring records containing personal information
  • Digital preservation specialists managing collections with identifiable individuals
  • Records managers preparing transfers to archival custody
  • Information governance teams advising on archival exemptions

This guide does NOT cover active records management, marketing databases, or operational data processing outside archival contexts.

Key Concepts and Definitions

Accessioning in the public interest: A processing basis under Article 89 GDPR and Part 5, Schedule 2 of the Data Protection Act 2018. It permits retention of personal data beyond normal storage limitation periods when specific safeguards are implemented.

Adapted requirements: Under Accessioning in the public interest, certain GDPR obligations apply differently. You're not exempt from data protection law; you operate under modified rules.

Specified safeguards: Technical and organizational measures required to invoke archival processing exemptions. These aren't optional add-ons; they're preconditions for using the adapted framework.

Transfer to archival custody: The point at which operational records become archival collections. This transition changes your legal obligations and available exemptions.

Requirements Breakdown

Article 89 GDPR: Research and Accessioning

Article 89(1) requires "appropriate safeguards" for archival processing. The Data Protection Act 2018 specifies these in Part 5, Schedule 2, Paragraph 27.

Core requirement: Implement technical and organizational measures ensuring personal data is processed only when necessary for archival purposes. You can't invoke archival exemptions without demonstrating these safeguards.

Adapted GDPR Rights

When processing under Accessioning in the public interest with appropriate safeguards:

Storage limitation (Article 5(1)(e)): You may retain personal data indefinitely if retention serves the archival purpose. Document your appraisal decision and public interest justification.

Right to rectification (Article 16): You may refuse rectification requests if rectification would compromise the archival record's integrity. You must explain this to the data subject and note their objection in your catalog or finding aid.

Initial notification (Article 13-14): You're not required to notify individuals when you acquire their personal data through archival transfer, provided the information comes from existing records and notification would require disproportionate effort.

Data Protection Act 2018 Provisions

Part 5, Schedule 2 extends GDPR's archival framework. Pay attention to:

Paragraph 27: Defines "Accessioning purposes" as preservation in the public interest, including historical research and statistical purposes. Your processing must fit this definition to use adapted requirements.

Paragraph 28: Permits processing of special category data (health, ethnicity, political opinions) for archival purposes without explicit consent, if you meet safeguard requirements and processing is necessary for your archival mission.

Implementation Guidance

Establish Your Safeguards

Before claiming archival exemptions, implement and document:

Access controls: Restrict personal data access to staff with legitimate archival duties. Use role-based permissions in your catalog system. Consider a scenario where your reading room provides public access to digitized collections: you need technical measures preventing bulk download of personal data while allowing legitimate research access.

Pseudonymization where feasible: In catalog descriptions and finding aids, use initials or reference numbers instead of full names when the archival purpose doesn't require identification. A probate record might be cataloged as "Estate of J.S., 1923" rather than listing the full name in your public-facing database.

Researcher agreements: Require researchers to sign data protection agreements before accessing collections with personal data. Specify permitted uses and prohibit re-identification attempts.

Retention documentation: Maintain appraisal reports explaining why each collection serves the public interest. Your justification should reference specific research value, historical significance, or accountability purposes.

Handle Rights Requests

When you receive a subject access request:

  1. Verify the requester's identity using your standard verification process.
  2. Search your catalog and finding aids for relevant records.
  3. If providing access would compromise others' privacy, redact third-party personal data before disclosure.
  4. If rectification is requested, assess whether it would damage the record's evidential value.
  5. Document your decision and reasoning in your case file.

For erasure requests ("right to be forgotten"), explain that archival retention serves public interest purposes under Article 89 and you've implemented appropriate safeguards. Provide your contact details for the Information Commissioner's Office if they wish to appeal.

Cloud and Social Media Archives

The National Archives' guidance specifically addresses modern archival contexts. If you're preserving social media content or cloud-based records:

Social media: A politician's public tweets may constitute archival records. You can capture and preserve these without individual consent under Accessioning in the public interest, but you must restrict access appropriately. Public tweets don't automatically become public archival records; apply your standard sensitivity review.

Cloud transfers: When receiving records from cloud platforms, verify that the transferring organization had a lawful basis for the original processing. Your archival basis doesn't retroactively legitimize unlawful collection.

Common Pitfalls

Assuming blanket exemption: Accessioning in the public interest doesn't exempt you from all GDPR obligations. You still must process lawfully, maintain security, and respond to rights requests. You're adapting requirements, not ignoring them.

Skipping safeguard implementation: You can't claim adapted requirements without first implementing appropriate safeguards. Document your measures before invoking archival exemptions.

Over-restricting access: Some archivists respond to GDPR by closing everything containing personal data. This defeats your archival mission. Instead, implement appropriate safeguards and provide managed access.

Ignoring appraisal: Not everything containing personal data qualifies for archival retention. Apply your standard appraisal criteria; GDPR doesn't change what's historically valuable.

Failing to document decisions: When you refuse rectification or erasure, document your reasoning. "It's an archival record" isn't sufficient; explain the specific public interest and why modification would compromise that interest.

Quick Reference Table

GDPR Requirement Standard Application Archival Adaptation Your Action
Storage limitation (Art. 5(1)(e)) Delete when purpose fulfilled Retain indefinitely if archival purpose continues Document appraisal decision and public interest
Rectification (Art. 16) Correct inaccurate data May refuse if damages record integrity Note objection in catalog; explain to requester
Erasure (Art. 17) Delete on request May refuse for public interest Accessioning Demonstrate safeguards; cite Article 89
Initial notification (Art. 13-14) Notify at collection Exemption if disproportionate effort Document why notification is impractical
Special category data (Art. 9) Requires explicit consent Permitted for archival purposes Implement safeguards per Schedule 2, Para. 28

The Data Protection Act 2018 didn't eliminate archival processing; it formalized it. Your job remains preserving collective memory. Now you have a defined legal framework for doing it compliantly.

You Might Also Like