VerbatimParliament, as it happens

Technology: Data Protection

Asked by Mr Andrew SnowdenConservativeDepartment for Science, Innovation and TechnologyTabled Answered 27 January 2026UIN 106650

The question

To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the effectiveness of current obligations of tech companies to communicate to customers about how their data will be used.

Answered by Ian Murray

The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA) impose obligations on tech companies to process customers’ personal data lawfully, fairly, transparently and securely, unless certain limited exemptions apply. Organisations must only process personal data where there are legitimate grounds to do so, and be clear with people about how and why their data is being used, such as through privacy notices.

The data protection legislation is monitored and enforced independently of Government by the Information Commissioner’s Office (ICO). The ICO has published guidance on transparency requirements here: https://ico.org.uk/for-organisations/advice-and-services/audits/data-protection-audit-framework/toolkits/accountability/transparency/.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim