VerbatimParliament, as it happens

Data Protection: Age Assurance

Asked by James McMurdockIndependentDepartment for Science, Innovation and TechnologyTabled Answered 20 July 2026UIN 17687

The question

To ask the Secretary of State for Science, Innovation and Technology, what assessment she has made of the potential impact of personal data retained by age-assurance providers on levels of a) cyber attacks and b) data breaches.

Answered by Kanishka Narayan

The government takes the threats of cyber-attacks and data breaches very seriously, which is why the ICO has the power to investigate any concerns raised about the misuse or mishandling of data. It can issue enforcement notices and substantial fines where organisations are found to be in breach of their obligations.

Organisations are required under UK GDPR and the Data Protection Act to keep personal data secure and process it fairly, lawfully, and transparently. Whilst the law does not set specific time limits on how long personal data can be held, it stipulates that it cannot be kept for longer than needed.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim