United Kingdom · Data Protection Act 2018, Part 3

Run law-enforcement processing on the regime that actually governs it

For police forces, prosecutors, and other competent authorities — AccessPoint runs s.45 subject access on the strict one-month clock, the case-by-case s.45(4) restrictions and neither-confirm-nor-deny, sensitive-processing policy documents, s.62 logging, and 72-hour breach notification.

United Kingdom — DPA 2018 Part 3 at a glance

Access deadline
One month, with extension only in the limited circumstances Part 3 allows
Restrictions
s.45(4) applied case by case, with the reason recorded and the data subject informed unless that would prejudice the purpose
NCND
Neither confirm nor deny, where confirming would itself prejudice a law-enforcement purpose
Sensitive processing
An appropriate policy document in place and reviewed
Breach
72 hours to the ICO where the duty is engaged
Languages
English

Built for United Kingdom — DPA 2018 Part 3

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

s.45 subject access

Run the Part 3 right of access on the one-month clock — a tighter regime than UK GDPR, with far less room to extend — and produce a response that identifies what was restricted and on what basis.

Case-by-case s.45(4) restrictions

Part 3 restrictions are not exemptions to be claimed wholesale. Each one is applied to a specific piece of information for a stated reason, recorded on the file — which is precisely what an ICO complaint asks to see.

Neither confirm nor deny

Where confirming that information exists would itself prejudice a law-enforcement purpose, record the NCND decision, its authoriser, and its rationale, and issue a response consistent with it.

s.62 logging

Part 3 requires logs of consultation and disclosure in automated systems. AccessPoint's hash-chained audit ledger records who accessed what and when, in a form that can be produced rather than asserted.

Appropriate policy documents

Keep the sensitive-processing policy document current, versioned, and linked to the processing it authorises, with review dates that surface before they lapse.

In your own tenant

Law-enforcement data stays inside your own Microsoft 365 and Azure tenant — a material consideration when the data concerns live operations.

Part 3 is not UK GDPR

Running law-enforcement subject access on a UK GDPR workflow is the most common way to get it wrong.

Competent authorities frequently process under both regimes, and the temptation is to run one process for both. Part 3 does not permit that. Its clock is tighter and its extension grounds narrower. Its restrictions under s.45(4) must be applied to specific information for stated reasons rather than claimed as categories, and the data subject must generally be told that a restriction was applied — unless saying so would itself cause the prejudice. It carries a logging duty under s.62 that UK GDPR does not, and an appropriate policy document requirement for sensitive processing. AccessPoint ships Part 3 as its own pack with its own clock, vocabulary, and restriction model, so a force running both regimes runs each correctly instead of averaging them.

A tighter clock One month, with narrower grounds to extend than UK GDPR.
Per-item restrictions s.45(4) justified against specific information, not claimed.
Logs you can produce s.62 consultation and disclosure logging, on the ledger.

Configured out of the box

Installing the uk-dpa-le jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • DPA 2018 Part 3 as the legal-authority spine, distinct from the UK GDPR pack
  • The s.45 one-month access clock with Part 3's limited extension grounds
  • The s.45(4) restrictions modelled per item, with reasons recorded and notification handling
  • Neither-confirm-nor-deny decisions with authoriser and rationale
  • Appropriate policy document management for sensitive processing, versioned and review-dated
  • s.62 logging of consultation and disclosure via the hash-chained audit ledger
  • 72-hour ICO breach notification and data-subject communication workflows
  • Response templates carrying Part 3 wording rather than UK GDPR wording

United Kingdom — DPA 2018 Part 3 Questions

Who processes under Part 3 rather than UK GDPR?

Competent authorities — police forces, prosecutors, and other bodies with statutory law-enforcement functions — when they process for law-enforcement purposes. The same organization's HR and corporate processing generally falls under UK GDPR, which is why AccessPoint ships the two as separate packs that can run side by side in one tenant.

How are s.45(4) restrictions different from FOIA exemptions?

They are applied case by case to specific information, for a reason that must be recorded, and the data subject must generally be informed that a restriction was applied and of their right to complain to the ICO — unless providing that information would itself prejudice the purpose. They are not categories to be claimed across a whole file, and the ICO has been clear that blanket application is not compliance.

Does AccessPoint satisfy the s.62 logging duty?

It records consultation and disclosure of the records it holds in a hash-chained, append-only audit ledger with server-side integrity verification, which is the evidence s.62 contemplates for the processing within AccessPoint. Logging obligations across your other operational systems remain those systems' responsibility.

Where does law-enforcement data reside?

Entirely within your own Microsoft 365 and Azure tenant, under your existing security controls and your own conditional access — no third-party cloud, no vendor access, and no cross-border transfers.

Run DPA 2018 Part 3 in Your Own Tenant

Try AccessPoint free for 30 days, configured for law-enforcement processing. No credit card required.

Start Free Trial