Frameworks / UK Data Protection Act 2018 / UK-DPA18-LE-03 UK Data Protection Act 2018
Law Enforcement Processing (Part 3)
UK Data Protection Act 2018 UK-DPA18-LE-03: International Transfers (Law Enforcement) Transfers of law enforcement personal data outside the UK require adequacy decision, appropriate safeguards, or specific conditions. Enhanced safeguards for sensitive data.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 170 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
GDPR-Art.10 Processing of personal data relating to criminal convictions GDPR-Art.11 Processing which does not require identification GDPR-Art.15 Right of access by the data subject GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction GDPR-Art.45 Transfers on the basis of an adequacy decision GDPR-Art.9 Processing of special categories of personal data APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information APP-8 APP 8 - Cross-border disclosure of personal information BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-17 Section 24 - Appropriate Safeguards BB-DPA-21 Sections 61-69 - Data Privacy Officer APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing SOC2-P3.1 Personal information is collected consistent with privacy commitments SOC2-P4.3 Personal information is securely disposed of SOC2-P6.1 Personal information is disclosed to third parties only as committed SWE-1 Scope and Purpose SWE-11 Integritetsskyddsmyndigheten (IMY) SWE-2 Relationship to GDPR UGA-13 Unlawful Obtaining or Disclosure UGA-15 Unauthorized Sale of Data P1-S4 Targeting and Communication DS-2 Ensure software supply chain security CA-10 Selects and Develops Control Activities ICP-25 Supervisory Cooperation and Coordination RIDTPPA-11 Data Minimisation and Purpose Limitation OB-CX.2 Granular Consent Management SO3.2 Regulatory frameworks for digital health Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Law Enforcement Processing (Part 3) Query this from an agent The graph holds this control, the 170 it maps to, and the evidence behind each claim, over MCP and REST.