Back to Frameworks

UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018

United Kingdom
vSI 2018/356 as amended by SI 2019/742 reg. 133 (revised text valid from 31 December 2020; checked up to date on legislation.gov.uk 2026-09-30)
2 domains
14 controls

The UK rule that lets a business or public body monitor or record calls, email, messaging and network traffic on its own telecommunication system without both parties' consent: the controller effects or expressly consents to the interception, the purpose is one of the seven listed (facts, regulatory compliance, standards, national security, crime, unauthorised use, effective operation) or monitoring-only to sort business communications or supervise a free anonymous helpline, the interception is solely for business communications on a system provided for the business, and all reasonable efforts have been made to tell every user. Built from the revised text on legislation.gov.uk with the Act's offence and civil liability context.

Verified

UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 is a compliance framework from United Kingdom with 2 domains and 14 controls that map to 2 other frameworks. The largest domains are Regulation 3: Lawful interception of communications – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 (10 controls), Regulation 4: Restrictions on lawful interception – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (2)

Regulation 3: Lawful interception of communications – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018

10 controls
Controls in the Regulation 3: Lawful interception of communications – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 domain of UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 — 10 controls
CodeTitle
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(1)(a)Regulation 3(1)(a) Interception effected by, or with the express consent of, the system controller
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(a)Regulation 3(2)(a) Purpose: to establish the existence of facts
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(b)Regulation 3(2)(b) Purpose: to ascertain compliance with regulatory or self-regulatory practices or procedures
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(c)Regulation 3(2)(c) Purpose: to ascertain or demonstrate standards achieved or to be achieved by users in the course of their duties
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(d)Regulation 3(2)(d) Purpose: in the interests of national security
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(e)Regulation 3(2)(e) Purpose: preventing or detecting crime
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(f)Regulation 3(2)(f) Purpose: investigating or detecting unauthorised use of a telecommunication system
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(2)(g)Regulation 3(2)(g) Purpose: securing, or as an inherent part of, the effective operation of the system
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(3)Regulation 3(3) Monitoring only: determining whether communications relate to the business
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::3(4)Regulation 3(4) Monitoring only: calls to a free, anonymous confidential counselling or support service

Regulation 4: Restrictions on lawful interception – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018

4 controls
Controls in the Regulation 4: Restrictions on lawful interception – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 domain of UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 — 4 controls
CodeTitle
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::4(1)(a)Regulation 4(1)(a) Sole purpose: monitoring or recording communications relevant to the business
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::4(1)(b)Regulation 4(1)(b) The system is provided for use wholly or partly in connection with the business
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::4(1)(c)Regulation 4(1)(c) All reasonable efforts to inform every user that communications may be intercepted
uk-investigatory-powers-interception-by-businesses-etc-for-monitoring-and-record-keeping-purposes-regulations-2018::4(1)(d)Regulation 4(1)(d) National security interception only by or for a person listed in section 18(1)(a) to (g)

Maps to 2 other frameworks

14 total controls
ISO 27001:2022
3 source controls mapped|2 target controls covered
21%
UK GDPR (UK General Data Protection Regulation)
2 source controls mapped|2 target controls covered
14%

Coverage is not the same as your position

This page shows what UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 and who does it apply to?

UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 is a compliance framework from United Kingdom with 2 domains and 14 controls. The UK rule that lets a business or public body monitor or record calls, email, messaging and network traffic on its own telecommunication system without both parties' consent: the controller effects or expressly consents to the interception, the purpose is one of the seven listed (facts, regulatory compliance, standards, national security, crime, unauthorised use, effective operation) or monitoring-only to sort business communications or supervise a free anonymous helpline, the interception is solely for business communications on a system provided for the business, and all reasonable efforts have been made to tell every user. Built from the revised text on legislation.gov.uk with the Act's offence and civil liability context. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 actually require?

UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 has 14 controls organised across 2 domains. The largest domains are Regulation 3: Lawful interception of communications – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 (10 controls), Regulation 4: Restrictions on lawful interception – UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 do I already cover?

UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 maps to 2 other compliance frameworks. The top mapping partners are ISO 27001:2022 (21% coverage), UK GDPR (UK General Data Protection Regulation) (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018?

Start your UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Investigatory Powers (Interception by Businesses etc. for Monitoring and Record-keeping Purposes) Regulations 2018 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 14 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 820 frameworks.

Get Started Free →

Free forever — no credit card required