Britain’s privacy regulator has issued new guidance explaining how organisations should protect personal information as the UK prepares to expand Smart Data schemes beyond Open Banking.
The Information Commissioner’s Office published the guidance on October 9 for government departments, regulators, standards bodies and other organisations designing Smart Data systems.
The schemes are intended to let customers securely share their data with authorised third parties so they can access new services, compare products or make better decisions.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
Smart Data Could Move Beyond Banking
The UK’s Data (Use and Access) Act 2025 gives the government powers to create Smart Data schemes in sectors where competition is weak, customer engagement is low or outcomes are poor.
Open Banking is the best-known existing example.
Under a Smart Data model, a customer could allow one organisation to securely share information with another authorised provider through standardised systems.
The aim is to make data portability more useful by allowing continuous or real-time sharing rather than requiring customers to manually request their information each time.
Permission to Share Data Is Not Always GDPR Consent
One of the most important clarifications concerns consent.
The ICO says Smart Data schemes may use the word “consent” to describe a customer giving permission for their information to be shared.
But that permission is not automatically the same as consent under UK GDPR.
An organisation receiving data to provide a service may rely on performance of a contract.
A data holder required by law to share information may rely on a legal obligation.
Some uses could rely on legitimate interests, while genuinely optional features may use consent.
This distinction matters because organisations must identify the correct legal basis for each processing activity instead of assuming that one user click covers everything.
Users Must Still Be Able to Stop Sharing
Even where GDPR consent is not the legal basis, the ICO says people should retain meaningful control over whether data continues to flow through a Smart Data scheme.
Future sharing that depends on the customer’s permission should stop quickly when that permission is withdrawn.
Organisations should also clearly explain what happens to information already shared.
In some cases, that data may still be retained or processed if another lawful basis applies.
The ICO recommends tools such as permission dashboards that allow people to see which organisations have access to their information and withdraw sharing permissions easily.
Companies Must Know Whether They Are Controllers or Processors
The guidance also warns that labels used inside a Smart Data scheme do not automatically determine an organisation’s role under privacy law.
A bank holding customer information may be a controller.
An authorised third party providing a new service may also act as a controller.
A cloud provider that only handles data on documented instructions may instead be a processor.
Some organisations may even become joint controllers if they decide together how and why personal data will be used.
The legal role matters because it determines which GDPR obligations each organisation must meet.
The ICO says participants must assess what they actually do with personal data rather than relying on the label given to them by the Smart Data scheme.
Sharing Data Outside the Scheme Needs Separate Legal Justification
The regulator also addresses what happens when information leaves the controlled Smart Data environment.
An authorised third party may want to pass information to another service provider, affiliate or business partner.
The ICO says that onward sharing is not automatically lawful simply because the information originally came through an authorised Smart Data scheme.
The organisation must still establish a lawful basis, limit the information to what is necessary and clearly tell people who will receive their data and why.
International transfers must also comply with UK GDPR transfer requirements.
Sensitive Data Gets Extra Protection
Smart Data schemes could eventually involve health information, biometric data, religion, race or other categories that receive stronger protection under UK GDPR.
Where such information is processed, organisations need both a normal Article 6 lawful basis and a separate Article 9 condition for special-category data.
The ICO says explicit consent may be necessary in many cases even when the main legal basis for providing the service is contractual.
The regulator also says schemes should be designed so that service providers cannot simply collect sensitive information they do not actually need.
That reflects the GDPR principle of data minimisation.
Privacy Must Be Designed Into the Scheme From the Start
The ICO is pushing scheme designers to build privacy safeguards directly into technical standards and governance rules rather than trying to add them later.
UK GDPR already requires controllers to follow data protection by design and default.
For Smart Data schemes, that could mean clear role allocation, access controls, permission systems, security standards and processes for handling failures or breaches.
The regulator says weak transparency or poor security could damage public trust and undermine adoption of Smart Data itself.
The ICO will not approve individual Smart Data schemes.
Its role is to enforce data-protection law where personal information is processed and assess whether organisations act lawfully, fairly, transparently and securely.
What this means for you
If Smart Data expands beyond banking, users could gain more control over moving information between trusted services. But the ICO is making clear that convenience does not override privacy law: companies must still justify every use of personal data, minimise what they collect and make it easy for people to stop future shar
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics