Census data confidentiality and UK law
Statistics and Registration Service Act 2007 (SRSA)
Census data confidentiality is protected by the Statistics and Registration Service Act 2007 (SRSA).
The SRSA transferred the Census and other statistical functions of the Registrar General for England and Wales to the Statistics Board (UK Statistics Authority) formed on 1 April 2008.
The confidentiality provisions in SRSA and the duty on the Board to maintain confidentiality in the Census in England and Wales have replaced the confidentiality provisions of the Census Act.
Section 39 of the SRSA prohibits the disclosure of personal information with a penalty of imprisonment for a maximum of two years, a fine, or both.
Section 40 states that where personal information is held by or on behalf of the Statistics Board, it is exempt from any disclosure sought under the Freedom of Information Act.
Data Protection Act
The Data Protection Act requires that where data processing is carried out on behalf of a ‘data controller’ (ONS), there must be a written contract that specifies the actions to be carried out by the contractor, and which prohibits any other action. The data controller (ONS) is responsible for upholding the data protection principles and is therefore responsible for the actions of any data processors.