Skip to main content
Legal4 March 2026• 11 min read

GDPR for UK Journalists: What You Actually Need to Know

Data protection law is one of those areas that makes most journalists' eyes glaze over — until they receive a subject access request or a complaint from someone demanding their personal data be deleted from a published article. Here is a clear, practical guide to how the UK GDPR actually affects your daily work.

10 min read

Last reviewed: Next review due:

Quick answer

Section 26 of the Data Protection Act 2018 gives UK journalists a broad exemption from most UK GDPR obligations — including consent, the right to erasure, and subject access requests — where processing is for a journalistic purpose, serves the public interest, and compliance would be incompatible with that purpose; data breaches still require ICO notification within 72 hours, and the exemption does not eliminate the duty to handle personal data responsibly.

This guide is for staff and freelance reporters who handle interview recordings, leaked documents, and source contact details; editors deciding how to respond to subject access requests and erasure demands; investigative journalists building case files on named individuals and companies; data journalists processing bulk datasets containing personal information; and student journalists who need to understand the journalism exemption before their first data protection complaint arrives.

UK GDPR Basics: What It Is and Why It Matters

After Brexit, the EU GDPR was incorporated into UK law as the UK General Data Protection Regulation, supplemented by the Data Protection Act 2018. Together, these form the UK's data protection framework, enforced by the Information Commissioner's Office (ICO).

The UK GDPR regulates the processing of personal data — any information relating to an identified or identifiable living individual. This includes names, photographs, email addresses, IP addresses, and any other information that could identify someone directly or indirectly.

For journalists, this matters because virtually every story involves personal data. You process personal data when you:

  • Interview someone and record their responses
  • Photograph or film individuals
  • Name people in articles
  • Store contact details for sources
  • Research individuals' backgrounds using public records or social media
  • Handle leaked documents containing personal information

The Journalism Exemption: Section 26 DPA 2018

The good news is that UK law provides a specific and substantial exemption for journalism. Section 26 of the Data Protection Act 2018 (known as the “special purposes” exemption) disapplies most of the UK GDPR's requirements where personal data is processed for the purposes of journalism, provided three conditions are met:

  1. The processing is carried out with a view to the publication of journalistic material
  2. The data controller reasonably believes that publication would be in the public interest
  3. The data controller reasonably believes that compliance with the relevant provision of the UK GDPR is incompatible with the journalistic purpose

What the exemption covers: When it applies, the journalism exemption disapplies most data protection principles (including the right to erasure, the right to object, and requirements for consent), as well as the individual rights provisions. This means you do not need someone's consent to process their personal data for a legitimate journalistic purpose.

What “Public Interest” Means in Practice

The public interest test is central to the journalism exemption. The ICO has published guidance stating that public interest includes (but is not limited to):

  • Exposing crime, corruption, or serious wrongdoing
  • Protecting public health and safety
  • Preventing the public from being misled
  • Holding public figures and institutions to account
  • Promoting transparency in matters of public concern

Public interest is not the same as “interesting to the public.” Celebrity gossip or prurient material that merely satisfies curiosity is unlikely to meet the public interest threshold. However, the test is applied broadly, and the ICO has shown considerable deference to journalistic judgment in this area.

Subject Access Requests: How to Respond

Under Article 15 of the UK GDPR, individuals have the right to request access to personal data held about them. Journalists and media organisations do receive SARs, particularly from individuals who are the subject of investigations or critical reporting.

However, the journalism exemption can apply to SARs. If complying with a subject access request would compromise a journalistic investigation or reveal confidential sources, you may be exempt from the requirement to respond. Key points:

  • Do not ignore SARs: Even if the journalism exemption applies, acknowledge the request and explain (in general terms) that the data is being processed for journalistic purposes.
  • Assess each request individually: The exemption is not automatic — you must genuinely believe that compliance would be incompatible with your journalistic purpose.
  • Never reveal confidential sources in response to a SAR. Source protection is a legitimate reason to refuse disclosure.
  • Seek legal advice for complex or contentious SARs, particularly those that appear designed to obstruct an investigation.

Lawful Basis and the Special Category Data Problem

Even with the journalism exemption disapplying most of the UK GDPR's machinery, you still need a lawful basis for processing personal data under Article 6, and an additional condition under Article 9 if the data falls into a “special category” — health, sexual orientation, criminal allegations, ethnicity, religious or political beliefs, and trade union membership. For most journalism, the relevant Article 6 basis is “legitimate interests,” supported by the specific journalism provisions in Schedule 2 and Schedule 1 (paragraph 36) of the DPA 2018 for special category data processed for journalistic purposes.

  • Criminal offence data: Reporting that someone has been charged, convicted, or is under investigation involves criminal offence data under Article 10, which has its own separate condition requirement, again met through the journalism-specific provisions in the DPA 2018.
  • Sensitive personal circumstances: Health conditions, sexuality, and immigration status disclosed by interviewees require particular care — confirm the person understands what will be published and consider whether identifying detail is genuinely necessary to the story.
  • Data minimisation still applies in spirit: Even though the exemption disapplies the strict data minimisation principle, good practice is to hold only what your story genuinely requires and to avoid retaining excessive personal detail “just in case.”

Data Breaches: What You Need to Know

A data breach is any incident that leads to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data. For journalists, common breach scenarios include:

  • Losing an unencrypted USB drive or laptop containing source material
  • Accidentally sending confidential information to the wrong recipient
  • Having your email or cloud storage compromised by hackers
  • Inadvertently publishing personal data that should have been redacted

Under the UK GDPR, data controllers must report certain breaches to the ICO within 72 hours. If you are a freelancer, you are the data controller for the personal data you process. If you work for a publication, your employer should have a breach reporting procedure — follow it immediately.

Critical: If a breach involves confidential source material, the consequences go beyond data protection compliance. A breach could endanger your source, compromise an investigation, and destroy professional trust. Treat data security as seriously as you treat editorial integrity.

Practical Data Handling Tips for Journalists

Even with the journalism exemption, responsible data handling is both a legal and ethical obligation. Here are practical steps every UK journalist should take:

  1. Encrypt your devices: Enable full-disk encryption on your laptop, phone, and any external storage. This is the single most important security measure you can take.
  2. Use secure communications: Signal for messaging, ProtonMail for sensitive emails. Standard SMS and unencrypted email are not secure for confidential source communication.
  3. Minimise data collection: Only collect and retain personal data that you genuinely need for your journalistic purpose. Delete data you no longer require.
  4. Secure your cloud storage: Use strong, unique passwords and two-factor authentication on all accounts. Consider where your data is physically stored — UK or EU-based services may be preferable for GDPR compliance.
  5. Redact carefully: When publishing documents, ensure redactions are genuine — metadata in PDFs and other formats can reveal information you intended to conceal. Use proper redaction tools, not simply black highlighting.
  6. Have a data retention policy: Decide how long you will keep research material and source data after publication. There is no fixed legal requirement, but keeping personal data indefinitely without a clear purpose is difficult to justify.

The Right to Be Forgotten and Journalism

Article 17 of the UK GDPR gives individuals the right to have their personal data erased (the “right to be forgotten”). However, this right does not override the journalism exemption. If someone asks you to remove their name from a published article, you are not obliged to comply if the article was published in the public interest.

That said, consider each request on its merits. There may be cases where updating or amending an article is the right thing to do — for example, if factual errors are identified or if the individual's circumstances have changed significantly. Good journalism involves ongoing editorial responsibility, not just legal compliance.

International Data Transfers and Cross-Border Investigations

Collaborative cross-border investigations — increasingly common through networks such as the International Consortium of Investigative Journalists — raise a further layer of data protection complexity. Transferring personal data (leaked databases, source contact lists, document caches) to journalists or partner organisations outside the UK is technically a “restricted transfer” under UK GDPR Chapter 5, even though the journalism exemption still applies to the underlying processing purpose.

  • Adequacy decisions: Transfers to the EU/EEA and countries covered by a UK adequacy decision (including most of the EU's adequacy list) do not require additional safeguards. Transfers to other jurisdictions may require standard contractual clauses or reliance on a specific derogation.
  • Practical approach: Most cross-border journalism collaborations rely on the position that data shared for a joint journalistic investigation, in the public interest, falls within the spirit of the journalism exemption framework, but it is good practice to document the public interest justification for the transfer itself, not just the eventual publication.
  • Secure transfer methods: Use encrypted transfer tools (SecureDrop, encrypted archives with separately transmitted passwords) rather than standard email attachments when sharing source material with international partners.

FOI and Data Protection: How They Interact

If you use Freedom of Information requests in your journalism, be aware that public bodies can refuse to disclose information if doing so would breach data protection principles. Section 40 of the Freedom of Information Act 2000 exempts personal data from disclosure where release would contravene the UK GDPR.

This does not mean all personal data is automatically exempt — the public body must conduct a balancing test between the individual's privacy rights and the public interest in disclosure. If you believe a refusal under Section 40 is unjustified, you can appeal to the ICO.

Practical Checklist

Run through these on any story that involves handling personal data at scale, or that concerns a named individual's private circumstances:

Common Mistakes

  • Assuming the journalism exemption is automatic: It is not — you must be able to show a genuine, contemporaneous belief that compliance with the relevant GDPR provision was incompatible with your journalistic purpose.
  • Ignoring SARs entirely: Even where the exemption clearly applies, failing to acknowledge a subject access request at all looks evasive and can itself become a complaint to the ICO.
  • Ignoring the 72-hour breach clock: Many freelancers do not realise they are personally the data controller for their own source material and are therefore personally responsible for breach notification.
  • Publishing unredacted document metadata: Leaked PDFs and Word documents frequently retain author names, tracked changes, and organisational metadata that can expose a source even when the visible text has been redacted.
  • Treating “right to be forgotten” requests as automatically valid: Article 17 does not override the journalism exemption for genuinely public-interest reporting — but every request still deserves individual consideration.
  • Confusing GDPR redaction with legal privilege: Withholding a source's identity from a SAR response is a source-protection decision, not primarily a data protection technicality — treat it with the same seriousness as any other confidentiality obligation.

Red Flags to Watch For

  • A SAR or erasure request arrives shortly before a scheduled publication date, suggesting an attempt to disrupt rather than a genuine access request
  • Your organisation has no documented breach response procedure or ICO reporting contact
  • Source material is stored on unencrypted personal devices or shared consumer cloud accounts without 2FA
  • A story relies on special category data (health, sexuality, ethnicity) where the public interest justification has not been clearly documented
  • Metadata has not been checked before a leaked document is published or shared with colleagues

Jurisdiction notes: UK GDPR and the Data Protection Act 2018 apply uniformly across England, Wales, Scotland, and Northern Ireland — data protection is a reserved matter, unlike defamation or much of media regulation. The ICO is the single regulator for the whole of the UK. However, journalists working across the Irish border should note that the Republic of Ireland remains subject to the EU GDPR, which has its own journalism derogation implemented through Irish data protection law — the frameworks are similar but not identical, and cross-border investigations involving Irish subjects may need to consider both regimes.

Further Resources

Related guides

Primary sources

Related articles