The Information Commissioner’s Office (ICO) recently published draft updated guidance on the research, archiving and statistics (RAS) provisions under UK GDPR. The draft guidance reflects changes introduced to UK data protection law by the Data (Use and Access) Act 2025 (DUAA) and sets out how the ICO is proposing to interpret “research” under UK data protection law. In particular, the amendments to the UK GDPR move research beyond traditional academic or public interest research and recognise the role of commercial and technology-driven research, including the development of AI systems.

What are the RAS provisions?

Under the UK GDPR, the RAS provisions apply where personal information is processed for one of the following purposes:

  1. Archiving in the public interest;
  2. Scientific research;
  3. Historical research; or
  4. Statistical purposes.

These are collectively referred to as “RAS purposes.” For many organisations, the key question is therefore whether their activity genuinely qualifies as “research” for these purposes.

A broader concept of “scientific research”

A key change in the draft guidance is the expanded definition of scientific research. Following the DUAA, the UK GDPR now defines scientific research as:

any research that can reasonably be described as scientific, whether publicly or privately funded and whether carried out as a commercial or non-commercial activity.

This is a significant change. While the concept of research was always intended to be interpreted broadly, the legislation now expressly confirms that commercial research falls within scope. The draft guidance says that this includes activities such as:

  • Technological development or demonstration;
  • Fundamental and applied research; and
  • Public health studies carried out in the public interest.

In practice, this brings a wide range of private sector activity, particularly in the technology sector, squarely within the RAS framework.

The draft guidance sets out four key criteria for determining whether an activity qualifies as “scientific research”:

  1. Scientific objective: the activity must aim to achieve a meaningful improvement in science or technology;
  2. Scientific method: it should be planned, documented and carried out systematically;
  3. Uncertainty: it should seek to address a genuine scientific or technical question; and
  4. Transferability: it should generate knowledge capable of wider use or application.

Organisations seeking to apply the RAS provisions to the use of personal data in their research activities will need to be able to demonstrate that the processing satisfies these requirements.

The draft guidance provides a number of helpful examples, including research by a provider of biometric identification systems to improve the accuracy of its technology and the use by an insurance company of personal data to better understand life expectancy and mortality to help define future pricing strategies.

What makes RAS processing different?

  • Purpose and storage limitation: Data collected for one research purpose may be reused for another compatible research project and can be kept longer if necessary for RAS purposes, provided legal safeguards are in place.
  • Special category and criminal offence data: There are tailored legal bases to enable the processing of sensitive data for RAS, subject to strong protections and documentation requirements.
  • Rights exemptions: Certain rights (such as erasure, rectification, restriction, portability and objection) can be limited where complying would seriously impair or render impossible the research or statistical purpose, provided appropriate safeguards are in place.

What safeguards and steps are required?

Under new Article 84 of UK GDPR, controllers may only process for RAS purposes if it is to collect or anonymise personal data for the RAS purposes or the RAS purposes cannot otherwise be fulfilled without processing personal data. This means if the RAS purpose can be fulfilled using anonymised personal data, then the RAS provisions cannot be engaged.

The first step is therefore to determine at the outset of a project whether the activity can be carried out without processing personal data. If it cannot then an organisation can rely upon the RAS provisions, subject to appropriate safeguards.

Article 84C sets out the appropriate safeguards:

  • the processing must not be likely to cause substantial damage or distress to the data subject;
  • the processing must not be carried out for the purposes of measures or decisions in respect of a data subject to whom the personal data relates (other than approved medical research); and
  • technical and organisational measures must be used to ensure respect for the data minimisation principle.

The ICO’s draft guidance sets out other safeguards that organisations should have in place to ensure compliance with data protection law, including implementing data protection by design and default, carrying out a DPIA where necessary, security measures and appropriate staff training.

In practice, this means

  • Data minimisation and de-identification: Wherever possible, personal data should be anonymised, failing which it should be pseudonymised or minimised.
  • Documentation: Organisations need to demonstrate that each project genuinely meets the RAS purpose claimed and satisfies the four research criteria.
  • Transparency: Privacy information must be accessible, and any rights-limiting must be duly justified and recorded.

Organisations should also ensure thar they have a valid legal basis for the processing, including an appropriate Article 9 condition where processing for RAS purposes involves the processing of special category data.

Why this matters: commercial research and AI

The explicit inclusion in UK GDPR of commercial research is particularly important for organisations developing and deploying AI systems. As noted above, the draft guidance contains a number of examples to assist organisations in determining whether their activities will constitute research.

Where the project involves systematic investigation, genuine uncertainty and a broader scientific objective, it is likely to qualify as scientific research.

The guidance marks an important evolution in the ICO’s approach to research-related processing. Now that commercial research is now clearly in scope, AI training and algorithm development are likely to qualify where they meet the scientific research criteria.

These amendments to UK data protection law mark a significant divergence from (EU) GDPR, meaning that the UK may provide a more flexible regulatory framework for the development of AI systems.

More information

You can find the draft guidance on the ICO website.

If you would like to discuss the guidance in more detail or your organisation’s use of the RAS provisions, please contact Martin Sloan, Rachel Lawson or Ussamah Nasar.

Contributors

Martin Sloan

Partner

Ussamah Nasar

Senior Solicitor

Rachel Lawson

Associate

Chloe Docherty

Second year Trainee