Skip to main content
Category: Special Category Data

Appropriate Policy Document

Also known as: APD, Appropriate Policy Document (APD), APD
Simply put

An Appropriate Policy Document (APD) is a written document that an organisation in the UK must have in place when it relies on certain legal conditions to process especially sensitive information, such as special category data or criminal offence data. It explains how the organisation handles this data and how it complies with data protection rules. This requirement comes from UK law rather than the GDPR text itself, so readers should verify the current requirements against the official legislation and regulator guidance.

Formal definition

An Appropriate Policy Document (APD) is a compliance document required under the UK Data Protection Act 2018 where a controller relies on specified Schedule 1 conditions to process special category personal data or criminal offence data. According to guidance and templates from the UK Information Commissioner's Office (ICO), an APD typically records the relevant Schedule 1 condition(s) being relied upon and demonstrates how the controller complies with associated safeguards, including retention and erasure practices. This is a UK-specific instrument arising from the DPA 2018 and its Schedule 1 conditions rather than from the EU GDPR itself; it should not be conflated with a Data Protection Impact Assessment (DPIA) or a records of processing activities obligation. Practitioners should note that the precise triggering conditions and required content are set by the DPA 2018 and current ICO guidance, and the exact scope should be verified against the applicable statutory text.

Why it matters

The Appropriate Policy Document sits at the intersection of the most sensitive processing an organisation can carry out and the accountability principle that underpins UK data protection law. Special category data (such as health, biometric, or data revealing racial or ethnic origin) and criminal offence data attract heightened protections, and several of the Schedule 1 conditions in the Data Protection Act 2018 that permit this processing can only be relied upon if an APD is in place. Where an organisation relies on one of these conditions without maintaining a compliant APD, the lawful basis for that processing may be undermined, so the document is not a mere formality but a component of demonstrating that the processing is properly grounded.

Beyond legality, the APD serves an evidential function. It records which Schedule 1 condition is being relied upon and shows how the controller meets the associated safeguards, including its retention and erasure practices. This supports the broader accountability expectations under UK data protection law and provides a reference point that can be produced to the Information Commissioner's Office or to affected individuals if questions arise. Because the requirement derives from the DPA 2018 rather than from the EU GDPR text itself, organisations operating across the UK and EU should not assume that an equivalent standalone document is mandated in every jurisdiction, and should verify the position under each applicable framework.

Practitioners should treat the precise triggering conditions and required content as matters to confirm against the current statutory text and ICO guidance, both of which can be updated. The APD should also not be confused with, or substituted for, a Data Protection Impact Assessment or a record of processing activities, which serve distinct purposes; relying on one to satisfy the other would leave gaps in a compliance programme.

Who it's relevant to

Data Protection Officers and compliance leads
Those responsible for an organisation's compliance programme need to determine when processing of special category or criminal offence data relies on a Schedule 1 condition that requires an APD, and to ensure the document is prepared, kept current, and available on request. They should confirm the triggering conditions against the DPA 2018 and current ICO guidance rather than assuming the requirement applies uniformly.
Controllers processing special category or criminal offence data
Organisations acting as controllers over health, biometric, criminal offence, or other sensitive data are the primary parties on whom the APD obligation can fall. This includes public bodies, universities, and other entities that rely on relevant Schedule 1 conditions; several such organisations publish APDs describing how they process this data and meet the associated safeguards.
Privacy lawyers and advisers
Legal advisers assessing the lawfulness of sensitive processing should verify whether the chosen Schedule 1 condition carries an APD requirement, and should distinguish the APD from a DPIA or a record of processing activities. They should note that this is a UK-specific instrument arising from the DPA 2018 and that requirements should be checked against the current statutory text.
Public sector and education-sector organisations
Local authorities, universities, and similar bodies frequently process special category and criminal offence data under conditions that can trigger the APD requirement, and a number publish their APDs. Such organisations should ensure their documentation reflects the specific conditions they rely upon and their actual retention and erasure practices.

Inside APD

Scope and Conditions Covered
An identification of the Schedule 1 conditions (under the UK Data Protection Act 2018) being relied upon, describing which processing activities of special category or criminal offence data the document supports. This is a UK-specific requirement and does not derive from the GDPR text itself; readers should verify the applicable conditions against the current official DPA 2018 provisions.
Article 5 Principles Compliance
An explanation of how the controller's processing procedures secure compliance with the data protection principles (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality), typically framed by reference to the principles set out in Article 5 GDPR / UK GDPR.
Retention and Erasure Policies
A statement of the retention periods applied to the special category or criminal offence data, or the criteria used to set them, and the arrangements for erasure or review. This should reflect the storage limitation principle rather than assert a fixed universal period.
Record-Keeping Linkage
A connection to the controller's wider records of processing, indicating how this document supplements accountability documentation. In most cases it is retained alongside, but is distinct from, the record of processing activities and any Data Protection Impact Assessment.

Common questions

Answers to the questions practitioners most commonly ask about APD.

Is an Appropriate Policy Document the same thing as a Data Protection Impact Assessment?
No. These are distinct instruments serving different purposes. An Appropriate Policy Document (APD) is a UK GDPR concept, derived from the Data Protection Act 2018, that must accompany certain processing of special category and criminal offence data by explaining how you comply with the data protection principles and your retention and erasure policies for that data. A Data Protection Impact Assessment under Article 35 GDPR is a risk-assessment exercise carried out where processing is likely to result in a high risk to individuals. One documents compliance with principles for specific lawful conditions; the other assesses and mitigates risk. They may both be required for the same processing, but neither substitutes for the other.
Does having an Appropriate Policy Document mean I have a lawful basis to process special category data?
Not on its own. An Appropriate Policy Document is a supplementary requirement, not a standalone lawful basis or condition. Processing special category data generally requires both an Article 6 lawful basis and an Article 9 condition, and processing criminal offence data has its own requirements. The APD is a document that certain of those conditions require you to have in place as an additional safeguard; it supports and evidences your reliance on the relevant condition rather than creating the condition itself. You should confirm which specific conditions in the UK legal framework trigger the APD requirement, as it does not attach to every Article 9 condition.
What should an Appropriate Policy Document typically contain?
In most cases an Appropriate Policy Document is expected to explain how you comply with the data protection principles when carrying out the relevant processing, and to set out your policies regarding retention and erasure of the personal data concerned, including an indication of how long the data is likely to be retained. Because the specific content expectations derive from the UK Data Protection Act 2018 and associated regulator guidance, you should check the current official text and guidance to confirm the required elements, as expectations can be updated.
When does the Appropriate Policy Document need to be in place relative to the processing?
Generally the document is expected to be in place at the time you carry out the processing that relies on a condition requiring it, rather than created retrospectively. It functions as a safeguard demonstrating compliance during the processing. You should verify the precise timing and retention obligations against the current statutory text, as there are specific requirements about maintaining and reviewing the document while the processing continues and for a period afterward.
Do I need a separate Appropriate Policy Document for each processing activity?
Not necessarily. Organisations can typically address multiple processing activities within a single document or maintain separate documents, provided the content adequately covers each relevant condition being relied upon and each type of processing. The practical approach depends on the complexity and range of your processing. Whichever structure you adopt, it should clearly connect to the specific conditions triggering the requirement and remain accurate for the processing it covers.
How does the Appropriate Policy Document relate to the record of processing activities?
They are complementary but distinct. Records of processing activities are a separate documentation obligation and cover processing more broadly, while the Appropriate Policy Document specifically addresses how you comply with the principles and manage retention and erasure for the special category or criminal offence data processing that requires it. In practice, information in the APD may overlap with or cross-reference your wider records, but you should maintain each to meet its own requirements rather than treating one as a replacement for the other.

Common misconceptions

An Appropriate Policy Document is a GDPR requirement that applies across the EU.
It is generally a feature of the UK Data Protection Act 2018 framework, associated with certain Schedule 1 conditions for processing special category and criminal offence data. It is UK-specific and should not be assumed to apply under other member states' implementing laws, which may impose different safeguards; verify against the current official text.
Having an Appropriate Policy Document is the legal basis for processing special category data.
It is a supplementary safeguard and accountability measure, not itself a legal basis. Processing special category data typically still requires an Article 6 basis together with a separate Article 9 condition, and, where relevant, a corresponding Schedule 1 condition. The document evidences compliance rather than replacing those requirements.
The document is a one-off record that can be filed and forgotten.
It is generally expected to be reviewed and kept up to date while the relevant processing continues, and retained for a period after processing ends. Its currency matters for demonstrating accountability, so it should be maintained rather than treated as static.

Best practices

Identify precisely which Schedule 1 condition(s) under the DPA 2018 you are relying on, and map each to the specific processing activity it supports, verifying the wording against the current official text.
Document how your procedures deliver compliance with each Article 5 principle, rather than making a general assertion of compliance, given that compliance is context and risk dependent.
State retention periods or the criteria used to determine them, and record erasure and review arrangements consistent with the storage limitation principle.
Keep the document distinct from, but cross-referenced to, related accountability records such as your record of processing activities and any DPIA, so roles and instruments are not conflated.
Review and update the document while the relevant processing continues, and retain it for the period expected after processing ends.
Confirm whether you are subject to the UK regime and check the ICO's current guidance, noting that requirements may diverge from other regulators and that this safeguard is UK-specific.