Appropriate Policy Document
An Appropriate Policy Document (APD) is a written document that an organisation in the UK must have in place when it relies on certain legal conditions to process especially sensitive information, such as special category data or criminal offence data. It explains how the organisation handles this data and how it complies with data protection rules. This requirement comes from UK law rather than the GDPR text itself, so readers should verify the current requirements against the official legislation and regulator guidance.
An Appropriate Policy Document (APD) is a compliance document required under the UK Data Protection Act 2018 where a controller relies on specified Schedule 1 conditions to process special category personal data or criminal offence data. According to guidance and templates from the UK Information Commissioner's Office (ICO), an APD typically records the relevant Schedule 1 condition(s) being relied upon and demonstrates how the controller complies with associated safeguards, including retention and erasure practices. This is a UK-specific instrument arising from the DPA 2018 and its Schedule 1 conditions rather than from the EU GDPR itself; it should not be conflated with a Data Protection Impact Assessment (DPIA) or a records of processing activities obligation. Practitioners should note that the precise triggering conditions and required content are set by the DPA 2018 and current ICO guidance, and the exact scope should be verified against the applicable statutory text.
Why it matters
The Appropriate Policy Document sits at the intersection of the most sensitive processing an organisation can carry out and the accountability principle that underpins UK data protection law. Special category data (such as health, biometric, or data revealing racial or ethnic origin) and criminal offence data attract heightened protections, and several of the Schedule 1 conditions in the Data Protection Act 2018 that permit this processing can only be relied upon if an APD is in place. Where an organisation relies on one of these conditions without maintaining a compliant APD, the lawful basis for that processing may be undermined, so the document is not a mere formality but a component of demonstrating that the processing is properly grounded.
Beyond legality, the APD serves an evidential function. It records which Schedule 1 condition is being relied upon and shows how the controller meets the associated safeguards, including its retention and erasure practices. This supports the broader accountability expectations under UK data protection law and provides a reference point that can be produced to the Information Commissioner's Office or to affected individuals if questions arise. Because the requirement derives from the DPA 2018 rather than from the EU GDPR text itself, organisations operating across the UK and EU should not assume that an equivalent standalone document is mandated in every jurisdiction, and should verify the position under each applicable framework.
Practitioners should treat the precise triggering conditions and required content as matters to confirm against the current statutory text and ICO guidance, both of which can be updated. The APD should also not be confused with, or substituted for, a Data Protection Impact Assessment or a record of processing activities, which serve distinct purposes; relying on one to satisfy the other would leave gaps in a compliance programme.
Who it's relevant to
Inside APD
Common questions
Answers to the questions practitioners most commonly ask about APD.