Data privacy for customers in vulnerable circumstances

Many firms question whether they can record and share data about vulnerable customers without falling foul of GDPR. The joint FCA/ICO statement of March 2026 made clear that data protection law is not a barrier but an enabler.

Drawing on the CII's recent practical guide to GDPR and data privacy, three of the guide’s co-authors – Andrew Gething of MorganAsh, Robert Bell, and Vanessa Riboloni of the CII – move the conversation from “are we allowed?” to “how can we do this well?”.

Overview

  • Introduction: customer vulnerability data requirements

  • Proactive and reactive data collection

  • Data accuracy – inferred data, objectivity and consistency

  • Why explicit consent is the preferred lawful basis

  • When explicit consent is not practical – scenario matrix

  • Data minimisation – what to store and at what level

  • Deletion, retention and subject access requests

  • Sharing data within and between firms – tiered access

Peter Labrow

Head of marketing at MorganAsh. Writer and storyteller. Author of The Well. Co-author: Is It News?

Next
Next

Effective vulnerable customer reporting