Data privacy for customers in vulnerable circumstances
Many firms question whether they can record and share data about vulnerable customers without falling foul of GDPR. The joint FCA/ICO statement of March 2026 made clear that data protection law is not a barrier but an enabler.
Drawing on the CII's recent practical guide to GDPR and data privacy, three of the guide’s co-authors – Andrew Gething of MorganAsh, Robert Bell, and Vanessa Riboloni of the CII – move the conversation from “are we allowed?” to “how can we do this well?”.
Overview
Introduction: customer vulnerability data requirements
Proactive and reactive data collection
Data accuracy – inferred data, objectivity and consistency
Why explicit consent is the preferred lawful basis
When explicit consent is not practical – scenario matrix
Data minimisation – what to store and at what level
Deletion, retention and subject access requests
Sharing data within and between firms – tiered access