What a Bulk Personal Dataset Warrant Lets the Agencies Keep
The UK's intelligence agencies are allowed to hold databases about people they have no interest in. That is not a leak or a conspiracy theory; it is the stated design of Part 7 of the Investigatory Powers Act 2016 (IPA). The legal test for a "bulk personal dataset" (BPD) practically requires that most of the people in it are irrelevant to the agency.
This post walks through what a BPD warrant actually covers, who approves it, and where the limits sit. It is general information, not legal advice, and I have marked where I am interpreting rather than quoting.
The definition is oddly self-incriminating
Section 199 of the Act defines the thing. A personal dataset is, in outline, a set of information that includes personal data about a number of individuals, where most of those individuals are not, and are unlikely to become, of interest to the agency in carrying out its functions. It must also be held, or be about to be held, electronically.
So the "bulk" label is about the mismatch: lots of people, very few targets. Think of something like a travel dataset or a public register. Intelligence and Security Committee reporting from 2015 described examples of this sort, though the exact contents of current datasets are not public.
Who can hold one
Part 7 applies to the three intelligence services only: MI5, MI6 and GCHQ. Police forces and the wider list of public authorities that use other IPA powers are not in scope here.
The basic rule is that an agency must not retain or examine a BPD unless a warrant authorises it. Retention and examination are both covered, and that distinction matters later.
Two kinds of warrant
Part 7 provides two routes:
- Class BPD warrant (section 204): covers datasets falling into a described category, such as a type of travel or financial data. The agency can add new datasets of that class without a fresh warrant each time.
- Specific BPD warrant (section 205): covers one named dataset, or is used where a class warrant is not available.
As I read it, the more sensitive the content, the narrower the route. Health records, and datasets with a substantial proportion of particularly sensitive personal data, are steered to the specific warrant, so the approvers look at that exact dataset. Check the text of section 204 itself before relying on my paraphrase.
The double lock
A warrant is issued by the Secretary of State, but it does not take effect until a Judicial Commissioner has approved the decision. The Commissioner reviews the necessity and proportionality conclusions, applying judicial review principles. This is the "double lock" that the IPA applies to its most intrusive powers.
The Secretary of State has to be satisfied that retention and examination are necessary for the agency's statutory functions, proportionate, and that the safeguards are adequate. Warrants run for a fixed period (six months, as I understand it) and need renewing, with the same approvals.
Quick detour: what happens before there is a warrant?
Hang on, how does an agency decide whether it wants a dataset without already examining it? The Act anticipates that. There is an initial examination provision (section 220) letting the agency look at a newly acquired set for a limited time, broadly a few months, to decide whether to apply for a warrant.
If the application is refused, or none is made, the agency must delete the data. This is the bit where "can they keep it?" has a clean answer: not indefinitely, and not without approval.
Retention is not the same as examination
A warrant lets the agency hold the dataset. It does not mean every analyst can run any query they like against it. The Act and the Home Office code of practice put conditions on examination, including that it must be for permitted purposes and be necessary and proportionate.
There are also criminal offences around misuse, and the Investigatory Powers Commissioner's Office (IPCO) inspects how agencies use their datasets in practice. I would treat the inspection regime as the part that actually does the day-to-day work, because a warrant is a one-off decision while examination happens thousands of times.
Where it came from
For years, BPD holding rested on general information-gathering powers in the Security Service Act 1989 and the Intelligence Services Act 1994, with no published regime. The existence of the datasets was confirmed publicly in 2015.
The Investigatory Powers Tribunal then found, in the Privacy International case in 2016, that the regime had breached Article 8 of the European Convention on Human Rights for a period, because the safeguards were not sufficiently public or overseen. That is a court decision, and the finding was about the past arrangements, not the IPA. Part 7 put the whole thing on a statutory footing.
The 2024 addition: Part 7A
The Investigatory Powers (Amendment) Act 2024 added a lighter regime for "third party" bulk personal datasets where there is a low or no reasonable expectation of privacy. This is a different test and a different approval structure from Part 7.
My reading is that it relies more on category-level authorisation, with less scrutiny of each individual acquisition. The precise approval mechanics are worth checking against the amended Act if they matter to you. Whether "low expectation of privacy" is a sensible line to draw is a fair debate; I am wary of any test where the boundary depends on how public a dataset is rather than what can be inferred by joining it to others.
What a warrant does not tell you
- Which datasets exist, or who is in them.
- Whether your own data is held.
- Anything you can usually obtain through a standard subject access request, since national security exemptions apply to the agencies.
If you think an agency has handled your data unlawfully, the Investigatory Powers Tribunal is the route for complaints, and it can hear them without you proving you were targeted. The primary text is on legislation.gov.uk (IPA 2016, Part 7), and it is short enough to read in one sitting.