Law Enforcement Data Service Data Protection Impact Assessment (DPIA) Date: October 2020 Version: 1.0 © Crown copyright 2020 This publication is licensed under the terms of the Open Government Licence v3.0 except where otherwise stated. To view this licence, visit nationalarchives.gov.uk/doc/open- government-licence/version/3 or write to the Information Policy Team, The National Archives, Kew, London TW9 4DU, or email:
[email protected]. Where we have identified any third-party copyright information you will need to obtain permission from the copyright holders concerned. This publication is available at www.gov.uk/government/publications. Any enquiries regarding this publication should be sent to us at
[email protected]. Contents The need for a DPIA 4 The nature of the processing 6 Introduction 6 The types of data processed 6 Organisations processing data in LEDS 7 Processing Driver and Vehicle Licensing Agency data 8 Details of processing 9 How is data used? 10 How is data collected? 11 What are the access routes to LEDS data? 12 Who has access to the data and by what methods? 14 Who will share the data? 14 What types of processing identified as likely high risk are involved? 16 Are processors used? 17 What are the retention periods? 17 How is data stored? 19 How will data be deleted? 19 What security measures are in place? 19 Are any new technologies in use? 20 The scope of the processing 21 What is the nature of the data? 21 What is the volume and variety of the data? 21 What might be the sensitivity of the personal