Wales gets the first approved UK GDPR code of conduct for public and third-sector information sharing
EditorialBy TrustList Editorial
The ICO approved the WASPI code of conduct for information sharing protocols on 24 September 2026. Members must use the WASPI template, review sharing agreements and accept monitoring; the monitoring body still awaits ICO approval.
About Wales gets the first approved UK GDPR code of conduct for public and third-sector information sharing
Wales gets the first approved UK GDPR code of conduct for public and third-sector information sharing
28 September 2026 — The Information Commissioner's Office announced on 28 September 2026 that it has approved a UK GDPR code of conduct from the Wales Accord on the Sharing of Personal Information (WASPI). The ICO's register gives the approval date as 24 September 2026. WASPI describes it as the first code of conduct across the UK to cover public and third-sector partners. The code is approved under Article 40 of the UK GDPR, which lets sector bodies set out how data-protection law applies to their work and have it independently monitored.
What the code requires
The WASPI UK GDPR Code of Conduct for Information Sharing Protocols applies when personal information is shared to deliver health, education, social care, safeguarding and other public services to people in Wales. According to the ICO and WASPI, it sets six requirements for members:
- governance arrangements;
- mandatory use of the WASPI information sharing protocol (ISP) template;
- a quality-assurance process;
- accountability controls;
- regular review of information sharing arrangements, including the lawful basis relied on;
- compliance with ongoing monitoring.
The code adds a tier rather than replacing the existing framework. More than 1,000 organisations have signed the WASPI Accord and can remain "Tier 1" signatories; code membership is "Tier 2". WASPI says the code is aimed at all data controllers, particularly those that regularly share high volumes of personal data or special-category data with several partners. It stresses that sharing can be lawful without membership, and that following the code does not mean an organisation complies with the whole of the UK GDPR, only the elements the code covers.
What is not in place yet
The monitoring body that will check members' compliance is listed on the ICO register as pending ICO approval. WASPI says it will work with the ICO to establish its service as that independent body and will support organisations applying for membership "during the coming months".
Who is affected
Health boards, local authorities, schools, police and fire services, housing associations and charities that share personal data about people in Wales, plus the care providers, IT suppliers and service contractors that work inside those sharing arrangements. Suppliers may be asked to show that the ISPs they operate under follow the WASPI template and review cycle.
What to do
- List the information sharing protocols your organisation is party to in Wales and check whether they use the current WASPI template and have a review date.
- Decide whether code membership is worth seeking once the monitoring body is approved, based on the volume and sensitivity of what you share.
- If you supply services to Welsh public bodies, expect questions about ISP compliance in tenders and contract reviews, and prepare evidence of your own reviews.
- Keep the code alongside the ICO's data sharing code of practice in your data-protection documentation.
Sources
- ICO: WASPI UK GDPR Code of Conduct for Information Sharing Protocols published — 28 September 2026
- ICO register of UK GDPR codes of conduct: The Wales Accord on the Sharing of Personal Information (WASPI) UK GDPR Code of Conduct for Information Sharing Protocols (approval date 24 September 2026) — 24 September 2026
- WASPI: UK GDPR Code of Conduct for Information Sharing Protocols (page read 28 September) — 28 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.