Brokers occupy a peculiar position in the data protection landscape. They sit between lenders, insurers or product providers on one side and consumers on the other, routinely collecting sensitive financial information, sharing it onward, and relying on it to demonstrate compliance with the Consumer Duty and other FCA rules. This dual exposure, to both the UK GDPR and the FCA Handbook, means that data protection failures are rarely just an Information Commissioner’s Office (ICO) problem. They are also a conduct risk that the Financial Conduct Authority (FCA) actively supervises.
This article sets out what the FCA expects of brokers when it comes to handling personal data, how that interacts with the UK GDPR and the Data Protection Act 2018, and what practical steps firms should take to stay on the right side of both regimes.
Why the FCA Cares About Data Protection
The UK GDPR is enforced by the ICO, not the FCA. However, the FCA has made clear that mishandling personal data is also a regulatory issue in its own right. In a long-standing statement on client data, the FCA warned firms, and intermediaries, to be responsible when handling client data and to ensure they lawfully process and transfer client data. The FCA has said it will act where it identifies breaches of relevant parts of the Handbook, even though the underlying issue is fundamentally a data protection one.
This matters for brokers because so much of the job is built around the movement of personal data: passing applications to lenders, sharing claims information with insurers, providing fact-finds to product providers, and retaining records to evidence suitability and good outcomes. Each of these steps is also a piece of personal data processing under UK GDPR.
The Core Data Protection Principles Brokers Must Apply
Both the FCA and the ICO point brokers back to the same foundation: the data protection principles of GDPR. These should sit at the heart of any broker’s approach to client data, and firms must be able to demonstrate compliance with each one.
- Lawfulness, fairness and transparency: brokers need a valid lawful basis for processing personal data, must use it fairly, and must be clear and upfront with clients about how their data will be used from the outset.
- Purpose limitation: clients should be told why their data is being collected, for example to assess suitability or arrange a product, and data should not be repurposed beyond that without further justification.
- Accuracy: client records, particularly financial and circumstantial details used for affordability or suitability assessments, must be kept accurate and up to date.
- Data minimisation and storage limitation: brokers should only collect what is needed for the purpose at hand and should not retain client files indefinitely once the regulatory retention period has passed.
- Security and accountability: appropriate technical and organisational measures must protect client data, with records in place to evidence compliance if challenged by the ICO or the FCA.
Lawful Basis and Privacy Information
The UK GDPR requires firms to provide clients with clear privacy information, setting out the purposes for which personal data is collected and processed, and explaining individuals’ rights. For brokers, this typically needs to happen at the point of taking on a new client, before any meaningful data collection begins.
Brokers should also identify and record the lawful basis relied on for each type of processing. Common bases include performance of a contract (arranging a mortgage, policy or credit product the client has asked for), legal obligation (anti-money laundering checks), and legitimate interests. Where consent is used as the basis, firms must keep an audit trail showing how and when consent was given, and clients must be able to withdraw it easily.
Sharing Data Across the Distribution Chain
Brokers sit in the middle of what the FCA calls the distribution chain: the network of manufacturers (lenders, insurers) and distributors (brokers, advisers) involved in getting a product to the end customer. Under the Consumer Duty, the FCA expects these parties to share relevant information to deliver good outcomes, but this must still be done in line with data protection law.
A joint statement issued by the FCA and the ICO in March 2026 directly addresses this tension for the first time, focusing on data about customers in vulnerable circumstances. The statement confirms that UK data protection law does not stop firms sharing or using personal information where it is appropriate and necessary to protect customers or meet their needs. This is a significant clarification for brokers, who had previously cited GDPR concerns as a reason for under-recording or failing to pass on vulnerability information.
The joint statement sets out several practical expectations relevant to brokers:
- Where possible, prefer sharing anonymised or aggregated information about groups of vulnerable customers with manufacturers, reserving individual-level data sharing for cases where it is genuinely necessary to meet a client’s needs or avoid foreseeable harm.
- Where individual data is shared, be transparent with the client about what is shared, with whom, and why, and ensure the receiving firm also has a lawful basis to process it.
- Use data sharing agreements that clarify each party’s role, for example whether the broker is acting as a controller, joint controller or processor for a given data flow.
- Check the accuracy of data received from third parties, not just data collected directly, since brokers may be relying on information passed to them by another firm in the chain.
Data Protection Impact Assessments
Brokers should carry out a data protection impact assessment (DPIA) for any processing likely to be high risk. The ICO’s guidance, echoed in FCA-facing material, flags several scenarios particularly relevant to brokers, including processing special category data at scale, using profiling or automated decision-making to make significant decisions about clients (for example automated credit decisioning), and matching or combining personal data from multiple sources such as several lenders’ systems. A DPIA is also good practice whenever a broker takes on a new system, CRM platform or significant change to how client data is processed.
Security Expectations
The FCA’s guidance on data security makes clear that brokers are expected to put in place systems and controls that minimise the risk of client data being exploited by fraudsters. This includes encrypting devices that leave the office, controlling remote and home-working access to client data, and applying robust caller identification procedures so that fraudsters cannot use publicly available information to impersonate a client and request changes to their records. Firms should have written, proportionate data security policies that reflect the day-to-day reality of how staff actually work, rather than generic, box-ticking documents.
For brokers, GDPR compliance and FCA compliance are no longer separate workstreams. The FCA has been explicit that mishandling client data is a regulatory failing in its own right, and its 2026 joint statement with the ICO removes one of the long-standing excuses for under-recording vulnerability data: the mistaken belief that GDPR is a barrier to good customer outcomes. The reality is the opposite. Good data protection practice, accurate records, clear lawful bases, proportionate sharing and strong security, is what allows brokers to meet both their data protection obligations and their Consumer Duty obligations at the same time. Firms that treat the two as connected, rather than competing, will find compliance considerably easier to evidence if the FCA or the ICO comes asking.
This article is for informational purposes only and does not constitute legal or compliance advice. Brokers should consult their compliance function or a qualified regulatory adviser for guidance specific to their business.
Written by the Ecompli founder — With over 20 years in financial services and having founded Ecompli in 2006, these blogs are written by a specialist with hands-on expertise in FCA regulation across the mortgage, general insurance, equity release, and insurance claims handling sectors.
