Data management approach
Updated 17 July 2026
Introduction
The Department for Business and Trade (DBT) produces official statistics in line with practices required in the Code of Practice for Statistics. This statement sets out the department’s commitments on data management (standard 4.1).
Ethics
DBT is committed to collecting, accessing, using and sharing data in an ethical manner. DBT has a number of measures in place to ensure this.
DBT has an internal Data and Research Ethics Committee, which reviews and advises on the ethics of potentially sensitive data collection, research, and analysis, and ensures it meets the standards set out in the Government Social Research (GSR) Ethical Assurance for Social and Behavioural Research guidelines and the Government Digital Service’s Data and AI Ethics Framework.
DBT also has an internal Survey Control function, which reviews all external surveys conducted by DBT, including consultations. The Survey Control Group encourages the use of Government Statistical Service (GSS) harmonised questions as part of DBT’s wider alignment with GSS harmonisation standards and guidance. The Survey Control Group also encourages those launching surveys to review our records of surveys that have previously taken place to reduce the risk of duplicating surveys and reduce response burden.
Finally, DBT has a disclosure control policy, which outlines how we minimise the risk that businesses or individuals are identified in our outputs.
Data management
Each statistical dataset maintained by DBT from which official statistics are produced has a specified data owner and data steward. Their roles are to ensure that the department manages its data resources in accordance with the best practice principles and standards set out in:
- the Code of Practice for Statistics and its supporting Protocols
- the department’s other corporate standards and procedures
- the department’s statutory obligations
Regular reviews of data ownership are undertaken for Data Workspace, DBT’s data catalogue and analysis platform. These reviews ensure that all personal data has a retention policy.
DBT adheres to the requirements of the General Data Protection Regulation (GDPR) in the processing of personal data. All data sharing agreements, service level agreements, and procurements follow standard departmental procedures to ensure compliance with GDPR. Personal data is retained for the minimum period required and disposed of in a secure and responsible manner.
All staff working in DBT and all visitors to its sites require a pass to access the premises. There is no public access to any part of the organisation where confidential statistical data may be held. Information is classified according to standard government security classifications and managed according to its sensitivity, value, and criticality. Staff regularly monitor and review information security arrangements to ensure that policy, standards and procedures remain relevant and effective.
All DBT staff must complete mandatory training on Security and Data Protection annually. Official Sensitive data is only shared externally when necessary, and must be shared with appropriate handling instructions and a sensitivity label. Before sharing data, permission must be sought from the data owner and, for personal data, the Data Protection team. When data is shared, it is done so via a secure link.
DBT also manages access and usage of microdata. Microdata refers to record-level data relating to individuals, businesses or households, and is sourced from surveys, censuses and administrative data sources. Due to the granular and sensitive nature of microdata, DBT ensures that the confidentiality of data subjects are protected through processes that enable users to prove they can safely handle the data, as well as mechanisms such as disclosure control that ensure microdata outputs are safe to be shared onwards.
Where microdata is collected and owned by DBT, the data collection and usage arrangements are in accordance with statistical legislation. Where microdata is owned by a department or organisation other than DBT, arrangements for access are in accordance with the Memorandum of Understanding, contracts, or other confidentiality agreements between DBT and the data owners.
DBT will place the minimum load necessary on data providers.
Data retention
DBT only retains personal data for as long as necessary to fulfil the purposes it was collected for, up to a standard maximum of 15 years from the date on which it was provided or subsequently updated. For more information, see DBT’s privacy policy. Exceptions to this are made on a case-by-case basis, and detailed in the privacy policy of the output. DBT holds an internal retention schedule detailing types of data and their retention periods.
Once a retention period elapses, relevant approval will be sought from the Head of Records to extend this period, transfer the data, or destroy the data. Where data is to be destroyed, all copies of the data are safely and irreversibly removed from all systems according to their classification, following DBT’s Information Classification and Handling guidance.
Our statistical practice is regulated by the Office for Statistics Regulation (OSR).