Skip to main content
Guidance

Connected Places Cyber Security Principles

Secure design, build and management of public realm technology, infrastructure, and data-rich environments for local authorities.

Page 8 of 19

#5 Understanding legal and regulatory requirements

You must ensure that the data architecture of your connected place infrastructure is built and configured to fulfil the regulatory requirements set out in the GDPR and the Data Protection Act 2018, including in your choice of organisations acting as data processors. Engage with the relevant bodies (including the Information Commissioner’s Office) at the earliest opportunity to ensure legal compliance. You should also consider any additional legal and regulatory requirements that may currently influence your connected place, such as Health & Safety and Network and Information Systems (NIS) Regulations 2018. This is especially important if your connected place can affect safety-related or safety-critical systems. In addition, you should monitor future legal and regulatory requirements that may be relevant to your connected place.

Published

Reviewed

Version

1.0