The Department for Work and Pensions (DWP) is facing fresh scrutiny over new "snooping" powers allowing it to access information from bank accounts, amid warnings that public trust - and claimants’ privacy - could be put at risk.
The warning comes from the Public Accounts Committee (PAC), which says the DWP has not yet fully explained how it will use the powers in a way that reassures the public and protects individual rights.
Despite these safeguards, the PAC says the DWP has not yet demonstrated how it will ensure the powers are used proportionately in practice.
The committee points to past failures - including 26,000 carers wrongly recorded as having overpaid benefits - as evidence of the real harm administrative errors can cause.
It is calling on the DWP to publicly report how often the powers are used and what impact they have, to allow proper scrutiny.
A Wider Privacy Debate
Sir Geoffrey Clifton-Brown, chair of the Public Accounts Committee, warned the new measures represent a shift in how closely the state can examine citizens’ financial lives.
“The DWP’s new powers to reach further into citizens’ lives are significant,” he said, adding that the risk of over-reach must be mitigated from the outset.
Privacy advocates argue that while fraud prevention is important, financial surveillance should not become normalised, particularly for people already reliant on state support.
What has changed and why privacy campaigners are watching closely
Under the Public Authorities (Fraud, Error and Recovery) Act 2025, the DWP can now make banks and financial institutions give over limited information about accounts that receive certain benefits.
While the government says the powers are necessary to tackle fraud and error, critics warn they represent a significant expansion of state access to personal financial data.
What information can the DWP see?
Despite concerns, the DWP insists the powers are narrowly defined.
Banks can only be asked to share:
- Basic account details (such as sort code and account number)
- Limited personal details (name and date of birth)
- Confirmation that an account meets specific eligibility indicators
They cannot share:
- Transaction histories
- Details of what claimants spend their money on
- Sensitive personal data such as health, ethnicity or political beliefs
Any bank that overshares information could face penalties.
Why the DWP says the new powers are necessary
Currently, the DWP already cross-checks some claimant information with HMRC, particularly employment and income data. However, it relies heavily on self-reporting for other eligibility rules, such as savings thresholds or time spent abroad.
When claimants fail to report changes - sometimes unintentionally - this can lead to:
- Large overpayments
- Debts that build up unnoticed
- Stress and hardship when repayments are demanded
The DWP argues earlier detection through data checks could prevent debt accruing and ensure people are paid the correct amount from the outset.
Eligibility Verification Notices explained
The new system centres on Eligibility Verification Notices, which instruct banks to check whether accounts receiving specific benefits appear to breach eligibility rules.
For example:
- Universal Credit claimants generally cannot hold more than £16,000 in savings
- Banks may be asked to identify accounts that appear to exceed this limit
Importantly:
- No benefit will be stopped or reduced automatically
- Flagged cases only trigger further investigation
- A human decision-maker must be involved in any outcome
Which benefit claimants are affected?
Initially, the powers apply only to:
- Universal Credit
- Pension Credit
- Employment and Support Allowance
The State Pension is excluded, and any expansion to other benefits would require Parliamentary approval.
Oversight and safeguards designed to protect privacy
To address privacy concerns, the DWP says the powers will be subject to strict controls, including:
- Independent oversight, with annual reports to Parliament
- A mandatory Code of Practice, consulted on publicly
- Legal limits on which organisations can be compelled to share data
- Restrictions on the type and amount of data that can be shared
- Compliance with UK GDPR and the Data Protection Act 2018
- A gradual “test and learn” rollout, rather than immediate full use
What claimants should know about the changes
- The DWP cannot monitor day-to-day spending
- There is no automated decision-making
- Any action must involve a human review
- The powers apply only to specific benefits
- Oversight mechanisms exist — but transparency will be key
As the PAC warns, the success of the policy will depend not just on how much money it saves, but on whether the DWP can enforce the rules without undermining public trust.
Share