UK Data Protection Act 2018 Explained: Scope, Principles & Business Compliance

This is some text inside of a div block.
7 mins
September 23, 2026

Table of contents

Key takeaways

  • The UK Data Protection Act 2018 (DPA 2018) and the UK GDPR together form the UK's data protection regime. The UK GDPR sets the general rules; the DPA 2018 adds UK-specific detail, exemptions and separate regimes for law enforcement and intelligence.
  • The Data (Use and Access) Act 2025 (DUAA) amended both laws. Most changes took effect on 5 February 2026, and the statutory complaints procedure applies from 19 June 2026.
  • Seven principles govern all processing: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability.
  • The maximum fine is £17.5 million or 4% of global annual turnover, whichever is higher. The same ceiling now also applies to marketing and cookie breaches under PECR.
  • EU to UK data flows remain covered by the EU adequacy decisions, renewed on 19 December 2025 and valid until 27 December 2031.

The UK's Data Protection Act 2018 (DPA 2018) is the backbone of modern data privacy law in the United Kingdom. It works in tandem with the UK General Data Protection Regulation (UK GDPR) to govern how organisations collect, process, store, and share personal information. In plain terms, the DPA 2018 builds on the framework of the EU's GDPR (the General Data Protection Regulation, in force since 2018) and adapts it for the UK context. 

It includes standard data protection rules and also adds UK-specific provisions for sectors like law enforcement and national security. In summary, the DPA 2018 fulfils three primary purposes: (1) to incorporate EU GDPR into UK law, (2) to allow the UK to modify or exempt certain GDPR provisions, and (3) to extend data protection into areas not originally covered by the EU GDPR. Since 2025, the Data (Use and Access) Act has updated both the UK Data Protection Act and the UK GDPR, so this guide reflects the law as it stands in September 2026. In this guide, we will dig deep into the UK Data Protection Act 2018, its relation with the UK GDPR, how you can comply with it, and the precautions you must take.

What Is the Data Protection Act 2018?

The Data Protection Act 2018 is the UK's national data privacy law that came into force on 25 May 2018. It replaces the older 1998 Act and implements the GDPR into UK law. This means that any organisation handling personal data in the UK must follow strict rules about privacy and security. These rules cover when and how data can be collected, how long it can be kept, and the rights people have over their data. Importantly, the Act was designed to be read alongside the UK GDPR. Before Brexit, it was paired with the EU GDPR, but now the Data Protection Act 2018 and UK GDPR together form the UK's data protection regime. The DPA 2018 also introduced rules for new areas such as law enforcement processing and intelligence services. For example, it creates a legal framework for how police and security services handle personal data.

The Act is organised into seven Parts. Part 2 supplements the UK GDPR for general processing, Part 3 covers law enforcement processing, Part 4 covers the intelligence services, Parts 5 and 6 set out the regulator's powers and enforcement, and Part 7 contains supplementary provisions. The Schedules hold the detail, including the conditions for processing special category data (Schedule 1) and the exemptions (Schedules 2 to 4). The Data (Use and Access) Act 2025 amended the Act rather than replacing it, so the structure above still applies.

Key Principles of the Data Protection Act 2018

The Data Protection Act 2018 (which implements the UK's GDPR) establishes seven core principles for handling personal data. These Data Protection Act 2018 principles lie at the heart of UK data protection law and ensure that organisations collect, use, and protect personal data in a responsible way. Each principle is explained below, with a practical business example. For a deeper treatment of each one, read our guide to the key data protection principles under UK GDPR.

1. Lawfulness, fairness, and transparency

Organisations must only process personal data for a valid legal reason (a "lawful basis") and handle it fairly and openly. Companies should not do anything illegal with the data, should use the data in ways people would reasonably expect, and must be upfront about how they use personal data. For example, a marketing team sends a newsletter only after obtaining explicit consent (or another lawful basis), and provides clear privacy information explaining how email addresses will be used.

2. Purpose limitation

Personal data should be collected for specific, explicit, and legitimate purposes and not used in ways incompatible with those original purposes. In other words, a business must decide up front why it needs data, record that purpose, and stick to it. If a company later wants to use the data for a new purpose, it usually needs a new legal basis or fresh consent. The DUAA added a new Article 8A to the UK GDPR that lists situations where further processing is treated as compatible, for example where the individual consents to the new purpose or where the processing is needed to comply with a legal obligation.

For example, an online shop gathers a customer's address to ship an order. It cannot later sell that address to third parties for unrelated marketing unless the customer is informed and agrees, because that would fall outside the data's original purpose.

3. Data minimisation

Businesses should collect only the personal data that is adequate, relevant, and necessary for the stated purpose. This means identifying the minimum amount of information needed and not keeping extra or unused data. Holding excessive data beyond what's needed is wasteful and unlawful. For instance, a job application form asks only for contact details and relevant qualifications, not for unrelated personal information like marital status or hobbies. This way, the company gathers only what's necessary for hiring.

4. Accuracy

Organisations must keep personal data accurate and up to date. They should take reasonable steps to correct or erase incorrect information as soon as possible. Suppose a client moves to a new address: a financial services firm must update the client's record promptly.

5. Storage limitation

Personal data should not be kept longer than necessary for the purpose it was collected. Organisations need retention policies that justify how long they keep different types of data, and they should regularly delete or anonymise data once it's no longer needed. This also supports other Data Protection Act 2018 principles by reducing the chance of using outdated or excessive information.

For example, a membership club should delete or anonymise former members' details a year after membership ends (unless there's a legal reason to keep them). By doing this, the club avoids holding on to old personal data longer than needed.

6. Integrity and confidentiality (security)

Businesses must protect personal data with appropriate security measures. This security principle (often called data "integrity and confidentiality") requires technical and organisational safeguards against unauthorised access, loss, theft, or damage. Measures can include encryption, access controls, staff training, and regular security reviews.

7. Accountability

Under the accountability principle, organisations must take responsibility for compliance and be able to demonstrate it. This means having clear policies, staff training, records, and governance in place. Companies should document how each principle is met (for example, keeping logs of processing activities or Data Protection Impact Assessments) so that they can show regulators or customers that they follow the law.

Rights of the Data Subject

The DPA 2018 also codifies the rights of individuals ("data subjects") over their data. These rights are meant to give people control and visibility. Under the Act, data subjects have rights such as the right to be informed about how their data is used, the right to access their personal data, and the right to correction or deletion. Specifically, people generally have the right to:

  • Be informed: Individuals must be told why their data is collected and how it will be used (for example, via a privacy notice).
  • Access: People can request copies of their personal data from an organisation.
  • Rectification: Individuals can have incorrect personal data corrected.
  • Erasure ("right to be forgotten"): Under certain conditions (e.g., data no longer needed), people can ask to have their data deleted.
  • Restrict processing: In some cases, data subjects can ask to limit how their data is used.
  • Data portability: They can request their data in a machine-readable format to move to another service.
  • Object: Individuals can object to or withdraw consent for certain types of processing (e.g., direct marketing).
  • Rights in automated decisions: People have rights related to profiling or automated decision-making.
  • Complain to the organisation: Since 19 June 2026, organisations must offer a direct route for individuals to complain about how their data is handled, and must acknowledge the complaint within 30 days.

These rights mirror the GDPR rights and apply unless a specific exemption covers the situation. For instance, there are lawful exemptions (e.g., public interest or legal claims) where some rights (like erasure or access) may be limited. Importantly, organisations must have processes to manage data subject rights, for example, a way to handle a Data Subject Access Request in a timely manner. The DUAA confirmed that a controller only needs to carry out a reasonable and proportionate search when responding to an access request, and that the one-month clock pauses while the controller waits for information it reasonably needs to identify the data.

Data Processing and Article 5 in Practice

"Data processing" simply means any action performed on personal data (collecting, storing, sharing, deleting, etc.). Practically, applying the Article 5 principles to data processing involves careful planning and documentation. Under the DPA 2018, any processing of personal data must satisfy at least one lawful basis (often called a condition for processing). The main lawful bases include:

  • Consent: The individual has given clear consent for a specific purpose.
  • Contract: Processing is necessary to fulfil a contract with the individual.
  • Legal obligation: The processing is required by law.
  • Vital interests: Protecting someone's life in an emergency.
  • Public task: Processing for official public functions (especially in government or charities).
  • Legitimate interests: A balancing test where an organisation's legitimate interest (that does not override the individual's rights) is used, provided it is not otherwise unlawful.
  • Recognised legitimate interests: A basis added by the DUAA in February 2026 for a closed list of purposes set out in Annex 1 to the UK GDPR, such as crime prevention, safeguarding vulnerable people and responding to emergencies. No balancing test is required for these purposes.

All processing must also adhere to the seven principles above (lawfulness, purpose, etc.).

General data processing principles

In every sector, businesses must bake the Article 5 principles into their operations. For example, when designing a new customer database, a company should apply privacy by design: limit fields to only what's needed (data minimisation), set clear retention schedules (storage limitation), and encrypt data at rest (security). When communicating with customers, it should explain (transparently) why it needs their data. Audits and impact assessments can help verify that processing is in line with the Data Protection Act 2018 Article 5 requirements.

Lawful processing of employee data

Processing staff or employee data is lawful under the DPA 2018 if it meets an appropriate condition. Common bases include fulfilling employment contracts (e.g., payroll data processed for salary) or complying with legal obligations (such as tax or health and safety requirements). For example, keeping CCTV footage for premises security might rely on legitimate interests, provided it is clearly communicated and balanced against privacy rights. Employers should document the basis they use and ensure transparent notices for staff.

Conditions for processing

Depending on what personal data you handle, you may need different conditions or additional safeguards. For ordinary personal data, one of the seven bases above is required (consent, contract, etc.). But certain data requires special care:

Special category data

"Special category" data refers to sensitive information (race, religion, health, genetics, sexual orientation, etc.). The DPA 2018 requires an extra legal basis to process this data. You often need explicit consent or a clear statutory reason, and Schedule 1 of the Act sets out the specific UK conditions, many of which require an "appropriate policy document". For instance, health data of employees can only be processed if the employer needs it for sick pay (a legal obligation) or if the employee consents. Processing criminal conviction data is also specially regulated. Outside official authorities, criminal offence data can only be processed under a Schedule 1 condition, for example where it is necessary for legal proceedings.

Law enforcement processing

Part 3 of the DPA 2018 specifically covers personal data used by police, courts, and other law enforcement agencies. It parallels the principles but tailors them to law enforcement. For example, data collected for preventing or prosecuting crime must be handled lawfully and only used for legitimate law enforcement purposes. Only "competent authorities" (like police forces) can rely on these rules. Other organisations generally must follow the normal UK GDPR rules when sharing data with the police (unless a legal requirement applies).

What Is the Scope of the Data Protection Act 2018?

The scope of the UK Data Protection Act is wide: it applies to any controller or processor that handles personal data about living individuals in connection with activities in the UK, whatever its size, sector or legal form. The three questions below settle most scope issues.

Who must comply with the DPA 2018?

Every organisation established in the UK that processes personal data must comply, including companies, charities, public authorities, sole traders and partnerships. Organisations outside the UK are also caught where they offer goods or services to people in the UK or monitor their behaviour there (Article 3 of the UK GDPR). Those organisations generally have to appoint a UK GDPR Representative under Article 27 unless an exemption applies. Processors that act on a controller's instructions have their own direct obligations, in particular on security and breach reporting.

What types of personal data are covered?

Personal data means any information relating to an identified or identifiable living individual. This includes obvious identifiers (name, email address, national insurance number) and indirect ones (an IP address, a customer reference or location data that can be linked back to a person). Special category data (health, ethnicity, religion, biometrics, sexual orientation and others) and criminal offence data attract extra conditions. The Act does not cover data about deceased people or genuinely anonymised data. Pseudonymised data is still personal data if the key to re-identify people exists.

When does the DPA 2018 apply?

The DPA 2018 applies to automated processing of personal data and to manual processing where the data forms part of a filing system. It applies throughout the UK, including Scotland, Wales and Northern Ireland: a search for "Data Protection Act 2018 Scotland" returns the same UK-wide statute, because data protection is a reserved matter and Scotland has no separate act. Searches for "Data Protection Act 2018 Scotland" or "Data Protection Act 2018 Wales" therefore lead to this one Act. It also applies from the moment personal data is collected until it is deleted, so retention and secure disposal fall within scope.

How the Data Protection Act 2018 Works with UK GDPR

The Data Protection Act 2018 and UK GDPR together form the UK's core data protection law. You can think of the UK GDPR as the broad framework (modelled on the EU GDPR) and the DPA 2018 as the detail layer that fills in UK-specific elements.

Under Brexit, the EU GDPR ceased to apply in the UK after 31 December 2020. To avoid a legal gap, UK lawmakers "lifted" the EU GDPR into UK law (the UK GDPR) and amended the DPA 2018 accordingly. Now, when we refer to UK data protection law, "UK GDPR" covers most of the same ground as the EU GDPR did, and the DPA 2018 supplements it. For example, if a company was already following EU GDPR in 2018, continuing compliance means updating terminology (GDPR → UK GDPR) and checking the DPA for any special UK rules.

Data Protection Act 2018 vs UK GDPR: similarities and differences

At their core, the UK GDPR and DPA 2018 mirror the requirements of the old EU GDPR. They share the same principles, data subject rights, and legal bases for processing. However, the DPA 2018 adds UK-tailored content. For instance:

  • Law enforcement and intelligence: The DPA 2018 contains separate Parts (3 and 4) that specifically regulate processing by police and intelligence agencies, which the EU GDPR did not include.
  • Fines structure: Both UK GDPR and DPA 2018 permit ICO fines up to £17.5 million (4% of turnover) for serious breaches, and up to £8.7 million (2%) for others. Since 5 February 2026 the same upper limit applies to breaches of the Privacy and Electronic Communications Regulations (PECR), which govern marketing emails, texts and cookies.
  • Age of consent: The DPA 2018 sets the digital age of consent at 13 (vs. 16 in EU GDPR) under certain conditions.
  • Ministerial powers and sectoral codes: The UK government has powers under the DPA to create or approve specific codes of practice (for example, in health or education).

For businesses, the practical obligations remain the same under both laws (rights handling, data security, notices, etc.). You can check out our detailed article on UK GDPR vs EU GDPR for a detailed comparison of these regimes.

What changed in UK data protection after Brexit?

Brexit primarily changed legal references and transfer rules. As of the end of the transition period, the UK enacted the UK GDPR (mirroring EU GDPR text) and amended the DPA 2018 to refer to it. One key change: the UK is now a "third country" under EU law, so data transfers from the EU to the UK rely on adequacy or other safeguards. Domestically, much stayed the same: the ICO still enforces the law, and most guidance and practices continued uninterrupted. In fact, the EU granted the UK an adequacy decision in 2021, meaning data can flow from the EU to the UK without extra safeguards. The European Commission renewed both UK adequacy decisions on 19 December 2025 for a further six years, to 27 December 2031. The DPA 2018 itself was updated so that terms like "EU GDPR" were replaced with "UK GDPR," and references to EU bodies (like the European Data Protection Board) were removed. Otherwise, companies that were compliant with GDPR in 2018 generally remain compliant.

"UK GDPR Act", "General Data Protection Act UK" and other names people search for

There is no statute called the UK GDPR Act, and no "General Data Protection Act UK" either. Both are common search terms for the same two instruments: the UK GDPR, which is a retained EU regulation rather than an Act of Parliament, and the Data Protection Act 2018, which is the Act. When a supplier or a contract refers to the "UK GDPR Act", read it as a reference to the UK GDPR as supplemented by the DPA 2018. The same applies to "General Data Protection Act UK": the correct names are the UK GDPR and the UK Data Protection Act. Using the precise titles matters in privacy notices and contracts, because the ICO and the courts will interpret your obligations against the real legislation.

What Businesses Need to Do to Comply

To comply with the Data Protection Act 2018 and UK GDPR, organisations should take a structured approach. Here are key steps:

Conduct a gap analysis

Start by auditing your current data protection practices. A GDPR gap analysis compares what you do today against what UK GDPR and DPA 2018 require. For example, identify where you lack documented policies, where you haven't updated notices, or where you store data unnecessarily. This assessment uncovers weaknesses so you know exactly what to fix. Our UK GDPR Compliance Services include in-depth gap analyses and audits.

Update privacy policies and notices

Your privacy policy and notices should reflect the DPA 2018 requirements. They must clearly state: what personal data you collect, why (the lawful basis), how you use it, and the rights of data subjects (and how to exercise them). Also, update cookie notices to cover UK users. You must ensure your templates include all mandatory information: data categories, retention periods, any transfers (see cross-border), and contact details for queries. Add the new complaints route required from 19 June 2026, and, if you rely on recognised legitimate interests, name that basis explicitly.

Raising staff awareness

Train your team on the new rules. Employees (especially HR, IT, and marketing) should understand basic DPA principles. Use simple sessions or e-learning to explain things like how to recognise personal data, how to handle requests, and the importance of security. Regular awareness helps ensure "privacy by culture," not just by policy.

Manage data subject rights

Implement a process for handling data subject requests (access, rectification, erasure, etc.). Under the DPA 2018, most requests must be responded to within one month, with some extensions allowed, and the clock now pauses while you wait for clarification you reasonably need. Keep clear records of requests and responses. For example, use a standardised DSAR form and tracking system so nothing falls through the cracks. This shows you respect individuals' rights and helps avoid breaches of process.

Maintain records of processing activities

The Act requires many organisations to keep a Record of Processing Activities (ROPA) under Article 30. This includes details like what data you hold, for what purpose, retention periods, and with whom it's shared. An up-to-date ROPA proves accountability and readiness for ICO inspections. Even small businesses should document key processes. The full list of documents you should hold is set out in the "Data Protection Records and Documentation" section below.

Breach Notification & Penalties Under the DPA 2018

If a personal data breach occurs (for example, a lost laptop or a cyber attack), the organisation must assess the risk. Under UK GDPR/DPA 2018 rules, certain breaches must be notified to the Information Commissioner's Office (ICO) within 72 hours, and sometimes to affected individuals if there's high risk of harm. The ICO enforces the law and can impose penalties. For the most serious infringements (like violating core principles or individuals' rights), fines can reach up to £17.5 million or 4% of global turnover. Lesser breaches (such as administrative failures) carry fines up to £8.7 million or 2% of turnover. Beyond fines, companies can face enforcement notices, and individuals may sue for compensation. The high penalties underscore the importance of robust compliance measures.

Two changes from the DUAA affect enforcement. First, the same £17.5 million or 4% ceiling now applies to PECR breaches (marketing and cookies), which were previously capped at £500,000. Second, the ICO is being reconstituted as the Information Commission under Part 6 of the DUAA, with the transfer of functions scheduled for 30 September 2026. Its powers and existing guidance carry over, so you do not need to re-register or change your privacy notices solely because of the name change, but update references the next time you refresh your documents.

Sector-Specific Obligations & Exemptions

Some sectors have extra rules under the DPA 2018:. The four groups below account for most of the sector-specific questions we receive.

Healthcare and public sector

Health and social care data is often special-category data. Providers typically rely on explicit consent or legal bases (like providing medical care) to process it. The DPA 2018 also allows special research and statistical uses of health data under certain conditions. Public authorities (like schools, councils, and hospitals) must appoint a Data Protection Officer (DPO) and follow public-sector-specific codes. Exemptions for freedom of information may also apply, but data protection rights still hold (e.g., patient records).

Finance and insurance

Financial services organisations must handle personal and financial data securely under both DPA 2018 and sector-specific regulations (like PSD2 or AML laws). They often use legitimate interests or contractual necessity as processing bases. Extra care is needed if profiling or automated decisions (e.g., credit scoring) are involved. The Financial Conduct Authority (FCA) may also issue guidance on data use.

Education providers

Schools and universities handle children's data, which has special safeguards. Parental consent may be needed for under-13s. Education data often intersects with safeguarding duties. Education providers must also follow any education-specific data protection codes (for example, in exam boards or welfare). Data about children can often be used with parental permission for education or care purposes.

Small businesses

All organisations, no matter how small, generally must comply with the DPA 2018 and UK GDPR. That said, small businesses can sometimes rely on different lawful bases and may not need a DPO unless processing is a core activity. However, they still must adhere to the principles, protect data appropriately, and handle basic rights requests. The law does not outright exempt SMEs, but requirements are scaled to the context. For example, a small retailer selling a few products online might only need basic consent notices and data security, whereas a large retailer needs more formal processes.

Data Protection Exemptions Under the DPA 2018

The UK Data Protection Act exemptions are set out in Schedules 2 to 4 of the Act. They do not remove the duty to comply with the Act. They allow a controller to set aside specific rights or transparency obligations, to the extent necessary, where applying them would prejudice a competing public or private interest. The table below groups the exemptions organisations meet most often.

Exemption group Typical situation What it can set aside
Crime, taxation and immigration (Schedule 2, Part 1) Fraud investigations, HMRC enquiries, immigration control Transparency and some rights where they would prejudice the purpose
Legal proceedings and legal professional privilege (Schedule 2, Part 4) Litigation, legal advice Right of access to privileged material
Management forecasts and negotiations (Schedule 2, Part 4) Restructuring plans, salary negotiations Access rights where disclosure would prejudice the business
Confidential references and exam scripts (Schedule 2, Part 4) Employment or academic references, exam answers Right of access, in whole or in part
Journalism, academic, artistic and literary purposes (Schedule 2, Part 5) Publishing in the public interest Most rights and principles where compliance is incompatible with the purpose
Research, statistics and archiving (Schedule 2, Part 6) Scientific or historical research, public archives Certain rights, subject to safeguards
Health, social work and education data (Schedule 3) Medical records, social care files, pupil records Access where disclosure would cause serious harm

Two practical rules apply. Exemptions are applied case by case, never as a blanket policy, and you should record why you relied on one. Where you rely on the journalism, research or legal exemptions, keep evidence that the processing would have been prejudiced without it, because the ICO expects the controller to justify the decision.

Data Protection Records and Documentation

Data protection documentation under the DPA 2018 and UK GDPR is the evidence that you meet the accountability principle. The core set has not changed with the DUAA, but two items have been added: a complaints log and, where relevant, a record of reliance on recognised legitimate interests. The list below is what a well-run compliance programme keeps up to date.

  • Record of Processing Activities (Article 30): Mandatory for organisations with 250 or more employees, and for smaller organisations where processing is not occasional, involves special category or criminal offence data, or is likely to result in a risk to individuals. Most SMEs fall into scope for at least part of their processing.
  • Lawful basis register: The basis relied on for each processing activity, with the legitimate interest assessment where that basis is used.
  • Privacy notices and consent records: The current notice for each audience (customers, staff, candidates) plus proof of consent where consent is the basis.
  • Data Protection Impact Assessments (Article 35): Required before high-risk processing such as large-scale profiling or systematic monitoring. Our guide on what a DPIA is explains when one is needed.
  • Retention schedule: Retention periods and the justification for each, aligned with the storage limitation principle.
  • Breach register (Article 33(5)): Every personal data breach, including those not reported to the ICO, with the facts, effects and remedial action.
  • Rights request and complaints logs: DSARs, erasure requests and, from 19 June 2026, complaints received under the statutory complaints procedure, with response times.
  • Appropriate policy document: Required when relying on most Schedule 1 conditions for special category or criminal offence data.

Case in point: when DPO Consulting runs a compliance audit, the missing item is rarely the ROPA. It is usually the retention schedule or the appropriate policy document, both of which the ICO asks for early in an investigation. Build these into the same register so a single export answers a regulator's request.

Codes of Practice & Future Regulatory Changes

The ICO and UK government publish codes of practice for specific contexts (for example, digital marketing or data sharing in health). These practical guides explain how to apply the law in real situations. For instance, the ICO's codes on data sharing, age-appropriate design for online services used by children, and journalism help businesses stay compliant.

The major update has now happened. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends the UK GDPR, the DPA 2018 and PECR rather than consolidating them. Most of its data protection provisions came into force on 5 February 2026. The changes businesses feel most are the recognised legitimate interests basis, the clarified rules on purpose limitation and DSAR searches, a relaxed regime for automated decision-making outside special category data, consent exemptions for low-risk analytics cookies, the statutory complaints procedure from 19 June 2026, and the creation of the Information Commission. The ICO has published or is finalising guidance on each of these areas, so check its DUAA hub before changing your processes.

On the horizon, new regulations like the EU AI Act (and any future UK AI regulations) will impact how personal data is used in artificial intelligence systems. For example, high-risk AI systems will require transparency and impact assessments, aligning with data protection standards. The UK has so far chosen a sector-led approach rather than a single AI statute; our guide to UK AI regulation tracks where that stands.

Cross-Border Data Transfers Under the DPA 2018

When transferring personal data outside the UK, firms must ensure a legal mechanism. Thanks to the EU's 2021 adequacy decision, renewed on 19 December 2025 until 27 December 2031, data can still flow freely from the European Union and EEA to the UK as if it were domestic. Likewise, transfers from the UK to the EU need no new arrangements while the UK's own adequacy regulations for the EEA remain in place. For transfers to other countries, organisations should rely on adequacy decisions (if any), the ICO's UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or other UK-approved safeguards.

Note: the renewed EU adequacy decisions now also cover personal data transferred for UK immigration control purposes, which the 2021 decisions had excluded. The DUAA also replaced the UK's adequacy test with a "data protection test" that asks whether the destination country's standard is not materially lower than the UK's. In all cases, update your privacy notices to mention international transfers and safeguards in place.

Get Support with DPA 2018 Compliance

Applying the UK Data Protection Act can be complex, but you don't have to go it alone. Our UK GDPR Compliance Services offer expert guidance on DPA 2018 and UK GDPR. Whether you need a gap analysis, policy updates, training, or ongoing consulting, we can help you turn compliance into a competitive asset. Our consultants have helped many clients across industries implement effective data protection frameworks.

To explore how we can assist your business in meeting UK (and international) data privacy obligations, request a quote or book a call with a GDPR expert

FAQ

What is the difference between the DPA 2018 and UK GDPR?

The UK GDPR and the DPA 2018 work together. The UK GDPR (essentially the EU GDPR converted into UK law) sets out the general data protection requirements. The DPA 2018 supplements it with UK-specific rules, for example, sections on law enforcement, special category data, and certain exemptions. In effect, the UK GDPR provides the broad framework, and the DPA 2018 fills in the details and exceptions.

Does the DPA 2018 still apply after Brexit?

Yes. The Data Protection Act 2018 is still in force. What changed is that references to the EU GDPR were replaced with the UK GDPR. After Brexit, the UK used the EU Withdrawal Act to copy GDPR into domestic law and updated the DPA 2018 accordingly. So UK organisations continue to follow the combined framework of the UK GDPR and DPA 2018. EU companies dealing with UK data must follow UK rules (with a UK representative if needed), and UK companies dealing with EU data must follow both UK and EU GDPR.

Do small businesses need to comply with the DPA 2018?

Generally, yes. Any UK organisation that processes personal data of UK residents must comply with the Data Protection Act 2018 and UK GDPR. There are no blanket exemptions for SMEs. However, regulatory expectations are proportional. A small business still needs to handle data lawfully (e.g. via consent or contract), keep it secure, and respect individuals' rights. Often, small businesses can fulfil many requirements more simply (for example, a brief privacy policy instead of dozens of pages). The ICO does focus more on high-risk processing, but compliance is mandatory for all.

What are the penalties for breaching the DPA 2018?

The Information Commissioner's Office (ICO) can impose hefty fines for DPA/UK GDPR violations. For serious infringements of data protection principles or rights, fines can reach up to £17.5 million or 4% of annual global turnover (whichever is higher). For lesser breaches (e.g., failing to appoint a DPO when required), fines can go up to £8.7 million or 2% of turnover. There are also non-monetary penalties: the ICO can issue reprimands, enforcement orders, and, in some cases, prosecutors can seek criminal sanctions for offences like destroying data to avoid disclosure. Since February 2026, PECR breaches carry the same £17.5 million or 4% maximum.

Can you help us comply with both UK and international data laws?

Absolutely. Our services cover UK GDPR and Data Protection Act 2018 compliance, and we also advise on international regimes like EU GDPR, PIPEDA (Canada), and others. For UK-focused support, our UK GDPR Compliance Services can guide you through the DPA 2018 requirements. We can also act as your UK or EU representative if you need one. We help businesses put in place policies, procedures, and tools that satisfy multiple jurisdictions' laws, so you're protected globally.

How does the DPA 2018 apply to cross-border data flows?

Under the DPA 2018 (together with UK GDPR), cross-border transfers need a lawful mechanism. With an EU adequacy decision in place, data from the EEA can flow to the UK freely. Transfers from the UK to the EU also continue as before, The EU decisions were renewed on 19 December 2025 and run until 27 December 2031. For other countries, UK organisations must use approved safeguards (e.g., the UK IDTA or UK Addendum, binding corporate rules) or ensure an adequacy finding exists.

What data protection rights do individuals have under the DPA 2018?

Individuals have eight core rights under the UK Data Protection Act and UK GDPR: to be informed, to access their data, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision-making. Since 19 June 2026 they also have a statutory right to complain directly to the organisation and receive an acknowledgement within 30 days.

What types of personal data are covered by the DPA 2018?

The DPA 2018 covers any information relating to an identified or identifiable living person, including online identifiers such as IP addresses and cookie IDs. Special category data (health, ethnic origin, religion, biometrics, sexual orientation and others) and criminal offence data are covered with additional conditions. Anonymised data and data about deceased people are outside scope.

Who is responsible for complying with the DPA 2018?

The controller (the organisation deciding why and how personal data is processed) carries primary responsibility. Processors acting on the controller's behalf have direct duties on security, breach notification and record-keeping. Senior management remains accountable to the ICO even where a Data Protection Officer or an outsourced DPO handles the day-to-day work.

What is a Data Protection Officer's role under the DPA 2018?

A Data Protection Officer monitors compliance with the DPA 2018 and UK GDPR, advises on Data Protection Impact Assessments, trains staff and acts as the contact point for the ICO and for individuals. Appointment is mandatory for public authorities and for organisations whose core activities involve large-scale regular monitoring or large-scale special category data processing. Many organisations outsource the role to gain independent expertise without a full-time hire.

What records must organisations maintain under the DPA 2018?

Organisations must maintain a Record of Processing Activities where Article 30 applies, a breach register, evidence of lawful basis and consent, Data Protection Impact Assessments for high-risk processing, an appropriate policy document where Schedule 1 conditions are used, and logs of rights requests and, from June 2026, complaints. Keeping these current is how you demonstrate the accountability principle.

References

  • Data Protection Act 2018, c. 12. (2018). legislation.gov.uk. https://www.legislation.gov.uk/ukpga/2018/12/contents
  • Data (Use and Access) Act 2025, c. 18. (2025). legislation.gov.uk. https://www.legislation.gov.uk/ukpga/2025/18/contents
  • The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, SI 2026/82. (2026). legislation.gov.uk. https://www.legislation.gov.uk/uksi/2026/82/made
  • Department for Science, Innovation and Technology. (2025). Data Use and Access Act 2025: plans for commencement. GOV.UK. https://www.gov.uk/guidance/data-use-and-access-act-2025-plans-for-commencement
  • European Commission. (2025, December 19). Commission renews decisions to allow for the free and safe flow of personal data with the UK [Press release IP/25/3059]. https://europa.eu/newsroom/ecpc-failover/pdf/ip-25-3059_en.pdf
  • Information Commissioner's Office. (2026, February 5). Statement on the commencement of the Data (Use and Access) Act (DUAA). https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/02/statement-on-the-commencement-of-the-data-use-and-access-act-duaa/
  • Information Commissioner's Office. (n.d.). Data (Use and Access) Act 2025. Retrieved 18 September 2026, from https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/

Read this next

See all