Data Protection Act 2018
Tier 1 Partially in forceThe UK's domestic data protection statute. It supplies the UK-specific detail the GDPR leaves to member state law, transposes the Law Enforcement Directive in Part 3, and covers processing outside the UK GDPR's scope (intelligence services, Part 4). It is read with the UK GDPR as a single regime rather than as a standalone code. Its most-missed layer is criminal: five distinct offences, all fine-only, sitting entirely separately from the ICO's regulatory penalties.
Identity
- Citation
- Data Protection Act 2018, c. 12
- Jurisdiction
- United Kingdom
- Type
- comprehensive
- Structure
- 7 Parts, 20 Schedules, ~215 sections
- Royal assent
- 23 May 2018
- Main commencement
- 25 May 2018
Commenced essentially in full alongside the GDPR on 25 May 2018 and has been amended in place since, rather than left with dangling uncommenced sections. Status is "partially in force" only because the amending Data (Use and Access) Act 2025 is itself commencing in phases through 2025–26.
Reads together with
- UK GDPR (retained Regulation (EU) 2016/679)
Inseparable. The two are read as a single regime via a Keeling-schedule-style construction — the Act is not self-contained and cannot be interpreted alone.
Asymmetry checklist
All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap. Checked by Owen S on 25 July 2026.
| # | Point | Finding | Notes |
|---|---|---|---|
| 1 | Territorial extent | Asymmetry found | Extends to England and Wales, Scotland and Northern Ireland uniformly except for the Schedule 2, Part 2 corporate finance exemption, which per ICO guidance can only apply in England, Wales and Northern Ireland and cannot apply in Scotland. No other section carves out a UK nation. This is a narrow, specific asymmetry, not evidence of a wider devolved pattern — data protection is a reserved matter under the Scotland Act 1998 and its equivalents. |
| 2 | Commencement | None found — checked | No asymmetry, but not static. The Act commenced essentially in full on 25 May 2018 (s.198, for instance, is in force from that date). The live edit is the Data (Use and Access) Act 2025, which is itself commencing in phases through 2025–26 — so any date-sensitive claim about the amended text needs its commencement confirmed before publication. |
| 3 | Sunset / mandatory review | None found — checked | The Act carries no built-in expiry or mandatory review. The related but external UK adequacy decisions do carry a sunset-adjacent mechanism (renewed 19 December 2025 to 27 December 2031, with a mandatory review at the four-year mark) — worth cross-referencing, but not internal to the Act. |
| 4 | Criminal liability | Asymmetry found | A distinct criminal track exists, separate from regulatory fines: ss.170, 171, 173, 184 and 132. All are fine-only — no imprisonment is available for any of them — and all carry an unlimited fine ceiling. The practical consequence is an escalation asymmetry: high-harm conduct a prosecutor thinks merits custody is charged instead under the Fraud Act 2006 or the Computer Misuse Act 1990. |
| 5 | Civil liability | None found — checked | Compensation runs through Article 82 UK GDPR read with s.168 DPA 2018, covering material and non-material damage, in the County Court or High Court (sheriff court or Court of Session in Scotland). There is no general private right of action of the California type. |
| 6 | Regulatory enforcement toolkit | None found — checked | Four instruments, uniformly available: information notice, assessment notice, enforcement notice and penalty notice (s.155), the last capped at the higher of £17.5m or 4% of global annual turnover, with a lower tier for less serious infringements mirroring the GDPR's two-tier structure. |
| 7 | Personal / director liability | Asymmetry found | Section 198 makes a director, manager, secretary or similar officer personally guilty alongside the body corporate where an offence is committed with their consent or connivance, or is attributable to their neglect. s.198(3) extends the same logic to partnerships and unincorporated membership bodies. This is criminal only — there is no civil equivalent making directors personally liable for Art 82 compensation claims in the ordinary case. |
| 8 | Public vs private sector split | Asymmetry found | No public/private split in the statute (contrast Mexico, Switzerland), but the Parts diverge internally by purpose: Part 2 (general processing under the UK GDPR), Part 3 (law enforcement, transposing the LED) and Part 4 (intelligence services, overseen partly by IPCO rather than solely the ICO). A single controller can be a Part 2 body for most of its processing and a Part 3 or 4 body for a slice of it. |
| 9 | Legal-person coverage | None found — checked | Natural persons only, consistent with the GDPR. No extension to companies or other legal persons (contrast POPIA and the old Swiss FADP). |
| 10 | Exemptions — with conditions | Asymmetry found | Schedules 2, 3 and 4 disapply specific rights subject to specific tests, not as blanket carve-outs. Triggers differ materially between them — a prejudice test for crime and taxation, a policy-document-and-vulnerability safeguard for immigration (post-2022), and a geographic limit for corporate finance. Recorded individually below with their trigger conditions. |
Criminal liability
A distinct track, separate from the regulatory penalties below. The same failure can attract both — a penalty notice against the organisation and a prosecution of the individual.
s.170 — Unlawfully obtaining, disclosing, procuring or retaining personal data
Obtaining or disclosing personal data without the controller's consent; procuring its disclosure to another person without consent; or retaining personal data after obtaining it without the consent of the person who was the controller at the time — the extension over the old DPA 1998 s.55 offence. Selling, or offering to sell, data knowingly or recklessly obtained or disclosed this way is also caught. Historically the most-charged data offence, commonly used against people who accessed healthcare or financial records out of curiosity or for gain.
- Mens reaMens reaThe mental element an offence requires — intention, knowledge, recklessness or negligence. An offence with no mens rea is one you can commit without meaning to.Defined in: General criminal law, not data protection statutes
- Knowingly or recklessly
- Penalty
- Unlimited fine (no custodial sentence available)
- Imprisonment
- Not available
- Recordable
- Yes
Defences
- Reasonable belief in the controller's consent
- Acting under legal compulsion or a court order
- For journalism, a reasonable belief that the conduct was justified in the public interest
s.171 — Re-identification of de-identified personal data
Re-identifying information that has been de-identified (for example by redaction) without the consent of the controller who de-identified it. Introduced on the recommendation of the National Data Guardian for Health and Care.
- Mens reaMens reaThe mental element an offence requires — intention, knowledge, recklessness or negligence. An offence with no mens rea is one you can commit without meaning to.Defined in: General criminal law, not data protection statutes
- Knowingly or recklessly
- Penalty
- Unlimited fine
- Imprisonment
- Not available
- Recordable
- Yes
Defences
- Re-identification necessary for preventing or detecting crime
- Required or authorised by an enactment, a rule of law, or a court/tribunal order
s.173 — Altering records to prevent disclosure
A controller — or someone employed by, an officer of, or otherwise directed by the controller — who alters, defaces, blocks, erases, destroys or conceals information intending to prevent its disclosure to someone who had made a subject access request and would have been entitled to receive it. Builds on an equivalent FOIA 2000 offence.
- Penalty
- Unlimited fine
- Imprisonment
- Not available
- Recordable
- Yes
Defences
- The alteration or destruction would have happened regardless of the request
s.184 — Enforced subject access
Requiring another person to exercise their own subject access right and supply the resulting records as a condition of employment, of a contract, or of the provision of goods, facilities or services to the public — the "let us see your DSAR results before we'll hire, insure or serve you" scenario. Builds on DPA 1998 s.56; the "relevant records" concept is defined in Schedule 18.
- Penalty
- Unlimited fine
- Imprisonment
- Not available
s.132 — Unlawful disclosure by the Commissioner's staff
Criminalises current or former ICO staff, and those acting on the Commissioner's behalf, who unlawfully disclose information obtained in the course of their duties. Replaces DPA 1998 s.59.
- Penalty
- Unlimited fine
- Imprisonment
- Not available
Civil liability
Compensation is available for material and non-material damage. Non-material damage (distress, loss of control over one's data) is expressly compensable — a genuine expansion over the pre-GDPR position, where UK courts were initially reluctant to award damages for distress alone. There is no general private right of action of the California type: individuals rely on Art 82/s.168 for money and on the ICO's regulatory toolkit for orders requiring compliance.
- Article 82 UK GDPR, read with DPA 2018 s.168
County Court or High Court (sheriff court or Court of Session in Scotland) · Material and non-material damage — Claim lies against the controller or the processor.
- DPA 2018 s.167 — compliance orders
County Court or High Court — The court may order a controller or processor to take specified steps to comply, alongside or instead of ordering compensation.
Regulatory enforcement
- Penalty ceiling
- Higher of £17.5m or 4% of global annual turnover — the UK-currency mirror of the GDPR's €20m/4% ceiling. A lower tier applies to less serious categories of infringement, mirroring the GDPR's two-tier structure.
- Information notice
Requires the recipient to provide specified information within a set period.
- Assessment notice
Permits the ICO to assess whether a controller or processor is complying — an audit power.
- Enforcement notice
Requires specified steps to bring processing into compliance, or stops specified processing altogether.
- Penalty notice s.155
The financial penalty, at the ceiling above.
These sit entirely separately from the criminal offences. A company can face a s.155 penalty notice for the underlying data protection failure and, independently, an employee can be prosecuted under s.170 for what they personally did with the data.
Personal / director liability
- Available
- Yes
- Basis
- s.198 (and s.198(3) for partnerships and unincorporated membership bodies)
Where an offence is committed by a body corporate with the consent or connivance of, or attributable to neglect on the part of, a director, manager, secretary or similar officer (or someone purporting to act as one), that individual is personally guilty alongside the body corporate and liable to be proceeded against and punished accordingly. Offences under ss.170, 171 and 173 are recordable, so a conviction leaves a criminal record.
Legal-person coverage
- Covers legal persons
- No — natural persons only
Protection runs to identified or identifiable natural persons only, consistent with the GDPR. Contrast POPIA and the old Swiss FADP, which covered legal persons.
Public / private sector split
- Separate regimes
- No — one statute
One statute for public and private sectors alike. The real internal asymmetry is not public/private but which Part governs which purpose — a police force is a Part 3 body for its investigations and a Part 2 body for its HR data.
- Part 2
General processing under the UK GDPR — public and private sector alike.
- Part 3
Competent authorities processing for law enforcement purposes (transposing the Law Enforcement Directive), with its own principles and rights, distinct from Part 2.
- Part 4
Intelligence services processing, with its own distinct regime and oversight via the Investigatory Powers Commissioner, not solely the ICO.
Exemptions
Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.
Sch 2, para 2 — Crime and taxation — general
Trigger
Applies only to the extent that applying the right would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of a tax or duty. A prejudice test applied case by case — not an automatic exemption for anyone processing crime-adjacent data.
Disapplies
- The principles, so far as inconsistent
- Transparency obligations
- The right of access
- Related rights
Sch 2, para 3 — Crime and taxation — risk assessment systems
Trigger
A classification applied to a data subject under a government or local-authority risk-assessment system, for example for housing benefit fraud risk. Narrower than the general crime and taxation exemption.
Disapplies
- Specified rights in relation to the classification
Sch 2, para 4 — Immigration
Trigger
Applies where applying the right would be likely to prejudice effective immigration control. Since the 2022 amendment the Secretary of State must maintain a published immigration exemption policy document, and must take into account the data subject's vulnerability, their Convention rights and relevant UK obligations — including under the Refugee Convention, the Trafficking Convention, and the s.55 Borders, Citizenship and Immigration Act 2009 duty regarding child welfare — before relying on it.
Disapplies
- Specified data subject rights
The most contested exemption in the Act. Found unlawful in the Open Rights Group litigation for lacking adequate safeguards, then amended in 2022 to add the safeguards above.
Sch 2, Part 2 — Corporate finance
Trigger
Processing in connection with a corporate finance service — underwriting, corporate finance advice — permitted under FSMA 2000.
Disapplies
- The GDPR's transparency provisions in relation to that processing
- The right of access in relation to that processing
Territorial limit
England, Wales and Northern Ireland only. Per ICO guidance this exemption cannot apply in Scotland — the Act's single territorial asymmetry.
Amendment history
| Instrument | Year | Effect |
|---|---|---|
| Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 | 2019 | Created the UK GDPR by onshoring Regulation (EU) 2016/679. |
| Data Protection Act 2018 (Amendment of Schedule 2 Exemptions) Regulations 2022 | 2022 | Added the immigration exemption policy-document safeguard and the vulnerability and Convention-rights considerations. |
| Retained EU Law (Revocation and Reform) Act 2023 | 2023 | Removed the historic supremacy of EU law over UK domestic statute, with the live consequence for Schedule 2 recorded under live issues below. |
| Data (Use and Access) Act 2025 | 2025 | The largest substantive amendment to date — recognised legitimate interests (no balancing test for a defined list of purposes); reformed automated decision-making (Arts 22A–22D, permitting more automated significant decisions with safeguards); a codified "reasonable and proportionate" standard for subject access searches with a stop-the-clock provision; and restructuring of the ICO into an Information Commission, a board replacing the corporation-sole Commissioner. Commencing in phases through 2025–26. Confirm the current commencement status before publishing any date-sensitive claim that depends on it. |
Interactions and conflicts
The cross-instrument texture that profiling an Act in isolation misses — including where the real answer to a question about this Act is found in a different one.
| Instrument | Relationship | Note |
|---|---|---|
| UK GDPR | Reads with | Inseparable — read as a single regime via the Keeling-schedule construction. The DPA cannot be interpreted in isolation from it. |
| Privacy and Electronic Communications Regulations 2003 (PECR) | Lex specialis | Lex specialis for direct marketing and cookies. Amended alongside the DUAA to add consent-free exceptions for low-risk analytics, with PECR fines raised to UK GDPR levels. |
| Freedom of Information Act 2000 | Cross-reference | The s.40 FOIA exemption routes personal-data requests back through the DPA's framework, and DPA s.173 builds directly on an equivalent FOIA offence. Note the devolution contrast: FOI is devolved in Scotland (Freedom of Information (Scotland) Act 2002, separate regulator, separate 20-working-day public-interest-test rule) while data protection is reserved — the two Acts diverge in exactly opposite directions on devolution. |
| Fraud Act 2006 / Computer Misuse Act 1990 | Escalation route | Because s.170 is fine-only, a sophisticated or high-harm breach a prosecutor feels merits custody is often charged under these instead. The honest answer to "what is my criminal exposure for unlawfully accessing data?" frequently is not found in the DPA 2018 at all. |
| Investigatory Powers Act 2016 | Overlapping oversight | Governs the intelligence-services processing that Part 4 DPA sits alongside; oversight is shared between the ICO and the Investigatory Powers Commissioner. |
Live issues
Sources
- Primary Data Protection Act 2018 (c. 12) legislation.gov.uk
- Regulator ICO guidance on exemptions Information Commissioner's Office
Source of the Scotland limitation on the corporate finance exemption. Deep link not yet recorded — capture the exact guidance URL on the next verification pass.
- Primary Data (Use and Access) Act 2025 legislation.gov.uk no verified URL yet
URL not yet verified; confirm chapter number and commencement regulations before citing.
- Case law R (Open Rights Group) v Secretary of State for the Home Department no verified URL yet
The immigration exemption litigation referenced under Sch 2 para 4. Full citation to be recorded on the next verification pass.
Last verified 25 July 2026 by Owen S