Retained EU Law 2016 United Kingdom

UK GDPR

What this means for your business

1 guides
Enforced by
ICO
Applies to
United Kingdom
On this page
1 practical guide
Read full text on legislation.gov.uk

Practical guidance

Our guides explain how to comply with the requirements above.

Sections and provisions

119 classified provisions from this legislation.

Duties 35

  • s.5 Principles relating to processing of personal data reasonable step
  • s.7 Conditions for consent
  • s.8 Conditions applicable to child's consent in relation to information society services Paragraph 1
  • s.12 Transparent information, communication and modalities for the exercise of the rights of the data subject information referred
  • s.14 Information to be provided where personal data have not been obtained from the data subject
  • s.15 Right of access by the data subject available information as
  • s.16 Right to rectification
  • s.19 Notification obligation regarding rectification or erasure of personal data or restriction of processing recipient
  • s.21 Right to object time
  • s.24 Responsibility of the controller
  • s.25 Data protection by design and by default such measures
  • s.26 Joint controllers
  • s.28 Processor The processor
  • s.29 Processing under the authority of the controller or processor
  • s.31 Cooperation with the Commissioner
  • s.32 Security of processing
  • s.33 Notification of a personal data breach to the Commissioner is unlikely
  • s.34 Communication of a personal data breach to the data subject is likely
  • s.35 Data protection impact assessment
  • s.36 Prior consultation of its powers referred
  • ... and 15 more duties

Offences and penalties 2

  • s.10 Processing of personal data relating to criminal convictions and offences
  • s.84 Penalties

Powers 10

  • s.23 Restrictions
  • s.58 Powers
  • s.80 Representation of data subjects
  • s.85 Processing and freedom of expression and information
  • Appropriate safeguards: further provision Appropriate safeguards: further provision
  • Further provision about automated decision-making Further provision about automated decision-making
  • Purpose limitation: further processing Purpose limitation: further processing
  • Restriction in the public interest Restriction in the public interest
  • Transfers approved by regulations Transfers approved by regulations
  • Transfers subject to appropriate safeguards: furth Transfers subject to appropriate safeguards: further provision

Definitions 7

  • s.4 Definitions direct marketing tribunal
  • Appropriate safeguards Appropriate safeguards approved medical research relevant NHS body
  • Automated processing and significant decisions Automated processing and significant decisions
  • Further provision about processing of special cate Further provision about processing of special categories of personal data added processing
  • Meaning of “applicable time period” Meaning of “applicable time period” the applicable time period The relevant time
  • Periods of time Periods of time the Periods of Time Regulation
  • The data protection test The data protection test

Exemptions 18

  • s.2 Material scope
  • s.6 Lawfulness of processing
  • s.9 Processing of special categories of personal data
  • s.11 Processing which does not require identification
  • s.13 Information to be provided where personal data are collected from the data subject
  • s.17 Right to erasure (‘right to be forgotten’)
  • s.18 Right to restriction of processing
  • s.20 Right to data portability
  • s.27 Representatives of controllers or processors not established in the United Kingdom
  • s.30 Records of processing activities
  • s.41 Monitoring of approved codes of conduct
  • s.47 Transfers subject to appropriate safeguards: Binding corporate rules
  • s.49 Derogations for specific situations
  • s.82 Right to compensation and liability
  • s.86 Processing and public access to official documents
  • s.95 Relationship with domestic law made before IP completion day implementing Directive 2002/58/EC of the European Parliament and of the Council of 12th July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector
  • Processing and national security and defence Processing and national security and defence
  • Regulations made by Secretary of State Regulations made by Secretary of State