UK Act of Parliament 2018 United Kingdom

Data Protection Act 2018

At a glance

Enforced by

ICO, SRA, LSB, RQIA, Forestry Commission

What's here

87 compliance obligations, 140 practical guides across 6 topics · 36 journeys · 9 statutory instruments

Penalty landscape

54 of 87 obligations carry a fine up to £17,500,000. 12 carry different penalties and 21 have no criminal penalty — flagged in the list below.

Who this Act binds

Business-side actors with duties under this Act, ranked by how often they appear.

  • Data Controller 46
  • Any Person 17
  • Director or Officer 1
  • Contractor 1

Plus 22 non-business duties on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

Step-by-step journeys using this legislation

Walkthroughs that take you from a real business situation to compliance.

Relevant guidance

Practical guides for businesses affected by this Act, ordered by how closely they engage with it.

Other Acts binding the same actors

For each actor bound by this Act, the other UK Acts that bind them most often. Useful for understanding the full compliance landscape facing each role.

Data Controllers also bound by 7 other Acts (top 5 shown)
Any Person also bound by 749 other Acts (top 5 shown)
Directors and Officers also bound by 224 other Acts (top 5 shown)
Contractors also bound by 56 other Acts (top 5 shown)

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

Part 1 — Preliminary

Browse 2 other sections in this Part — procedural / definitional / commencement

Part 3 — Law enforcement processing

s.041

Safeguards: archiving

Fine up to £17,500,000
  • Do not use archived law enforcement data to make decisions about individuals Data Controller
s.046

Right to rectification

Fine up to £17,500,000
  • Correct or complete inaccurate personal data upon request Data Controller
s.050

Restrictions on automated decision-making based on sensitive processing

Fine up to £17,500,000
  • Do not make significant decisions using only automated sensitive data processing Data Controller
s.050

Safeguards for automated decision-making

Fine up to £17,500,000
  • Provide safeguards for automated decision-making Data Controller
s.058

Joint controllers

Fine up to £17,500,000
  • Create a formal agreement and contact point with joint data controllers Data Controller
s.059

Processors

Fine up to £17,500,000
  • Use only compliant data processors and maintain written contracts Data Controller
s.062

Logging

Fine up to £17,500,000
  • Maintain and share automated logs of data processing operations Data Controller
s.066

Security of processing

Fine up to £17,500,000
  • Implement appropriate security measures for personal data Data Controller
s.074

Transfers approved by regulations: monitoring

Other duties (1) — Crown / regulator
  • Secretary of State must monitor and update approved data transfer lists Crown / Minister / Government department
s.078

Subsequent transfers

Fine up to £17,500,000
  • Control further transfers of law enforcement data abroad Data Controller
Browse 31 other sections in this Part — procedural / definitional / commencement

Part 4 — Intelligence services processing

s.082

Records of designation notices

Other duties (1) — Crown / regulator
  • Secretary of State must notify ICO of designation notices Crown / Minister / Government department
s.094

Right of access

Fine up to £17,500,000
  • Respond to personal data access requests Data Controller
Browse 15 other sections in this Part — procedural / definitional / commencement
s.082

Designation of processing by a qualifying competent authority

s.082

Duration of designation notice

s.082

Review and withdrawal of designation notice

s.082

Appeal against designation notice

s.091

Further provision about sensitive processing

Part 5 — The Information Commissioner

s.114

The Information Commission

Amended 1 time
s.119

Standard clauses for transfers to third countries etc

Amended 4 times
s.120

Principal objective

Amended 9 times
s.120

Duties in relation to functions under the data protection legislation

Amended 9 times
Other duties (1) — Crown / regulator
  • ICO must consider innovation and competition when enforcing data laws Statutory regulator
s.120

Strategy

Amended 9 times
Other duties (1) — Crown / regulator
  • Information Commissioner must publish a data protection strategy Statutory regulator
s.120

Duty to consult other regulators

Amended 9 times
s.121

Data-sharing code

Amended 2 times
Other duties (1) — Crown / regulator
  • ICO must produce and maintain a data-sharing code of practice Statutory regulator
s.122

Direct marketing code

Fine up to £17,500,000 Amended 2 times
Other duties (1) — Crown / regulator
  • ICO must produce and maintain a direct marketing code of practice Statutory regulator
s.124

Other codes of practice

Amended 3 times
Other duties (1) — Crown / regulator
  • ICO must prepare codes of practice on personal data processing Statutory regulator
s.124

Panels to consider codes of practice

Amended 3 times
s.124

Impact assessments for codes of practice

Amended 3 times
Other duties (1) — Crown / regulator
  • ICO must conduct impact assessments for codes of practice Statutory regulator
s.136

Guidance about fees

Amended 5 times
Other duties (1) — Crown / regulator
  • ICO must publish guidance on fees and consult the Secretary of State Statutory regulator
s.139

Analysis of performance

Amended 9 times
Other duties (1) — Crown / regulator
  • ICO must publish an annual analysis of its own performance Statutory regulator

Part 6 — Enforcement

s.146

Assessment notices: approval of person to prepare report etc

Fine up to £17,500,000 Amended 16 times
  • Nominate a person to prepare an assessment report Data Controller
s.148

Interview notices

Amended 7 times
s.148

Interview notices: restrictions

Amended 7 times
s.148

False statements made in response to interview notices

2 years imprisonment Amended 7 times
  • Make false statement in response to interview notice Any Person
s.161

Annual report on regulatory action

Amended 6 times
s.164

Complaints by data subjects to controllers

Fine up to £17,500,000 Amended 4 times
  • Establish and manage a formal data protection complaint process Data Controller
s.164

Controllers to notify the Commissioner of the number of complaints

Amended 4 times
s.180

Procedure in connection with subject access requests

Amended 4 times

Part 7 — Supplementary and final provision

s.183

Protection of prohibitions and restrictions etc on processing: relevant enactments

Amended 5 times
s.183

Protection of prohibitions and restrictions etc on processing: other enactments

Amended 5 times
s.186

Protection of data subject’s rights: further provision

Amended 8 times
Browse 2 other sections in this Part — procedural / definitional / commencement

Other sections — not classified into a Part

These sections exist in the Act but the contents-of-Parts walker did not place them under a Part. Likely amendments or sections inserted out of the original Part structure.

Browse 1 other unclassified section
s.processing in reliance on relevant international l

Processing in reliance on relevant international law

Official guidance

Authoritative sources published by regulators or government explaining this legislation.

Enforcement and responsible bodies

The regulators that administer or enforce this legislation.

ICO

Primary

Information Commissioner's Office

Data protection, freedom of information, privacy and electronic communications regulation. Enforces UK GDPR and Data Protection Act 2018. Issues fines for breaches. …

SRA

Solicitors Regulation Authority

Regulates solicitors and law firms in England and Wales. Sets standards, authorises firms, investigates misconduct, and can impose sanctions including fines and …

LSB

Legal Services Board

Oversight regulator for legal services in England and Wales. Supervises approved regulators including SRA, Bar Standards Board, and CILEx. Ensures regulation serves …

Regulation and Quality Improvement Authority

Independent regulator for health and social care services in Northern Ireland. Registers and inspects hospitals, care homes, dental practices, and other care …

Government department responsible for protecting, expanding, and promoting the sustainable management of woodlands in England. Issues felling licences, administers woodland creation grants, …

9 statutory instruments

Explore more

Browse legislation

Find other UK business legislation with related guidance.

Regulators

Learn more about the bodies that enforce this legislation.