The Data Protection Act (DPA) 2018 is the UK’s updated data protection law, effective from 25 May 2018 and amended on 1 January 2021 to reflect the UK’s exit from the EU. It sits alongside the UK GDPR and replaces the Data Protection Act 1998.
The United Kingdom is no longer part of the EU, and the Data Protection Act alongside the UK GDPR are the current laws governing personal data processing in the UK.
Data Protection Parts

The Data Protection Act is made up of four “data protection regimes”:
- Part One: Preliminary
- Part Two: General processing
- Part Three: Law enforcement processing
- Part Four: Intelligence services processing
For most businesses, Parts One and Two are the most relevant.
Part One: Preliminary

Part One sets out definitions of key terms, most of which mirror the GDPR: personal data, identifiable living individual, processing, data subject, controller/processor, personal data relating to criminal convictions, and “court” (which doesn’t include a tribunal under the DPA).
Part Two: General Processing

Part Two supplements the UK GDPR and covers processing both within and outside the scope of the EU GDPR.
Processing included in the GDPR: the DPA aligns with the GDPR’s core data protection principles: personal data is processed lawfully, fairly, and transparently; used only for specific, explicit purposes; adequate, relevant, and limited to what’s necessary; accurate and kept up to date; not retained longer than necessary; and handled securely.
Where the DPA differs from the GDPR: the DPA sets the age of consent for online data processing at 13 (versus 16 under the GDPR), covers processing for law enforcement, national security, and immigration (areas the GDPR doesn’t cover), specifies fines for illegally re-identifying anonymised personal data, and allows automated processing where there are legitimate grounds.

Legal bases for processing: under the DPA, there are six legal bases for collecting and processing personal data: consent, fulfilling a contract, protecting an individual’s vital interests, a legal obligation, a task carried out in the public interest or under official authority, and a legitimate interest.
Where you rely on consent, it must be unambiguous, explicit (obtained as a standalone action), informed, freely given, and recorded.
Data Subjects’ Rights
The DPA, like the GDPR, sets out data protection rights for individuals (with limited exceptions for intelligence and immigration services). Individuals have the right to:
- Access a copy of their personal data
- Be informed about what’s collected, processed, shared, or stored
- Rectification of incorrect personal data
- Be forgotten: have their data erased
- Data portability: receive their data for use with other services
- Withdraw consent at any time
- Object to how their data is used
- Object to automated decision-making
- Object to profiling

Conclusion
To comply with the DPA’s data protection principles and data subject rights, consider creating a privacy policy (required by most privacy laws, not just the DPA), creating a data protection policy so staff understand their responsibilities around processing and breach handling, and performing a data audit to understand what data you hold and how it’s secured.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.