Data Protection Matters
← All privacy laws

United Kingdom

UK GDPR & DPA 2018

UK General Data Protection Regulation and the Data Protection Act 2018 (2018 c. 12)

Keywords

UK GDPRData Protection Act 2018DPA 2018United KingdomICOInformation Commissionerpersonal datacontrollerprocessorlawful basisDPIADPOdata breachIDTAUK AddendumData (Use and Access) Act 2025
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

UK data protection law rests on two instruments that work together. The UK GDPR is the retained version of the EU General Data Protection Regulation, which has applied in the UK in its own form since the end of the Brexit transition period on 31 December 2020. The Data Protection Act 2018 (DPA 2018) supplements it with UK-specific rules, exemptions, the regulator's powers and separate regimes for law enforcement and intelligence services. Both have been amended by the Data (Use and Access) Act 2025, whose provisions are being brought into force in stages.

Who it applies to

The UK GDPR applies to organizations established in the UK and to organizations elsewhere that offer goods or services to people in the UK or monitor their behaviour in the UK. As under the EU law, a "controller" decides why and how personal data is processed and a "processor" acts on the controller's behalf. Part 3 of the DPA 2018 covers processing by competent authorities for law enforcement purposes, and Part 4 covers the intelligence services.

Core principles

Personal data must be processed lawfully, fairly and transparently, collected for specified purposes, limited to what is necessary, kept accurate, retained no longer than needed, and kept secure. Controllers are also accountable: they must be able to demonstrate compliance, not just claim it.

Every processing activity needs a lawful basis: consent, contract, legal obligation, vital interests, public task or legitimate interests. Special category data, such as health or biometric data, needs an additional condition, and Schedule 1 of the DPA 2018 sets out many of those conditions. The Data (Use and Access) Act 2025 added a list of "recognised legitimate interests" that controllers can rely on without carrying out the usual balancing test.

Individual rights

Individuals have the rights to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision-making and profiling. Organizations generally have one month to respond to a request. The 2025 Act clarifies that searches for personal data in response to an access request need only be reasonable and proportionate.

Key obligations

Organizations must apply appropriate technical and organizational security, keep records of processing, build in data protection by design and by default, carry out a Data Protection Impact Assessment (DPIA) for high-risk processing, and appoint a Data Protection Officer (DPO) in defined cases. Written contracts are required between controllers and processors. Most organizations that process personal data must also pay a data protection fee to the regulator, unless exempt.

Data breaches

A personal data breach must be reported to the Information Commissioner's Office (ICO) without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Where the risk is high, the affected individuals must be told directly. All breaches must be recorded internally, whether or not they are reported.

International transfers

Personal data can be sent outside the UK only with a safeguard in place. The main routes are UK adequacy regulations (sometimes called data bridges), the International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, and Binding Corporate Rules. Transfers also need a risk assessment of the destination country's laws.

Enforcement and penalties

The ICO, the UK's independent regulator, enforces the regime and is being restructured into a body called the Information Commission under the 2025 Act. The UK GDPR sets a higher maximum fine of the greater of 17.5 million pounds or 4% of worldwide annual turnover, and a standard maximum of the greater of 8.7 million pounds or 2%. Individuals can also seek compensation through the courts, and the DPA 2018 creates criminal offences such as unlawfully obtaining personal data.

The official text

The authoritative version of the Data Protection Act 2018 is published by the UK government on legislation.gov.uk, and the UK GDPR is published in its retained form at https://www.legislation.gov.uk/eur/2016/679/contents. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →