Skip to content

Data Protection Act 2018

(DPA 2018)

The UK statute supplementing the UK GDPR with domestic provisions, exemptions, and enforcement mechanisms. Implements the EU Law Enforcement Directive for criminal justice processing, and the Intelligence Services Directive. Section 170 makes unauthorised obtaining of personal data a criminal offence.

The DPA 2018 implements detailed UK rules alongside the UK GDPR: Part 2 (the GDPR's domestic implementation), Part 3 (Law Enforcement processing under Directive 2016/680), Part 4 (Intelligence Services). The criminal offences include: unlawful obtaining, disclosure, or procurement (s.170 — maximum unlimited fine), re-identification of de-identified data (s.171), and obstruction (s.179). Specific exemptions for journalism, art, literature, research, statistics, archiving (Schedule 2). The Information Commissioner is the regulator.

In practice, you rarely rely on the DPA 2018 alone — you rely on it together with the UK GDPR, because the Act is what makes the Regulation work in a UK context. Its most practical content for individuals is in the schedules: the conditions that allow special category data such as health, ethnicity or sexual orientation to be processed at all, and the exemptions that let an organisation withhold information it would otherwise have to disclose.

Worked example: Nadine makes a subject access request to a company that is investigating an allegation against her. It discloses most of the file but withholds two documents, citing the exemption for information processed for the prevention or detection of crime and the legal professional privilege exemption. Those are recognised exemptions in Schedule 2, but they must be applied to specific documents and justified, not asserted over the whole file. Nadine asks the company to confirm which exemption applies to which document and why disclosure would prejudice the stated purpose. When the answer is generic, she complains to the ICO, which can require a proper item-by-item review.

The misconceptions matter. The DPA 2018 did not replace the UK GDPR and the two are read together, so citing only one usually misses the point. Section 170 makes it a criminal offence to obtain or disclose personal data without the controller's consent — which is why an employee who looks up a neighbour's records out of curiosity can be prosecuted, not merely disciplined. Law enforcement processing under Part 3 has its own rules and different rights, so a request to a police force is not identical to one made to a shop. And the exemptions are permissive, not mandatory: an organisation can choose to disclose anyway.

The Act sits alongside the UK GDPR, is enforced by the Information Commissioner's Office, and shapes what you receive from a subject access request. Read our guides to your data protection rights and what to do after a data breach.

Official guidance Back to glossary