Data Protection Act 2018
(DPA 2018)
The UK statute supplementing the UK GDPR with domestic provisions, exemptions, and enforcement mechanisms. Implements the EU Law Enforcement Directive for criminal justice processing, and the Intelligence Services Directive. Section 170 makes unauthorised obtaining of personal data a criminal offence.
The DPA 2018 implements detailed UK rules alongside the UK GDPR: Part 2 (the GDPR's domestic implementation), Part 3 (Law Enforcement processing under Directive 2016/680), Part 4 (Intelligence Services). The criminal offences include: unlawful obtaining, disclosure, or procurement (s.170 — maximum unlimited fine), re-identification of de-identified data (s.171), and obstruction (s.179). Specific exemptions for journalism, art, literature, research, statistics, archiving (Schedule 2). The Information Commissioner is the regulator.
In practice, you rarely rely on the DPA 2018 alone — you rely on it together with the UK GDPR, because the Act is what makes the Regulation work in a UK context. Its most practical content for individuals is in the schedules: the conditions that allow special category data such as health, ethnicity or sexual orientation to be processed at all, and the exemptions that let an organisation withhold information it would otherwise have to disclose.
Worked example: Nadine makes a subject access request to a company that is investigating an allegation against her. It discloses most of the file but withholds two documents, citing the exemption for information processed for the prevention or detection of crime and the legal professional privilege exemption. Those are recognised exemptions in Schedule 2, but they must be applied to specific documents and justified, not asserted over the whole file. Nadine asks the company to confirm which exemption applies to which document and why disclosure would prejudice the stated purpose. When the answer is generic, she complains to the ICO, which can require a proper item-by-item review.
The misconceptions matter. The DPA 2018 did not replace the UK GDPR and the two are read together, so citing only one usually misses the point. Section 170 makes it a criminal offence to obtain or disclose personal data without the controller's consent — which is why an employee who looks up a neighbour's records out of curiosity can be prosecuted, not merely disciplined. Law enforcement processing under Part 3 has its own rules and different rights, so a request to a police force is not identical to one made to a shop. And the exemptions are permissive, not mandatory: an organisation can choose to disclose anyway.
The Act sits alongside the UK GDPR, is enforced by the Information Commissioner's Office, and shapes what you receive from a subject access request. Read our guides to your data protection rights and what to do after a data breach.
Related guides
UK GDPR Rights for Individuals
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018) give individuals in the UK eight legally enforceable rights over how organisations collect, store, and use their personal data. These rights apply whether the data is held by a business, public body, or online platform.
6 min
When a Company Has a Data Breach: Notification and Next Steps
A personal data breach occurs when an organisation accidentally or unlawfully destroys, loses, alters, discloses, or gives access to your personal data without authorisation. This guide covers the organisation's duty to tell you and to tell the regulator, and what you should do in the days afterwards to limit the damage. If you have already decided you want to complain to the ICO or claim compensation, go straight to <a href="/complaints-ombudsmen/data-breach-complaints">data breach compensation and ICO complaints</a>.
6 min
Complaining to the Information Commissioner about a Data Breach
The Information Commissioner's Office (ICO) regulates data protection in the UK. They handle complaints about misuse of personal data, failure to respond to Subject Access Requests, marketing breaches under PECR, and breaches of UK GDPR. Many complaints are resolved with a written reminder to the organisation; serious breaches lead to fines up to £17.5 million. This guide explains how to use the ICO and how to claim separately for compensation.
10 min