Every day, your business collects data. Names. Email addresses. Phone numbers. Maybe even health information or bank details. All of this needs to be looked after properly.
That’s where the Data Protection Act 2018 comes in.
In this guide, we’ll explain what the Act is, why it matters, and what’s changed recently. We’ll also walk you through the key principles, your customers’ rights, and what happens if things go wrong. By the end, you’ll know exactly where your business stands.
Table of Contents
What Is the Data Protection Act 2018?
The Data Protection Act 2018 (DPA 2018) is the UK’s main law on how personal data must be collected, stored, and used. It exists to protect people’s privacy and to hold organisations accountable for the data they hold.
The Act works alongside the UK GDPR (General Data Protection Regulation). Think of UK GDPR as the main rulebook, and the DPA 2018 as the UK-specific add-on that fills in the gaps.
The DPA 2018 replaced an older version, the Data Protection Act 1998, which had become out of date. Back in 1998, nobody could have predicted smartphones, social media, or cloud storage. The law needed a serious update, and that’s exactly what happened in 2018.
Here’s a quick timeline to make sense of it all:
- 1998 – The original Data Protection Act becomes law.
- 2016 – The EU introduces the General Data Protection Regulation (GDPR).
- 2018 – The UK brings in the Data Protection Act 2018 to reflect GDPR.
- 2021 – After Brexit, the UK creates its own version, known as “UK GDPR.”
- 2025–2026 – The Data (Use and Access) Act 2025 updates parts of the law (more on this below).
Why Was the Data Protection Act 2018 Introduced?
The Data Protection Act 2018 was introduced to close the gaps left by the outdated 1998 Act and to bring UK law in line with the EU’s GDPR.
Before 2018, data protection rules were much looser. Companies could hold onto your information for as long as they liked. Sometimes it was sold on to third parties without you ever knowing. There wasn’t much you could do about it either.
The new Act changed all of that. It gave people real, enforceable rights over their own data. It also gave the regulator, the Information Commissioner’s Office (ICO), stronger powers to act when organisations get it wrong.
Who Does the Data Protection Act 2018 Apply To?
The short answer: almost every organisation in the UK, no matter how big or small. If you collect, store, or use anyone’s personal data, this law applies to you.
That includes:
- Sole traders and small businesses
- Large companies and corporations
- Charities and non-profits
- Public sector bodies like schools, councils, and the NHS
- Overseas companies that handle the data of people living in the UK
There’s a common myth that small businesses are exempt. They’re not. If you keep a spreadsheet of customer emails or store staff records in an HR system, you need to follow the rules.
Do you need to register with the ICO?
Most organisations that process personal data need to register with the ICO and pay an annual data protection fee. The fee depends on your size:
- Micro-organisations: £40 to £45
- Small and medium organisations: £60
- Large organisations: £60 or more, based on turnover
You can check whether you’re exempt using the ICO’s self-assessment tool on their website.
Do you need a Data Protection Officer (DPO)?
Most small businesses don’t need to formally appoint a DPO. It’s only a legal requirement if you’re a public authority, or if your core activities involve large-scale monitoring of people, or large-scale processing of sensitive data (like health records).
That said, even if it’s not compulsory, it’s a good idea to have one person in your team who’s responsible for data protection. Somebody needs to own it.
The Four Key Areas of the Data Protection Act 2018
The Data Protection Act 2018 is split into four main parts, each covering a different type of data processing.
- General data processing. This is the part that applies to most businesses. It brings UK law in line with GDPR standards and sets the age of consent for online services at 13 years old.
- Law enforcement processing. This covers how police forces and other criminal justice agencies use personal data, including safeguards for sharing information internationally.
- Intelligence services processing. This governs how UK intelligence agencies handle personal data, in line with international standards.
- Regulation and enforcement. This section gives the ICO its powers, including the ability to issue fines and bring criminal prosecutions.
The 7 Principles of the Data Protection Act 2018
Every organisation that handles personal data has to follow these principles. Get these right, and most of your compliance is sorted.
- Lawfulness, fairness, and transparency. You need a legal reason to process someone’s data, and you need to be upfront about how you’re using it. No hidden agendas.
- Purpose limitation. You can only collect data for a specific, clearly stated reason. You can’t then use it for something completely different later on.
- Data minimisation. Only collect what you actually need. If you’re running a newsletter sign-up, you probably don’t need someone’s date of birth.
- Accuracy. Keep the data correct and up to date. Wrong information about the wrong person can cause real harm.
- Storage limitation. Don’t keep data longer than you need it. Once its purpose is served, it should be deleted or anonymised.
- Integrity and confidentiality. Keep the data secure. That means proper passwords, encryption, and access controls, depending on how sensitive the data is.
- Accountability. You need to be able to prove you’re following all the rules above. This means keeping records, running training, and having policies in place.
That last one, accountability, is easy to overlook. But it’s the principle the ICO checks first when something goes wrong. If you can’t show your working, it looks like you never did the work.
Your Rights Under the Data Protection Act 2018
If you’re an individual (the law calls you a “data subject”), you have eight specific rights over your own data.
- The right to be informed. Organisations must tell you clearly how they’re using your data.
- The right of access. You can ask for a copy of the data a company holds on you. This is called a Subject Access Request.
- The right to rectification. You can ask for incorrect or incomplete data to be corrected.
- The right to erasure. Also known as “the right to be forgotten.” You can ask for your data to be deleted in certain situations.
- The right to restrict processing. You can ask a company to pause using your data while a dispute is sorted out.
- The right to data portability. You can ask for your data in a format you can transfer to another provider.
- The right to object. You can object to your data being used, for example for direct marketing.
- Rights around automated decision-making. You have the right not to be subject to a decision based solely on automated processing, including profiling, if it has a significant effect on you.
The 6 Lawful Bases for Processing Personal Data
Before you can process anyone’s personal data, you need a valid legal reason. UK GDPR sets out six lawful bases:
- Consent – The person has clearly agreed to it.
- Contract – It’s necessary to fulfil a contract with them.
- Legal obligation – You’re required to process it by law.
- Vital interests – It’s necessary to protect someone’s life.
- Public task – It’s needed to perform a task in the public interest.
- Legitimate interests – It’s necessary for your genuine business interests, as long as it doesn’t override the person’s rights.
Most businesses rely on either consent or legitimate interests day to day. If you’re not sure which one applies, it’s worth documenting your reasoning, because the ICO will ask for it if there’s ever an investigation
What Happens If You Breach the Data Protection Act 2018?
If your organisation breaches the Data Protection Act 2018, you could face a fine, a formal reprimand, or even criminal prosecution, depending on how serious the breach is.
There are two tiers of fines:
- The standard maximum: £8.7 million, or 2% of your global annual turnover, whichever is higher.
- The higher maximum: £17.5 million, or 4% of your global annual turnover, whichever is higher.
In practice, most fines are nowhere near these maximums. The ICO looks at things like how serious the breach was, whether it was deliberate, and whether you cooperated with their investigation.
What counts as a data breach?
The most common cause is simple human error. Think of an email sent to the wrong recipient, an unencrypted laptop left on a train, or a spreadsheet of customer details accidentally shared publicly. Cyberattacks and unauthorised access also count.
The 72-hour rule.
If a breach is likely to put someone at risk, you must report it to the ICO within 72 hours of finding out. If the risk is high, you may also need to tell the affected individuals directly.
Criminal offences.
Some actions under the Act are criminal offences, not just fines. This includes knowingly obtaining someone’s personal data without permission, or re-identifying data that had been anonymised. These carry the possibility of an unlimited fine and, in serious cases, prosecution.
It's not always about fines.
The ICO has other tools too. They can issue a formal reprimand, an enforcement notice, or a “stop now” order requiring you to halt a particular activity until you fix the problem.
What's Changing Under the Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025, known as the DUAA, is the biggest update to UK data law since 2018. It doesn’t replace the Data Protection Act 2018 or UK GDPR, but it makes some significant changes to both.
The DUAA received Royal Assent on 19th June 2025, and its changes are being rolled out in stages, with most provisions in force by June 2026.
Here’s what’s actually changing:
- A new regulator name. The Information Commissioner’s Office is being restructured into the Information Commission, made up of a board rather than a single commissioner. Its powers stay largely the same, but the way it’s run is changing.
- A simpler lawful basis for some activities. The DUAA introduces “recognised legitimate interests.” This gives businesses a shortcut for certain types of processing, like preventing crime or safeguarding, without needing to carry out the usual balancing test.
- Easier rules for some cookies. Certain low-risk cookies, like those used for basic website analytics, may no longer need explicit consent. This should make cookie banners a little less annoying for everyone.
- Clearer rules for research and AI. The DUAA makes it easier to use personal data for scientific research, including commercial research, and clarifies how “broad consent” can work for ongoing studies.
- A new complaints process. Individuals now have a clearer route to complain directly to an organisation before going to the regulator, which should speed up how disputes are resolved.
- What this means for your business right now: review your privacy notices, your cookie policy, and your lawful basis documentation against these changes. Even though the rules are described as a “light-touch” update, ignoring them could leave your paperwork out of date.
How to Make Sure Your Organisation Is Compliant
Compliance doesn’t have to be complicated. Here’s a practical checklist to work through:
- Map your data. Know what personal data you hold, where it’s stored, and why you have it.
- Write a clear privacy notice. Explain simply how you collect and use data, and make it easy to find on your website.
- Confirm your lawful basis. For every type of data processing you do, write down which of the six lawful bases applies.
- Set retention periods. Decide how long you’ll keep each type of data, and actually delete it once that time is up.
- Secure your systems. Use strong passwords, encryption, and limit who can access sensitive data.
- Have a breach response plan. Know exactly what to do and who to contact if something goes wrong, so you’re not scrambling within the 72-hour window.
- Train your team. Most breaches come down to human error, so regular training makes a real difference.
- Review the DUAA changes. Check your current policies against the new rules as they come into force.
If your team needs a refresher, our GDPR and Data Protection training course walks through all of this in more detail, with practical examples for everyday situations.
Data Protection Act 2018 vs UK GDPR vs EU GDPR
These three terms get mixed up a lot, so here’s a simple breakdown.
| Data Protection Act 2018 | UK GDPR | EU GDPR | |
|---|---|---|---|
| What it is | UK law that supplements UK GDPR | The UK's version of GDPR, post-Brexit | The EU's data protection law |
| Applies to | UK organisations and data | Data of people in the UK | Data of people in the EU/EEA |
| Enforced by | ICO (becoming the Information Commission) | ICO | Individual EU data protection authorities |
| Maximum fine | £17.5m or 4% of turnover | £17.5m or 4% of turnover | €20m or 4% of turnover |
If your business only deals with UK customers, UK GDPR and the DPA 2018 are what matter. If you also handle data from customers in the EU, you’ll need to comply with both regimes.
Summary
The Data Protection Act 2018 is the backbone of how personal data is handled in the UK. It sets out clear principles, gives individuals real rights, and holds organisations accountable when things go wrong.
To recap the essentials:
- It applies to every organisation, regardless of size.
- Follow the seven principles and you’re most of the way to compliance.
- Know your lawful basis before you process any personal data.
- The Data (Use and Access) Act 2025 is changing parts of the law right now, so it’s worth reviewing your policies.
Getting this right protects your customers, and it protects your business from fines and reputational damage. If you’d like your team to build real confidence around data protection, our Essentials of Data Protection (GDPR) training course is a practical place to start.
Sources: Information Commissioner’s Office (ico.org.uk), legislation.gov.uk, and official guidance on the Data (Use and Access) Act 2025.
This article is for general information and does not constitute legal advice. If you need guidance specific to your organisation, consult a qualified data protection professional or solicitor.
Frequently Asked Questions (FAQ)
What is the Data Protection Act 2018 in simple terms?
The Data Protection Act 2018 is the UK law that controls how organisations collect, store, and use personal data. It gives people rights over their own information and requires businesses to handle data fairly, securely, and only for clear, legitimate reasons.
What is the difference between the Data Protection Act 2018 and GDPR?
UK GDPR is the main rulebook for data protection in the UK, while the Data Protection Act 2018 supplements it with UK-specific details, such as law enforcement processing and criminal offences. In short, they work together rather than replacing each other. The EU’s own GDPR is a separate law that applies to EU and EEA countries.
Does the Data Protection Act 2018 apply to small businesses?
Yes, it applies to businesses of all sizes, including sole traders. If you collect personal data such as customer names, emails, or employee records, the law applies to you regardless of your turnover or number of staff.
What are the 7 principles of the Data Protection Act 2018?
The seven principles are: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Together, they set the standard for how personal data must be handled.
What is an example of a breach of the Data Protection Act?
A common example is human error, such as sending an email containing personal data to the wrong recipient. Other examples include losing an unencrypted device, unauthorised access to records, and cyberattacks that expose customer data.
What is the maximum fine under the Data Protection Act 2018?
The maximum fine is £17.5 million or 4% of a company’s global annual turnover, whichever is higher, for the most serious breaches. Less severe infringements carry a lower maximum of £8.7 million or 2% of turnover.
Do I need to register with the ICO?
Most organisations that process personal data must register with the ICO and pay an annual data protection fee, which ranges from around £40 to £60 or more depending on your size. You can use the ICO’s online self-assessment tool to check if you’re exempt.
What is the Data (Use and Access) Act 2025 and how does it change the DPA 2018?
The Data (Use and Access) Act 2025 is a new law that updates parts of the Data Protection Act 2018 and UK GDPR without replacing them. Key changes include a new “recognised legitimate interests” lawful basis, simpler cookie consent rules, and the Information Commissioner’s Office being restructured into the Information Commission.
What rights do I have under the Data Protection Act 2018?
You have eight key rights, including the right to access your data, the right to have incorrect data corrected, the right to have your data erased, and the right to object to how your data is used. You also have rights around automated decision-making and profiling.
Who enforces the Data Protection Act 2018 in the UK?
The Information Commissioner’s Office (ICO) enforces the Data Protection Act 2018 and UK GDPR. Under the Data (Use and Access) Act 2025, the ICO is being restructured into a new body called the Information Commission.
Robert Lawrence
Author | Specialise in E-Learning.
Robert Lawrence is an author at Training Express, with over 5 years of experience creating practical resources and strategies to support learners and enhance their professional & personal development.
Food Hygiene
Health & Safety
Safeguarding
First Aid
Business Skills
Personal Development


