Data Protection Act 2018
The Data Protection Act 2018 is a UK Act of Parliament that governs how organisations and government bodies collect, store, and handle personal information about individuals. It works alongside broader data protection rules to help ensure personal data is used lawfully and responsibly. Note that a separate Data Protection Act 2018 also exists in Ireland; the two are distinct national laws and should not be confused.
The Data Protection Act 2018 is an Act of the UK Parliament (c. 12) making provision for the regulation of the processing of information relating to individuals and for connected matters concerning the supervisory authority. In the UK context, the DPA 2018 sits alongside and implements aspects of the EU General Data Protection Regulation, giving effect to it in domestic law and exercising available member state derogations; following EU exit, it operates in conjunction with the UK GDPR. Practitioners should treat the DPA 2018 and the UK GDPR as a combined framework rather than substitutes, and should verify specific provisions and cross-references against the current official consolidated text, as amendments and retained-EU-law reforms can alter the position. A separate Data Protection Act 2018 enacted in the Republic of Ireland is a distinct instrument and outside the scope of this entry.
Why it matters
The Data Protection Act 2018 is a central pillar of the UK's data protection framework. It governs how organisations and government bodies collect, store, and handle personal information about individuals, and it operates in conjunction with the UK GDPR rather than as a standalone replacement for it. For any organisation processing personal data in a UK context, understanding the DPA 2018 is generally essential, because compliance obligations, individual rights, and the powers of the supervisory authority are shaped by how the Act and the UK GDPR interact as a combined framework.
The Act matters in practice because it exercises available member state derogations and makes domestic provision that fills in areas the UK GDPR leaves to national law, along with provisions connected to the supervisory authority. This means practitioners cannot rely on the UK GDPR alone to determine the full domestic position; specific provisions may be found in the DPA 2018. Because retained-EU-law reforms and amendments can alter the position over time, readers should verify specific provisions and cross-references against the current official consolidated text rather than treating any single description as permanent.
A common source of confusion worth highlighting is that a separate Data Protection Act 2018 was enacted in the Republic of Ireland. These are distinct national instruments, and conflating them can lead to material errors in a compliance analysis. Care should be taken to identify which jurisdiction's Act applies to a given processing activity.
Who it's relevant to
Inside DPA 2018
Common questions
Answers to the questions practitioners most commonly ask about DPA 2018.