Data Protection Act 2018

United KingdomPrivacy2018
ByDecipherU Editorial

The Data Protection Act 2018 supplements the UK GDPR and provides the full cybersecurity and data protection legal framework for the UK. It covers processing not within EU GDPR scope, including law enforcement processing (Part 3) and intelligence services processing (Part 4). It also sets out exemptions, the ICO's powers, and criminal offenses related to personal data.

Quick Reference

EnactedMay 23, 2018
Enforcement BodyInformation Commissioner's Office (ICO)
PenaltiesAligned with UK GDPR (up to 17.5 million GBP or 4% of turnover); criminal offenses for knowingly or recklessly obtaining personal data
Applicable ToSame as UK GDPR plus law enforcement bodies and intelligence services

Key Requirements

Part 3, Section 66 (Law Enforcement Processing: Security)

Law enforcement controllers must implement appropriate security measures for automated processing, including encryption and pseudonymization where appropriate

Section 170

Criminal offense to knowingly or recklessly obtain, disclose, or procure personal data without the consent of the controller

Part 2, Chapter 2 (Exemptions)

Sets out specific exemptions from data subject rights including national security, crime and taxation, and journalism

How Does UK DPA 2018 Affect Cybersecurity Careers?

Cybersecurity professionals in UK law enforcement and intelligence agencies operate under Part 3 and Part 4, which have different rules than standard UK GDPR. Security professionals handling employee data or conducting internal investigations must understand the criminal offense provisions. GRC analysts must map DPA 2018 exemptions when determining what data subject rights apply.

Cybersecurity Roles That Work With UK DPA 2018

Related Cybersecurity Certifications

Related Cybersecurity Laws

Read the full text of UK DPA 2018 at the official source: https://www.legislation.gov.uk/ukpga/2018/12/contents

Frequently Asked Questions

The Data Protection Act 2018 supplements the UK GDPR and provides the full cybersecurity and data protection legal framework for the UK. It covers processing not within EU GDPR scope, including law enforcement processing (Part 3) and intelligence services processing (Part 4). It also sets out exemptions, the ICO's powers, and criminal offenses related to personal data.

Cybersecurity professionals in UK law enforcement and intelligence agencies operate under Part 3 and Part 4, which have different rules than standard UK GDPR. Security professionals handling employee data or conducting internal investigations must understand the criminal offense provisions. GRC analysts must map DPA 2018 exemptions when determining what data subject rights apply.

Aligned with UK GDPR (up to 17.5 million GBP or 4% of turnover); criminal offenses for knowingly or recklessly obtaining personal data

Last verified: April 2026?Report an inaccuracy

Explore Related Cybersecurity Resources

Was this page helpful?