Guide · Data & Privacy

UK GDPR & DPA 2018

How the UK GDPR and Data Protection Act 2018 fit together and why the correct legal regime matters.

UK data-protection law is a framework of principles, lawful bases, individual rights and accountability duties - not just a rule about consent.

The UK GDPR and Data Protection Act 2018 remain the core data-protection framework. The Data (Use and Access) Act 2025 amended parts of that framework but did not replace it. All DUAA provisions affecting data protection were in force by 19 June 2026.

For consumers, the framework matters because it controls how organisations collect, use, share, retain, secure and correct personal data, and it gives enforceable rights such as access, rectification, erasure in qualifying cases, restriction and objection.

Key points

  • An organisation needs a lawful basis for processing, but consent is only one possible basis.
  • The data-protection principles include lawfulness/fairness/transparency, purpose limitation, data minimisation, accuracy, storage limitation and security.
  • Special-category data has additional protections.
  • Individual rights operate alongside exemptions and restrictions in the DPA 2018 and other law.
  • The DUAA changed some procedures, including SAR searches, time-limit rules, automated decision-making and organisational complaint handling.

The principles are the foundation

The principles are not abstract slogans. They help test real disputes. If a company keeps an incorrect date of birth and then uses it to classify a customer incorrectly, the accuracy principle is directly relevant. If it keeps data for longer than necessary, storage limitation may be relevant. If it uses data for a purpose the person would not reasonably expect, fairness, transparency and purpose limitation can matter.

Lawful basis does not mean “they can do anything”

An organisation can sometimes process personal data without consent - for example where processing is necessary for a contract, legal obligation or legitimate interests. But it still has to comply with the other principles and any conditions applying to the particular data. A lawful basis does not excuse inaccurate, excessive or insecure processing.

The DPA 2018 supplies UK-specific rules and exemptions

The Data Protection Act 2018 supplements the UK GDPR and contains separate regimes for law-enforcement and intelligence processing. It also contains exemptions that can limit particular rights in defined circumstances. An organisation should identify the actual exemption and apply it to the relevant information rather than using “data protection” as a vague reason to withhold everything.

What the DUAA changed

The Data (Use and Access) Act 2025 clarified that SAR searches need only be reasonable and proportionate, introduced “stop the clock” rules for reasonably required clarification, changed automated-decision rules, and from 19 June 2026 requires organisations to operate a data-protection complaints process for qualifying complaints. Always check current ICO guidance because the regulator has been updating individual-rights material as these provisions came into force.

In practice

  • Identify the specific data, processing activity and right/principle at issue.
  • Do not frame every data dispute as “GDPR breach”; explain the concrete failure.
  • Use SARs to obtain personal data, not as a substitute for every other disclosure process.
  • Where accuracy is disputed, distinguish incorrect fact from a genuinely held opinion or allegation.

Evidence worth keeping

Privacy notice or explanation of processing
The personal data or processing activity in issue
Relevant request or objection
Organisation response
Records showing what happened and when
Any decision or impact linked to the processing